This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

extreme system slowness, possible virus?

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

HI, thanks for your help upfront.

I have extreme system slowness. When I start IE, the first window freezes, a second one will open after a long time.

I thought I had a virus and my anti-virus was not fixing the problem. I changed my anti-virus softwre to comcast's free software b/c I heard it was a robust progrm that really helps. It has a good interface and I like it better than most, seems very throghout.

I ran the scan it only seems to remove tracking cookies and the occasional small virus, but system remains very slow.
I ran system defrag tool, cleaned up disk some what, but not great.

I ran the hijack this and DDS, logs posted below
It took me two tries to DL OT, and it's running now, but it's taking forever. I'll post it when it's finshed.

Here's my logs.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:53:07 AM, on 3/1/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Borland\Interbase\Bin\IBGuard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ccSvcHst.exe
C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe
C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Borland\Interbase\Bin\IBServer.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ccSvcHst.exe
C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe
C:\Program Files\Dell AIO Printer A940\dlbabmon.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\dllhost.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.chicagobears.com/index.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\IPSBHO.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO:  - {79CEEA4E-C231-4614-9E3B-53B2A02F39B7} - C:\Program Files\comcasttb\comcastdx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Comcast Toolbar - {79CEEA4E-C231-4614-9E3B-53B2A02F39B7} - C:\Program Files\comcasttb\comcastdx.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coIEPlg.dll
O4 - HKLM\..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe"
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil10k_ActiveX.exe -update activex
O4 - HKUS\S-1-5-21-606747145-1214440339-839522115-1005\..\Run: [ComcastAntispyClient] "C:\Program Files\comcasttb\ComcastSpywareScan\ComcastAntispy.exe" /hide (User 'Angelina')
O4 - HKUS\S-1-5-21-606747145-1214440339-839522115-1005\..\Run: [WAB] C:\Documents and Settings\Angelina\Application Data\Macromedia\Common\3abfc02619.exe (User 'Angelina')
O4 - HKUS\S-1-5-21-606747145-1214440339-839522115-1005\..\Run: [rundll32.exe] (User 'Angelina')
O4 - HKUS\S-1-5-21-606747145-1214440339-839522115-1005\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Angelina')
O4 - HKUS\S-1-5-21-606747145-1214440339-839522115-1005\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (User 'Angelina')
O4 - HKUS\S-1-5-21-606747145-1214440339-839522115-1010\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Dan's iPhone')
O4 - HKUS\S-1-5-21-606747145-1214440339-839522115-500\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Administrator')
O4 - HKUS\S-1-5-21-606747145-1214440339-839522115-501\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Guest')
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Comcast AntiSpyware (AntiSpywareService) - Unknown owner - C:\Program Files\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InterBase Guardian (InterBaseGuardian) - Inprise Corporation - C:\Program Files\Borland\Interbase\Bin\IBGuard.exe
O23 - Service: InterBase Server (InterBaseServer) - Inprise Corporation - C:\Program Files\Borland\Interbase\Bin\IBServer.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Norton Security Suite (N360) - Symantec Corporation - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ccSvcHst.exe
O23 - Service: NkPtpEnumP2 - Nikon Corporation - C:\Program Files\Nikon\Wireless Camera Setup Utility\NkPtpEnum.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe
O23 - Service: Retrospect WD Service (RetroWDSvc) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
O23 - Service: VET Message Service (VETMSGNT) - Unknown owner - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe (file missing)

–
End of file - 10348 bytes



DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 6:05:25.23 on Tue 03/01/2011
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_11
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.188 [GMT -6:00]

AV: Anti-Virus - SBC Yahoo! Online Protection *On-access scanning disabled* (Updated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93}
AV: Norton Security Suite *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Security Suite *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
svchost.exe
C:\Program Files\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Borland\Interbase\Bin\IBGuard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ccSvcHst.exe
C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe
C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Borland\Interbase\Bin\IBServer.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ccSvcHst.exe
C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe
C:\Program Files\Dell AIO Printer A940\dlbabmon.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\dllhost.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\Meow Meow and Meow\Desktop\dds.scr

============== Pseudo HJT Report ===============

uSearch Page = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http://www.yahoo.com
uStart Page = hxxp://www.chicagobears.com/index.html
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
mSearch Page =
mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
uInternet Settings,ProxyOverride =
mURLSearchHooks: H - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton security suite\engine\4.3.0.5\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton security suite\engine\4.3.0.5\IPSBHO.DLL
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Comcast Toolbar: {79ceea4e-c231-4614-9e3b-53b2a02f39b7} - c:\program files\comcasttb\comcastdx.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Comcast Toolbar: {79ceea4e-c231-4614-9e3b-53b2a02f39b7} - c:\program files\comcasttb\comcastdx.dll
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton security suite\engine\4.3.0.5\coIEPlg.dll
c:\docume~1\meowme~1\locals~1\temp\rarsfx0\temp00
c:\docume~1\meowme~1\locals~1\temp\rarsfx0\temp00
c:\docume~1\meowme~1\locals~1\temp\rarsfx0\temp00
c:\docume~1\meowme~1\locals~1\temp\rarsfx0\temp00
c:\docume~1\meowme~1\locals~1\temp\rarsfx0\temp00
c:\docume~1\meowme~1\locals~1\temp\rarsfx0\temp00
c:\docume~1\meowme~1\locals~1\temp\rarsfx0\temp00
c:\docume~1\meowme~1\locals~1\temp\rarsfx0\temp00
c:\docume~1\meowme~1\locals~1\temp\rarsfx0\temp00
c:\docume~1\meowme~1\locals~1\temp\rarsfx0\temp00
c:\docume~1\meowme~1\locals~1\temp\rarsfx0\temp00
c:\docume~1\meowme~1\locals~1\temp\rarsfx0\temp00
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
mPolicies-explorer: =
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
LSP: c:\windows\system32\VetRedir.dll
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
Notify: AtiExtEvent - Ati2evxx.dll

================= FIREFOX ===================

FF - ProfilePath -
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqz9s", true); // Traditional
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–fiqs8s", true); // Simplified
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–j6w193g", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgba3a4f16a", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgba3a4fra", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4a87g", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7c0a67fbc", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbqly7cvafr", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kpry57d", true); // Traditional
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–kprw13d", true); // Simplified
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", "-1");
c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); // now unused
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.delay", 50);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0403000.005\symds.sys [2011-2-1 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0403000.005\symefa.sys [2011-2-1 173104]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.0.0.127\definitions\bashdefs\20110225.002\BHDrvx86.sys [2011-2-25 800376]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0403000.005\cchpx86.sys [2011-2-1 501888]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0403000.005\ironx86.sys [2011-2-1 116784]
R1 VET-FILT;VET File System Filter;c:\windows\system32\drivers\Vet-Filt.sys [2006-1-5 21031]
R1 VET-REC;VET File System Recognizer;c:\windows\system32\drivers\Vet-Rec.sys [2006-1-5 15478]
R1 VETEFILE;VET File Scan Engine;c:\windows\system32\drivers\VetEFile.sys [2006-1-5 879832]
R1 VETFDDNT;VET Floppy Boot Sector Monitor;c:\windows\system32\drivers\VetFDDNT.sys [2006-1-5 15735]
R1 VETMONNT;VET File Monitor;c:\windows\system32\drivers\vetmonnt.sys [2006-7-31 26787]
R2 AntiSpywareService;Comcast AntiSpyware;c:\program files\comcasttb\comcastspywarescan\ComcastAntiSpyService.exe [2009-3-16 616408]
R2 N360;Norton Security Suite;c:\program files\norton security suite\engine\4.3.0.5\ccsvchst.exe [2011-2-1 126392]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2011-2-1 102448]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.0.0.127\definitions\ipsdefs\20110228.002\IDSXpx86.sys [2011-3-1 341944]
R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.0.0.127\definitions\virusdefs\20110228.040\NAVENG.SYS [2011-3-1 86008]
R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.0.0.127\definitions\virusdefs\20110228.040\NAVEX15.SYS [2011-3-1 1360760]
R3 VBus;Virtual Bus;c:\windows\system32\drivers\NkVBus.sys [2005-6-17 17664]
R3 VETEBOOT;VET Boot Scan Engine;c:\windows\system32\drivers\VetEBoot.sys [2006-1-5 108360]
S1 bcbus;BestCrypt bus driver;c:\windows\system32\drivers\bcbus.sys –> c:\windows\system32\drivers\bcbus.sys [?]
S2 NkPtpEnumP2;NkPtpEnumP2;c:\program files\nikon\wireless camera setup utility\NkPtpEnum.exe [2005-6-17 24064]
S2 VETMSGNT;VET Message Service;c:\program files\yahoo!\antivirus\vetmsg.exe –> c:\program files\yahoo!\antivirus\VetMsg.exe [?]
S3 krdpdre;krdpdre;\??\c:\docume~1\meowme~1\locals~1\temp\krdpdre.sys –> c:\docume~1\meowme~1\locals~1\temp\krdpdre.sys [?]
S4 CAISafe;CAISafe;c:\program files\yahoo!\antivirus\isafe.exe –> c:\program files\yahoo!\antivirus\ISafe.exe [?]

