v6rs97
Topic Starter
I have no idea what my father did but my whole desktop is gone, start menu is blank and when i alt control and delete it says disabled by admin. I am in safe mode right now and can find some of those files from my other user name. i will post what i can. Thanks
OTL logfile created on: 11/14/2011 9:23:13 PM - Run 2
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Administrator.BASEMENT\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 72.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 90.00% Paging File free
Paging file location(s): C:\pagefile.sys 672 1344 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS.0 | %ProgramFiles% = C:\Program Files
Drive C: | 147.14 Gb Total Space | 98.28 Gb Free Space | 66.79% Space Free | Partition Type: NTFS
Drive D: | 5.52 Gb Total Space | 2.57 Gb Free Space | 46.65% Space Free | Partition Type: NTFS
Drive E: | 242.60 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: BASEMENT | User Name: Administrator | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
PRC - C:\Documents and Settings\Administrator.BASEMENT\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
PRC - C:\WINDOWS.0\explorer.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Administrator.BASEMENT\Desktop\NoLop.exe (PunkTools)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Administrator.BASEMENT\Desktop\OTL.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (AppMgmt) – C:\WINDOWS.0\System32\appmgmts.dll File not found
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SRV - (HPSLPSVC) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\HPSLPSVC32.DLL (Hewlett-Packard Co.)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (hpqcxs08) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.)
SRV - (hpqddsvc) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqddsvc.dll (Hewlett-Packard Co.)
SRV - (AOL ACS) – C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (AOL LLC)
SRV - (SNDSrvc) – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (wuauserv) – C:\WINDOWS\system32\wuauserv.dll (Microsoft Corporation)
SRV - (WANMiniportService) WAN Miniport (ATW) – C:\WINDOWS.0\wanmpsvc.exe (America Online, Inc.)
========== Driver Services (SafeList) ==========
DRV - (Lbd) – C:\WINDOWS.0\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (Lavasoft Kernexplorer) – C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys ()
DRV - (NPF) WinPcap Packet Driver (NPF) – C:\WINDOWS.0\system32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (MBAMSwissArmy) – C:\WINDOWS.0\system32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (Tcpip6) – C:\WINDOWS.0\system32\drivers\tcpip6.sys (Microsoft Corporation)
DRV - (NwlnkIpx) – C:\WINDOWS.0\system32\drivers\nwlnkipx.sys (Microsoft Corporation)
DRV - (nm) – C:\WINDOWS.0\system32\drivers\nmnt.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS.0\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (Cdralw2k) – C:\WINDOWS.0\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (Cdr4_xp) – C:\WINDOWS.0\System32\drivers\cdr4_xp.sys (Sonic Solutions)
DRV - (SymEvent) – C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
DRV - (cdudf_xp) – C:\WINDOWS.0\System32\drivers\Cdudf_xp.sys (Sonic Solutions)
DRV - (dvd_2K) – C:\WINDOWS.0\System32\drivers\dvd_2k.sys (Sonic Solutions)
DRV - (DVDVRRdr_xp) – C:\WINDOWS.0\System32\drivers\DVDVRRdr_xp.sys (Windows ® 2000 DDK provider)
DRV - (UDFReadr) – C:\WINDOWS.0\System32\drivers\Udfreadr.sys (Sonic Solutions)
DRV - (mmc_2K) – C:\WINDOWS.0\System32\drivers\mmc_2k.sys (Sonic Solutions)
DRV - (pwd_2k) – C:\WINDOWS.0\System32\drivers\Pwd_2k.sys (Sonic Solutions)
DRV - (SYMTDI) – C:\WINDOWS.0\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\WINDOWS.0\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (AFS2K) – C:\WINDOWS.0\System32\drivers\AFS2K.SYS (Oak Technology Inc.)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS.0\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (ltmodem5) – C:\WINDOWS.0\system32\drivers\ltmdmnt.sys (LT)
DRV - (ALCXSENS) – C:\WINDOWS.0\system32\drivers\ALCXSENS.SYS (Sensaura)
DRV - (viasraid) – C:\WINDOWS.0\System32\DRIVERS\viasraid.sys (VIA Technologies inc,.ltd)
DRV - (psa805) Aurilium Sound Agent 2 (WDM) – C:\WINDOWS.0\system32\drivers\psa805.sys (QSound Labs, Inc.)
