All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
No active process named net.net was found!
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\jedugikuf deleted successfully.
C:\WINDOWS\system32\hazafupe.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\net deleted successfully.
C:\WINDOWS\system32\net.net moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\windows\system32\libukifu.dll c:\windows\system32\hazafupe.dll deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:moyomego.dll deleted successfully.
C:\WINDOWS\system32\moyomego.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\kaludafap deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{141a9890-8ffc-4f80-92b7-7b9b6d992846}\ deleted successfully.
File C:\WINDOWS\system32\hazafupe.dll not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\wukatuhow deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b8dd6e4d-809f-412f-a2a2-cc3789aa7f12}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\\{141a9890-8ffc-4f80-92b7-7b9b6d992846} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{141a9890-8ffc-4f80-92b7-7b9b6d992846}\ deleted successfully.
File C:\WINDOWS\system32\hazafupe.dll not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\\{b8dd6e4d-809f-412f-a2a2-cc3789aa7f12} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b8dd6e4d-809f-412f-a2a2-cc3789aa7f12}\ not found.
C:\WINDOWS\System32\dllcache\SET92.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SET93.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SET94.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SET95.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SET96.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SET97.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SET98.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SET99.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SET9A.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SET9B.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SET9C.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SET9D.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SET9E.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SET9F.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETA0.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETA1.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETA2.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETA3.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETA4.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETA5.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETA6.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETA7.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETA8.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETA9.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETAA.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETAB.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETAC.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETAD.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETAE.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETAF.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETB0.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETB1.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETB2.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETB3.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETB4.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETB5.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETB6.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETB7.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETB8.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETB9.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETBA.tmp deleted successfully.
C:\WINDOWS\System32\dllcache\SETBB.tmp deleted successfully.
C:\WINDOWS\000001_.tmp deleted successfully.
C:\WINDOWS\003242_.tmp deleted successfully.
C:\WINDOWS\3FA195A010BE43159B7C1486845BD002.TMP\WiseCustomCall.dll deleted successfully.
C:\WINDOWS\3FA195A010BE43159B7C1486845BD002.TMP\WiseCustomCalla.dll deleted successfully.
C:\WINDOWS\3FA195A010BE43159B7C1486845BD002.TMP\WiseCustomCalla2.exe deleted successfully.
C:\WINDOWS\3FA195A010BE43159B7C1486845BD002.TMP\WiseData.ini deleted successfully.
C:\WINDOWS\3FA195A010BE43159B7C1486845BD002.TMP folder deleted successfully.
File C:\WINDOWS\System32\hazafupe.dll not found.
File C:\WINDOWS\System32\zahatahe.dll not found.
C:\WINDOWS\system32\vamegeye.dll moved successfully.
File C:\WINDOWS\System32\moyomego.dll not found.
C:\WINDOWS\system32\gahipewo.dll moved successfully.
C:\WINDOWS\system32\fanenoto.dll moved successfully.
C:\WINDOWS\system32\jimiwemo.dll moved successfully.
C:\WINDOWS\system32\bimedufo.dll moved successfully.
C:\WINDOWS\system32\dikabagu moved successfully.
File C:\WINDOWS\tasks\dcsmkojo.job not found.
File C:\WINDOWS\System32\net.net not found.
C:\WINDOWS\System32\bohumoye.dll.tmp deleted successfully.
C:\WINDOWS\System32\CONFIG.TMP deleted successfully.
C:\WINDOWS\System32\jemaluja.dll.tmp deleted successfully.
C:\WINDOWS\System32\samazaho.dll.tmp deleted successfully.
C:\WINDOWS\System32\SET100.tmp deleted successfully.
C:\WINDOWS\System32\SET101.tmp deleted successfully.
C:\WINDOWS\System32\SET102.tmp deleted successfully.
C:\WINDOWS\System32\SET103.tmp deleted successfully.
C:\WINDOWS\System32\SET105.tmp deleted successfully.
C:\WINDOWS\System32\SET4F.tmp deleted successfully.
C:\WINDOWS\System32\SET50.tmp deleted successfully.
C:\WINDOWS\System32\SETA0.tmp deleted successfully.
C:\WINDOWS\System32\SETA5.tmp deleted successfully.
C:\WINDOWS\System32\SETAC.tmp deleted successfully.
C:\WINDOWS\System32\SETD1.tmp deleted successfully.
C:\WINDOWS\System32\SETD2.tmp deleted successfully.
C:\WINDOWS\System32\SETD4.tmp deleted successfully.
C:\WINDOWS\System32\SETD5.tmp deleted successfully.
C:\WINDOWS\System32\SETD6.tmp deleted successfully.
C:\WINDOWS\System32\SETD7.tmp deleted successfully.
C:\WINDOWS\System32\SETD8.tmp deleted successfully.
C:\WINDOWS\System32\SETDA.tmp deleted successfully.
C:\WINDOWS\System32\SETDC.tmp deleted successfully.
C:\WINDOWS\System32\SETDD.tmp deleted successfully.
C:\WINDOWS\System32\SETDE.tmp deleted successfully.
C:\WINDOWS\System32\SETE1.tmp deleted successfully.
C:\WINDOWS\System32\SETE2.tmp deleted successfully.
C:\WINDOWS\System32\SETE5.tmp deleted successfully.
C:\WINDOWS\System32\SETE6.tmp deleted successfully.
C:\WINDOWS\System32\SETE8.tmp deleted successfully.
C:\WINDOWS\System32\SETEA.tmp deleted successfully.
C:\WINDOWS\System32\SETEB.tmp deleted successfully.
C:\WINDOWS\System32\SETEC.tmp deleted successfully.
C:\WINDOWS\System32\SETED.tmp deleted successfully.
C:\WINDOWS\System32\SETEE.tmp deleted successfully.
C:\WINDOWS\System32\SETEF.tmp deleted successfully.
C:\WINDOWS\System32\SETF0.tmp deleted successfully.
C:\WINDOWS\System32\SETF1.tmp deleted successfully.
C:\WINDOWS\System32\SETF3.tmp deleted successfully.
C:\WINDOWS\System32\SETF4.tmp deleted successfully.
C:\WINDOWS\System32\SETF5.tmp deleted successfully.
C:\WINDOWS\System32\SETF6.tmp deleted successfully.
C:\WINDOWS\System32\SETF7.tmp deleted successfully.
C:\WINDOWS\System32\SETF8.tmp deleted successfully.