=============== Created Last 30 ================

2011-02-01 08:58 124,976 a——- c:\windows\system32\drivers\SYMEVENT.SYS
2011-02-01 08:58 60,808 a——- c:\windows\system32\S32EVNT1.DLL
2011-02-01 08:58 7,443 a——- c:\windows\system32\drivers\SYMEVENT.CAT
2011-02-01 08:58 805 a——- c:\windows\system32\drivers\SYMEVENT.INF
2011-02-01 08:58 –d—– c:\program files\Symantec
2011-02-01 08:56 –d—– c:\windows\system32\drivers\N360
2011-02-01 08:55 –d—– c:\program files\Norton Security Suite
2011-02-01 08:47 –d—– c:\program files\NortonInstaller

==================== Find3M ====================

2011-03-01 05:34 2,036 a——- c:\docume~1\meowme~1\applic~1\wklnhst.dat
2011-01-21 08:44 439,296 a——- c:\windows\system32\shimgvw.dll
2011-01-07 08:09 290,048 a——- c:\windows\system32\atmfd.dll
2010-12-31 07:10 1,854,976 a——- c:\windows\system32\win32k.sys
2010-12-22 06:34 301,568 a——- c:\windows\system32\kerberos.dll
2010-12-20 17:59 916,480 a——- c:\windows\system32\wininet.dll
2010-12-20 17:59 43,520 a——- c:\windows\system32\licmgr10.dll
2010-12-20 11:26 730,112 a——- c:\windows\system32\lsasrv.dll
2010-12-09 09:15 718,336 a——- c:\windows\system32\ntdll.dll
2010-12-09 08:30 33,280 a——- c:\windows\system32\csrsrv.dll
2010-12-09 07:42 2,148,864 ——– c:\windows\system32\ntoskrnl.exe
2010-12-09 07:07 2,027,008 ——– c:\windows\system32\ntkrnlpa.exe
2010-08-28 15:45 70,352 a——- c:\docume~1\meowme~1\applic~1\GDIPFONTCACHEV1.DAT
2007-05-17 20:26 20 —-h— c:\docume~1\alluse~1\applic~1\PKP_DLec.DAT
2008-09-01 02:23 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008090120080902\index.dat
2009-05-12 14:20 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009051220090513\index.dat

============= FINISH: 6:07:52.12 ===============
OTL logfile created on: 3/1/2011 6:12:50 AM - Run 1
OTL by OldTimer - Version 3.2.22.2 Folder = C:\Documents and Settings\Meow Meow and Meow\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,023.00 Mb Total Physical Memory | 246.00 Mb Available Physical Memory | 24.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 54.00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0E:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.46 Gb Total Space | 11.20 Gb Free Space | 15.04% Space Free | Partition Type: NTFS
Drive D: | 662.68 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive F: | 149.01 Gb Total Space | 26.04 Gb Free Space | 17.47% Space Free | Partition Type: FAT32

Computer Name: FLYINGPLATYPUS | User Name: Meow Meow and Meow | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Meow Meow and Meow\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe (Trend Micro Inc.)
PRC - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe ()
PRC - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Dantz\Retrospect\wdsvc.exe (Dantz Development Corporation)
PRC - C:\Program Files\Dantz\Retrospect\retrorun.exe (Dantz Development Corporation)
PRC - C:\Program Files\Borland\Interbase\Bin\ibserver.exe (Inprise Corporation)
PRC - C:\Program Files\Borland\Interbase\Bin\ibguard.exe (Inprise Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Meow Meow and Meow\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\asoehook.dll (Symantec Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\microsoft.vc90.crt\msvcr90.dll (Microsoft Corporation)
MOD - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\microsoft.vc90.crt\msvcp90.dll (Microsoft Corporation)
MOD - C:\Program Files\Comcast\Desktop Doctor\bin\sprthook.dll (SupportSoft, Inc.)


========== Win32 Services (SafeList) ==========

SRV - (x10nets) – File not found
SRV - (VETMSGNT) – File not found
SRV - (HidServ) – File not found
SRV - (CAISafe) – File not found
SRV - (AppMgmt) – File not found
SRV - (N360) – C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ccSvcHst.exe (Symantec Corporation)
SRV - (AntiSpywareService) – C:\Program Files\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe ()
SRV - (sprtsvc_ddoctorv2) SupportSoft Sprocket Service (ddoctorv2) – C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (LVSrvLauncher) – C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe (Logitech Inc.)
SRV - (NkPtpEnumP2) – C:\Program Files\Nikon\Wireless Camera Setup Utility\NkPtpEnum.exe (Nikon Corporation)
SRV - (UleadBurningHelper) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
SRV - (RetroWDSvc) – C:\Program Files\Dantz\Retrospect\wdsvc.exe (Dantz Development Corporation)
SRV - (RetroLauncher) – C:\Program Files\Dantz\Retrospect\retrorun.exe (Dantz Development Corporation)
SRV - (InterBaseServer) – C:\Program Files\Borland\Interbase\Bin\IBServer.exe (Inprise Corporation)
SRV - (InterBaseGuardian) – C:\Program Files\Borland\Interbase\Bin\IBGuard.exe (Inprise Corporation)


========== Driver Services (SafeList) ==========

DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20110225.002\BHDrvx86.sys (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (NAVEX15) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20110228.040\NAVEX15.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20110228.040\NAVENG.SYS (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20110228.002\IDSXpx86.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\N360\0403000.005\SYMTDI.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\N360\0403000.005\Ironx86.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\N360\0403000.005\SYMEFA.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\System32\Drivers\N360\0403000.005\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\WINDOWS\system32\drivers\N360\0403000.005\SRTSPX.SYS (Symantec Corporation)
DRV - (ccHP) – C:\WINDOWS\system32\drivers\N360\0403000.005\ccHPx86.sys (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\N360\0403000.005\SYMDS.SYS (Symantec Corporation)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (VETEFILE) – C:\WINDOWS\System32\drivers\VetEFile.sys (Computer Associates International, Inc.)
DRV - (VETEBOOT) – C:\WINDOWS\System32\drivers\VetEBoot.sys (Computer Associates International, Inc.)
DRV - (VETMONNT) – C:\WINDOWS\System32\drivers\vetmonnt.sys (Computer Associates International, Inc.)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (VET-FILT) – C:\WINDOWS\System32\drivers\Vet-Filt.sys (Computer Associates International, Inc.)
DRV - (VETFDDNT) – C:\WINDOWS\System32\drivers\VetFDDNT.sys (Computer Associates International, Inc.)
DRV - (VET-REC) – C:\WINDOWS\System32\drivers\Vet-Rec.sys (Computer Associates International, Inc.)
DRV - (VBus) – C:\WINDOWS\system32\drivers\NkVBus.sys (Nikon Corporation)
DRV - (WinDriver6) – C:\WINDOWS\system32\drivers\windrvr6.sys (Jungo)
DRV - (P16X) Creative SB Live! Series (WDM) – C:\WINDOWS\system32\drivers\P16X.sys (Creative Technology Ltd.)
DRV - (MDC8021X) AEGIS Protocol (IEEE 802.1x) – C:\WINDOWS\system32\drivers\mdc8021x.sys (Meetinghouse Data Communications)
DRV - (ATI Remote Wonder II) – C:\WINDOWS\system32\drivers\atirwvd.sys (Jungo)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (bvrp_pci) – C:\WINDOWS\system32\drivers\bvrp_pci.sys ()
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (PfModNT) – C:\WINDOWS\system32\drivers\PFMODNT.SYS (Creative Technology Ltd.)
DRV - (OMCI) – C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS (Dell Computer Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://red.clientapps.yahoo.com/customize/…/search/ie.html

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr;=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.chicagobears.com/index.html
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Bing"
FF - prefs.js..browser.search.defaulturl: "http://www.bing.com/search?FORM=BO2TDF&PC;=B8MS&q;="
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.chicagobears.com"
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.5.200812101546
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:4.6
FF - prefs.js..keyword.URL: "http://www.bing.com/search?FORM=BO2TDF&PC;=B8MS&q;="

FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\IPSFFPlgn\ [2011/02/01 19:20:57 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\coFFPlgn\ [2011/02/01 09:02:23 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/02/23 18:36:13 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/01/23 08:08:32 | 000,000,000 | —D | M]

[2008/12/08 10:37:00 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Meow Meow and Meow\Application Data\Mozilla\Extensions
[2011/02/28 19:20:56 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Meow Meow and Meow\Application Data\Mozilla\Firefox\Profiles\75p2ovg1.default\extensions
[2009/09/03 06:37:50 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Meow Meow and Meow\Application Data\Mozilla\Firefox\Profiles\75p2ovg1.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/01/24 01:27:37 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\Meow Meow and Meow\Application Data\Mozilla\Firefox\Profiles\75p2ovg1.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009/06/09 20:20:18 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Meow Meow and Meow\Application Data\Mozilla\Firefox\Profiles\75p2ovg1.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/08/12 08:36:00 | 000,001,832 | —- | M] () – C:\Documents and Settings\Meow Meow and Meow\Application Data\Mozilla\Firefox\Profiles\75p2ovg1.default\searchplugins\bing.xml
[2009/06/15 06:30:01 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/02/01 09:02:23 | 000,000,000 | —D | M] (Norton Toolbar) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\COFFPLGN
[2011/02/01 19:20:57 | 000,000,000 | —D | M] (Norton IPS) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\IPSFFPLGN
[2009/01/03 09:40:21 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF

O1 HOSTS File: ([2009/12/22 21:52:51 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Comcast Toolbar) - {79CEEA4E-C231-4614-9E3B-53B2A02F39B7} - C:\Program Files\comcasttb\comcastdx.dll ()
O3 - HKLM\..\Toolbar: (Comcast Toolbar) - {79CEEA4E-C231-4614-9E3B-53B2A02F39B7} - C:\Program Files\comcasttb\comcastdx.dll ()
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [ddoctorv2] C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [Yahoo! Pager] File not found
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil10k_ActiveX.exe (Adobe Systems, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Meow Meow and Meow\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Meow Meow and Meow\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/01/04 23:57:15 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2007/08/14 10:32:04 | 000,000,000 | R–D | M] - D:\Autorun – [ CDFS ]
O32 - AutoRun File - [2007/06/14 17:23:01 | 000,263,744 | R— | M] (Firaxis Games) - D:\autorun.exe – [ CDFS ]
O32 - AutoRun File - [2007/07/17 11:11:01 | 000,006,299 | R— | M] () - D:\autorun.inf – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.ctmp3 - C:\WINDOWS\system32\ctmp3.acm (Creative Technology Ltd.)
Drivers32: msacm.iac2 - C:\WINDOWS\System32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.I420 - lvcodec2.dll File not found
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax ()
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll ()
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (56590025235628032)

