Thank you for your detailed reply. I believe I followed all of your instructions and I've posted the log reports below.
GMER 1.0.15.15281 -
http://www.gmer.net
Rootkit scan 2010-04-11 23:48:16
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\JASONR~1\LOCALS~1\Temp\fwtdakob.sys
—- System - GMER 1.0.15 —-
SSDT 89A45C60 ZwCreateKey
SSDT 89A45160 ZwCreateProcess
SSDT 89A45420 ZwCreateProcessEx
SSDT 89A46AC0 ZwCreateThread
SSDT 89A461E0 ZwDeleteKey
SSDT 89A464A0 ZwDeleteValueKey
SSDT 89A46C60 ZwLoadDriver
SSDT 89A456E0 ZwOpenProcess
SSDT 89A45F20 ZwSetValueKey
SSDT 89A459A0 ZwTerminateProcess
SSDT 89A46920 ZwWriteVirtualMemory
—- Kernel code sections - GMER 1.0.15 —-
.text C:\WINDOWS\System32\DRIVERS\nv4_mini.sys section is writeable [0xB9A02380, 0x346307, 0xE8000020]
.rsrc C:\WINDOWS\System32\DRIVERS\rasacd.sys entry point in ".rsrc" section [0xBAD91C14]
—- User code sections - GMER 1.0.15 —-
.text C:\Program Files\Webroot\Washer\WasherSvc.exe[688] kernel32.dll!CreateThread + 1A 7C8106F1 4 Bytes CALL 0008ED99 C:\Program Files\Webroot\Washer\WasherSvc.exe (Window Washer Engine/Webroot Software, Inc.)
.text C:\WINDOWS\System32\svchost.exe[1416] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0099000A
.text C:\WINDOWS\System32\svchost.exe[1416] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 009A000A
.text C:\WINDOWS\System32\svchost.exe[1416] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 0098000C
.text C:\WINDOWS\System32\svchost.exe[1416] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 0302000A
.text C:\WINDOWS\Explorer.EXE[1784] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00B6000A
.text C:\WINDOWS\Explorer.EXE[1784] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00C0000A
.text C:\WINDOWS\Explorer.EXE[1784] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00B5000C
.text C:\Program Files\Internet Explorer\iexplore.exe[3388] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00A3000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3388] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00DD000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3388] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00A2000C
.text C:\Program Files\Internet Explorer\iexplore.exe[3388] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E215505 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3388] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDAC4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3388] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E473F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3388] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4671 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3388] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E46DC C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3388] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4542 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3388] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E45A4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3388] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E47A2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3388] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4606 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00A3000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00DD000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00A2000C
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E215505 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9A75 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DD101 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDAC4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E25466E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E473F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4671 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E46DC C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4542 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E45A4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E47A2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4606 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 3E2EDB20 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3968] ole32.dll!OleLoadFromStream 77529C85 5 Bytes JMP 3E3E4AA7 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
—- Devices - GMER 1.0.15 —-
AttachedDevice \FileSystem\Ntfs \Ntfs SiWinAcc.sys (Windows Accelerator Driver/Silicon Image, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip tmtdi.sys (Trend Micro TDI Driver (i386-fre)/Trend Micro Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp tmtdi.sys (Trend Micro TDI Driver (i386-fre)/Trend Micro Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp tmtdi.sys (Trend Micro TDI Driver (i386-fre)/Trend Micro Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp tmtdi.sys (Trend Micro TDI Driver (i386-fre)/Trend Micro Inc.)