C:\WINDOWS\System32\SETF9.tmp deleted successfully.
C:\WINDOWS\System32\SETFA.tmp deleted successfully.
C:\WINDOWS\System32\SETFB.tmp deleted successfully.
C:\WINDOWS\System32\SETFC.tmp deleted successfully.
C:\WINDOWS\System32\SETFD.tmp deleted successfully.
C:\WINDOWS\System32\SETFE.tmp deleted successfully.
C:\WINDOWS\tasks\SpywareStop Scheduled Scan.job moved successfully.
========== COMMANDS ==========
Restore point Set: OTL Restore Point (64424509440)
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 241441 bytes
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: HP_Administrator
->Temp folder emptied: 23073443 bytes
->Temporary Internet Files folder emptied: 14734689 bytes
->Java cache emptied: 689346625 bytes
->FireFox cache emptied: 92731760 bytes
User: LocalService
->Temp folder emptied: 66051 bytes
->Temporary Internet Files folder emptied: 163974 bytes
User: MCX1
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: MCX2
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: MCX3
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: NetworkService
->Temp folder emptied: 2621136 bytes
->Temporary Internet Files folder emptied: 98510955 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1341289 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 23970461 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 357319096 bytes
Total Files Cleaned = 1,244.00 mb
OTL by OldTimer - Version 3.1.28.0 log created on 02102010_122739
Files\Folders moved on Reboot…
File\Folder C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Temporary Internet Files\Content.IE5\DXUPOV2Y\p;vpec=sp;atf=1;atf=s;pfl=1;dt=s;!c=hagl;!c=hagn;afid=356682832;dsid=699259;cp3=ret;cp3=cmt;;tt=j;u=b0031iew2oo13p3flw
q,f0f12sa,g10005c;sz=728x90;tile=1;ord=5948120701051589;[1] not found!
File\Folder C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Temporary Internet Files\Content.IE5\DXUPOV2Y\p;vpec=sp;atf=1;atf=s;pfl=1;dt=s;!c=hagl;!c=hagn;afid=356682832;dsid=699259;cp3=ret;cp3=cmt;;tt=j;u=b0032iew2oo13p3flw
q,f0f12sa,g10005c;sz=728x90;tile=2;ord=5948120701051589;[1] not found!
File\Folder C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Temporary Internet Files\Content.IE5\8TR2XC8I\ec=tgt;ec=tls;ec=tmu;ec=ttec;ia=pc;p=1;pec=be;to=kyb;vec=sp;vpec=sp;atf=1;a
tf=s;pfl=1;dt=s;!c=hagl;!c=hagn;;afid=356682832;dsid=699259;;sz=888x11;ord=5948120701051589;_g_cv=1[1
] not found!
C:\Documents and Settings\HP_Administrator\Local Settings\Temp\4.tmp moved successfully.
File\Folder C:\WINDOWS\temp\ZLT04c7d.TMP not found!
Registry entries deleted on Reboot…
OTL logfile created on: 2/11/2010 10:15:32 PM - Run
OTLPE by OldTimer - Version 3.1.28.0 Folder = X:\Programs\OTLPE
Microsoft Windows XP Service Pack 3 (Version = 5.1.2600) - Type = SYSTEM
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
958.00 Mb Total Physical Memory | 645.00 Mb Available Physical Memory | 67.00% Memory free
858.00 Mb Paging File | 672.00 Mb Available in Paging File | 78.00% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 177.79 Gb Total Space | 79.94 Gb Free Space | 44.96% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
Drive H: | 8.50 Gb Total Space | 1.12 Gb Free Space | 13.13% Space Free | Partition Type: FAT32
I: Drive not present or media not loaded
Drive X: | 429.26 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: REATOGO
Current User Name: SYSTEM
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
Using ControlSet: ControlSet001
========== Win32 Services (SafeList) ==========
SRV - [2010/02/03 21:06:40 | 000,135,664 | —- | M] (Google Inc.) [Auto] – C:\Program Files\Google\Update\GoogleUpdate.exe – (gupdate) Google Update Service (gupdate)
SRV - [2009/11/12 16:33:00 | 000,545,568 | —- | M] (Apple Inc.) [On_Demand] – C:\Program Files\iPod\bin\iPodService.exe – (iPod Service)
SRV - [2009/08/28 08:13:46 | 000,908,056 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto] – C:\Program Files\AVG\AVG8\avgemc.exe – (avg8emc)
SRV - [2009/08/28 08:13:38 | 000,297,752 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto] – C:\Program Files\AVG\AVG8\avgwdsvc.exe – (avg8wd)
SRV - [2009/07/09 11:22:18 | 000,144,712 | —- | M] (Apple Inc.) [Auto] – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe – (Apple Mobile Device)
SRV - [2009/05/07 15:50:24 | 001,089,536 | —- | M] () [Auto] – C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe – (LeapFrog Connect Device Service)
SRV - [2009/03/29 09:33:48 | 000,183,280 | —- | M] (Google) [Auto] – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe – (gusvc)
SRV - [2008/12/12 10:17:38 | 000,238,888 | —- | M] (Apple Inc.) [Auto] – C:\Program Files\Bonjour\mDNSResponder.exe – (Bonjour Service)
SRV - [2008/10/09 14:25:32 | 002,405,776 | —- | M] (Check Point Software Technologies LTD) [Auto] – C:\WINDOWS\System32\ZoneLabs\vsmon.exe – (vsmon)
SRV - [2008/09/10 22:37:36 | 000,024,576 | —- | M] (Intuit) [Auto] – C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe – (QBCFMonitorService)
SRV - [2008/08/08 21:10:46 | 000,061,440 | —- | M] (Intuit Inc.) [On_Demand] – C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe – (QBFCService)
SRV - [2007/01/04 16:38:08 | 000,024,652 | —- | M] (Viewpoint Corporation) [Auto] – C:\Program Files\Viewpoint\Common\ViewpointService.exe – (Viewpoint Manager Service)
SRV - [2006/11/02 19:40:12 | 000,174,656 | —- | M] () [Auto] – C:\WINDOWS\system32\PSIService.exe – (ProtexisLicensing)
SRV - [2006/01/06 21:25:12 | 000,069,632 | —- | M] (Sony Corporation) [Disabled] – C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe – (SSScsiSV)
SRV - [2005/11/24 16:03:22 | 000,053,337 | —- | M] (Sony Corporation) [On_Demand] – C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe – (MSCSPTISRV)
SRV - [2005/11/24 15:57:44 | 000,053,337 | —- | M] (Sony Corporation) [On_Demand] – C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe – (PACSPTISVR)
SRV - [2005/11/24 15:47:30 | 000,069,718 | —- | M] (Sony Corporation) [Disabled] – C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe – (SPTISRV)
SRV - [2005/10/23 08:46:44 | 000,069,632 | —- | M] (Hewlett-Packard Company) [Disabled] – C:\Program Files\Common Files\LightScribe\LSSrvc.exe – (LightScribeService)
SRV - [2005/10/20 19:55:40 | 000,028,160 | —- | M] (Microsoft Corporation) [Disabled] – C:\WINDOWS\ehome\RMSvc.exe – (RMSvc)
SRV - [2005/09/09 02:24:30 | 000,102,400 | —- | M] () [Disabled] – C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe – (AdobeActiveFileMonitor4.0)
SRV - [2005/08/14 00:29:40 | 000,376,832 | —- | M] (ATI Technologies Inc.) [Auto] – C:\WINDOWS\system32\ati2evxx.exe – (Ati HotKey Poller)