========== Files/Folders - Created Within 30 Days ==========

[2011/03/01 06:04:31 | 000,581,120 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Meow Meow and Meow\Desktop\OTL.exe
[2011/03/01 05:57:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Meow Meow and Meow\Desktop\What the Tech Slowness help
[2011/03/01 04:28:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Meow Meow and Meow\Start Menu\Programs\HiJackThis
[2011/02/26 20:49:01 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2011/02/26 20:38:00 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2011/02/10 22:25:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Meow Meow and Meow\My Documents\Donor INfo
[2011/02/05 21:17:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Meow Meow and Meow\My Documents\2010 Taxes
[2011/02/02 13:18:16 | 000,000,000 | R–D | C] – C:\Documents and Settings\Meow Meow and Meow\Start Menu\Programs\Administrative Tools
[2011/02/01 20:28:31 | 000,361,904 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0403000.005\symtdi.sys
[2011/02/01 20:28:31 | 000,339,504 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0403000.005\symtdiv.sys
[2011/02/01 20:28:31 | 000,173,104 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0403000.005\symefa.sys
[2011/02/01 20:28:30 | 000,328,752 | R— | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0403000.005\symds.sys
[2011/02/01 20:28:30 | 000,325,680 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0403000.005\srtsp.sys
[2011/02/01 20:28:30 | 000,043,696 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0403000.005\srtspx.sys
[2011/02/01 20:28:29 | 000,501,888 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0403000.005\cchpx86.sys
[2011/02/01 20:28:29 | 000,116,784 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\N360\0403000.005\ironx86.sys
[2011/02/01 20:27:09 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\N360\0403000.005
[2011/02/01 08:58:24 | 000,124,976 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2011/02/01 08:58:24 | 000,060,808 | —- | C] (Symantec Corporation) – C:\WINDOWS\System32\S32EVNT1.DLL
[2011/02/01 08:58:24 | 000,000,000 | —D | C] – C:\Program Files\Symantec
[2011/02/01 08:56:15 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\N360
[2011/02/01 08:55:54 | 000,000,000 | —D | C] – C:\Program Files\Norton Security Suite
[2011/02/01 08:55:48 | 000,000,000 | —D | C] – C:\Program Files\Windows Sidebar
[2011/02/01 08:55:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Norton Security Suite
[2011/02/01 08:47:21 | 000,000,000 | —D | C] – C:\Program Files\NortonInstaller
[2011/02/01 08:47:20 | 000,000,000 | —D | C] – C:\Documents and Settings\Meow Meow and Meow\My Documents\Symantec
[2011/02/01 08:43:46 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\Norton
[2006/01/05 10:58:57 | 000,065,536 | —- | C] ( ) – C:\WINDOWS\System32\A3d.dll
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/03/01 06:04:54 | 000,359,929 | —- | M] () – C:\Documents and Settings\Meow Meow and Meow\Desktop\dds.scr
[2011/03/01 06:04:28 | 000,581,120 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Meow Meow and Meow\Desktop\OTL.exe
[2011/03/01 05:52:21 | 000,002,473 | —- | M] () – C:\Documents and Settings\Meow Meow and Meow\Desktop\HiJackThis.lnk
[2011/03/01 05:34:28 | 000,002,036 | —- | M] () – C:\Documents and Settings\Meow Meow and Meow\Application Data\wklnhst.dat
[2011/03/01 04:25:13 | 001,402,880 | —- | M] () – C:\Documents and Settings\Meow Meow and Meow\Desktop\HiJackThis.msi
[2011/02/28 22:02:10 | 000,732,736 | —- | M] () – C:\WINDOWS\System32\drivers\N360\0403000.005\Cat.DB
[2011/02/28 01:31:01 | 000,000,292 | —- | M] () – C:\WINDOWS\tasks\Advanced Registry Optimizer.job
[2011/02/26 20:49:04 | 000,001,542 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/02/26 19:47:11 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/02/20 08:35:15 | 000,001,403 | —- | M] () – C:\Documents and Settings\Meow Meow and Meow\My Documents\2210 Start
[2011/02/19 08:40:47 | 000,000,140 | —- | M] () – C:\Documents and Settings\Meow Meow and Meow\Desktop\Invade Earth.url
[2011/02/10 22:30:21 | 000,000,596 | —- | M] () – C:\WINDOWS\DELLSTAT.INI
[2011/02/10 22:20:42 | 000,198,144 | —- | M] () – C:\Documents and Settings\Meow Meow and Meow\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/09 05:37:16 | 000,002,010 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Norton Security Suite.LNK
[2011/02/09 05:35:25 | 000,254,752 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/02/09 05:17:03 | 000,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/02/05 21:18:19 | 000,036,324 | —- | M] () – C:\Documents and Settings\Meow Meow and Meow\My Documents\Daniel Sudten Loan Int 2010.pdf
[2011/02/05 20:44:51 | 000,001,854 | —- | M] () – C:\Documents and Settings\Meow Meow and Meow\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2011/02/05 20:44:50 | 000,001,854 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2011/02/05 20:34:54 | 000,000,629 | —- | M] () – C:\WINDOWS\System32\mapisvc.inf
[2011/02/02 13:34:16 | 000,000,523 | —- | M] () – C:\WINDOWS\Sfc3ng.ini
[2011/02/01 15:00:18 | 000,000,933 | —- | M] () – C:\Documents and Settings\Meow Meow and Meow\Desktop\Play Star Trek New Worlds (2).lnk
[2011/02/01 08:58:24 | 000,124,976 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2011/02/01 08:58:24 | 000,060,808 | —- | M] (Symantec Corporation) – C:\WINDOWS\System32\S32EVNT1.DLL
[2011/02/01 08:58:24 | 000,007,443 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2011/02/01 08:58:24 | 000,000,805 | —- | M] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2011/02/01 08:48:36 | 000,002,577 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2011/02/01 08:43:48 | 000,000,825 | —- | M] () – C:\Documents and Settings\Meow Meow and Meow\Desktop\Norton Installation Files.lnk
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/03/01 06:04:53 | 000,359,929 | —- | C] () – C:\Documents and Settings\Meow Meow and Meow\Desktop\dds.scr
[2011/03/01 04:28:36 | 000,002,473 | —- | C] () – C:\Documents and Settings\Meow Meow and Meow\Desktop\HiJackThis.lnk
[2011/03/01 04:25:12 | 001,402,880 | —- | C] () – C:\Documents and Settings\Meow Meow and Meow\Desktop\HiJackThis.msi
[2011/02/26 20:49:03 | 000,001,542 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/02/20 08:35:05 | 000,001,403 | —- | C] () – C:\Documents and Settings\Meow Meow and Meow\My Documents\2210 Start
[2011/02/19 08:40:47 | 000,000,140 | —- | C] () – C:\Documents and Settings\Meow Meow and Meow\Desktop\Invade Earth.url
[2011/02/09 05:34:44 | 000,732,736 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0403000.005\Cat.DB
[2011/02/05 21:18:19 | 000,036,324 | —- | C] () – C:\Documents and Settings\Meow Meow and Meow\My Documents\Daniel Sudten Loan Int 2010.pdf
[2011/02/01 20:28:31 | 000,007,787 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0403000.005\symnetv.cat
[2011/02/01 20:28:31 | 000,007,368 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0403000.005\symnet.cat
[2011/02/01 20:28:31 | 000,001,473 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0403000.005\symnetv.inf
[2011/02/01 20:28:31 | 000,001,445 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0403000.005\symnet.inf
[2011/02/01 20:28:30 | 000,007,873 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0403000.005\symefa.cat
[2011/02/01 20:28:30 | 000,007,442 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0403000.005\srtspx.cat
[2011/02/01 20:28:30 | 000,007,438 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0403000.005\srtsp.cat
[2011/02/01 20:28:30 | 000,007,425 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0403000.005\symds.cat
[2011/02/01 20:28:30 | 000,003,373 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0403000.005\symefa.inf
[2011/02/01 20:28:30 | 000,002,793 | R— | C] () – C:\WINDOWS\System32\drivers\N360\0403000.005\symds.inf
[2011/02/01 20:28:30 | 000,001,388 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0403000.005\srtspx.inf
[2011/02/01 20:28:30 | 000,001,382 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0403000.005\srtsp.inf
[2011/02/01 20:28:29 | 000,007,438 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0403000.005\iron.cat
[2011/02/01 20:28:29 | 000,007,396 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0403000.005\cchpx86.cat
[2011/02/01 20:28:29 | 000,001,754 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0403000.005\cchpx86.inf
[2011/02/01 20:28:29 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0403000.005\iron.inf
[2011/02/01 20:27:09 | 000,000,172 | —- | C] () – C:\WINDOWS\System32\drivers\N360\0403000.005\isolate.ini
[2011/02/01 15:00:18 | 000,000,933 | —- | C] () – C:\Documents and Settings\Meow Meow and Meow\Desktop\Play Star Trek New Worlds (2).lnk
[2011/02/01 08:58:24 | 000,007,443 | —- | C] () – C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2011/02/01 08:58:24 | 000,000,805 | —- | C] () – C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2011/02/01 08:58:04 | 000,002,010 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Norton Security Suite.LNK
[2011/02/01 08:43:47 | 000,000,825 | —- | C] () – C:\Documents and Settings\Meow Meow and Meow\Desktop\Norton Installation Files.lnk
[2010/03/27 08:32:35 | 000,002,036 | —- | C] () – C:\Documents and Settings\Meow Meow and Meow\Application Data\wklnhst.dat
[2010/03/22 07:24:04 | 000,011,842 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\OIXQ
[2010/03/22 07:24:04 | 000,011,840 | -HS- | C] () – C:\Documents and Settings\Meow Meow and Meow\Local Settings\Application Data\OIXQ
[2010/02/22 20:36:53 | 000,000,092 | —- | C] () – C:\WINDOWS\MFPD.INI
[2009/12/22 21:16:06 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2009/12/22 21:16:06 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2009/12/22 21:16:06 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2009/12/22 21:16:06 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2009/12/22 21:16:06 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2009/11/30 21:40:40 | 000,050,260 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/11/28 16:39:44 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2009/11/28 14:25:42 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2009/07/17 14:27:04 | 000,000,141 | —- | C] () – C:\Documents and Settings\Meow Meow and Meow\Local Settings\Application Data\fusioncache.dat
[2008/11/03 06:52:12 | 000,000,092 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\Ts_infos.ini
[2008/08/24 10:27:59 | 000,087,312 | —- | C] () – C:\WINDOWS\mws.exe
[2008/07/26 10:25:01 | 000,000,165 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2008/05/02 06:24:27 | 000,198,144 | —- | C] () – C:\Documents and Settings\Meow Meow and Meow\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/04/09 02:23:16 | 000,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2008/03/21 10:03:58 | 000,001,070 | —- | C] () – C:\WINDOWS\EF.ini
[2007/12/22 17:00:48 | 000,000,025 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2007/11/27 08:27:11 | 000,035,382 | —- | C] () – C:\WINDOWS\scunin.dat
[2007/08/12 21:52:22 | 000,000,058 | —- | C] () – C:\WINDOWS\tutorial.INI
[2007/08/10 17:17:47 | 000,000,173 | —- | C] () – C:\WINDOWS\srlink.ini
[2007/08/10 17:17:47 | 000,000,040 | —- | C] () – C:\WINDOWS\System32\sx96.ini
[2007/08/10 17:15:33 | 000,021,504 | —- | C] () – C:\WINDOWS\System32\docobj.dll
[2007/01/26 17:53:15 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2007/01/25 22:14:26 | 000,000,245 | —- | C] () – C:\WINDOWS\PowerReg.dat
[2007/01/13 19:53:41 | 000,520,192 | —- | C] () – C:\WINDOWS\System32\ati2sgag.exe
[2006/12/02 17:55:30 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2006/05/25 00:22:06 | 000,053,248 | —- | C] () – C:\WINDOWS\bdoscandel.exe
[2006/04/29 13:38:31 | 000,003,077 | —- | C] () – C:\WINDOWS\mozver.dat
[2006/04/28 14:05:14 | 000,127,614 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2006/03/11 22:29:56 | 000,000,523 | —- | C] () – C:\WINDOWS\Sfc3ng.ini
[2006/02/24 17:32:36 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/02/20 22:32:36 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2006/01/30 19:11:48 | 000,000,020 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
[2006/01/25 00:09:43 | 000,000,000 | —- | C] () – C:\WINDOWS\ATIMMC.INI
[2006/01/21 16:16:43 | 000,002,572 | —- | C] () – C:\WINDOWS\MIXDEF.INI
[2006/01/21 00:15:38 | 000,001,008 | —- | C] () – C:\WINDOWS\STA2.ini
[2006/01/05 12:36:57 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2006/01/05 11:17:01 | 000,000,325 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/01/05 10:59:13 | 000,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2006/01/05 10:59:12 | 001,048,576 | —- | C] () – C:\WINDOWS\System32\SFMAN.DAT
[2006/01/05 10:58:58 | 000,002,516 | —- | C] () – C:\WINDOWS\System32\P16X.ini
[2006/01/05 10:58:58 | 000,000,026 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2006/01/05 10:58:57 | 000,047,616 | —- | C] () – C:\WINDOWS\System32\P16X.dll
[2006/01/05 10:58:54 | 000,000,064 | —- | C] () – C:\WINDOWS\P16x.ini
[2006/01/05 10:58:07 | 000,000,245 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2006/01/05 01:16:03 | 000,000,596 | —- | C] () – C:\WINDOWS\DELLSTAT.INI
[2006/01/05 01:15:48 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\dlbavs.dll
[2006/01/05 01:15:30 | 000,000,177 | —- | C] () – C:\WINDOWS\System32\dlbacoin.ini
[2006/01/05 00:58:10 | 000,004,272 | R— | C] () – C:\WINDOWS\System32\drivers\bvrp_pci.sys
[2006/01/05 00:27:07 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\YCRWin32.dll
[2006/01/05 00:02:58 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2006/01/04 23:54:55 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2006/01/04 17:31:09 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2006/01/04 17:30:11 | 000,254,752 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/03/01 14:30:20 | 000,000,453 | —- | C] () – C:\WINDOWS\bdoscandellang.ini
[2004/01/28 11:42:06 | 000,013,601 | —- | C] () – C:\WINDOWS\System32\vctest.ini
[2003/11/20 15:39:58 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2003/07/16 14:54:55 | 000,004,594 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2003/07/16 14:54:54 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2003/07/16 14:41:25 | 000,441,552 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2003/07/16 14:41:25 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2003/07/16 14:41:23 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2003/07/16 14:41:21 | 000,071,488 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2003/07/16 14:39:07 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2003/07/16 14:33:50 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2003/07/16 14:33:39 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2003/07/16 14:27:41 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2003/07/16 14:26:37 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2003/07/14 13:30:28 | 000,197,120 | —- | C] () – C:\WINDOWS\patchw32.dll
[2002/11/14 12:58:04 | 000,200,192 | —- | C] () – C:\WINDOWS\System32\ir50_qc.dll
[2002/11/14 12:58:04 | 000,183,808 | —- | C] () – C:\WINDOWS\System32\ir50_qcx.dll
[2002/11/14 12:58:02 | 000,755,200 | —- | C] () – C:\WINDOWS\System32\ir50_32.dll
[2002/11/14 12:58:02 | 000,338,432 | —- | C] () – C:\WINDOWS\System32\ir41_qcx.dll
[2002/11/14 12:58:02 | 000,120,320 | —- | C] () – C:\WINDOWS\System32\ir41_qc.dll
[2000/11/10 14:57:04 | 000,005,025 | —- | C] () – C:\WINDOWS\System32\patterns.dat