DRV - (viaagp1) – C:\WINDOWS.0\System32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (QsndEnum) – C:\WINDOWS.0\system32\drivers\QsndEnum.sys (QSound Labs, Inc.)
DRV - (NwlnkNb) – C:\WINDOWS.0\system32\drivers\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx) – C:\WINDOWS.0\system32\drivers\nwlnkspx.sys (Microsoft Corporation)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS.0\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (ViaIde) – C:\WINDOWS.0\System32\DRIVERS\viaidexp.sys (VIA Technologies, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS.0\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = A8 D6 F8 0D 12 82 CB 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/10/09 11:22:50 | 000,000,000 | -H-D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/05/18 11:07:29 | 000,000,000 | -H-D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/21 08:08:31 | 000,000,000 | -H-D | M]
[2010/11/11 21:24:44 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.BASEMENT\Application Data\Mozilla\Extensions
[2010/11/11 21:24:44 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.BASEMENT\Application Data\Mozilla\Firefox\Profiles\y4fw1cy4.default\extensions
[2010/11/11 21:24:50 | 000,000,000 | -H-D | M] (No name found) – C:\Documents and Settings\Administrator.BASEMENT\Application Data\Mozilla\Firefox\Profiles\y4fw1cy4.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/11/11 21:24:49 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.BASEMENT\Application Data\Mozilla\Firefox\Profiles\y4fw1cy4.default\extensions\staged-xpis
[2006/09/27 19:21:40 | 000,000,000 | -H-D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/05/18 11:06:13 | 000,000,000 | -H-D | M] – C:\Program Files\Mozilla Firefox\extensions\[removed]
O1 HOSTS File: ([2008/08/26 08:42:00 | 000,259,167 | RH– | M]) - C:\WINDOWS.0\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 1001-search.info
O1 - Hosts: 127.0.0.1 www.1001-search.info
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 9024 more lines…
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\Hewlett-Packard\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Shareaza Web Download Hook) - {0EEDB912-C5FA-486F-8334-57288578C627} - C:\CreativesFiles\RazaWebHook32.dll (Shareaza Development Team)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found.
O2 - BHO: (AOL Toolbar Launcher) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\Hewlett-Packard\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\AOL\1168712829\ee\AOLSoftware.exe (AOL Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\Hewlett-Packard\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS.0\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://www2.snapfish.com/SnapfishActivia.cab (Snapfish Activia)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-24-0.cab (EPUImageControl Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} http://picture.vzw.com/activex/VerizonWire…loadControl.cab (Verizon Wireless Media Upload)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} https://www.secure-session.com/include/XUpload.ocx (Persits Software XUpload)
O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} http://216.249.24.62/code/iPIX-ImageWell-ipix.cab (iPIX Media Send Class)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS.0\explorer.exe (Microsoft Corporation)