SRV - [2005/08/03 02:19:16 | 000,058,880 | —- | M] (Microsoft) [Auto] – C:\WINDOWS\arservice.exe – (ARSVC)
SRV - [2005/04/03 23:41:10 | 000,069,632 | —- | M] (Macrovision Corporation) [On_Demand] – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe – (IDriverT)
SRV - [2004/09/29 11:14:36 | 000,069,632 | —- | M] (HP) [Boot] – C:\WINDOWS\system32\HPZipm12.exe – (Pml Driver HPZ12)
SRV - [2003/07/28 22:28:22 | 000,089,136 | —- | M] (Microsoft Corporation) [On_Demand] – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand] – – (WDICA)
DRV - File not found [Kernel | On_Demand] – – (PDRFRAME)
DRV - File not found [Kernel | On_Demand] – – (PDRELI)
DRV - File not found [Kernel | On_Demand] – – (PDFRAME)
DRV - File not found [Kernel | On_Demand] – – (PDCOMP)
DRV - File not found [Kernel | System] – – (PCIDump)
DRV - File not found [Kernel | System] – – (lbrtfdc)
DRV - File not found [Kernel | System] – – (i2omgmt)
DRV - File not found [Kernel | System] – – (Changer)
DRV - [2009/08/28 08:13:53 | 000,335,240 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System] – C:\WINDOWS\System32\Drivers\avgldx86.sys – (AvgLdx86)
DRV - [2009/08/28 08:13:53 | 000,027,784 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System] – C:\WINDOWS\System32\Drivers\avgmfx86.sys – (AvgMfx86)
DRV - [2009/06/06 09:41:36 | 000,018,560 | —- | M] (LeapFrog) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\FlyUsb.sys – (FlyUsb)
DRV - [2009/05/20 08:51:26 | 000,108,552 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System] – C:\WINDOWS\System32\Drivers\avgtdix.sys – (AvgTdiX)
DRV - [2009/05/18 13:17:00 | 000,026,600 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV - [2008/10/09 14:25:36 | 000,353,680 | —- | M] (Check Point Software Technologies LTD) [Kernel | System] – C:\WINDOWS\system32\vsdatant.sys – (vsdatant)
DRV - [2008/04/21 07:19:58 | 000,051,648 | —- | M] (Check Point Software Technologies LTD) [Kernel | Boot] – C:\WINDOWS\system32\ZoneLabs\srescan.sys – (srescan)
DRV - [2008/04/13 13:45:32 | 000,059,136 | —- | M] (Microsoft Corporation) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\gckernel.sys – (GcKernel)
DRV - [2008/04/13 13:45:12 | 000,060,032 | —- | M] (Microsoft Corporation) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\usbaudio.sys – (usbaudio) USB Audio Driver (WDM)
DRV - [2008/04/13 13:40:30 | 000,096,512 | —- | M] () [Kernel | Boot] – C:\WINDOWS\system32\drivers\atapi.sys – (atapi)
DRV - [2007/11/13 05:25:53 | 000,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\secdrv.sys – (Secdrv)
DRV - [2007/06/05 10:56:40 | 000,044,928 | —- | M] (Panda Software) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\SDTHOOK.SYS – (SDTHOOK)
DRV - [2005/10/26 15:12:48 | 000,020,640 | —- | M] (Sonic Solutions) [Kernel | Boot] – C:\WINDOWS\system32\drivers\pxhelp20.sys – (PxHelp20)
DRV - [2005/08/29 17:11:00 | 003,644,928 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\ALCXWDM.SYS – (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2005/08/14 00:35:54 | 001,313,792 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\ati2mtag.sys – (ati2mtag)
DRV - [2005/07/04 02:30:34 | 000,026,624 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\PS2.sys – (Ps2)
DRV - [2005/06/30 03:03:18 | 000,175,104 | —- | M] (Promise Technology, Inc.) [Kernel | Boot] – C:\WINDOWS\system32\drivers\ftsata2.sys – (ftsata2)
DRV - [2005/06/17 16:33:40 | 000,872,064 | —- | M] (Intel Corporation) [Kernel | Boot] – C:\WINDOWS\system32\drivers\iaStor.sys – (iaStor)
DRV - [2005/03/09 16:53:00 | 000,036,352 | —- | M] (Advanced Micro Devices) [Kernel | System] – C:\WINDOWS\system32\drivers\AmdK8.sys – (AmdK8)
DRV - [2005/03/08 13:52:28 | 000,021,744 | —- | M] (HP) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\HPZius12.sys – (HPZius12)
DRV - [2005/03/08 13:52:28 | 000,016,496 | —- | M] (HP) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\HPZipr12.sys – (HPZipr12)
DRV - [2005/03/08 13:52:26 | 000,051,120 | —- | M] (HP) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\HPZid412.sys – (HPZid412)
DRV - [2005/03/04 13:10:26 | 000,074,496 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\Rtlnicxp.sys – (RTL8023xp)
DRV - [2004/12/15 17:18:32 | 000,220,928 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\HSFHWBS2.sys – (HSFHWBS2)
DRV - [2004/12/15 17:18:28 | 000,703,232 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\HSF_CNXT.sys – (winachsf)
DRV - [2004/12/15 17:18:26 | 001,038,208 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\HSF_DP.sys – (HSF_DP)
DRV - [2004/10/07 20:16:04 | 000,035,840 | —- | M] (Oak Technology Inc.) [Kernel | System] – C:\WINDOWS\system32\drivers\AFS2K.SYS – (AFS2K)
DRV - [2004/09/15 03:42:14 | 000,068,672 | R— | M] (2Wire, Inc.) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\2WirePCP.sys – (2WIREPCP)
DRV - [2004/08/10 07:00:00 | 000,017,792 | —- | M] (Parallel Technologies, Inc.) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\ptilink.sys – (Ptilink)
DRV - [2004/08/10 07:00:00 | 000,007,936 | —- | M] (Microsoft Corporation) [Recognizer | System] – C:\WINDOWS\system32\drivers\fs_rec.sys – (Fs_Rec)
DRV - [2004/08/10 07:00:00 | 000,002,864 | —- | M] (Microsoft Corporation) [Adapter | On_Demand] – C:\WINDOWS\system32\winsock.dll – (Winsock)
DRV - [2004/08/04 00:31:34 | 000,020,992 | —- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\RTL8139.sys – (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2004/04/13 19:20:08 | 000,015,781 | R— | M] (Meetinghouse Data Communications) [Kernel | Auto] – C:\WINDOWS\system32\drivers\mdc8021x.sys – (MDC8021X) AEGIS Protocol (IEEE 802.1x)
DRV - [2004/03/17 13:04:14 | 000,013,059 | —- | M] (Conexant) [Kernel | Auto] – C:\WINDOWS\system32\drivers\mdmxsdk.sys – (mdmxsdk)
DRV - [2004/03/08 12:55:50 | 000,013,567 | —- | M] (B.H.A Corporation) [Kernel | System] – C:\WINDOWS\system32\drivers\CDRBSDRV.SYS – (cdrbsdrv)
DRV - [2003/11/05 17:45:12 | 000,017,408 | —- | M] (Promise Technology, Inc.) [Kernel | Boot] – C:\WINDOWS\system32\drivers\bb-run.sys – (bb-run)
DRV - [2002/10/15 21:41:06 | 000,102,220 | —- | M] (Sony Corporation) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\sonypvs1.sys – (sonypvs1)
DRV - [2001/08/17 14:02:56 | 000,003,968 | —- | M] (Microsoft Corporation) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\SWUSBFLT.SYS – (SWUSBFLT)
DRV - [2001/08/17 14:02:50 | 000,002,688 | —- | M] (Microsoft Corporation) [Kernel | On_Demand] – C:\WINDOWS\system32\drivers\hidswvd.sys – (HIDSwvd)
========== Standard Registry (All) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\Administrator_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\Administrator_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKU\Administrator_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