AttachedDevice \FileSystem\Fastfat \Fat SiWinAcc.sys (Windows Accelerator Driver/Silicon Image, Inc.)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device -> \Driver\atapi \Device\Harddisk0\DR0 89BEDAC8
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xB2 0x02 0x18 0x72 …
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xB2 0x02 0x18 0x72 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xB2 0x02 0x18 0x72 …
—- Files - GMER 1.0.15 —-
File C:\WINDOWS\System32\DRIVERS\rasacd.sys suspicious modification
File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification
—- EOF - GMER 1.0.15 —-
OTL logfile created on: 4/11/2010 11:58:19 PM - Run 1
OTL by OldTimer - Version 3.2.1.1 Folder = C:\Reiny's Stuff\filelib\aquadeath2\Virus Removal Stuff
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 73.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 89.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 149.38 Gb Free Space | 64.15% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: REINYSCOMP
Current User Name: Jason Reinhard
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Reiny's Stuff\filelib\aquadeath2\Virus Removal Stuff\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Trend Micro\Internet Security\TmPfw.exe ()
PRC - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe ()
PRC - C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe ()
PRC - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Trend Micro\BM\TMBMSRV.exe ()
PRC - C:\Program Files\Webroot\Washer\WasherSvc.exe (Webroot Software, Inc.)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - C:\Reiny's Stuff\filelib\aquadeath2\Virus Removal Stuff\OTL.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (TmPfw) – C:\Program Files\Trend Micro\Internet Security\TmPfw.exe ()
SRV - (SfCtlCom) – C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe ()
SRV - (tmproxy) – C:\Program Files\Trend Micro\Internet Security\TmProxy.exe ()
SRV - (TMBMServer) – C:\Program Files\Trend Micro\BM\TMBMSRV.exe ()
SRV - (wwEngineSvc) – C:\Program Files\Webroot\Washer\WasherSvc.exe (Webroot Software, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (FirebirdServerMAGIXInstance) – C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe (MAGIX®)
========== Driver Services (SafeList) ==========
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (tmxpflt) – C:\WINDOWS\system32\drivers\tmxpflt.sys (Trend Micro Inc.)
DRV - (tmpreflt) – C:\WINDOWS\system32\drivers\tmpreflt.sys (Trend Micro Inc.)
DRV - (vsapint) – C:\WINDOWS\system32\drivers\vsapint.sys (Trend Micro Inc.)
DRV - (tmactmon) – C:\WINDOWS\system32\drivers\tmactmon.sys ()
DRV - (tmevtmgr) – C:\WINDOWS\system32\drivers\tmevtmgr.sys ()
DRV - (tmcomm) – C:\WINDOWS\system32\drivers\tmcomm.sys ()
DRV - (dvd43llh) – C:\WINDOWS\system32\drivers\dvd43llh.sys (RIF)
DRV - (tmcfw) – C:\WINDOWS\system32\drivers\TM_CFW.sys (Trend Micro Inc.)
DRV - (tmtdi) – C:\WINDOWS\system32\drivers\tmtdi.sys (Trend Micro Inc.)
DRV - (sptd) – C:\WINDOWS\system32\drivers\sptd.sys (Duplex Secure Ltd.)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (JRAID) – C:\WINDOWS\system32\DRIVERS\jraid.sys (JMicron Technology Corp.)
DRV - (JGOGO) – C:\WINDOWS\system32\DRIVERS\JGOGO.sys (JMicron )
DRV - (mcdbus) – C:\WINDOWS\system32\drivers\mcdbus.sys (MagicISO, Inc.)
DRV - (WINFLASH) – C:\Program Files\U-ABIT\FlashMenu\WINFLASH.SYS ()
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.Sys (Realtek Semiconductor Corp.)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (Memctl) – C:\Program Files\U-ABIT\FlashMenu\MEMCTL.SYS ()
DRV - (RT25USBAP) – C:\WINDOWS\system32\drivers\rt25usbap.sys (Ralink Technology Inc.)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS (SuperAdBlocker, Inc.)
DRV - (SI3132) – C:\WINDOWS\System32\DRIVERS\SI3132.sys (Silicon Image, Inc.)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (SiFilter) – C:\WINDOWS\System32\DRIVERS\SiWinAcc.sys (Silicon Image, Inc.)
DRV - (ASPI32) – C:\WINDOWS\system32\drivers\ASPI32.SYS (Adaptec)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=localhost:7171
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.fantasysports.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "
http://sports.yahoo.com/fantasy"
FF - prefs.js..network.proxy.http: "localhost"
FF - prefs.js..network.proxy.http_port: 7171
FF - prefs.js..network.proxy.no_proxies_on: "*.local,localhost,127.0.0.1"
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.18\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/11 03:31:12 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.18\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/11 03:31:12 | 000,000,000 | —D | M]
[2009/05/25 03:25:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Jason Reinhard\Application Data\Mozilla\Extensions
[2010/04/11 03:31:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Jason Reinhard\Application Data\Mozilla\Firefox\Profiles\2hqnyucz.default\extensions
[2010/04/10 18:46:21 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Jason Reinhard\Application Data\Mozilla\Firefox\Profiles\2hqnyucz.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}(2)
[2009/05/25 03:25:16 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: ([2009/05/25 11:04:03 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [itype] C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispAppearancePage = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 181
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFind = 0
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll (Sun Microsystems, Inc.)