O24 - Desktop BackupWallPaper:
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/10/10 21:32:03 | 000,000,000 | -H– | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS.0\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/11/14 20:37:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator.BASEMENT\Local Settings\Application Data\Adobe
[2011/11/14 20:36:54 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator.BASEMENT\Application Data\Malwarebytes
[2011/11/14 15:35:40 | 000,494,592 | -H– | C] (Rec0ver Inc) – C:\Documents and Settings\All Users.WINDOWS.0\Application Data\WNicVIllUbjiXg.exe
[5 C:\WINDOWS.0\System32\*.tmp files -> C:\WINDOWS.0\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/11/14 21:15:57 | 000,000,486 | —- | M] () – C:\WINDOWS.0\tasks\Ad-Aware Update (Weekly).job
[2011/11/14 21:15:43 | 000,002,048 | –S- | M] () – C:\WINDOWS.0\bootstat.dat
[2011/11/14 20:42:16 | 000,000,899 | -HS- | M] () – C:\boot.ini
[2011/11/14 20:34:13 | 000,001,374 | -H– | M] () – C:\WINDOWS.0\System32\wpa.dbl
[2011/11/14 15:33:19 | 000,069,530 | -H– | M] () – C:\VETlog.dmp
[2011/11/14 15:31:36 | 000,494,592 | -H– | M] (Rec0ver Inc) – C:\Documents and Settings\All Users.WINDOWS.0\Application Data\WNicVIllUbjiXg.exe
[2011/11/13 09:46:00 | 000,000,064 | -H– | M] () – C:\WINDOWS.0\System32\rp_stats.dat
[2011/11/13 09:46:00 | 000,000,044 | -H– | M] () – C:\WINDOWS.0\System32\rp_rules.dat
[2011/11/10 02:00:11 | 000,000,338 | -H– | M] () – C:\WINDOWS.0\tasks\AdobeAAMUpdater-1.0-BASEMENT-Tom.job
[5 C:\WINDOWS.0\System32\*.tmp files -> C:\WINDOWS.0\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/06/17 10:24:58 | 000,000,010 | -H– | C] () – C:\WINDOWS.0\msoffice.ini
[2010/04/08 22:30:03 | 000,009,916 | -HS- | C] () – C:\Documents and Settings\All Users.WINDOWS.0\Application Data\6e6301sD6p
[2009/12/15 14:06:50 | 000,044,544 | -H– | C] () – C:\WINDOWS.0\System32\GIF89.DLL
[2009/11/26 08:37:08 | 000,323,584 | -H– | C] () – C:\WINDOWS.0\System32\FoxImager.dll
[2008/10/06 11:29:11 | 000,065,536 | -H– | C] () – C:\WINDOWS.0\System32\HPPLVS.dll
[2008/03/13 02:01:49 | 000,003,413 | -H– | C] () – C:\WINDOWS.0\System32\MRT.INI
[2007/12/11 14:43:44 | 000,012,288 | -H– | C] () – C:\WINDOWS.0\System32\DivXWMPExtType.dll
[2007/10/15 09:53:34 | 000,000,722 | -H– | C] () – C:\WINDOWS.0\wininit.ini
[2007/08/05 22:05:34 | 000,005,252 | -H– | C] () – C:\WINDOWS.0\CDPlayer.ini
[2007/08/05 22:04:53 | 000,000,503 | -H– | C] () – C:\WINDOWS.0\CDRip.INI
[2007/08/05 22:04:21 | 000,151,040 | -H– | C] () – C:\WINDOWS.0\System32\wimadll.dll
[2007/07/26 11:01:50 | 000,114,688 | -H– | C] () – C:\WINDOWS.0\System32\hppatusg01.dll
[2007/04/22 19:15:29 | 003,596,288 | -H– | C] () – C:\WINDOWS.0\System32\qt-dx331.dll
[2007/02/15 22:53:03 | 000,000,147 | -H– | C] () – C:\WINDOWS.0\bizpub32.INI
[2007/02/03 10:19:55 | 000,000,003 | -H– | C] () – C:\Documents and Settings\All Users.WINDOWS.0\Application Data\DragToDiscUserNameF.txt
[2007/02/03 08:09:30 | 000,000,926 | -H– | C] () – C:\WINDOWS.0\CDRipper.ini
[2007/01/13 13:25:07 | 000,000,030 | -H– | C] () – C:\WINDOWS.0\atid.ini
[2006/11/16 13:25:12 | 000,000,754 | -H– | C] () – C:\WINDOWS.0\WORDPAD.INI
[2006/10/16 00:08:20 | 000,001,759 | -H– | C] () – C:\Documents and Settings\All Users.WINDOWS.0\Application Data\QTSBandwidthCache