IE - HKU\Administrator_ON_C\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
IE - HKU\Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\HP_Administrator_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\HP_Administrator_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKU\HP_Administrator_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKU\HP_Administrator_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKU\HP_Administrator_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://swagbucks.com/
IE - HKU\HP_Administrator_ON_C\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\HP_Administrator_ON_C\..\URLSearchHook: {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - C:\Program Files\Swag_Bucks\tbSwa1.dll (Conduit Ltd.)
IE - HKU\HP_Administrator_ON_C\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
IE - HKU\HP_Administrator_ON_C\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKU\HP_Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\HP_Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKU\MCX1_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
IE - HKU\MCX1_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
IE - HKU\MCX1_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\MCX1_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
IE - HKU\MCX1_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
IE - HKU\MCX1_ON_C\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
IE - HKU\MCX1_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\MCX2_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
IE - HKU\MCX2_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
IE - HKU\MCX2_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\MCX2_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
IE - HKU\MCX2_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
IE - HKU\MCX2_ON_C\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch =
http://red.clientapps.yahoo.com/customize/…/search/ie.html
IE - HKU\MCX2_ON_C\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
IE - HKU\MCX2_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\MCX3_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
IE - HKU\MCX3_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
IE - HKU\MCX3_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\MCX3_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
IE - HKU\MCX3_ON_C\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
IE - HKU\MCX3_ON_C\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch =
http://red.clientapps.yahoo.com/customize/…/search/ie.html
IE - HKU\MCX3_ON_C\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
IE - HKU\MCX3_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\NetworkService_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/09/01 21:00:40 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/02/08 22:40:14 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/02/08 22:40:14 | 000,000,000 | —D | M]
[2009/11/06 17:38:45 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/02/08 22:40:14 | 000,000,000 | —D | M] (Default) – C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2010/02/08 22:40:00 | 000,023,000 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browserdirprovider.dll
[2010/02/08 22:40:00 | 000,138,712 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\brwsrcmp.dll
[2010/01/18 22:21:34 | 000,393,216 | —- | M] (Invenda Corporation) – C:\Program Files\Mozilla Firefox\plugins\NPcol400.dll
[2008/06/18 01:43:04 | 000,086,016 | —- | M] (Coupons, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2009/03/18 09:03:40 | 000,214,272 | —- | M] (Midasplayer Ltd) – C:\Program Files\Mozilla Firefox\plugins\npmidas.dll
[2010/02/08 22:40:06 | 000,064,984 | —- | M] (mozilla.org) – C:\Program Files\Mozilla Firefox\plugins\npnul32.dll
[2009/12/25 07:58:57 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
[2009/12/25 07:58:57 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
[2009/12/25 07:58:57 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
[2009/12/25 07:58:58 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
[2009/12/25 07:58:58 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
[2009/12/25 07:58:58 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
[2009/12/25 07:58:58 | 000,159,744 | —- | M] (Apple Inc.) – C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
[2007/04/16 12:07:12 | 000,180,293 | —- | M] () – C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
[2010/02/08 22:40:08 | 000,001,394 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazondotcom.xml
[2010/02/08 22:40:08 | 000,002,193 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\answers.xml
[2010/02/08 22:40:08 | 000,001,534 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\creativecommons.xml
[2010/02/08 22:40:08 | 000,002,344 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay.xml
[2010/02/08 22:40:08 | 000,002,371 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\google.xml
[2010/02/08 22:40:08 | 000,001,178 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\wikipedia.xml
[2010/02/08 22:40:08 | 000,001,096 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo.xml
O1 HOSTS File: ([2004/08/10 14:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Swag Bucks Toolbar) - {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - C:\Program Files\Swag_Bucks\tbSwa1.dll (Conduit Ltd.)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Swag Bucks Toolbar) - {8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94} - C:\Program Files\Swag_Bucks\tbSwa1.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Yahoo! ¤u¨ã¦C) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKU\Administrator_ON_C\..\Toolbar\WebBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKU\Administrator_ON_C\..\Toolbar\WebBrowser: (&Links) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O3 - HKU\Administrator_ON_C\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKU\HP_Administrator_ON_C\..\Toolbar\ShellBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKU\HP_Administrator_ON_C\..\Toolbar\ShellBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKU\HP_Administrator_ON_C\..\Toolbar\WebBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKU\HP_Administrator_ON_C\..\Toolbar\WebBrowser: (&Links) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O3 - HKU\HP_Administrator_ON_C\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKU\HP_Administrator_ON_C\..\Toolbar\WebBrowser: (Swag Bucks Toolbar) - {8BDEA9D6-6F62-45EB-8EE9-8A81AF0D2F94} - C:\Program Files\Swag_Bucks\tbSwa1.dll (Conduit Ltd.)