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (America Online, Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71}
http://download.microsoft.com/download/e/2…78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {41564D57-9980-0010-8000-00AA00389B71} http://download.microsoft.com/download/0/A…01F/wmvadvd.cab (Reg Error: Key error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://www.update.microsoft.com/microsoftu…b?1194497498187 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/microsoftu…b?1194497457718 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\itss.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Jason Reinhard\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Jason Reinhard\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/11/08 00:13:58 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010/04/11 14:37:24 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Jason Reinhard\Recent
[2010/04/11 12:21:22 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2010/04/11 12:05:45 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2010/04/11 12:02:19 | 000,181,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MpSigStub.exe
[2010/04/11 12:01:14 | 000,000,000 | —D | C] – C:\Program Files\Windows Defender
[2010/04/11 11:37:49 | 000,000,000 | —D | C] – C:\Program Files\HiJackThis
[2010/04/11 11:24:31 | 000,000,000 | —D | C] – C:\Documents and Settings\Jason Reinhard\Application Data\Malwarebytes
[2010/04/11 11:24:21 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/11 11:24:19 | 000,020,824 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/11 11:24:19 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/04/11 11:24:18 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/04/11 00:52:12 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/04/11 00:02:45 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2010/04/10 23:25:54 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/04/10 23:25:54 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/04/10 19:18:37 | 000,067,200 | R— | C] (Silicon Image, Inc.) – C:\WINDOWS\System32\drivers\SI3132_2.sys
[2010/04/10 18:42:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Jason Reinhard\Application Data\QuickScan
[2010/04/10 17:40:57 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2010/04/10 15:23:21 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2010/04/09 17:22:21 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/04/09 17:22:03 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/03/24 16:42:00 | 000,000,000 | —D | C] – C:\Program Files\Doom
[2009/07/18 16:25:14 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2009/05/25 02:13:27 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Application Data\Mozilla
[2007/12/13 14:57:01 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2007/11/08 03:43:16 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[1996/11/17 17:00:00 | 000,018,944 | —- | C] ( ) – C:\WINDOWS\IMPLODE.DLL
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/04/11 23:57:51 | 000,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/04/11 23:55:07 | 000,000,433 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.ics
[2010/04/11 23:54:46 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/04/11 23:54:44 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/04/11 22:11:11 | 000,002,521 | —- | M] () – C:\Documents and Settings\Jason Reinhard\Desktop\Microsoft Outlook.lnk
[2010/04/11 19:31:53 | 006,553,600 | —- | M] () – C:\Documents and Settings\Jason Reinhard\ntuser.dat
[2010/04/11 19:31:53 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Jason Reinhard\ntuser.ini
[2010/04/11 19:31:48 | 003,712,656 | -H– | M] () – C:\Documents and Settings\Jason Reinhard\Local Settings\Application Data\IconCache.db
[2010/04/11 19:31:43 | 000,000,634 | —- | M] () – C:\WINDOWS\win.ini
[2010/04/11 19:31:43 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/04/11 19:31:43 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2010/04/11 12:00:57 | 000,013,702 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/04/10 23:05:26 | 000,008,832 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rasacd.sys
[2010/04/04 12:34:05 | 000,870,128 | —- | M] () – C:\Documents and Settings\Jason Reinhard\Application Data\mcs.rma
[2010/04/04 12:34:05 | 000,000,004 | —- | M] () – C:\Documents and Settings\Jason Reinhard\Application Data\A0C936
[2010/03/30 00:46:30 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/03/30 00:45:52 | 000,020,824 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/03/28 16:37:40 | 000,024,064 | —- | M] () – C:\Documents and Settings\Jason Reinhard\Desktop\Will Geroni.doc
[2010/03/24 16:44:00 | 000,000,044 | —- | M] () – C:\WINDOWS\WININIT.INI