[2006/10/12 01:23:14 | 000,002,473 | -H– | C] () – C:\Documents and Settings\All Users.WINDOWS.0\Application Data\hpzinstall.log
[2006/10/11 23:34:50 | 000,000,061 | -H– | C] () – C:\WINDOWS.0\smscfg.ini
[2006/10/11 23:27:54 | 000,363,520 | -H– | C] () – C:\WINDOWS.0\System32\psisdecd.dll
[2006/10/11 16:20:03 | 000,004,249 | -H– | C] () – C:\WINDOWS.0\ODBCINST.INI
[2004/09/17 16:37:42 | 000,069,632 | -H– | C] () – C:\WINDOWS.0\System32\vuins32.dll
[2004/02/09 18:18:18 | 000,155,648 | -H– | C] () – C:\WINDOWS.0\System32\RTLCPAPI.dll
[2003/10/31 16:28:25 | 000,000,312 | -H– | C] () – C:\WINDOWS.0\System32\OEMINFO.INI
[2003/03/08 23:31:04 | 000,561,152 | -H– | C] () – C:\WINDOWS.0\System32\hpotscl.dll
========== LOP Check ==========
[2007/07/16 14:55:53 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.BASEMENT\Application Data\Viewpoint
[2007/07/16 18:30:01 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users.WINDOWS.0\Application Data\cake link byte time
[2011/02/22 13:45:09 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users.WINDOWS.0\Application Data\regid.1986-12.com.adobe
[2007/01/22 00:36:28 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Viewpoint
[2011/11/14 21:15:57 | 000,000,486 | —- | M] () – C:\WINDOWS.0\Tasks\Ad-Aware Update (Weekly).job
[2009/01/27 23:26:20 | 000,000,338 | -H– | M] () – C:\WINDOWS.0\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1224905129.job
< End of report >
OTL logfile created on: 11/14/2011 9:23:13 PM - Run 2
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Administrator.BASEMENT\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 72.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 90.00% Paging File free
Paging file location(s): C:\pagefile.sys 672 1344 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS.0 | %ProgramFiles% = C:\Program Files
Drive C: | 147.14 Gb Total Space | 98.28 Gb Free Space | 66.79% Space Free | Partition Type: NTFS
Drive D: | 5.52 Gb Total Space | 2.57 Gb Free Space | 46.65% Space Free | Partition Type: NTFS
Drive E: | 242.60 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: BASEMENT | User Name: Administrator | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
PRC - C:\Documents and Settings\Administrator.BASEMENT\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
PRC - C:\WINDOWS.0\explorer.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Administrator.BASEMENT\Desktop\NoLop.exe (PunkTools)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Administrator.BASEMENT\Desktop\OTL.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (AppMgmt) – C:\WINDOWS.0\System32\appmgmts.dll File not found
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SRV - (HPSLPSVC) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\HPSLPSVC32.DLL (Hewlett-Packard Co.)
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (hpqcxs08) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.)
SRV - (hpqddsvc) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqddsvc.dll (Hewlett-Packard Co.)
SRV - (AOL ACS) – C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (AOL LLC)
SRV - (SNDSrvc) – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (wuauserv) – C:\WINDOWS\system32\wuauserv.dll (Microsoft Corporation)
SRV - (WANMiniportService) WAN Miniport (ATW) – C:\WINDOWS.0\wanmpsvc.exe (America Online, Inc.)