O3 - HKU\HP_Administrator_ON_C\..\Toolbar\WebBrowser: (Yahoo! ¤u¨ã¦C) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKU\HP_Administrator_ON_C\..\Toolbar\WebBrowser: (&Links) - {F2CF5485-4E02-4F68-819C-B92DE9277049} - C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
O3 - HKU\MCX1_ON_C\..\Toolbar\WebBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKU\MCX1_ON_C\..\Toolbar\WebBrowser: (&Links) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O3 - HKU\MCX1_ON_C\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKU\MCX2_ON_C\..\Toolbar\WebBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKU\MCX2_ON_C\..\Toolbar\WebBrowser: (&Links) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O3 - HKU\MCX2_ON_C\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKU\MCX3_ON_C\..\Toolbar\WebBrowser: (&Address) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKU\MCX3_ON_C\..\Toolbar\WebBrowser: (&Links) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O3 - HKU\MCX3_ON_C\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [jedugikuf] C:\WINDOWS\System32\melasora.DLL ()
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [Monitor] C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe ()
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
O4 - HKLM..\Run: [SsAAD.exe] C:\Program Files\Sony\SonicStage\SSAAD.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKU\Administrator_ON_C..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKU\HP_Administrator_ON_C..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKU\HP_Administrator_ON_C..\Run: [msnmsgr] C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O4 - HKU\HP_Administrator_ON_C..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKU\HP_Administrator_ON_C..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O4 - HKU\MCX1_ON_C..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKU\MCX2_ON_C..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O4 - HKU\MCX3_ON_C..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKU\Administrator_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\HP_Administrator_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\LocalService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\MCX1_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\MCX2_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\MCX3_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\NetworkService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O9 - Extra 'Tools' menuitem : Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm ()
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\rsvpsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: trymedia.com ([]http in Trusted sites)
O15 - HKLM\..Trusted Domains: trymedia.com ([]https in Trusted sites)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab (Checkers Class)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/4…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files/Risk/Images/stg_drm.ocx (SpinTop DRM Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab (Minesweeper Flags Class)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {3107C2A8-9F0B-4404-A58B-21BD85268FBC}
http://www.pogo.com/cdl/launcher/PogoWebLa…erInstaller.CAB (PogoWebLauncher Control)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://photo.walgreens.com/WalgreensActivia.cab (Snapfish Activia)
O16 - DPF: {45A0A292-ECC6-4D8F-9EA9-A4BD411D24C1}
http://www.king.com/ctl/kingcomie.cab (king.com)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4}
http://h20264.www2.hp.com/ediags/dd/instal…nosticsxp2k.cab (DeviceEnum Class)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://go.divx.com/plugin/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab (MessengerStatsClient Class)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} http://web1.shutterfly.com/downloads/Uploader.cab (Shutterfly Picture Upload Plugin)
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1}
http://acs.pandasoftware.com/activescan/as5free/asinst.cab (ActiveScan Installer Class)
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} http://offers.e-centives.com/cif/download/bin/actxcab.cab (CBSTIEPrint Class)
O16 - DPF: {BE319D04-18BD-4B34-AECC-EE7CB610FCA9}
http://download.games.yahoo.com/games/web_…itched/main.cab (BewitchedGameClass Control)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/Monopoly/Images/armhelper.ocx (ArmHelper Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D}
http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?326 (QDiagHUpdateObj Class)
O16 - DPF: {F137B9BA-89EA-4B04-9C67-2074A9DF61FD}
http://cvs.pnimedia.com/upload/activex/v2_…upv2.0.0.10.cab? (Photo Upload Plugin Class)
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1}
http://dlm.tools.akamai.com/dlmanager/vers…ivex-latest.cab (DownloadManager Control)
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\intu-help-qb2 {84D77A00-41B5-4b8b-8ADF-86486D72E749} - C:\Program Files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\qbwc {FC598A64-626C-4447-85B8-53150405FD57} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\WINDOWS\System32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\Class Install Handler {32B533BB-EDAE-11d0-BD5A-00AA00B92AF1} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\deflate {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\gzip {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\lzdhtml {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/webviewhtml {733AC4CB-F1A4-11d0-B951-00A0C90312E1} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (c:\windows\system32\libukifu.dll) - C:\WINDOWS\System32\libukifu.dll File not found
O20 - AppInit_DLLs: (moyomego.dll) - File not found
O20 - AppInit_DLLs: (c:\windows\system32\melasora.dll) - C:\WINDOWS\system32\melasora.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (rundll32.exe) - File not found
O20 - HKLM Winlogon: Shell - (ajhg.kqo) - File not found
O20 - HKLM Winlogon: Shell - (prect) - File not found
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\sdra64.exe) - C:\WINDOWS\system32\sdra64.exe (aSRcyOXSlEIiW)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\System32\logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\System32\sysdm.cpl (Microsoft Corporation)
O20 - HKU\MCX1_ON_C Winlogon: Shell - (C:\WINDOWS\eHome\McrMgr.exe) - C:\WINDOWS\ehome\mcrmgr.exe (Microsoft Corporation)
O20 - HKU\MCX2_ON_C Winlogon: Shell - (C:\WINDOWS\eHome\McrMgr.exe) - C:\WINDOWS\ehome\mcrmgr.exe (Microsoft Corporation)