[2010/03/14 11:05:42 | 000,360,124 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/03/14 11:05:42 | 000,314,838 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/03/14 11:05:42 | 000,041,040 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/04/11 12:04:20 | 000,000,330 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/04/10 19:05:19 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/04/08 16:47:28 | 000,000,803 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Desktop\Internet Explorer.lnk
[2010/03/28 13:48:40 | 000,024,064 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Desktop\Will Geroni.doc
[2010/03/25 21:39:30 | 006,553,600 | —- | C] () – C:\Documents and Settings\Jason Reinhard\ntuser.dat
[2010/03/24 16:44:00 | 000,000,044 | —- | C] () – C:\WINDOWS\WININIT.INI
[2010/03/24 16:42:00 | 000,004,711 | —- | C] () – C:\WINDOWS\System32\dmouse.vxd
[2009/09/07 14:52:19 | 000,000,028 | —- | C] () – C:\WINDOWS\Robota.INI
[2009/09/07 14:46:27 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\mgxasio2.dll
[2009/09/07 14:45:23 | 000,120,200 | —- | C] () – C:\WINDOWS\System32\DLLDEV32i.dll
[2009/09/07 14:45:08 | 000,006,211 | —- | C] () – C:\WINDOWS\mgxoschk.ini
[2009/05/25 04:10:42 | 000,000,445 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Application Data\burnaware.ini
[2009/05/24 10:14:42 | 000,003,598 | —- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\773F1E3B-FA7D-4EFD-BA91-EDE8C94400CB.txt
[2009/05/23 15:52:56 | 000,005,270 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Local Settings\Application Data\773F1E3B-FA7D-4EFD-BA91-EDE8C94400CB.txt
[2009/05/23 00:10:22 | 000,003,638 | —- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\1B63A34D-D468-480C-9BFD-C7118A69BA98.txt
[2009/05/22 16:38:35 | 000,004,426 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Local Settings\Application Data\1B63A34D-D468-480C-9BFD-C7118A69BA98.txt
[2009/05/01 22:43:08 | 000,870,128 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Application Data\mcs.rma
[2009/05/01 22:43:08 | 000,000,004 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Application Data\A0C936
[2009/02/19 20:09:55 | 000,000,088 | —- | C] () – C:\WINDOWS\Battle.ini
[2009/02/19 20:09:55 | 000,000,037 | —- | C] () – C:\WINDOWS\progman.ini
[2008/09/05 17:35:43 | 000,354,816 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2008/07/31 19:37:00 | 000,142,864 | —- | C] () – C:\WINDOWS\System32\drivers\tmcomm.sys
[2008/07/31 19:37:00 | 000,052,752 | —- | C] () – C:\WINDOWS\System32\drivers\tmactmon.sys
[2008/07/31 19:37:00 | 000,052,624 | —- | C] () – C:\WINDOWS\System32\drivers\tmevtmgr.sys
[2008/05/20 17:49:20 | 000,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2008/05/20 17:49:20 | 000,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2008/05/20 17:49:20 | 000,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2008/05/19 21:56:56 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2008/05/17 00:16:25 | 000,000,041 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2008/05/16 23:45:01 | 000,197,120 | —- | C] () – C:\WINDOWS\patchw32.dll
[2008/05/09 23:33:40 | 000,000,252 | —- | C] () – C:\WINDOWS\dvdtoaviconverter.ini
[2008/04/24 22:00:07 | 000,000,000 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Application Data\AVSDVDPlayer.m3u
[2008/02/14 02:54:19 | 000,000,107 | —- | C] () – C:\Documents and Settings\Jason Reinhard\default.pls
[2008/02/12 15:48:36 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2008/02/12 10:20:02 | 000,001,024 | —- | C] () – C:\Documents and Settings\Jason Reinhard\.rnd
[2008/01/19 03:03:15 | 000,000,023 | —- | C] () – C:\WINDOWS\BlendSettings.ini
[2007/12/14 12:49:05 | 000,000,211 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Application Data\Network.ini
[2007/11/28 01:47:35 | 000,000,600 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Local Settings\Application Data\PUTTY.RND
[2007/11/11 23:58:04 | 000,019,456 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/11/10 19:32:20 | 000,000,480 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/11/10 14:10:34 | 000,000,321 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Application Data\SephirothSkirmishStats.ini
[2007/11/10 14:10:34 | 000,000,112 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Application Data\Skirmish.ini
[2007/11/10 14:08:50 | 000,000,407 | —- | C] () – C:\Documents and Settings\Jason Reinhard\Application Data\Options.ini
[2007/11/09 01:00:47 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2007/11/08 23:45:55 | 000,000,029 | —- | C] () – C:\WINDOWS\atid.ini
[2007/11/08 02:14:46 | 000,010,848 | —- | C] () – C:\WINDOWS\System32\drivers\WinFlash.sys
[2007/11/08 00:35:14 | 000,006,016 | —- | C] () – C:\WINDOWS\System32\drivers\ALLOW-IO.SYS
[2007/11/08 00:20:23 | 000,001,024 | -H– | C] () – C:\Documents and Settings\Jason Reinhard\ntuser.dat.LOG
[2007/11/08 00:20:23 | 000,000,278 | -HS- | C] () – C:\Documents and Settings\Jason Reinhard\ntuser.ini