========== Driver Services (SafeList) ==========
DRV - (Lbd) – C:\WINDOWS.0\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (Lavasoft Kernexplorer) – C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys ()
DRV - (NPF) WinPcap Packet Driver (NPF) – C:\WINDOWS.0\system32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (MBAMSwissArmy) – C:\WINDOWS.0\system32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (Tcpip6) – C:\WINDOWS.0\system32\drivers\tcpip6.sys (Microsoft Corporation)
DRV - (NwlnkIpx) – C:\WINDOWS.0\system32\drivers\nwlnkipx.sys (Microsoft Corporation)
DRV - (nm) – C:\WINDOWS.0\system32\drivers\nmnt.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS.0\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (Cdralw2k) – C:\WINDOWS.0\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (Cdr4_xp) – C:\WINDOWS.0\System32\drivers\cdr4_xp.sys (Sonic Solutions)
DRV - (SymEvent) – C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
DRV - (cdudf_xp) – C:\WINDOWS.0\System32\drivers\Cdudf_xp.sys (Sonic Solutions)
DRV - (dvd_2K) – C:\WINDOWS.0\System32\drivers\dvd_2k.sys (Sonic Solutions)
DRV - (DVDVRRdr_xp) – C:\WINDOWS.0\System32\drivers\DVDVRRdr_xp.sys (Windows ® 2000 DDK provider)
DRV - (UDFReadr) – C:\WINDOWS.0\System32\drivers\Udfreadr.sys (Sonic Solutions)
DRV - (mmc_2K) – C:\WINDOWS.0\System32\drivers\mmc_2k.sys (Sonic Solutions)
DRV - (pwd_2k) – C:\WINDOWS.0\System32\drivers\Pwd_2k.sys (Sonic Solutions)
DRV - (SYMTDI) – C:\WINDOWS.0\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SYMREDRV) – C:\WINDOWS.0\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (AFS2K) – C:\WINDOWS.0\System32\drivers\AFS2K.SYS (Oak Technology Inc.)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS.0\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (ltmodem5) – C:\WINDOWS.0\system32\drivers\ltmdmnt.sys (LT)
DRV - (ALCXSENS) – C:\WINDOWS.0\system32\drivers\ALCXSENS.SYS (Sensaura)
DRV - (viasraid) – C:\WINDOWS.0\System32\DRIVERS\viasraid.sys (VIA Technologies inc,.ltd)
DRV - (psa805) Aurilium Sound Agent 2 (WDM) – C:\WINDOWS.0\system32\drivers\psa805.sys (QSound Labs, Inc.)
DRV - (viaagp1) – C:\WINDOWS.0\System32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (QsndEnum) – C:\WINDOWS.0\system32\drivers\QsndEnum.sys (QSound Labs, Inc.)
DRV - (NwlnkNb) – C:\WINDOWS.0\system32\drivers\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx) – C:\WINDOWS.0\system32\drivers\nwlnkspx.sys (Microsoft Corporation)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS.0\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (ViaIde) – C:\WINDOWS.0\System32\DRIVERS\viaidexp.sys (VIA Technologies, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS.0\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = A8 D6 F8 0D 12 82 CB 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Hewlett-Packard\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/10/09 11:22:50 | 000,000,000 | -H-D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/05/18 11:07:29 | 000,000,000 | -H-D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/21 08:08:31 | 000,000,000 | -H-D | M]
[2010/11/11 21:24:44 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.BASEMENT\Application Data\Mozilla\Extensions
[2010/11/11 21:24:44 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.BASEMENT\Application Data\Mozilla\Firefox\Profiles\y4fw1cy4.default\extensions
[2010/11/11 21:24:50 | 000,000,000 | -H-D | M] (No name found) – C:\Documents and Settings\Administrator.BASEMENT\Application Data\Mozilla\Firefox\Profiles\y4fw1cy4.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/11/11 21:24:49 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.BASEMENT\Application Data\Mozilla\Firefox\Profiles\y4fw1cy4.default\extensions\staged-xpis
[2006/09/27 19:21:40 | 000,000,000 | -H-D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/05/18 11:06:13 | 000,000,000 | -H-D | M] – C:\Program Files\Mozilla Firefox\extensions\[removed]
O1 HOSTS File: ([2008/08/26 08:42:00 | 000,259,167 | RH– | M]) - C:\WINDOWS.0\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 1001-search.info
O1 - Hosts: 127.0.0.1 www.1001-search.info
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 9024 more lines…
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\Hewlett-Packard\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Shareaza Web Download Hook) - {0EEDB912-C5FA-486F-8334-57288578C627} - C:\CreativesFiles\RazaWebHook32.dll (Shareaza Development Team)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No CLSID value found.