O20 - HKU\MCX3_ON_C Winlogon: Shell - (C:\WINDOWS\eHome\McrMgr.exe) - C:\WINDOWS\ehome\mcrmgr.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\System32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\System32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\System32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\dimsntfy: DllName - %SystemRoot%\System32\dimsntfy.dll - C:\WINDOWS\system32\dimsntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\NavLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\System32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\System32\WgaLogon.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\System32\wlnotify.dll (Microsoft Corporation)
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: ladatizuk - {71360016-f38c-4a18-b416-7d26a6eeb975} - C:\WINDOWS\system32\melasora.dll ()
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {71360016-f38c-4a18-b416-7d26a6eeb975} - tokatiluy - C:\WINDOWS\system32\melasora.dll ()
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\welcome.htm
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\welcome.htm
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\System32\shell32.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\System32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (schannel.dll) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (digest.dll) - C:\WINDOWS\System32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msnsspc.dll) - C:\WINDOWS\System32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\System32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\System32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\System32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\System32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/05/14 17:49:12 | 000,000,150 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2001/07/28 05:07:38 | 000,000,000 | -HS- | M] () - H:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2004/04/30 06:01:14 | 000,000,053 | -HS- | M] () - H:\Autorun.inf – [ FAT32 ]
O32 - AutoRun File - [2006/03/24 06:06:41 | 000,000,053 | R— | M] () - X:\AUTORUN.INF – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2005/09/01 14:12:30 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
========== Files/Folders - Created Within 30 Days ==========
[2010/02/11 12:47:51 | 000,000,000 | -HSD | C] – C:\WINDOWS\System32\lowsec
[2010/02/10 12:27:39 | 000,000,000 | —D | C] – C:\_OTL
[2010/02/09 22:09:17 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/02/09 22:09:14 | 000,019,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/02/09 22:09:14 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/02/09 22:01:23 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/02/09 21:04:24 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/02/09 19:58:51 | 000,000,000 | -HSD | C] – C:\Documents and Settings\LocalService\IETldCache
[2010/02/09 07:45:48 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Administrator\PrivacIE
[2010/02/08 22:39:27 | 000,000,000 | —D | C] – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Cooliris
[2010/02/08 01:57:51 | 000,000,000 | —D | C] – C:\WINDOWS\Minidump
[2010/02/07 17:50:02 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Administrator\IETldCache
[2010/02/03 21:10:30 | 000,000,000 | —D | C] – C:\Program Files\Train3D
[2010/02/03 21:02:10 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\temp.001
[2010/02/03 21:02:10 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\temp.000
[2010/01/28 15:00:25 | 000,188,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\WINGDE.DLL
[2010/01/28 15:00:25 | 000,092,208 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\WING.DLL
[2010/01/28 15:00:25 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\WING32.DLL
[2010/01/28 15:00:25 | 000,006,736 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\WINGDIB.DRV
[2010/01/28 15:00:25 | 000,005,024 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\WINGPAL.WND
[2010/01/18 22:21:22 | 000,443,944 | —- | C] (E-centives ) – C:\Documents and Settings\HP_Administrator\Desktop\CouponActivator.exe
[2007/08/01 14:19:14 | 000,774,144 | —- | C] (RealNetworks, Inc.) – C:\Program Files\RngInterstitial.dll
[2005/05/12 09:36:48 | 000,012,288 | —- | C] (Hewlett-Packard Co.) – C:\WINDOWS\Fonts\RandFont.dll
========== Files - Modified Within 30 Days ==========
[2099/01/01 12:00:00 | 000,093,696 | -HS- | M] () – C:\WINDOWS\System32\korumore.dll
[2099/01/01 12:00:00 | 000,093,184 | -HS- | M] () – C:\WINDOWS\System32\melasora.dll
[2099/01/01 12:00:00 | 000,062,464 | -HS- | M] () – C:\WINDOWS\System32\vugukibo.dll
[2099/01/01 12:00:00 | 000,039,424 | -HS- | M] () – C:\WINDOWS\System32\vedilune.dll
[2099/01/01 12:00:00 | 000,039,424 | -HS- | M] () – C:\WINDOWS\System32\gizokoro.dll
[2010/02/11 12:51:10 | 000,262,144 | —- | M] () – C:\Documents and Settings\NetworkService\NTUSER.DAT
[2010/02/11 12:51:10 | 000,241,664 | —- | M] () – C:\Documents and Settings\LocalService\ntuser.dat
[2010/02/11 12:51:08 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/02/11 12:50:56 | 007,950,336 | —- | M] () – C:\Documents and Settings\HP_Administrator\ntuser.dat
[2010/02/11 12:50:50 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/02/11 12:50:45 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\HP_Administrator\ntuser.ini
[2010/02/11 12:48:38 | 055,460,643 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/02/11 12:44:46 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/02/11 12:44:40 | 000,352,608 | -H– | M] () – C:\WINDOWS\System32\vsconfig.xml
[2010/02/11 12:43:55 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2010/02/11 12:43:35 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/02/11 12:43:12 | 1005,113,344 | -HS- | M] () – C:\hiberfil.sys
[2010/02/10 18:00:36 | 000,000,296 | —- | M] () – C:\WINDOWS\tasks\ntmvdegi.job
[2010/02/10 12:31:44 | 000,001,744 | -H– | M] () – C:\WINDOWS\System32\dikabagu
[2010/02/10 12:11:01 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/02/09 11:46:26 | 001,048,576 | —- | M] () – C:\Documents and Settings\Administrator\ntuser.dat
[2010/02/09 11:46:26 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Administrator\ntuser.ini
[2010/02/08 19:16:31 | 000,001,138 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Facebook Home.url
[2010/02/08 14:12:06 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/02/07 17:41:07 | 004,285,014 | -H– | M] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\IconCache.db
[2010/02/05 21:55:17 | 000,743,752 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Gallatin Steel Company.tif
[2010/02/03 21:10:01 | 000,253,952 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Setup1.exe