[2007/10/19 20:56:16 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2007/10/18 05:02:34 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2007/06/28 12:43:00 | 001,703,936 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2007/06/28 12:43:00 | 001,474,560 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2007/06/28 12:43:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2007/06/28 12:43:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2007/06/28 12:43:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
========== LOP Check ==========
[2009/04/21 19:29:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Acoustica
[2008/09/05 17:43:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Age of Empires 3
[2008/08/01 20:35:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Funcom
[2009/09/07 19:15:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GoldWave
[2009/09/07 14:58:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MAGIX
[2008/06/16 18:43:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2007/12/14 03:49:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/04/12 16:14:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/04/21 19:33:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Jason Reinhard\Application Data\Acoustica
[2007/11/09 23:19:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Jason Reinhard\Application Data\Aim
[2008/08/16 01:08:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Jason Reinhard\Application Data\Amazon
[2008/05/16 15:35:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Jason Reinhard\Application Data\Atari
[2010/01/25 22:20:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Jason Reinhard\Application Data\Bioshock
[2008/04/08 18:31:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Jason Reinhard\Application Data\Feedreader
[2008/05/16 15:20:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Jason Reinhard\Application Data\Leadertech
[2009/09/07 14:52:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Jason Reinhard\Application Data\MAGIX
[2008/06/23 22:07:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Jason Reinhard\Application Data\My Battle for Middle-earth Files
[2010/04/10 18:44:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Jason Reinhard\Application Data\QuickScan
[2009/05/25 02:13:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Jason Reinhard\Application Data\qweoujzr(2)
[2007/11/15 11:49:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Jason Reinhard\Application Data\Viewpoint
[2010/04/11 23:57:51 | 000,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:411E1BE2
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6971CCC5
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:FB669950
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B835CF2D
< End of report >
OTL Extras logfile created on: 4/11/2010 11:58:19 PM - Run 1
OTL by OldTimer - Version 3.2.1.1 Folder = C:\Reiny's Stuff\filelib\aquadeath2\Virus Removal Stuff
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 73.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 89.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 149.38 Gb Free Space | 64.15% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: REINYSCOMP
Current User Name: Jason Reinhard
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\AIM\aim.exe" = C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger – (America Online, Inc.)
"C:\Program Files\Qnext\qnextclient.exe" = C:\Program Files\Qnext\qnextclient.exe:*:Enabled:qnextclient – ()
"C:\Program Files\Activision\Call To Power 2\ctp2_program\ctp\ctp2.exe" = C:\Program Files\Activision\Call To Power 2\ctp2_program\ctp\ctp2.exe:*:Enabled:Call to Power 2 – (Activision Studios)
"C:\Program Files\EA GAMES\The Battle for Middle-earth ™\game.dat" = C:\Program Files\EA GAMES\The Battle for Middle-earth ™\game.dat:*:Enabled:The Battle for Middle-earth ™ – ()
"C:\Program Files\EA GAMES\The Battle for Middle-earth ™\patchget.dat" = C:\Program Files\EA GAMES\The Battle for Middle-earth ™\patchget.dat:*:Enabled:patchgrabber – (Electronic Arts)
"C:\Program Files\Hasbro Interactive\Stratego\Stratego.exe" = C:\Program Files\Hasbro Interactive\Stratego\Stratego.exe:*:Enabled:Stratego – ( )
"C:\WINDOWS\system32\dplaysvr.exe" = C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper – (Microsoft Corporation)
"C:\Program Files\Microsoft Games\Age of Empires III\age3.exe" = C:\Program Files\Microsoft Games\Age of Empires III\age3.exe:*:Enabled:Age of Empires III – (Ensemble Studios)
"C:\Program Files\Microsoft Games\Age of Empires III\age3x.exe" = C:\Program Files\Microsoft Games\Age of Empires III\age3x.exe:*:Enabled:Age of Empires III - The WarChiefs – (Ensemble Studios)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\Program Files\Java\jre1.6.0_03\bin\java.exe" = C:\Program Files\Java\jre1.6.0_03\bin\java.exe:*:Enabled:Java™ Platform SE binary – (Sun Microsystems, Inc.)