O2 - BHO: (AOL Toolbar Launcher) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\Hewlett-Packard\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\AOL\1168712829\ee\AOLSoftware.exe (AOL Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\Hewlett-Packard\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS.0\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://www2.snapfish.com/SnapfishActivia.cab (Snapfish Activia)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-24-0.cab (EPUImageControl Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} http://picture.vzw.com/activex/VerizonWire…loadControl.cab (Verizon Wireless Media Upload)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_10)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_19)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} https://www.secure-session.com/include/XUpload.ocx (Persits Software XUpload)
O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} http://216.249.24.62/code/iPIX-ImageWell-ipix.cab (iPIX Media Send Class)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS.0\explorer.exe (Microsoft Corporation)
O24 - Desktop BackupWallPaper:
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/10/10 21:32:03 | 000,000,000 | -H– | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS.0\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/11/14 20:37:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator.BASEMENT\Local Settings\Application Data\Adobe
[2011/11/14 20:36:54 | 000,000,000 | —D | C] – C:\Documents and Settings\Administrator.BASEMENT\Application Data\Malwarebytes
[2011/11/14 15:35:40 | 000,494,592 | -H– | C] (Rec0ver Inc) – C:\Documents and Settings\All Users.WINDOWS.0\Application Data\WNicVIllUbjiXg.exe
[5 C:\WINDOWS.0\System32\*.tmp files -> C:\WINDOWS.0\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/11/14 21:15:57 | 000,000,486 | —- | M] () – C:\WINDOWS.0\tasks\Ad-Aware Update (Weekly).job
[2011/11/14 21:15:43 | 000,002,048 | –S- | M] () – C:\WINDOWS.0\bootstat.dat
[2011/11/14 20:42:16 | 000,000,899 | -HS- | M] () – C:\boot.ini
[2011/11/14 20:34:13 | 000,001,374 | -H– | M] () – C:\WINDOWS.0\System32\wpa.dbl
[2011/11/14 15:33:19 | 000,069,530 | -H– | M] () – C:\VETlog.dmp
[2011/11/14 15:31:36 | 000,494,592 | -H– | M] (Rec0ver Inc) – C:\Documents and Settings\All Users.WINDOWS.0\Application Data\WNicVIllUbjiXg.exe
[2011/11/13 09:46:00 | 000,000,064 | -H– | M] () – C:\WINDOWS.0\System32\rp_stats.dat
[2011/11/13 09:46:00 | 000,000,044 | -H– | M] () – C:\WINDOWS.0\System32\rp_rules.dat
[2011/11/10 02:00:11 | 000,000,338 | -H– | M] () – C:\WINDOWS.0\tasks\AdobeAAMUpdater-1.0-BASEMENT-Tom.job
[5 C:\WINDOWS.0\System32\*.tmp files -> C:\WINDOWS.0\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/06/17 10:24:58 | 000,000,010 | -H– | C] () – C:\WINDOWS.0\msoffice.ini
[2010/04/08 22:30:03 | 000,009,916 | -HS- | C] () – C:\Documents and Settings\All Users.WINDOWS.0\Application Data\6e6301sD6p