[2010/02/03 21:10:00 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\WINDOWS\temp.001
[2010/02/03 21:02:11 | 000,000,362 | —- | M] () – C:\WINDOWS\ST6UNST.000
[2010/02/03 21:02:10 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\WINDOWS\temp.000
[2010/02/03 20:04:07 | 000,040,448 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Meijer.doc
[2010/01/28 18:07:12 | 000,000,294 | —- | M] () – C:\WINDOWS\EReg077.dat
[2010/01/28 15:00:22 | 000,000,216 | —- | M] () – C:\WINDOWS\TLCAPPS.INI
[2010/01/26 13:52:42 | 000,004,212 | -H– | M] () – C:\WINDOWS\System32\zllictbl.dat
[2010/01/21 19:20:06 | 000,000,629 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Reader Rabbit's Toddler (2).lnk
[2010/01/21 18:55:59 | 000,086,016 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\2009.xls
[2010/01/19 21:39:36 | 000,142,495 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2010/01/19 16:45:14 | 000,048,640 | —- | M] () – C:\Documents and Settings\HP_Administrator\Desktop\Neil Petty - Industrial Electrician.doc
[2010/01/18 22:21:23 | 000,443,944 | —- | M] (E-centives ) – C:\Documents and Settings\HP_Administrator\Desktop\CouponActivator.exe
[2010/01/13 22:34:51 | 000,230,808 | R— | M] (Coupons, Inc.) – C:\WINDOWS\System32\cpnprt2.cid
[2010/01/13 22:10:23 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
========== Files Created - No Company Name ==========
[2099/01/01 12:00:00 | 000,093,696 | -HS- | C] () – C:\WINDOWS\System32\korumore.dll
[2099/01/01 12:00:00 | 000,093,184 | -HS- | C] () – C:\WINDOWS\System32\melasora.dll
[2099/01/01 12:00:00 | 000,062,464 | -HS- | C] () – C:\WINDOWS\System32\vugukibo.dll
[2099/01/01 12:00:00 | 000,039,424 | -HS- | C] () – C:\WINDOWS\System32\vedilune.dll
[2099/01/01 12:00:00 | 000,039,424 | -HS- | C] () – C:\WINDOWS\System32\gizokoro.dll
[2010/02/10 12:28:28 | 000,000,296 | —- | C] () – C:\WINDOWS\tasks\ntmvdegi.job
[2010/02/10 12:28:25 | 000,001,744 | -H– | C] () – C:\WINDOWS\System32\dikabagu
[2010/02/09 11:47:40 | 1005,113,344 | -HS- | C] () – C:\hiberfil.sys
[2010/02/07 15:31:03 | 007,950,336 | —- | C] () – C:\Documents and Settings\HP_Administrator\ntuser.dat
[2010/02/07 15:31:03 | 000,241,664 | —- | C] () – C:\Documents and Settings\LocalService\ntuser.dat
[2010/02/05 21:55:16 | 000,743,752 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\Gallatin Steel Company.tif
[2010/02/03 21:06:50 | 000,000,886 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/02/03 21:06:50 | 000,000,882 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/02/03 21:02:10 | 000,000,362 | —- | C] () – C:\WINDOWS\ST6UNST.000
[2010/01/28 18:07:11 | 000,000,294 | —- | C] () – C:\WINDOWS\EReg077.dat
[2010/01/21 19:20:06 | 000,000,629 | —- | C] () – C:\Documents and Settings\HP_Administrator\Desktop\Reader Rabbit's Toddler (2).lnk
[2009/09/21 18:32:56 | 000,000,216 | —- | C] () – C:\WINDOWS\TLCAPPS.INI
[2009/07/22 20:03:42 | 000,000,110 | —- | C] () – C:\WINDOWS\{47FB62DF-832D-485F-95FC-C93BB08B8FE3}_WiseFW.ini
[2008/12/19 22:41:13 | 000,000,067 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\photoshow_express_setup.txt
[2008/12/09 15:32:54 | 000,000,095 | —- | C] () – C:\WINDOWS\QBChanUtil_Trigger.ini
[2008/09/13 09:45:51 | 000,000,023 | —- | C] () – C:\WINDOWS\MathMagic Personal 3.64.INI
[2008/09/13 09:45:11 | 000,016,498 | —- | C] () – C:\Program Files\setuplog.txt
[2008/09/13 09:45:11 | 000,015,834 | —- | C] () – C:\Program Files\uninstall.log
[2008/05/21 17:33:21 | 000,000,343 | —- | C] () – C:\WINDOWS\SIERRA.INI
[2008/03/14 14:32:38 | 000,000,343 | —- | C] () – C:\WINDOWS\ULead32.ini
[2008/02/23 18:10:33 | 000,000,071 | —- | C] () – C:\WINDOWS\Pex.INI
[2008/02/04 17:23:10 | 000,693,792 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2008/02/03 12:19:20 | 000,006,144 | —- | C] () – C:\Documents and Settings\MCX3\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/02/03 10:51:00 | 000,000,127 | —- | C] () – C:\Documents and Settings\MCX3\Local Settings\Application Data\fusioncache.dat
[2007/10/29 19:24:32 | 000,000,190 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\G-Force Prefs (WindowsMediaPlayer).txt
[2007/08/03 14:09:41 | 000,003,454 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2007/08/03 14:09:41 | 000,000,008 | RHS- | C] () – C:\WINDOWS\System32\8036B57683.sys
[2007/05/21 18:43:37 | 000,000,560 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\ViewerApp.dat
[2007/05/14 17:47:01 | 000,003,654 | —- | C] () – C:\WINDOWS\System32\drivers\Sonyhcp.dll
[2007/05/13 18:58:44 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\resourceGeneric.dll
[2007/01/29 12:23:40 | 000,011,776 | —- | C] () – C:\WINDOWS\System32\ZPORT4AS.dll
[2007/01/19 20:42:01 | 000,000,000 | —- | C] () – C:\WINDOWS\PROTOCOL.INI
[2006/10/14 15:06:20 | 000,796,584 | —- | C] () – C:\WINDOWS\System32\libeay32_0.9.6l.dll
[2006/10/14 12:58:32 | 000,000,127 | —- | C] () – C:\Documents and Settings\MCX2\Local Settings\Application Data\fusioncache.dat
[2006/08/26 15:13:30 | 000,000,000 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\wklnhst.dat
[2006/08/19 08:45:20 | 000,372,736 | —- | C] () – C:\WINDOWS\System32\hpzidi01.dll
[2006/08/19 08:45:19 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\hpzids01.dll
[2006/07/09 20:58:44 | 000,000,091 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2006/05/06 19:20:36 | 000,065,382 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\PatchUpdate_HP_CounterReport_Update_HPSU.log
[2006/05/06 19:20:36 | 000,000,227 | —- | C] () – C:\WINDOWS\HP_CounterReport_Update_HPSU.ini
[2006/05/06 19:20:25 | 000,002,202 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\HPSU_48BitScanUpdate.log
[2006/05/06 19:20:25 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2006/05/06 19:19:00 | 000,003,013 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\PatchUpdate_InstantShareJPG.log
[2006/05/06 19:19:00 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_InstantSHareJPG.ini
[2006/05/06 19:17:50 | 000,006,926 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\GdiplusUpgrade_MSIApproach_Wrapper.log
[2006/05/06 19:17:50 | 000,000,206 | —- | C] () – C:\WINDOWS\HPGdiPlus.ini
[2006/05/06 19:01:58 | 000,049,385 | —- | C] () – C:\Documents and Settings\HP_Administrator\Application Data\Update_HP_RedboxHprblog_HPSU.log
[2006/05/06 19:01:58 | 000,000,221 | —- | C] () – C:\WINDOWS\HP_RedboxHprblog_HPSU.ini
[2006/05/03 17:56:01 | 000,000,000 | —- | C] () – C:\WINDOWS\vpc32.INI