"C:\Program Files\WiFiConnector\NintendoWFCReg.exe" = C:\Program Files\WiFiConnector\NintendoWFCReg.exe:*:Enabled:Nintendo Wi-Fi USB Connector – ()
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{047E5F60-5357-43FB-A080-1912EB0132A4}" = FlashMenu
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{1087BD66-01A3-40EA-949F-CD511E5189AA}" = TEAM MANAGER Lite 5.0
"{1C08A24C-B168-407E-A826-68FAF5F20710}" = Age of Empires III - The WarChiefs
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{32A3A4F4-B792-11D6-A78A-00B0D0160030}" = Java™ SE Development Kit 6 Update 3
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35CB6715-41F8-4F99-8881-6FC75BF054B0}" = Oblivion
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}" = JMB36X Raid Configurer
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{5D601655-6D54-4384-B52C-17EC5385FBBD}" = iTunes
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6C117F31-28A8-4477-BE91-64AC0A2204AD}" = Microsoft IntelliPoint 6.01
"{70F8B183-99EB-4304-BA35-080E2DFFD2A3}" = Age of Empires III
"{718D791F-F4E8-4aa7-98A6-15FDED17BDD0}" = Trend Micro Internet Security
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7B3F0113-E63C-4D6D-AF19-111A3165CCA2}" = Text-To-Speech-Runtime
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{8355F970-601D-442D-A79B-1D7DB4F24CAD}" = Apple Mobile Device Support
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{907B4640-266B-4A21-92FB-CD1A86CD0F63}" = RollerCoaster Tycoon 3
"{91110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{962E05CF-3394-496D-0091-850CF1762F6B}" = The Battle for Middle-earth ™
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A621B45A-D138-4A95-BE10-7CABA05EF94E}" = Trend Micro Internet Security
"{AC76BA86-7AD7-1033-7B44-A81100000003}" = Adobe Reader 8.1.1
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{D642E38E-0D24-486C-9A2D-E316DD696F4B}" = Microsoft XML Parser
"{D75915D3-6CFF-445F-A346-18ED6EF2F618}" = Microsoft IntelliType Pro 6.01
"{E280923D-C5D9-4728-8C79-AC9A0DC75875}" = BioShock
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"Acoustica Effects Pack" = Acoustica Effects Pack
"Acoustica Mixcraft 4.5" = Acoustica Mixcraft 4.5
"Acoustica MP3 Audio Mixer" = Acoustica MP3 Audio Mixer
"Acoustica_is1" = Acoustica 4.1
"Activision_CTP2UninstallKey" = Call To Power 2
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.3
"AOL Instant Messenger" = AOL Instant Messenger
"Audacity_is1" = Audacity 1.2.6
"AVS DVD Player_is1" = AVS DVD Player version 2.4
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.3
"AVS4YOU Video Converter 6_is1" = AVS Video Converter 6
"BurnAware Free_is1" = BurnAware Free 2.3.5
"CCleaner" = CCleaner
"DVD Flick_is1" = DVD Flick
"DVD Shrink_is1" = DVD Shrink 3.2
"DVDFab 6_is1" = DVDFab 6.1.2.5 (27/10/2009)
"DVDx_is1" = DVDx
"Firebird SQL Server US" = Firebird SQL Server - MAGIX Edition
"GoldWave v5.52" = GoldWave v5.52
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{1C08A24C-B168-407E-A826-68FAF5F20710}" = Age of Empires III - The WarChiefs
"InstallShield_{70F8B183-99EB-4304-BA35-080E2DFFD2A3}" = Age of Empires III
"MagicDisc 2.5.79" = MagicDisc 2.5.79
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mozilla Firefox (3.0.18)" = Mozilla Firefox (3.0.18)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"Qnext" = Qnext
"Rhapsody" = Rhapsody
"Stratego" = Stratego
"Viewpoint Manager" = Viewpoint Manager (Remove Only)
"ViewpointMediaPlayer" = Viewpoint Media Player
"WiFiConnector" = Nintendo Wi-Fi USB Connector Registration Tool
"Window Washer" = Window Washer
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 11/27/2008 10:55:05 AM | Computer Name = REINYSCOMP | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.