========== LOP Check ==========

[2006/01/05 01:16:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2006/12/14 17:29:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CA
[2009/05/27 04:46:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Comcast
[2011/01/28 00:02:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\dIjIiCd05200
[2006/01/30 19:11:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2008/04/29 06:14:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2009/11/28 15:24:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iPodtoComputer
[2010/02/22 20:30:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\JoyFaxClient
[2010/02/22 20:13:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\JoyFaxServer
[2010/04/03 12:00:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RegCure
[2008/12/09 08:01:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Retrospect
[2007/08/10 17:15:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2007/10/27 11:47:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2009/05/09 07:21:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2007/10/21 13:31:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/07/18 07:09:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\The Generations Network
[2006/01/30 19:11:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2007/11/27 08:18:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/03/15 06:08:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2010/04/17 08:11:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/09/19 19:16:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/04/11 18:58:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2007/11/21 21:08:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Meow Meow and Meow\Application Data\acccore
[2009/05/13 18:27:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Meow Meow and Meow\Application Data\AVGTOOLBAR
[2009/07/18 06:03:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Meow Meow and Meow\Application Data\comcasttb
[2009/06/20 13:11:35 | 000,000,000 | —D | M] – C:\Documents and Settings\Meow Meow and Meow\Application Data\ComcastToolbar
[2008/11/11 07:12:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Meow Meow and Meow\Application Data\FxFotoDB
[2007/10/27 11:49:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Meow Meow and Meow\Application Data\Grisoft
[2008/11/04 06:59:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Meow Meow and Meow\Application Data\gtk-2.0
[2008/11/04 06:57:01 | 000,000,000 | —D | M] – C:\Documents and Settings\Meow Meow and Meow\Application Data\Inkscape
[2008/08/24 10:27:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Meow Meow and Meow\Application Data\InterVideo
[2009/08/22 18:59:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Meow Meow and Meow\Application Data\iPod Copy Expert
[2009/07/18 07:09:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Meow Meow and Meow\Application Data\KeyingTool
[2006/03/16 20:58:17 | 000,000,000 | —D | M] – C:\Documents and Settings\Meow Meow and Meow\Application Data\Leadertech
[2006/01/05 19:11:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Meow Meow and Meow\Application Data\My Games
[2006/01/30 19:12:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Meow Meow and Meow\Application Data\Nikon
[2006/06/07 21:52:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Meow Meow and Meow\Application Data\Registry Booster
[2011/02/02 13:21:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Meow Meow and Meow\Application Data\Sammsoft
[2007/08/10 17:15:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Meow Meow and Meow\Application Data\ScanSoft
[2006/06/20 22:33:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Meow Meow and Meow\Application Data\System-Xf.{21EC2020-3AEA-1069-A2DD-08002B30309D}
[2006/07/14 06:28:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Meow Meow and Meow\Application Data\X10 Commander
[2011/02/28 01:31:01 | 000,000,292 | —- | M] () – C:\WINDOWS\Tasks\Advanced Registry Optimizer.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2009/07/17 11:50:25 | 000,001,131 | —- | M] () – C:\AA create new user.txt
[2006/01/04 23:57:15 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/05/13 20:17:23 | 000,000,211 | —- | M] () – C:\Boot.bak
[2009/05/20 19:38:02 | 000,000,281 | -HS- | M] () – C:\boot.ini
[2004/08/03 22:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2010/10/01 18:47:15 | 000,014,732 | —- | M] () – C:\ComboFix.txt
[2006/01/04 23:57:15 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2006/01/04 23:57:15 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/06/27 10:05:41 | 000,026,714 | —- | M] () – C:\kiwee-im-muggin.exe
[2006/01/04 23:57:15 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2006/01/05 12:53:01 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/08/31 06:31:36 | 000,250,048 | RHS- | M] () – C:\ntldr
[2004/02/23 03:31:13 | 1609,035,776 | -HS- | M] () – C:\pagefile.sys
[2011/02/02 14:41:21 | 000,000,150 | —- | M] () – C:\YServer.txt

< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/02 17:54:15 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2003/02/05 09:06:16 | 000,077,824 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\DLBAPP5C.DLL
[2008/07/06 06:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 04:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
[2002/05/14 16:50:34 | 000,011,264 | —- | M] (BVRP Software) – C:\WINDOWS\system32\spool\prtprocs\w32x86\wfxprint2000.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2008/12/17 23:24:56 | 000,001,706 | -H– | M] () – C:\Documents and Settings\Meow Meow and Meow\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2006/01/04 17:29:35 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2006/01/04 17:29:35 | 000,602,112 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2006/01/04 17:29:35 | 000,409,600 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/08/31 06:41:04 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/06/02 17:54:35 | 000,000,177 | -HS- | M] () – C:\Documents and Settings\Meow Meow and Meow\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2006/01/05 00:07:25 | 000,000,079 | —- | M] () – C:\Documents and Settings\Meow Meow and Meow\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2007/10/21 17:48:58 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Meow Meow and Meow\Desktop\ATF-Cleaner.exe
[2004/02/23 10:14:57 | 007,734,240 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Meow Meow and Meow\Desktop\mbam-setup.exe
[2011/03/01 06:04:28 | 000,581,120 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Meow Meow and Meow\Desktop\OTL.exe
[2000/02/24 17:26:40 | 001,425,408 | —- | M] (Deep Red Games Ltd) – C:\Documents and Settings\Meow Meow and Meow\Desktop\RiskII.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2004-02-23 10:10:04

========== Alternate Data Streams ==========

@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2

< End of report >
:blush:

OTL Extras logfile created on: 3/1/2011 6:12:50 AM - Run 1
OTL by OldTimer - Version 3.2.22.2 Folder = C:\Documents and Settings\Meow Meow and Meow\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,023.00 Mb Total Physical Memory | 246.00 Mb Available Physical Memory | 24.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 54.00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0E:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.46 Gb Total Space | 11.20 Gb Free Space | 15.04% Space Free | Partition Type: NTFS
Drive D: | 662.68 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive F: | 149.01 Gb Total Space | 26.04 Gb Free Space | 17.47% Space Free | Partition Type: FAT32

Computer Name: FLYINGPLATYPUS | User Name: Meow Meow and Meow | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"c:\Program Files\Yahoo!\Messenger\yserver.exe" = C:\Program Files\Yahoo!\Messenger\yserver.exe:*:Enabled:Yahoo! FT Server
"C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Civilization4.exe" = C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Civilization4.exe:*:Enabled:Sid Meier's Civilization 4 – (Firaxis Games)
"C:\Program Files\Activision\Star Trek Armada II\Armada2.exe" = C:\Program Files\Activision\Star Trek Armada II\Armada2.exe:*:Disabled:Star Trek Armada 2 – (Activision)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader – (AOL LLC)
"C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Beyond the Sword\Civ4BeyondSword.exe" = C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Beyond the Sword\Civ4BeyondSword.exe:*:Enabled:Sid Meier's Civilization 4 Beyond the Sword – (Firaxis Games)
"C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Beyond the Sword\Civ4BeyondSword_PitBoss.exe" = C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Beyond the Sword\Civ4BeyondSword_PitBoss.exe:*:Enabled:Sid Meier's Civilization 4 Beyond the Sword Pitboss – (Firaxis Games)
"C:\Program Files\Raven\Star Trek Voyager Elite Force\stvoyHM.exe" = C:\Program Files\Raven\Star Trek Voyager Elite Force\stvoyHM.exe:*:Disabled:stvoyHM – ()
"C:\Program Files\Alwil Software\Avast4\ashDisp.exe" = C:\Program Files\Alwil Software\Avast4\ashDisp.exe:*:Enabled:ashDisp


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02F6993D-B763-4F40-8F93-2A9CD97586E3}" = Microsoft IntelliType Pro 6.3
"{04410044-9149-45C6-A806-F2BF9CFCE762}" = Microsoft Encarta Encyclopedia Standard 2004
"{083F79E4-6FE9-46FB-A6C6-4F8862742947}" = ATI HYDRAVISION
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}" = OpenOffice.org Installer 1.0
"{0EE11800-A1BD-11D3-BFEB-005004AF2D32}" = Risk II
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{1EECBA68-8BE4-4076-94DF-E9ED206B1D21}" = Star Wars Jedi Knight Jedi Academy
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 11
"{2CCBABCB-6427-4A55-B091-49864623C43F}" = Google Toolbar for Firefox
"{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}" = Rhapsody Player Engine
"{32E4F0D2-C135-475E-A841-1D59A0D22989}" = Sid Meier's Civilization 4 - Beyond the Sword
"{3347F781-9C89-4C9B-B471-B1FFC3BC4A84}" = ATIRW2
"{33BEE6F3-9987-4F98-A069-97A64EC8321A}" = Microsoft Works Suite Add-in for Microsoft Word
"{34F0D55F-C386-4195-9A5B-961D3F6ACD46}" = InterVideo MediaOne Gallery
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35725FBC-A136-4A46-9F29-091759D9BB93}" = MVision
"{3B0F52AC-EF5C-4831-B221-06C782E41280}" = Quicken 2008
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{410438A3-B591-4028-B70A-3CC0B33FBCD1}" =
"{429AFF0D-03A4-4602-A896-0881EA169F1F}" = Ancestry World Archives Project - Keying Tool
"{4468EF97-A253-4699-9E1C-88CAE2C6832D}" = ABBYY FineReader 5.0 Sprint
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}" = Adobe® Photoshop® Album Starter Edition 3.0
"{54AE3C08-D7D8-45FF-9348-0B4BE0D5A6CB}" = Comcast Universal Installer v1.2
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5BF5F9C5-E95B-4AFA-94BE-F2A9CA73B61D}" = Apple Mobile Device Support
"{5E835305-63BB-4E55-BBB7-EEBBE67774DB}" = Sonic MyDVD
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{634EC9A4-FEF1-11D7-A65F-18181164CC00}" = BalanceLog
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{6675E71B-9843-4971-BC15-18AB52801134}" = Dragon NaturallySpeaking 7.3
"{66A9D30D-1464-4C7F-B2F3-507DADAF2595}" = Microsoft IntelliPoint 6.3
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6B9B0C6F-E5FA-4633-A640-AB98A272ECCA}" = Safari
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73B69C5C-87D6-471E-B695-0BD736C4B644}" = Retrospect 6.5
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{8988F5D0-C83F-41F4-B41B-86031F9B37F5}" = ATI Multimedia Center
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{911B0409-6000-11D3-8CFE-0050048383C9}" = Microsoft Word 2002
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{96E16100-A77F-4B31-B9AD-FFBA040EE1BD}" = Sound Blaster Live!
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5F68DC8-0278-4AD8-B413-861509B5F25B}" = ArcSoft Panorama Maker 3
"{A71D5E81-B967-43DB-93D7-FD31BFB95748}" = MobileMe Control Panel
"{A8589680-35C1-4732-ACCA-09B78921ECE3}" = Sid Meier's Civilization 4
"{AA0A1531-C625-4B1D-A3FA-273A181B017B}" = Wireless Camera Setup Utility
"{AAD47011-8518-4608-9656-951DA35B587B}" = iTunes
"{AC76BA86-7AD7-1033-7B44-A70900000002}" = Adobe Reader 7.0.9
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser
"{B9966F27-9678-4620-9579-925E3084647E}" = Microsoft Works
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BEF726DD-4037-4214-8C6A-E625C02D2870}" = Logitech Audio Echo Cancellation Component
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CFBCE791-2D53-4FCE-B3FB-D6E01F4112E8}" = Sid Meier's Civilization 4
"{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}" = Nikon Message Center
"{D596980D-17BE-4425-B8F0-5640719AADE9}" = LEGO® Star Wars™: The Complete Saga
"{D78653C3-A8FF-415F-92E6-D774E634FF2D}" = Dell ResourceCD
"{D87149B3-7A1D-4548-9CBF-032B791E5908}" = Desktop Doctor
"{DBA8B9E1-C6FF-4624-9598-73D3B41A0903}" = Microsoft Picture It! Photo Premium 9
"{DBCC73BA-C69A-4BF5-B4BF-F07501EE7039}" = AnswerWorks 5.0 English Runtime
"{DCFD26A8-60A5-4C69-A52D-264D0386FDB3}" = Microsoft Xbox 360 Accessories 1.2
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{EA516024-D84D-41F1-814F-83175A6188F2}" = Logitech Video Enumerator
"{EA9FAF16-0E5C-42C4-9742-9AF8D5F6D69B}" = ATI Catalyst Control Center
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{F45298E5-0083-426F-A668-1A2C5F04B8A0}" = FaxTools
"{FA54AFB1-5745-4389-B8C1-9F7509672ED1}" = iPhone Configuration Utility
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"{FF3999BE-1A7B-4738-88AA-97BF14094A4A}" = PictureProject
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"All ATI Software" = ATI - Software Uninstall Utility
"ATI Display Driver" = ATI Display Driver
"AudibleManager" = AudibleManager
"CNXT_MODEM_PCI_VEN_14F1&DEV_2702" = Conexant SmartHSFi V.9x 56K DF PCI Modem
"ComcastHSI" = Comcast High-Speed Internet Install Wizard
"comcasttb" = Comcast Toolbar 3.0
"Continuum_is1" = Continuum 0.40
"Cucusoft iPhone/iTouch/iPod to Computer Transfer_is1" = iPhone/iTouch/iPod to Computer Transfer 5.8.1
"Dell AIO Printer A940" = Dell AIO Printer A940
"Digital Camera Driver" = Digital Camera Driver
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DivX Setup.divx.com" = DivX Setup
"Homeworld2" = Homeworld2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{3347F781-9C89-4C9B-B471-B1FFC3BC4A84}" = ATI Remote Wonder 2.3
"InstallShield_{8988F5D0-C83F-41F4-B41B-86031F9B37F5}" = ATI Multimedia Center 9.01
"InstallShield_{D596980D-17BE-4425-B8F0-5640719AADE9}" = LEGO® Star Wars™: The Complete Saga
"iPod To Computer Transfer_is1" = iPod To Computer Transfer 5.5
"legacyqcam_10.50" = Logitech Legacy USB Camera Driver Package
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"N360" = Norton Security Suite
"NewWrlds" = NewWrlds
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"PictureIt_v9" = Microsoft Picture It! Photo Premium 9
"PictureProject In Touch Downloader" = PictureProject In Touch Downloader 1.0
"PROSet" = Intel® PRO Network Connections Drivers
"SpywareBlaster_is1" = SpywareBlaster v2.5.2
"Star Trek Armada II" = Star Trek Armada II
"Star Trek Voyager Elite Force" = Star Trek Voyager Elite Force
"Starcraft" = Starcraft
"The Sudoku Challenge-retail" = The Sudoku Challenge
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"WIC" = Windows Imaging Component
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMCSetup" = Windows Media Connect
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Works2004Setup" = Microsoft Works 2004 Setup Launcher
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Yahoo! Applications" = AT&T Yahoo! Applications
"Yahoo! Extras" = Yahoo! Browser Services
"Yahoo! Toolbar" = Yahoo! Toolbar