[2006/04/30 17:57:19 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2006/04/30 17:45:50 | 000,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2006/04/30 17:45:50 | 000,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2006/04/30 17:45:50 | 000,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2006/04/04 20:39:06 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\YCRWin32.dll
[2006/03/24 18:25:28 | 000,003,584 | —- | C] () – C:\Documents and Settings\MCX1\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/03/24 18:10:11 | 000,000,127 | —- | C] () – C:\Documents and Settings\MCX1\Local Settings\Application Data\fusioncache.dat
[2006/03/22 16:10:12 | 000,000,028 | —- | C] () – C:\WINDOWS\atid.ini
[2006/03/07 21:18:06 | 000,026,112 | —- | C] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/03/06 22:47:17 | 000,004,599 | —- | C] () – C:\WINDOWS\hpdj5600.ini
[2006/03/05 12:44:51 | 000,000,139 | —- | C] () – C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\fusioncache.dat
[2005/12/02 19:21:27 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/12/02 19:02:13 | 000,022,396 | —- | C] () – C:\WINDOWS\System32\drivers\USBkey.sys
[2005/12/02 18:57:42 | 000,014,316 | —- | C] () – C:\WINDOWS\System32\CHODDI.SYS
[2005/12/02 18:57:35 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2005/12/02 18:55:33 | 000,000,099 | —- | C] () – C:\WINDOWS\Quicken.ini
[2005/12/02 18:52:27 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005/12/02 18:48:06 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2005/12/02 18:48:06 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2005/12/02 18:48:06 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2005/12/02 18:48:06 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2005/12/02 18:48:06 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2005/12/02 18:48:06 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2005/12/02 18:42:51 | 000,000,108 | —- | C] () – C:\WINDOWS\WININIT.INI
[2005/12/02 18:41:57 | 000,000,698 | —- | C] () – C:\WINDOWS\NSSetDefaultBrowser.ini
[2005/12/02 18:16:15 | 000,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2005/12/02 18:13:04 | 000,000,136 | —- | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\fusioncache.dat
[2005/12/02 18:09:57 | 000,323,584 | —- | C] () – C:\WINDOWS\System32\pythoncom22.dll
[2005/12/02 18:09:57 | 000,094,208 | —- | C] () – C:\WINDOWS\System32\pywintypes22.dll
[2005/12/02 18:09:42 | 000,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2005/10/05 15:50:52 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2005/08/06 00:01:54 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/08/03 02:19:16 | 000,050,176 | —- | C] () – C:\WINDOWS\armcex.dll
[2004/09/16 13:26:40 | 000,012,634 | —- | C] () – C:\WINDOWS\System32\drivers\ADFUUD.SYS
[2004/08/10 07:00:00 | 000,096,512 | —- | C] () – C:\WINDOWS\System32\drivers\atapi.sys
[2004/07/26 17:51:38 | 000,000,560 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2003/01/08 01:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2001/07/07 01:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
[1998/08/16 05:00:00 | 000,004,096 | —- | C] () – C:\WINDOWS\System32\sysres.dll
========== LOP Check ==========
[2005/12/02 18:40:50 | 000,000,000 | —D | M] – C:\Documents and Settings\Administrator\Application Data\Digital Interactive Systems Corporation
[2005/12/02 18:40:50 | 000,000,000 | —D | M] – C:\Documents and Settings\MCX1\Application Data\Digital Interactive Systems Corporation
[2005/12/02 18:40:50 | 000,000,000 | —D | M] – C:\Documents and Settings\MCX2\Application Data\Digital Interactive Systems Corporation
[2005/12/02 18:40:50 | 000,000,000 | —D | M] – C:\Documents and Settings\MCX3\Application Data\Digital Interactive Systems Corporation
[2010/02/10 18:00:36 | 000,000,296 | —- | M] () – C:\WINDOWS\Tasks\ntmvdegi.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
[2009/03/11 18:57:50 | 000,997,616 | —- | M] (Microsoft Corporation) – C:\WindowsXP-KB894179-x86-ENU.exe
< MD5 for: AGP440.SYS >
[2004/08/10 14:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/04/14 04:51:44 | 020,056,462 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2004/08/10 07:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\I386\sp2.cab:AGP440.sys
[2008/04/14 04:51:44 | 020,056,462 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\dllcache\agp440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys
< MD5 for: ATAPI.SYS >
[2004/08/10 14:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/04/14 04:51:44 | 020,056,462 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2004/08/10 07:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\I386\sp2.cab:atapi.sys
[2008/04/14 04:51:44 | 020,056,462 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\dllcache\atapi.sys
[2004/08/04 08:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] () MD5=EA54621D39A62427A41B63CABBEF9A81 – C:\WINDOWS\system32\drivers\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\dllcache\eventlog.dll
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/10 07:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: IASTOR.SYS >
[2005/06/17 16:33:40 | 000,872,064 | —- | M] (Intel Corporation) MD5=9A65E42664D1534B68512CAAD0EFE963 – C:\hp\drivers\Intel_5_1_0_1022_PV\iastor.sys
[2005/06/17 16:33:40 | 000,872,064 | —- | M] (Intel Corporation) MD5=9A65E42664D1534B68512CAAD0EFE963 – C:\WINDOWS\system32\drivers\iaStor.sys
< MD5 for: NETLOGON.DLL >
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\dllcache\netlogon.dll
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2004/08/10 07:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: SCECLI.DLL >
[2004/08/10 07:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\dllcache\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2008/06/20 12:46:57 | 000,147,968 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\WINDOWS\system32\dnsapi.dll
[2009/12/21 14:14:02 | 011,070,464 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\WINDOWS\system32\ieframe.dll
[2009/12/21 14:14:03 | 001,985,536 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\WINDOWS\system32\iertutil.dll
[2008/04/13 19:12:00 | 000,274,944 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\WINDOWS\system32\mstask.dll
[2008/04/13 19:12:02 | 000,067,072 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\WINDOWS\system32\ntdsapi.dll
[2008/06/17 14:02:19 | 008,461,312 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\WINDOWS\system32\shell32.dll
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2005/08/30 23:51:10 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2005/08/30 23:51:10 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2005/08/30 23:51:10 | 000,888,832 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< End of report >