Error - 11/27/2008 4:39:09 PM | Computer Name = REINYSCOMP | Source = Application Error | ID = 1000
Description = Faulting application aim.exe, version 5.9.6089.0, faulting module
locateui.ocm, version 5.9.6089.0, fault address 0x00015627.
Error - 11/27/2008 10:24:39 PM | Computer Name = REINYSCOMP | Source = Application Error | ID = 1000
Description = Faulting application ctp2.exe, version 1.2.0.0, faulting module unknown,
version 0.0.0.0, fault address 0x00000000.
Error - 11/28/2008 2:09:42 AM | Computer Name = REINYSCOMP | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.
Error - 11/28/2008 10:27:43 AM | Computer Name = REINYSCOMP | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.
Error - 11/29/2008 1:14:34 AM | Computer Name = REINYSCOMP | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.
Error - 11/29/2008 1:00:11 PM | Computer Name = REINYSCOMP | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.
Error - 11/30/2008 1:37:24 PM | Computer Name = REINYSCOMP | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.
Error - 12/1/2008 7:26:13 AM | Computer Name = REINYSCOMP | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.
Error - 12/1/2008 4:49:38 PM | Computer Name = REINYSCOMP | Source = SecurityCenter | ID = 1802
Description = The Windows Security Center Service was unable to establish event
queries with WMI to monitor third party AntiVirus and Firewall.
[ System Events ]
Error - 4/11/2010 10:06:56 PM | Computer Name = REINYSCOMP | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.
Error - 4/11/2010 10:06:56 PM | Computer Name = REINYSCOMP | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.
Error - 4/11/2010 10:07:23 PM | Computer Name = REINYSCOMP | Source = Dhcp | ID = 1002
Description = The IP address lease [removed] for the Network Card with network
address 00508D9DC132 has been denied by the DHCP server 0.0.0.0 (The DHCP Server
sent a DHCPNACK message).
Error - 4/11/2010 10:09:41 PM | Computer Name = REINYSCOMP | Source = ipnathlp | ID = 31012
Description = The DNS proxy agent encountered an error while obtaining the local
list of name-resolution servers. Some DNS or WINS servers may be inaccessible to
clients on the local network. The data is the error code.
Error - 4/11/2010 10:09:41 PM | Computer Name = REINYSCOMP | Source = ipnathlp | ID = 31012
Description = The DNS proxy agent encountered an error while obtaining the local
list of name-resolution servers. Some DNS or WINS servers may be inaccessible to
clients on the local network. The data is the error code.
Error - 4/11/2010 10:09:48 PM | Computer Name = REINYSCOMP | Source = ipnathlp | ID = 31012
Description = The DNS proxy agent encountered an error while obtaining the local
list of name-resolution servers. Some DNS or WINS servers may be inaccessible to
clients on the local network. The data is the error code.
Error - 4/11/2010 10:10:42 PM | Computer Name = REINYSCOMP | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.100.11
on the Network Card with network address 00508D9DC132.
Error - 4/11/2010 11:54:57 PM | Computer Name = REINYSCOMP | Source = Service Control Manager | ID = 7000
Description = The MCSTRM service failed to start due to the following error: %%2
Error - 4/11/2010 11:55:11 PM | Computer Name = REINYSCOMP | Source = Ftdisk | ID = 262189
Description = The system could not sucessfully load the crash dump driver.
Error - 4/11/2010 11:55:11 PM | Computer Name = REINYSCOMP | Source = Ftdisk | ID = 262193
Description = Configuring the Page file for crash dump failed. Make sure there is
a page file on the boot partition and that is large enough to contain all physical
memory.
< End of report >