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Yahoo! BrowserPlus" = Yahoo! BrowserPlus 2.9.8

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/25/2004 9:06:14 PM | Computer Name = FLYINGPLATYPUS | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 2/25/2004 9:06:14 PM | Computer Name = FLYINGPLATYPUS | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file.

Error - 2/24/2011 7:22:01 PM | Computer Name = FLYINGPLATYPUS | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2/24/2011 7:23:43 PM | Computer Name = FLYINGPLATYPUS | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2/24/2011 7:23:58 PM | Computer Name = FLYINGPLATYPUS | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2/28/2011 12:44:48 AM | Computer Name = FLYINGPLATYPUS | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2/28/2011 12:45:50 AM | Computer Name = FLYINGPLATYPUS | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2/28/2011 1:11:50 AM | Computer Name = FLYINGPLATYPUS | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 3/1/2011 1:53:13 AM | Computer Name = FLYINGPLATYPUS | Source = Application Hang | ID = 1002
Description = Hanging application WINWORD.EXE, version 10.0.6866.0, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 3/1/2011 8:04:27 AM | Computer Name = FLYINGPLATYPUS | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 2/18/2011 11:05:55 PM | Computer Name = FLYINGPLATYPUS | Source = Service Control Manager | ID = 7023
Description = The HID Input Service service terminated with the following error:
%%126

Error - 2/18/2011 11:05:55 PM | Computer Name = FLYINGPLATYPUS | Source = Service Control Manager | ID = 7001
Description = The VET Message Service service depends on the CAISafe service which
failed to start because of the following error: %%1058

Error - 2/23/2004 5:32:57 AM | Computer Name = FLYINGPLATYPUS | Source = Service Control Manager | ID = 7023
Description = The HID Input Service service terminated with the following error:
%%126

Error - 2/23/2004 5:32:57 AM | Computer Name = FLYINGPLATYPUS | Source = Service Control Manager | ID = 7001
Description = The VET Message Service service depends on the CAISafe service which
failed to start because of the following error: %%1058

Error - 2/23/2004 5:49:51 AM | Computer Name = FLYINGPLATYPUS | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the N360 service.

Error - 2/23/2004 5:50:22 AM | Computer Name = FLYINGPLATYPUS | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the N360 service.

Error - 2/25/2004 5:36:41 AM | Computer Name = FLYINGPLATYPUS | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.

Error - 2/23/2011 9:48:03 PM | Computer Name = FLYINGPLATYPUS | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.

Error - 2/24/2011 7:22:38 PM | Computer Name = FLYINGPLATYPUS | Source = Service Control Manager | ID = 7034
Description = The NkPtpEnumP2 service terminated unexpectedly. It has done this
1 time(s).

Error - 2/26/2011 7:48:46 PM | Computer Name = FLYINGPLATYPUS | Source = Service Control Manager | ID = 7034
Description = The Ati HotKey Poller service terminated unexpectedly. It has done
this 1 time(s).


< End of report >
Hi, welcome to the WTT Forums. My username is Raktor, and I would be glad to help you with your malware issues. I'd be grateful if you would note the following:

  • Absence of symptoms does not always mean the computer is clean
  • Please do not run any scans or fixes without my direction.
  • Finally, stay with this topic until I give you the final 'All clear' post.

What anti-virus software are you actively using? You have switched to the Comcast provided program, but I still see signs of Norton, and VET by Computer Associates. I believe this is what is causing the conflict; can both of these be removed? :)
We'll remove it manually.

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
    O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
    
    :Services
    VETMSGNT
    CAISafe
    VETEFILE
    VETEBOOT
    VETMONNT
    VET-FILT
    VETFDDNT
    VET-REC
    
    :Commands
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
I ran OTL with the above script. It tried to reboot at the end but got hung up, i had to tell the comp to reboot through task manager. Then the internet wasn't working. I took a long time to get it back online. I had to run the fix connection utility to get it back online. OTL didn't automatically post a log. I looked in the OTL folder and it just had a moved files folder. Would the log be in a different spot?
A copy of the removal log should be saved in C:\_OTL\Moved Files\ as a text file. Could you also rerun an OTL scan like we did at the beginning please, so I get the long OTL output.
Here's the log from the OTL rerun.

What does this log entry near the end of the list mean?
2006/01/05 00:58:10 | 000,004,272 | R— | C] () – C:\WINDOWS\System32\drivers\bvrp_pci.sys

About a year ago when i tried to fix a few things on my comp my fax software, "bvrp" stopped working. It will launch, I can go through all the steps, but when you try to send it doesn't initialize. Does this entry mean anything related to this?

Do you know anyway to get it to work again. (it's not on any of the system disks i got when i bought the comp)

Thanks!

OTL logfile created on: 3/7/2011 10:10:40 PM - Run 2
OTL by OldTimer - Version 3.2.22.2 Folder = C:\Documents and Settings\Meow Meow and Meow\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1,023.00 Mb Total Physical Memory | 366.00 Mb Available Physical Memory | 36.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 64.00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0E:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.46 Gb Total Space | 9.29 Gb Free Space | 12.48% Space Free | Partition Type: NTFS
Drive F: | 149.01 Gb Total Space | 26.03 Gb Free Space | 17.47% Space Free | Partition Type: FAT32

Computer Name: FLYINGPLATYPUS | User Name: Meow Meow and Meow | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Meow Meow and Meow\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe ()
PRC - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Nikon\Wireless Camera Setup Utility\NkPtpEnum.exe (Nikon Corporation)
PRC - C:\Program Files\Dantz\Retrospect\wdsvc.exe (Dantz Development Corporation)
PRC - C:\Program Files\Dantz\Retrospect\retrorun.exe (Dantz Development Corporation)
PRC - C:\Program Files\Borland\Interbase\Bin\ibserver.exe (Inprise Corporation)
PRC - C:\Program Files\Borland\Interbase\Bin\ibguard.exe (Inprise Corporation)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Meow Meow and Meow\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\asoehook.dll (Symantec Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll (Microsoft Corporation)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll (Microsoft Corporation)
MOD - C:\Program Files\Comcast\Desktop Doctor\bin\sprthook.dll (SupportSoft, Inc.)