[2009/12/15 14:06:50 | 000,044,544 | -H– | C] () – C:\WINDOWS.0\System32\GIF89.DLL
[2009/11/26 08:37:08 | 000,323,584 | -H– | C] () – C:\WINDOWS.0\System32\FoxImager.dll
[2008/10/06 11:29:11 | 000,065,536 | -H– | C] () – C:\WINDOWS.0\System32\HPPLVS.dll
[2008/03/13 02:01:49 | 000,003,413 | -H– | C] () – C:\WINDOWS.0\System32\MRT.INI
[2007/12/11 14:43:44 | 000,012,288 | -H– | C] () – C:\WINDOWS.0\System32\DivXWMPExtType.dll
[2007/10/15 09:53:34 | 000,000,722 | -H– | C] () – C:\WINDOWS.0\wininit.ini
[2007/08/05 22:05:34 | 000,005,252 | -H– | C] () – C:\WINDOWS.0\CDPlayer.ini
[2007/08/05 22:04:53 | 000,000,503 | -H– | C] () – C:\WINDOWS.0\CDRip.INI
[2007/08/05 22:04:21 | 000,151,040 | -H– | C] () – C:\WINDOWS.0\System32\wimadll.dll
[2007/07/26 11:01:50 | 000,114,688 | -H– | C] () – C:\WINDOWS.0\System32\hppatusg01.dll
[2007/04/22 19:15:29 | 003,596,288 | -H– | C] () – C:\WINDOWS.0\System32\qt-dx331.dll
[2007/02/15 22:53:03 | 000,000,147 | -H– | C] () – C:\WINDOWS.0\bizpub32.INI
[2007/02/03 10:19:55 | 000,000,003 | -H– | C] () – C:\Documents and Settings\All Users.WINDOWS.0\Application Data\DragToDiscUserNameF.txt
[2007/02/03 08:09:30 | 000,000,926 | -H– | C] () – C:\WINDOWS.0\CDRipper.ini
[2007/01/13 13:25:07 | 000,000,030 | -H– | C] () – C:\WINDOWS.0\atid.ini
[2006/11/16 13:25:12 | 000,000,754 | -H– | C] () – C:\WINDOWS.0\WORDPAD.INI
[2006/10/16 00:08:20 | 000,001,759 | -H– | C] () – C:\Documents and Settings\All Users.WINDOWS.0\Application Data\QTSBandwidthCache
[2006/10/12 01:23:14 | 000,002,473 | -H– | C] () – C:\Documents and Settings\All Users.WINDOWS.0\Application Data\hpzinstall.log
[2006/10/11 23:34:50 | 000,000,061 | -H– | C] () – C:\WINDOWS.0\smscfg.ini
[2006/10/11 23:27:54 | 000,363,520 | -H– | C] () – C:\WINDOWS.0\System32\psisdecd.dll
[2006/10/11 16:20:03 | 000,004,249 | -H– | C] () – C:\WINDOWS.0\ODBCINST.INI
[2004/09/17 16:37:42 | 000,069,632 | -H– | C] () – C:\WINDOWS.0\System32\vuins32.dll
[2004/02/09 18:18:18 | 000,155,648 | -H– | C] () – C:\WINDOWS.0\System32\RTLCPAPI.dll
[2003/10/31 16:28:25 | 000,000,312 | -H– | C] () – C:\WINDOWS.0\System32\OEMINFO.INI
[2003/03/08 23:31:04 | 000,561,152 | -H– | C] () – C:\WINDOWS.0\System32\hpotscl.dll
========== LOP Check ==========
[2007/07/16 14:55:53 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator.BASEMENT\Application Data\Viewpoint
[2007/07/16 18:30:01 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users.WINDOWS.0\Application Data\cake link byte time
[2011/02/22 13:45:09 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users.WINDOWS.0\Application Data\regid.1986-12.com.adobe
[2007/01/22 00:36:28 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users.WINDOWS.0\Application Data\Viewpoint
[2011/11/14 21:15:57 | 000,000,486 | —- | M] () – C:\WINDOWS.0\Tasks\Ad-Aware Update (Weekly).job
[2009/01/27 23:26:20 | 000,000,338 | -H– | M] () – C:\WINDOWS.0\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1224905129.job
< End of report >