========== Win32 Services (SafeList) ==========

SRV - (x10nets) – File not found
SRV - (HidServ) – File not found
SRV - (AppMgmt) – File not found
SRV - (N360) – C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ccSvcHst.exe (Symantec Corporation)
SRV - (AntiSpywareService) – C:\Program Files\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe ()
SRV - (sprtsvc_ddoctorv2) SupportSoft Sprocket Service (ddoctorv2) – C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (LVSrvLauncher) – C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe (Logitech Inc.)
SRV - (NkPtpEnumP2) – C:\Program Files\Nikon\Wireless Camera Setup Utility\NkPtpEnum.exe (Nikon Corporation)
SRV - (UleadBurningHelper) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
SRV - (RetroWDSvc) – C:\Program Files\Dantz\Retrospect\wdsvc.exe (Dantz Development Corporation)
SRV - (RetroLauncher) – C:\Program Files\Dantz\Retrospect\retrorun.exe (Dantz Development Corporation)
SRV - (InterBaseServer) – C:\Program Files\Borland\Interbase\Bin\IBServer.exe (Inprise Corporation)
SRV - (InterBaseGuardian) – C:\Program Files\Borland\Interbase\Bin\IBGuard.exe (Inprise Corporation)


========== Driver Services (SafeList) ==========

DRV - (BHDrvx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\BASHDefs\20110225.002\BHDrvx86.sys (Symantec Corporation)
DRV - (SymEvent) – C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (NAVEX15) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20110306.002\NAVEX15.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVENG) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\VirusDefs\20110306.002\NAVENG.SYS (Symantec Corporation)
DRV - (IDSxpx86) – C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\Definitions\IPSDefs\20110303.001\IDSXpx86.sys (Symantec Corporation)
DRV - (SYMTDI) – C:\WINDOWS\System32\Drivers\N360\0403000.005\SYMTDI.SYS (Symantec Corporation)
DRV - (SymIRON) – C:\WINDOWS\system32\drivers\N360\0403000.005\Ironx86.SYS (Symantec Corporation)
DRV - (SymEFA) – C:\WINDOWS\system32\drivers\N360\0403000.005\SYMEFA.SYS (Symantec Corporation)
DRV - (SRTSP) – C:\WINDOWS\System32\Drivers\N360\0403000.005\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\WINDOWS\system32\drivers\N360\0403000.005\SRTSPX.SYS (Symantec Corporation)
DRV - (ccHP) – C:\WINDOWS\system32\drivers\N360\0403000.005\ccHPx86.sys (Symantec Corporation)
DRV - (SymDS) – C:\WINDOWS\system32\drivers\N360\0403000.005\SYMDS.SYS (Symantec Corporation)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (VET-FILT) – C:\WINDOWS\System32\drivers\Vet-Filt.sys (Computer Associates International, Inc.)
DRV - (VETFDDNT) – C:\WINDOWS\System32\drivers\VetFDDNT.sys (Computer Associates International, Inc.)
DRV - (VET-REC) – C:\WINDOWS\System32\drivers\Vet-Rec.sys (Computer Associates International, Inc.)
DRV - (VBus) – C:\WINDOWS\system32\drivers\NkVBus.sys (Nikon Corporation)
DRV - (WinDriver6) – C:\WINDOWS\system32\drivers\windrvr6.sys (Jungo)
DRV - (P16X) Creative SB Live! Series (WDM) – C:\WINDOWS\system32\drivers\P16X.sys (Creative Technology Ltd.)
DRV - (MDC8021X) AEGIS Protocol (IEEE 802.1x) – C:\WINDOWS\system32\drivers\mdc8021x.sys (Meetinghouse Data Communications)
DRV - (ATI Remote Wonder II) – C:\WINDOWS\system32\drivers\atirwvd.sys (Jungo)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (bvrp_pci) – C:\WINDOWS\system32\drivers\bvrp_pci.sys ()
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (krdpdre) – C:\Documents and Settings\Meow Meow and Meow\Local Settings\temp\krdpdre.sys ()
DRV - (PfModNT) – C:\WINDOWS\system32\drivers\PFMODNT.SYS (Creative Technology Ltd.)
DRV - (OMCI) – C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS (Dell Computer Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://red.clientapps.yahoo.com/customize/…/search/ie.html

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr;=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.chicagobears.com/index.html
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Bing"
FF - prefs.js..browser.search.defaulturl: "http://www.bing.com/search?FORM=BO2TDF&PC;=B8MS&q;="
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.chicagobears.com"
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.5.200812101546
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:4.6
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..keyword.URL: "http://www.bing.com/search?FORM=BO2TDF&PC;=B8MS&q;="

FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\IPSFFPlgn\ [2011/02/01 19:20:57 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\coFFPlgn\ [2011/02/01 09:02:23 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/02/23 18:36:13 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/05 19:10:26 | 000,000,000 | —D | M]

[2008/12/08 10:37:00 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Meow Meow and Meow\Application Data\Mozilla\Extensions
[2011/03/07 05:25:45 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Meow Meow and Meow\Application Data\Mozilla\Firefox\Profiles\75p2ovg1.default\extensions
[2009/09/03 06:37:50 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Meow Meow and Meow\Application Data\Mozilla\Firefox\Profiles\75p2ovg1.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/01/24 01:27:37 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\Meow Meow and Meow\Application Data\Mozilla\Firefox\Profiles\75p2ovg1.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009/06/09 20:20:18 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Meow Meow and Meow\Application Data\Mozilla\Firefox\Profiles\75p2ovg1.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/08/12 08:36:00 | 000,001,832 | —- | M] () – C:\Documents and Settings\Meow Meow and Meow\Application Data\Mozilla\Firefox\Profiles\75p2ovg1.default\searchplugins\bing.xml
[2011/03/07 05:25:45 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/03/05 19:10:35 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/02/01 09:02:23 | 000,000,000 | —D | M] (Norton Toolbar) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\COFFPLGN
[2011/02/01 19:20:57 | 000,000,000 | —D | M] (Norton IPS) – C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.0.0.127\IPSFFPLGN
[2011/03/05 19:09:25 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/03/05 19:09:19 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2009/12/22 21:52:51 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Comcast Toolbar) - {79CEEA4E-C231-4614-9E3B-53B2A02F39B7} - C:\Program Files\comcasttb\comcastdx.dll ()
O3 - HKLM\..\Toolbar: (Comcast Toolbar) - {79CEEA4E-C231-4614-9E3B-53B2A02F39B7} - C:\Program Files\comcasttb\comcastdx.dll ()
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Security Suite\Engine\4.3.0.5\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [ddoctorv2] C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [Yahoo! Pager] File not found
O4 - Startup: C:\Documents and Settings\Meow Meow and Meow\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Meow Meow and Meow\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Meow Meow and Meow\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/01/04 23:57:15 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/03/06 11:17:36 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2011/03/06 01:43:12 | 000,000,000 | —D | C] – C:\_OTL
[2011/03/05 19:51:28 | 000,000,000 | —D | C] – C:\Documents and Settings\Meow Meow and Meow\Application Data\OpenOffice.org
[2011/03/05 19:17:19 | 000,000,000 | –SD | C] – C:\Documents and Settings\All Users\Start Menu\Programs\OpenOffice.org 3.3
[2011/03/05 19:12:38 | 000,000,000 | —D | C] – C:\Program Files\OpenOffice.org 3
[2011/03/05 19:11:16 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2011/03/05 19:10:26 | 000,472,808 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2011/03/05 19:10:26 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/03/05 19:10:26 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/03/05 19:10:26 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2011/03/05 19:10:25 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/03/05 18:38:01 | 000,000,000 | —D | C] – C:\Documents and Settings\Meow Meow and Meow\Desktop\OpenOffice.org 3.3 (en-US) Installation Files
[2011/03/03 14:57:39 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2011/03/01 06:04:31 | 000,581,120 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Meow Meow and Meow\Desktop\OTL.exe
[2011/03/01 05:57:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Meow Meow and Meow\Desktop\What the Tech Slowness help
[2011/03/01 04:28:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Meow Meow and Meow\Start Menu\Programs\HiJackThis
[2011/02/10 22:25:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Meow Meow and Meow\My Documents\Donor INfo
[2006/01/05 10:58:57 | 000,065,536 | —- | C] ( ) – C:\WINDOWS\System32\A3d.dll
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/03/07 01:31:00 | 000,000,292 | —- | M] () – C:\WINDOWS\tasks\Advanced Registry Optimizer.job
[2011/03/06 19:31:26 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/03/06 03:54:41 | 000,043,520 | —- | M] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2011/03/06 02:13:50 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/03/06 01:48:44 | 000,281,816 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/03/05 20:03:10 | 000,031,626 | —- | M] () – C:\Documents and Settings\Meow Meow and Meow\Desktop\notification project.ods
[2011/03/05 19:58:34 | 000,000,864 | —- | M] () – C:\Documents and Settings\Meow Meow and Meow\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
[2011/03/05 19:47:23 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/03/05 19:17:28 | 000,000,885 | —- | M] () – C:\Documents and Settings\All Users\Desktop\OpenOffice.org 3.3.lnk
[2011/03/05 19:09:14 | 000,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/03/05 19:09:14 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/03/05 19:09:14 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/03/05 19:09:14 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2011/03/05 19:09:11 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2011/03/03 14:57:40 | 000,001,542 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/03/03 14:45:23 | 000,733,008 | —- | M] () – C:\WINDOWS\System32\drivers\N360\0403000.005\Cat.DB
[2011/03/02 06:15:33 | 000,002,260 | —- | M] () – C:\Documents and Settings\Meow Meow and Meow\Application Data\wklnhst.dat
[2011/03/01 06:04:54 | 000,359,929 | —- | M] () – C:\Documents and Settings\Meow Meow and Meow\Desktop\dds.scr
[2011/03/01 06:04:28 | 000,581,120 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Meow Meow and Meow\Desktop\OTL.exe
[2011/03/01 05:52:21 | 000,002,473 | —- | M] () – C:\Documents and Settings\Meow Meow and Meow\Desktop\HiJackThis.lnk
[2011/03/01 04:25:13 | 001,402,880 | —- | M] () – C:\Documents and Settings\Meow Meow and Meow\Desktop\HiJackThis.msi
[2011/02/20 08:35:15 | 000,001,403 | —- | M] () – C:\Documents and Settings\Meow Meow and Meow\My Documents\2210 Start
[2011/02/19 08:40:47 | 000,000,140 | —- | M] () – C:\Documents and Settings\Meow Meow and Meow\Desktop\Invade Earth.url
[2011/02/18 16:36:58 | 004,184,352 | —- | M] (Apple, Inc.) – C:\WINDOWS\System32\usbaaplrc.dll
[2011/02/10 22:30:21 | 000,000,596 | —- | M] () – C:\WINDOWS\DELLSTAT.INI
[2011/02/10 22:20:42 | 000,198,144 | —- | M] () – C:\Documents and Settings\Meow Meow and Meow\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/09 05:37:16 | 000,002,010 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Norton Security Suite.LNK
[2011/02/09 05:17:03 | 000,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/03/05 20:03:08 | 000,031,626 | —- | C] () – C:\Documents and Settings\Meow Meow and Meow\Desktop\notification project.ods
[2011/03/05 19:58:33 | 000,000,864 | —- | C] () – C:\Documents and Settings\Meow Meow and Meow\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
[2011/03/05 19:17:28 | 000,000,885 | —- | C] () – C:\Documents and Settings\All Users\Desktop\OpenOffice.org 3.3.lnk
[2011/03/03 14:57:40 | 000,001,542 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2011/03/01 06:04:53 | 000,359,929 | —- | C] () – C:\Documents and Settings\Meow Meow and Meow\Desktop\dds.scr
[2011/03/01 04:28:36 | 000,002,473 | —- | C] () – C:\Documents and Settings\Meow Meow and Meow\Desktop\HiJackThis.lnk
[2011/03/01 04:25:12 | 001,402,880 | —- | C] () – C:\Documents and Settings\Meow Meow and Meow\Desktop\HiJackThis.msi
[2011/02/20 08:35:05 | 000,001,403 | —- | C] () – C:\Documents and Settings\Meow Meow and Meow\My Documents\2210 Start
[2011/02/19 08:40:47 | 000,000,140 | —- | C] () – C:\Documents and Settings\Meow Meow and Meow\Desktop\Invade Earth.url
[2010/03/27 08:32:35 | 000,002,260 | —- | C] () – C:\Documents and Settings\Meow Meow and Meow\Application Data\wklnhst.dat
[2010/03/22 07:24:04 | 000,011,842 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\OIXQ
[2010/03/22 07:24:04 | 000,011,840 | -HS- | C] () – C:\Documents and Settings\Meow Meow and Meow\Local Settings\Application Data\OIXQ
[2010/02/22 20:36:53 | 000,000,092 | —- | C] () – C:\WINDOWS\MFPD.INI
[2009/12/22 21:16:06 | 000,256,512 | —- | C] () – C:\WINDOWS\PEV.exe
[2009/12/22 21:16:06 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2009/12/22 21:16:06 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2009/12/22 21:16:06 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2009/12/22 21:16:06 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2009/11/30 21:40:40 | 000,050,260 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009/11/28 16:39:44 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2009/11/28 14:25:42 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2009/07/17 14:27:04 | 000,000,141 | —- | C] () – C:\Documents and Settings\Meow Meow and Meow\Local Settings\Application Data\fusioncache.dat
[2008/11/03 06:52:12 | 000,000,092 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\Ts_infos.ini
[2008/08/24 10:27:59 | 000,087,312 | —- | C] () – C:\WINDOWS\mws.exe
[2008/07/26 10:25:01 | 000,000,165 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2008/05/02 06:24:27 | 000,198,144 | —- | C] () – C:\Documents and Settings\Meow Meow and Meow\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/04/09 02:23:16 | 000,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2008/03/21 10:03:58 | 000,001,070 | —- | C] () – C:\WINDOWS\EF.ini
[2007/12/22 17:00:48 | 000,000,025 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2007/11/27 08:27:11 | 000,035,382 | —- | C] () – C:\WINDOWS\scunin.dat
[2007/08/12 21:52:22 | 000,000,058 | —- | C] () – C:\WINDOWS\tutorial.INI
[2007/08/10 17:17:47 | 000,000,173 | —- | C] () – C:\WINDOWS\srlink.ini
[2007/08/10 17:17:47 | 000,000,040 | —- | C] () – C:\WINDOWS\System32\sx96.ini
[2007/08/10 17:15:33 | 000,021,504 | —- | C] () – C:\WINDOWS\System32\docobj.dll
[2007/01/26 17:53:15 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2007/01/25 22:14:26 | 000,000,245 | —- | C] () – C:\WINDOWS\PowerReg.dat
[2007/01/13 19:53:41 | 000,520,192 | —- | C] () – C:\WINDOWS\System32\ati2sgag.exe
[2006/12/02 17:55:30 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2006/05/25 00:22:06 | 000,053,248 | —- | C] () – C:\WINDOWS\bdoscandel.exe
[2006/04/29 13:38:31 | 000,003,077 | —- | C] () – C:\WINDOWS\mozver.dat
[2006/04/28 14:05:14 | 000,127,614 | —- | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2006/03/11 22:29:56 | 000,000,523 | —- | C] () – C:\WINDOWS\Sfc3ng.ini
[2006/02/24 17:32:36 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/02/20 22:32:36 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2006/01/30 19:11:48 | 000,000,020 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
[2006/01/25 00:09:43 | 000,000,000 | —- | C] () – C:\WINDOWS\ATIMMC.INI
[2006/01/21 16:16:43 | 000,002,572 | —- | C] () – C:\WINDOWS\MIXDEF.INI
[2006/01/21 00:15:38 | 000,001,008 | —- | C] () – C:\WINDOWS\STA2.ini
[2006/01/05 12:36:57 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2006/01/05 11:17:01 | 000,000,325 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/01/05 10:59:13 | 000,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2006/01/05 10:59:12 | 001,048,576 | —- | C] () – C:\WINDOWS\System32\SFMAN.DAT
[2006/01/05 10:58:58 | 000,002,516 | —- | C] () – C:\WINDOWS\System32\P16X.ini
[2006/01/05 10:58:58 | 000,000,026 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2006/01/05 10:58:57 | 000,047,616 | —- | C] () – C:\WINDOWS\System32\P16X.dll
[2006/01/05 10:58:54 | 000,000,064 | —- | C] () – C:\WINDOWS\P16x.ini
[2006/01/05 10:58:07 | 000,000,245 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2006/01/05 01:16:03 | 000,000,596 | —- | C] () – C:\WINDOWS\DELLSTAT.INI
[2006/01/05 01:15:48 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\dlbavs.dll
[2006/01/05 01:15:30 | 000,000,177 | —- | C] () – C:\WINDOWS\System32\dlbacoin.ini
[2006/01/05 00:58:10 | 000,004,272 | R— | C] () – C:\WINDOWS\System32\drivers\bvrp_pci.sys
[2006/01/05 00:27:07 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\YCRWin32.dll
[2006/01/05 00:02:58 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2006/01/04 23:54:55 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2006/01/04 17:31:09 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2006/01/04 17:30:11 | 000,281,816 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/03/01 14:30:20 | 000,000,453 | —- | C] () – C:\WINDOWS\bdoscandellang.ini
[2004/01/28 11:42:06 | 000,013,601 | —- | C] () – C:\WINDOWS\System32\vctest.ini
[2003/11/20 15:39:58 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2003/07/16 14:54:55 | 000,004,594 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2003/07/16 14:54:54 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2003/07/16 14:41:25 | 000,441,552 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2003/07/16 14:41:25 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2003/07/16 14:41:23 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2003/07/16 14:41:21 | 000,071,488 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2003/07/16 14:39:07 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2003/07/16 14:33:50 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2003/07/16 14:33:39 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2003/07/16 14:27:41 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2003/07/16 14:26:37 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2003/07/14 13:30:28 | 000,197,120 | —- | C] () – C:\WINDOWS\patchw32.dll
[2000/11/10 14:57:04 | 000,005,025 | —- | C] () – C:\WINDOWS\System32\patterns.dat

========== Alternate Data Streams ==========

@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2

< End of report >
That's definitely related to a modem/fax device - we'll look at that later, though I might have to handball you to our technical experts. Please try the following: Click Start->Run->and type in: unvet32.exe Pay attention to what the uninstaller displays, if it can't remove something please inform me.
The uninstall ran successfully, all components uninstalled. It required a reboot to complete and it took three reboots before the comp restarted without freezing up. Previously it had been working faster and without issue on restarts. Also the internet was working well, now it is 10 times slower again and the first IE freezes up again, and the second IE wil load, but only after a long time. Should removing this cause these problems to come back?
Unless it's a problem with the new Comcast suite, I can't imagine why. I can't see any evidence of any malware on there, and you have not said of any other issues like redirects or popups, so it's hard to tell.

Try the below instructions to see if they improve anything. The other possibility is that you are beginning to experience some hardware failure.

1) TFC
Please download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should reboot your machine, if not, manually reboot to ensure a complete clean

2) chkdsk
  • Close any open windows.
  • Go to the Start Menu, Run type in cmd.exe and press Enter
  • In the command window that appears, type chkdsk /r, and press enter
  • Agree to any prompts - then reboot the computer.
  • chkdsk should run as you boot the machine up - this will check the harddrive for damaged sectors and attempt to repair them.

3) Defrag
  • Close any open windows.
  • Go to the Start Menu, Programs, Accessories, System Tools, Disk Defragmenter
  • Defrag all drives in the Disk Defragmenter

4) Winsock Fix
Please download WinsockXP Fix to your desktop
  • Close any open windows.
  • Double click the WinsockXP Fix icon to run the program, and follow the prompts to repair your Winsock file.
  • Once its finished it should reboot your machine, if not, manually reboot to ensure a complete clean
I completed all four steps. System seems a bit faster. Is there a way to clean out the system cache without having to reboot? It seems from time to time a lot of my mem gets stuck in the system cache and I don't know how to restore it with out rebooting. Any more steps do you want me to do?
If your memory is being used up by another application, besides from identifying the culprit (Ctrl + Shift + Esc will bring up the task manager, then sort by memory usage), rebooting is the best option. I'd be inclined to think that the hardware in this PC is starting to fail, as I can't identify any serious software issues that would be slowing the machine down this much. On the upside, I also can't see any malware, so it looks like you are free from infection. :)

Unfortunately, there's not too much more I can recommend here, though our Tech Team might be able to help you if you post in our Microsoft Windows forum.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI