This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] horrible malware

24 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

here, i include my hijackthis scan. now, just to clarify; i originally went on pchell and the advice was to use this program in safe mode. only problem is that you cannot use hijack this in safe mode!
a little more info… i have no use of my task manager and i cannot get to regedit as my "run" option has been disabled as well. this is the worst i have ever had, and norton didnt pick up any of it.

Logfile of HijackThis v1.99.1
Scan saved at 07:55: VIRUS ALERT!, on 10/16/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Memeo\AutoBackup\MemeoService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\lphcl02j0el2a.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\Program Files\HP\hpcoretech\comp\hpdarc.exe
C:\Documents and Settings\nick petrotto\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=…6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://downloads.yahoo.com/internetexplorer/welcome.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: rosqxvmn - {7C554665-B775-4305-BAE6-E310B361F216} - C:\WINDOWS\rosqxvmn.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [StxTrayMenu] "C:\Program Files\Seagate\SystemTray\StxMenuMgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [lphcl02j0el2a] C:\WINDOWS\system32\lphcl02j0el2a.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [541ac234] rundll32.exe "C:\WINDOWS\system32\cxrxcwae.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: PalTalk.lnk = C:\Program Files\Paltalk Messenger\paltalk.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01010200-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Installer) - http://supportcenter.adelphia.net/sdccommo…ad/tgctlins.cab
O16 - DPF: {01111F00-3E00-11D2-8470-0060089874ED} (Support.com Installer) - http://supportsoft.adelphia.net/sdccommon/…ad/tgctlins.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_…aploader_v6.cab
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - AppInit_DLLs: yndkyu.dll dlmwvo.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O21 - SSODL: ngwstxfd - {10AF1933-A6EC-4C93-9775-D2DA7CE294FB} - C:\WINDOWS\ngwstxfd.dll
O21 - SSODL: qrbgltos - {F27D2547-5668-4321-B61E-DFB1C901BC04} - C:\WINDOWS\qrbgltos.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: AutoBackup (BMUService) - Memeo - C:\Program Files\Memeo\AutoBackup\MemeoService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WUSB54GCSVC - Unknown owner - C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe" "WUSB54GC.exe (file missing)
Hello

Before we begin, you should save these instructions in Notepad to your desktop, or print them, for easy reference. Much of our fix will be done in Safe mode, and you will be unable to access this thread at that time. If you have questions at any point, or are unsure of the instructions, feel free to post here and ask for clarification before proceeding.


Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum.



Download OTScanIt2.exe to your Desktop and double-click on it to extract the files. It will create a folder named OTScanIt2 on your desktop.
  • Open the OTScanIt2 folder and double-click on OTScanIt.exe to start the program.
  • Under File Age at the top, change it from 30 days to 90 days
  • Under Additional Scans check the boxes beside Reg - App Paths, Reg - Desktop Components, Reg - Disabled MS Config Items, Reg - File Associations, File - Lop Check, File - Purity Scan, and Evnt - EventViewer Logs ( Last 10 Errors).
  • Under Rootkit Search change it to Yes
  • Now click the Run Scan button on the toolbar.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Use the Add Reply button and post the information back here in an attachment. I will review it when it comes in. The last line is < End of Report >, so make sure that is the last line in the attached report.


Make sure you attach the report in your reply. If it is too big to upload, then zip the text file and upload it that way
SDFix: Version 1.236
Run by [removed] on Thu 10/16/2008 at 20:54

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services :


Restoring Default Security Values
Restoring Default Hosts File
Restoring Default HomePage Value
Restoring Default Desktop Components Value
Restoring Windows Product ID To Remove Fake Virus Alert
Restoring Time Format To Remove Fake Virus Alert

Rebooting


Checking Files :

Trojan Files Found:

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat - Contains Links to Malware Sites! - Deleted
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat - Contains Links to Malware Sites! - Deleted
C:\WINDOWS\system32\lphcl02j0el2a.exe - Deleted
C:\WINDOWS\system32\urqQiIxU.dll - Deleted
C:\WINDOWS\EFDV.EXE - Deleted
C:\Documents and Settings\nick petrotto\Desktop\Malware Defender.url - Deleted
C:\Documents and Settings\nick petrotto\Favorites\Malware Defender.url - Deleted
C:\Documents and Settings\nick petrotto\Desktop\Protect Your Privacy.url - Deleted
C:\Documents and Settings\nick petrotto\Favorites\Protect Your Privacy.url - Deleted
C:\Documents and Settings\nick petrotto\Desktop\System Error Fixer.url - Deleted
C:\Documents and Settings\nick petrotto\Favorites\System Error Fixer.url - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\.tt1.tmp - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\.tt113.tmp - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\.tt146.tmp - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\.tt1AB.tmp - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\.tt2.tmp - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\.tt3.tmp - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\.tt4.tmp - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\.tt46.tmp - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\.tt47.tmp - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\.tt4B.tmp - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\.tt4E.tmp - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\.tt5.tmp - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\.tt56.tmp - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\.tt6.tmp - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\.tt61.tmp - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\.tt66.tmp - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\.ttAF.tmp - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\.ttE5.tmp - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\.ttF1.tmp - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\.tt1.tmp.vbs - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\.tt2.tmp.vbs - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\.tt3.tmp.vbs - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\.tt4.tmp.vbs - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\.tt5.tmp.vbs - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\pwrmgr.exe.bat - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\smchk.exe.bat - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\windfr.exe.bat - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\TMP11.tmp - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\TMP16.tmp - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\tmp20.tmp - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\TMP2F.tmp - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\TMP36.tmp - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\TMP8.tmp - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\TMPA.tmp - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\TMPB6.tmp - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\TMPB7.tmp - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\TMPB8.tmp - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\TMPF.tmp - Deleted
C:\WINDOWS\grfxbanogtl.dll - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\myconfig.php.bat - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\removalfile.bat - Deleted
C:\DOCUME~1\NICKPE~1\LOCALS~1\Temp\svchost.exe - Deleted
C:\WINDOWS\qrbgltos.dll - Deleted
C:\WINDOWS\ngwstxfd.dll - Deleted
C:\WINDOWS\rosqxvmn.dll - Deleted
C:\WINDOWS\system32\ieexplorer32.exe - Deleted
C:\WINDOWS\system32\ieupdates.exe - Deleted
C:\WINDOWS\system32\winsrc.dll - Deleted





Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-16 21:12:29
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden services & system hive …

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000001
"ujdew"=hex:90,af,6a,6b,ae,e3,e6,3e,f4,68,5b,30,69,8e,48,f9,9f,85,ee,6d,d8,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:44,a6,ad,62,f7,88,c2,f8,b4,af,7b,ed,6c,12,17,ae,0f,0e,75,15,83,..
"p0"="C:\Program Files\DAEMON Tools\"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"khjeh"=hex:5f,4f,11,f4,22,6c,16,28,f6,fc,50,c6,47,3a,e2,cc,62,8d,31,3c,95,..
"a0"=hex:20,01,00,00,6f,7f,42,84,94,6a,0e,da,83,85,0e,e7,11,81,a3,1c,f1,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:ff,49,00,8c,13,76,f1,71,57,ac,4f,31,87,0c,f9,62,16,96,43,d2,42,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:d9,e0,37,6f,69,84,4f,67,6b,57,da,71,02,f4,41,d0,ba,3d,91,3f,da,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000001
"ujdew"=hex:90,af,6a,6b,ae,e3,e6,3e,f4,68,5b,30,69,8e,48,f9,9f,85,ee,6d,d8,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:44,a6,ad,62,f7,88,c2,f8,b4,af,7b,ed,6c,12,17,ae,0f,0e,75,15,83,..
"p0"="C:\Program Files\DAEMON Tools\"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"khjeh"=hex:5f,4f,11,f4,22,6c,16,28,f6,fc,50,c6,47,3a,e2,cc,62,8d,31,3c,95,..
"a0"=hex:20,01,00,00,6f,7f,42,84,94,6a,0e,da,83,85,0e,e7,11,81,a3,1c,f1,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:ff,49,00,8c,13,76,f1,71,57,ac,4f,31,87,0c,f9,62,16,96,43,d2,42,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:d9,e0,37,6f,69,84,4f,67,6b,57,da,71,02,f4,41,d0,ba,3d,91,3f,da,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000001
"ujdew"=hex:90,af,6a,6b,ae,e3,e6,3e,f4,68,5b,30,69,8e,48,f9,9f,85,ee,6d,d8,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:44,a6,ad,62,f7,88,c2,f8,b4,af,7b,ed,6c,12,17,ae,0f,0e,75,15,83,..
"p0"="C:\Program Files\DAEMON Tools\"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"khjeh"=hex:5f,4f,11,f4,22,6c,16,28,f6,fc,50,c6,47,3a,e2,cc,62,8d,31,3c,95,..
"a0"=hex:20,01,00,00,6f,7f,42,84,94,6a,0e,da,83,85,0e,e7,11,81,a3,1c,f1,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:86,d0,20,51,f3,12,a5,d8,83,c0,0e,68,0d,5a,74,a0,ba,89,0d,80,be,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:d9,e0,37,6f,69,84,4f,67,6b,57,da,71,02,f4,41,d0,ba,3d,91,3f,da,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:8ada402a
"s2"=dword:e672222b
"h0"=dword:00000002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000001
"ujdew"=hex:90,af,6a,6b,ae,e3,e6,3e,f4,68,5b,30,69,8e,48,f9,9f,85,ee,6d,d8,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:44,a6,ad,62,f7,88,c2,f8,b4,af,7b,ed,6c,12,17,ae,0f,0e,75,15,83,..
"p0"="C:\Program Files\DAEMON Tools\"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"khjeh"=hex:5f,4f,11,f4,22,6c,16,28,f6,fc,50,c6,47,3a,e2,cc,62,8d,31,3c,95,..
"a0"=hex:20,01,00,00,6f,7f,42,84,94,6a,0e,da,83,85,0e,e7,11,81,a3,1c,f1,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:ff,49,00,8c,13,76,f1,71,57,ac,4f,31,87,0c,f9,62,16,96,43,d2,42,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:d9,e0,37,6f,69,84,4f,67,6b,57,da,71,02,f4,41,d0,ba,3d,91,3f,da,..

scanning hidden registry entries …

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{8F24E4A6-56B6-C2C0-E24D-A0F742676E03}]
"abpmhocodefbpbplohckeciglpmfehmffi"=hex:61,62,6e,6a,69,68,6f,66,64,6f,64,6c,64,62,6b,62,66,6a,6c,6f,6e,..
"bbpmhocodefbpbplohnjkbcebpkimpibdogc"=hex:61,62,63,69,65,6e,64,63,6a,6b,64,6a,64,64,64,66,66,69,6f,6a,6f,..

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Compaq Connections\\6750491\\Program\\Compaq Connections.exe"="C:\\Program Files\\Compaq Connections\\6750491\\Program\\Compaq Connections.exe:*:Enabled:Compaq Connections"
"C:\\Program Files\\Paltalk Messenger\\paltalk.exe"="C:\\Program Files\\Paltalk Messenger\\paltalk.exe:*:Enabled:PaltalkScene"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Program Files\\AIM6\\aim6.exe"="C:\\Program Files\\AIM6\\aim6.exe:*:Enabled:AIM"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"="C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe:*:Enabled:MySpace Instant Messenger"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

Remaining Files :


File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes :

Sat 31 Dec 2005 211 A.SHR — "C:\BOOT.BAK"
Sat 11 Mar 2006 56 ..SHR — "C:\WINDOWS\system32\A6B7DD2808.sys"
Sat 11 Mar 2006 952 A.SH. — "C:\WINDOWS\system32\KGyGaAvL.sys"
Tue 16 Jan 2007 4,348 ..SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Fri 8 Dec 2006 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Sat 19 May 2007 456,224 A..HR — "C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\_is11A.exe"
Fri 18 Jan 2008 400 A..H. — "C:\Program Files\Common Files\Symantec Shared\COH\COH32LU.reg"
Fri 18 Jan 2008 403 A..H. — "C:\Program Files\Common Files\Symantec Shared\COH\COHDLU.reg"
Sun 19 Aug 2007 1,301 A..HR — "C:\Documents and Settings\Compaq_Owner\Application Data\SecuROM\UserData\securom_v7_01.bak"
Thu 5 Apr 2007 492,032 A..HR — "C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\{81A47537-3681-464E-9203-0B1D22800A5F}\ISSetup.dll"
Wed 17 May 2006 373,680 A..HR — "C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\{81A47537-3681-464E-9203-0B1D22800A5F}\_Setup.dll"

Finished!

———————————————————————————————————————————————————————————

OTScanIt2 logfile created on: 10/16/2008 9:38:05 PM - Run 1
OTScanIt2 by OldTimer - Version 1.0.0.14b Folder = C:\Documents and Settings\nick petrotto\Desktop\OTScanIt2
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1023.48 Mb Total Physical Memory | 567.81 Mb Available Physical Memory | 55.48% Memory free
2.31 Gb Paging File | 1.93 Gb Available in Paging File | 83.64% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 71.80 Gb Free Space | 48.17% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 149.05 Gb Total Space | 50.70 Gb Free Space | 34.01% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: YOUR-22CA86D5C4
Current User Name: nick petrotto
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Whitelist: On
File Age = 90 Days

[Processes - Safe List]
ccsvchst.exe -> %CommonProgramFiles%\Symantec Shared\ccSvcHst.exe -> [2008/01/25 21:47:02 | 00,149,864 | ---- | M] (Symantec Corporation)
applemobiledeviceservice.exe -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2008/10/01 13:06:14 | 00,116,040 | ---- | M] (Apple Inc.)
aluschedulersvc.exe -> %ProgramFiles%\Symantec\LiveUpdate\AluSchedulerSvc.exe -> [2008/02/09 20:06:34 | 00,238,968 | ---- | M] (Symantec Corporation)
memeoservice.exe -> %ProgramFiles%\Memeo\AutoBackup\MemeoService.exe -> [2007/02/14 12:09:06 | 00,056,344 | ---- | M] (Memeo)
mdnsresponder.exe -> %ProgramFiles%\Bonjour\mDNSResponder.exe -> [2008/08/29 10:18:44 | 00,238,888 | ---- | M] (Apple Inc.)
mdm.exe -> %CommonProgramFiles%\Microsoft Shared\VS7DEBUG\MDM.EXE -> [2003/06/20 09:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation)
nvsvc32.exe -> %SystemRoot%\system32\nvsvc32.exe -> [2006/08/12 00:42:50 | 00,155,715 | ---- | M] (NVIDIA Corporation)
ulcdrsvr.exe -> %CommonProgramFiles%\Ulead Systems\DVD\ULCDRSvr.exe -> [2005/01/31 10:45:20 | 00,049,152 | ---- | M] (Ulead Systems, Inc.)
viewpointservice.exe -> %ProgramFiles%\Viewpoint\Common\ViewpointService.exe -> [2007/01/04 17:38:08 | 00,024,652 | ---- | M] (Viewpoint Corporation)
wlservice.exe -> %ProgramFiles%\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe -> [2005/07/04 16:46:04 | 00,053,307 | ---- | M] (GEMTEKS)
wusb54gc.exe -> %ProgramFiles%\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe -> [2006/08/28 12:23:44 | 05,527,040 | ---- | M] (Linksys)
realsched.exe -> %CommonProgramFiles%\Real\Update_OB\realsched.exe -> [2008/09/02 23:34:41 | 00,185,896 | ---- | M] (RealNetworks, Inc.)
stxmenumgr.exe -> %ProgramFiles%\Seagate\SystemTray\StxMenuMgr.exe -> [2007/01/18 13:20:26 | 00,190,008 | ---- | M] (Seagate LLC)
ituneshelper.exe -> %ProgramFiles%\iTunes\iTunesHelper.exe -> [2008/10/01 18:57:12 | 00,289,576 | ---- | M] (Apple Inc.)
hpwuschd2.exe -> %ProgramFiles%\HP\HP Software Update\hpwuSchd2.exe -> [2005/02/16 23:11:42 | 00,049,152 | ---- | M] (Hewlett-Packard Co.)
rundll32.exe -> %SystemRoot%\system32\rundll32.exe -> [2008/04/13 20:12:33 | 00,033,280 | ---- | M] (Microsoft Corporation)
ccsvchst.exe -> %CommonProgramFiles%\Symantec Shared\ccSvcHst.exe -> [2008/01/25 21:47:02 | 00,149,864 | ---- | M] (Symantec Corporation)
compaq connections.exe -> %ProgramFiles%\Compaq Connections\6750491\Program\Compaq Connections.exe -> [2004/08/09 04:59:57 | 00,016,423 | ---- | M] ()
hpqtra08.exe -> %ProgramFiles%\HP\Digital Imaging\bin\hpqtra08.exe -> [2004/11/04 19:28:24 | 00,258,048 | ---- | M] (Hewlett-Packard Co.)
hpqgalry.exe -> %ProgramFiles%\HP\Digital Imaging\bin\hpqgalry.exe -> [2004/11/04 19:36:46 | 00,425,984 | ---- | M] (Hewlett-Packard Co.)
ipodservice.exe -> %ProgramFiles%\iPod\bin\iPodService.exe -> [2008/10/01 18:57:00 | 00,536,872 | ---- | M] (Apple Inc.)
hpdarc.exe -> %ProgramFiles%\HP\hpcoretech\comp\hpdarc.exe -> [2005/01/12 15:54:56 | 00,167,936 | ---- | M] (Hewlett-Packard Company)
notepad.exe -> %SystemRoot%\system32\notepad.exe -> [2008/04/13 20:12:29 | 00,069,120 | ---- | M] (Microsoft Corporation)
otscanit2.exe -> %UserProfile%\Desktop\OTScanIt2\OTScanIt2.exe -> [2008/10/13 14:25:18 | 00,416,768 | ---- | M] (OldTimer Tools)

[Win32 Services - Safe List]
(Apple Mobile Device) Apple Mobile Device [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> [2008/10/01 13:06:14 | 00,116,040 | ---- | M] (Apple Inc.)
(aspnet_state) ASP.NET State Service [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -> [2007/04/13 03:20:52 | 00,033,632 | ---- | M] (Microsoft Corporation)
(Automatic LiveUpdate Scheduler) Automatic LiveUpdate Scheduler [Win32_Own | Auto | Running] -> %ProgramFiles%\Symantec\LiveUpdate\AluSchedulerSvc.exe -> [2008/02/09 20:06:34 | 00,238,968 | ---- | M] (Symantec Corporation)
(BMUService) AutoBackup [Win32_Own | Auto | Running] -> %ProgramFiles%\Memeo\AutoBackup\MemeoService.exe -> [2007/02/14 12:09:06 | 00,056,344 | ---- | M] (Memeo)
(Bonjour Service) Bonjour Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Bonjour\mDNSResponder.exe -> [2008/08/29 10:18:44 | 00,238,888 | ---- | M] (Apple Inc.)
(ccEvtMgr) Symantec Event Manager [Win32_Shared | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\ccSvcHst.exe -> [2008/01/25 21:47:02 | 00,149,864 | ---- | M] (Symantec Corporation)
(ccSetMgr) Symantec Settings Manager [Win32_Shared | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\ccSvcHst.exe -> [2008/01/25 21:47:02 | 00,149,864 | ---- | M] (Symantec Corporation)
(clr_optimization_v2.0.50727_32) .NET Runtime Optimization Service v2.0.50727_X86 [Win32_Own | On_Demand | Stopped] -> %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -> [2007/04/13 03:21:18 | 00,068,952 | ---- | M] (Microsoft Corporation)
(CLTNetCnService) Symantec Lic NetConnect service [Win32_Shared | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\ccSvcHst.exe -> [2008/01/25 21:47:02 | 00,149,864 | ---- | M] (Symantec Corporation)
(IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\InstallShield\Driver\11\Intel 32\IDriverT.exe -> [2005/04/04 01:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation)
(iPod Service) iPod Service [Win32_Own | On_Demand | Running] -> %ProgramFiles%\iPod\bin\iPodService.exe -> [2008/10/01 18:57:00 | 00,536,872 | ---- | M] (Apple Inc.)
(LiveUpdate) LiveUpdate [Win32_Shared | On_Demand | Stopped] -> %ProgramFiles%\Symantec\LiveUpdate\LuComServer_3_4.EXE -> [2008/09/05 11:52:32 | 03,220,856 | ---- | M] (Symantec Corporation)
(LiveUpdate Notice) LiveUpdate Notice [Win32_Shared | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\ccSvcHst.exe -> [2008/01/25 21:47:02 | 00,149,864 | ---- | M] (Symantec Corporation)
(MDM) Machine Debug Manager [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Microsoft Shared\VS7DEBUG\MDM.EXE -> [2003/06/20 09:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation)
(NVSvc) NVIDIA Display Driver Service [Win32_Own | Auto | Running] -> %SystemRoot%\system32\nvsvc32.exe -> [2006/08/12 00:42:50 | 00,155,715 | ---- | M] (NVIDIA Corporation)
(odserv) Microsoft Office Diagnostics Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Microsoft Shared\OFFICE12\ODSERV.EXE -> [2007/08/24 03:19:12 | 00,443,776 | ---- | M] (Microsoft Corporation)
(ose) Office Source Engine [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Microsoft Shared\Source Engine\OSE.EXE -> [2006/10/26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation)
(Pml Driver HPZ12) Pml Driver HPZ12 [Win32_Own | Unknown | Stopped] -> %SystemRoot%\system32\HPZipm12.exe -> [2006/03/02 21:49:14 | 00,069,632 | ---- | M] (HP)
(Symantec Core LC) Symantec Core LC [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Symantec Shared\CCPD-LC\symlcsvc.exe -> [2008/10/14 18:25:30 | 01,245,064 | ---- | M] ()
(UleadBurningHelper) Ulead Burning Helper [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Ulead Systems\DVD\ULCDRSvr.exe -> [2005/01/31 10:45:20 | 00,049,152 | ---- | M] (Ulead Systems, Inc.)
(Viewpoint Manager Service) Viewpoint Manager Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Viewpoint\Common\ViewpointService.exe -> [2007/01/04 17:38:08 | 00,024,652 | ---- | M] (Viewpoint Corporation)
(WMPNetworkSvc) Windows Media Player Network Sharing Service [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Windows Media Player\wmpnetwk.exe -> [2006/10/18 21:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation)
(WUSB54GCSVC) WUSB54GCSVC [Win32_Own | Auto | Running] -> %ProgramFiles%\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe -> [2005/07/04 16:46:04 | 00,053,307 | ---- | M] (GEMTEKS)

[Driver Services - Safe List]
(AegisP) AEGIS Protocol (IEEE 802.1x) v3.4.3.0 [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\AegisP.sys -> [2008/10/04 19:33:32 | 00,020,747 | ---- | M] (Meetinghouse Data Communications)
(AgereSoftModem) Agere Systems Soft Modem [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\AGRSM.sys -> [2004/06/29 20:07:18 | 01,268,204 | ---- | M] (Agere Systems)
(ALCXSENS) Service for WDM 3D Audio Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\ALCXSENS.SYS -> [2003/12/11 18:54:14 | 00,391,424 | ---- | M] (Sensaura Ltd)
(ALCXWDM) Service for Realtek AC97 Audio (WDM) [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ALCXWDM.SYS -> [2004/10/01 11:24:02 | 02,279,424 | ---- | M] (Realtek Semiconductor Corp.)
(AmdK7) AMD K7 Processor Driver [Kernel | System | Running] -> %SystemRoot%\system32\drivers\amdk7.sys -> [2008/04/13 14:31:33 | 00,037,760 | ---- | M] (Microsoft Corporation)
(bkn50USB) Belkin 54Mbps Wireless USB Network Adapter [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\rt2500usb.sys -> [2004/07/16 12:14:30 | 00,140,416 | ---- | M] (Ralink Technology Inc.)
(catchme) catchme [Kernel | On_Demand | Stopped] -> %SystemDrive%\DOCUME~1\NICKPE~1\LOCALS~1\Temp\catchme.sys -> File not found
(COH_Mon) COH_Mon [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\COH_Mon.sys -> [2008/07/30 17:42:12 | 00,023,888 | ---- | M] (Symantec Corporation)
(dtscsi) dtscsi [Kernel | On_Demand | Stopped] -> %SystemRoot%\System32\Drivers\dtscsi.sys -> File not found
(eeCtrl) Symantec Eraser Control driver [Kernel | System | Running] -> %CommonProgramFiles%\Symantec Shared\EENGINE\eeCtrl.sys -> [2008/09/17 04:00:00 | 00,371,248 | ---- | M] (Symantec Corporation)
(EraserUtilRebootDrv) EraserUtilRebootDrv [Kernel | On_Demand | Running] -> %CommonProgramFiles%\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -> [2008/09/17 04:00:00 | 00,099,376 | ---- | M] (Symantec Corporation)
(FETND5BV) VIA Rhine-Family Fast Ethernet Adapter Driver Service [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\fetnd5bv.sys -> [2004/12/16 14:36:30 | 00,042,496 | ---- | M] (VIA Technologies, Inc. )
(FETNDIS) VIA PCI 10/100Mb Fast Ethernet Adapter NT Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\fetnd5.sys -> [2001/08/17 22:13:08 | 00,027,165 | ---- | M] (VIA Technologies, Inc. )
(FETNDISB) VIA Rhine Family Fast Ethernet Adapter Driver Service [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\fetnd5b.sys -> [2003/11/12 11:41:08 | 00,041,984 | R--- | M] (VIA Technologies, Inc. )
(GEARAspiWDM) GEAR ASPI Filter Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\GEARAspiWDM.sys -> [2008/04/17 13:12:54 | 00,015,464 | ---- | M] (GEAR Software Inc.)
(HPZid412) IEEE-1284.4 Driver HPZid412 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\HPZid412.sys -> [2005/07/06 15:50:05 | 00,051,120 | ---- | M] (HP)
(HPZipr12) Print Class Driver for IEEE-1284.4 HPZipr12 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\HPZipr12.sys -> [2005/07/06 15:50:05 | 00,016,496 | ---- | M] (HP)
(HPZius12) USB to IEEE-1284.4 Translation Driver HPZius12 [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\HPZius12.sys -> [2005/07/06 15:50:05 | 00,021,744 | ---- | M] (HP)
(LVUSBSta) Logitech USB Monitor Filter [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\LVUSBSta.sys -> [2005/01/31 06:12:46 | 00,022,016 | R--- | M] (Logitech Inc.)
(mcdbus) Driver for MagicISO SCSI Host Controller [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\mcdbus.sys -> [2006/09/22 14:06:10 | 00,092,160 | ---- | M] (MagicISO, Inc.)
(MREMPR5) MREMPR5 NDIS Protocol Driver [Kernel | On_Demand | Stopped] -> %CommonProgramFiles%\Motive\MREMPR5.sys -> [2007/09/28 14:30:57 | 00,019,345 | ---- | M] (Motive, Inc.)
(MRENDIS5) MRENDIS5 NDIS Protocol Driver [Kernel | On_Demand | Stopped] -> %CommonProgramFiles%\Motive\MRENDIS5.sys -> [2007/09/28 14:30:49 | 00,018,003 | ---- | M] (Motive, Inc.)
(NAVENG) NAVENG [Kernel | On_Demand | Running] -> %CommonProgramFiles%\Symantec Shared\VirusDefs\20081016.032\NAVENG.SYS -> [2008/09/17 04:00:00 | 00,089,104 | ---- | M] (Symantec Corporation)
(NAVEX15) NAVEX15 [Kernel | On_Demand | Running] -> %CommonProgramFiles%\Symantec Shared\VirusDefs\20081016.032\NAVEX15.SYS -> [2008/09/17 04:00:00 | 00,873,552 | ---- | M] (Symantec Corporation)
(nv) nv [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\nv4_mini.sys -> [2006/08/12 00:42:42 | 03,958,496 | ---- | M] (NVIDIA Corporation)
(oflpydin) oflpydin [Kernel | On_Demand | Stopped] -> %SystemDrive%\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\oflpydin.sys -> File not found
(pepifilter) Volume Adapter [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\lv302af.sys -> [2005/01/31 06:19:20 | 00,007,104 | R--- | M] (Logitech Inc.)
(PID_08A0) QuickCam IM(PID_08A0) [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\LV302AV.SYS -> [2005/01/31 06:26:06 | 00,912,768 | R--- | M] (Logitech Inc.)
(Ps2) Ps2 [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\PS2.sys -> [2005/12/12 18:27:00 | 00,019,072 | ---- | M] (Hewlett-Packard Company)
(Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\ptilink.sys -> [2004/08/04 08:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.)
(PxHelp20) PxHelp20 [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\pxhelp20.sys -> [2004/04/22 12:02:00 | 00,020,368 | ---- | M] (Sonic Solutions)
(RT73) Linksys Home Wireless-G USB Adapter Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\rt73.sys -> [2005/11/24 19:51:38 | 00,245,248 | ---- | M] (Ralink Technology, Corp.)
(rtl8139) Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\RTL8139.sys -> [2004/08/04 01:31:34 | 00,020,992 | ---- | M] (Realtek Semiconductor Corporation)
(sbp2port) SBP-2 Transport/Protocol Bus Driver [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\sbp2port.sys -> [2008/04/13 14:40:48 | 00,043,904 | ---- | M] (Microsoft Corporation)
(Secdrv) Secdrv [Kernel | Auto | Running] -> %SystemRoot%\system32\drivers\secdrv.sys -> [2007/11/13 06:25:53 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
(sfdrv01) StarForce Protection Environment Driver (version 1.x) [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\sfdrv01.sys -> [2005/05/17 08:48:21 | 00,050,176 | ---- | M] (Protection Technology)
(sfhlp02) StarForce Protection Helper Driver (version 2.x) [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\sfhlp02.sys -> [2005/05/16 09:20:39 | 00,006,656 | ---- | M] (Protection Technology)
(sfsync02) StarForce Protection Synchronization Driver (version 2.x) [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\sfsync02.sys -> [2005/05/16 09:23:38 | 00,019,968 | ---- | M] (Protection Technology)
(sfvfs02) StarForce Protection VFS Driver (version 2.x) [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\sfvfs02.sys -> [2005/06/27 03:14:35 | 00,066,560 | ---- | M] (Protection Technology)
(SPBBCDrv) SPBBCDrv [Kernel | On_Demand | Stopped] -> %CommonProgramFiles%\Symantec Shared\SPBBC\SPBBCDrv.sys -> [2008/01/17 00:05:42 | 00,447,024 | ---- | M] (Symantec Corporation)
(sptd) sptd [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\sptd.sys -> [2007/02/05 13:34:04 | 00,646,392 | ---- | M] ()
(SRTSP) SRTSP [File_System | System | Running] -> %SystemRoot%\system32\drivers\srtsp.sys -> [2008/01/31 21:51:16 | 00,279,088 | ---- | M] (Symantec Corporation)
(SRTSPL) SRTSPL [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\srtspl.sys -> [2008/01/31 21:51:16 | 00,317,616 | ---- | M] (Symantec Corporation)
(SRTSPX) SRTSPX [Kernel | System | Running] -> %SystemRoot%\system32\drivers\srtspx.sys -> [2008/01/31 21:51:16 | 00,043,696 | ---- | M] (Symantec Corporation)
(SYMDNS) SYMDNS [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\symdns.sys -> [2008/06/13 14:13:38 | 00,013,616 | ---- | M] (Symantec Corporation)
(SymEvent) SymEvent [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\SYMEVENT.SYS -> [2008/10/14 19:46:33 | 00,123,952 | ---- | M] (Symantec Corporation)
(SYMFW) SYMFW [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\symfw.sys -> [2008/06/13 14:13:38 | 00,096,432 | ---- | M] (Symantec Corporation)
(SYMIDS) SYMIDS [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\symids.sys -> [2008/06/13 14:13:38 | 00,038,576 | ---- | M] (Symantec Corporation)
(SYMIDSCO) SYMIDSCO [Kernel | On_Demand | Running] -> %CommonProgramFiles%\Symantec Shared\SymcData\ipsdefs\20081014.001\SymIDSCo.sys -> [2008/09/12 03:33:21 | 00,250,224 | ---- | M] (Symantec Corporation)
(SymIM) Symantec Network Security Intermediate Filter Service [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\SymIM.sys -> [2008/06/13 14:14:02 | 00,031,280 | ---- | M] (Symantec Corporation)
(SymIMMP) SymIMMP [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\SymIM.sys -> [2008/06/13 14:14:02 | 00,031,280 | ---- | M] (Symantec Corporation)
(SYMNDIS) SYMNDIS [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\symndis.sys -> [2008/06/13 14:13:38 | 00,037,424 | ---- | M] (Symantec Corporation)
(SYMREDRV) SYMREDRV [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\symredrv.sys -> [2008/06/13 14:13:38 | 00,022,320 | ---- | M] (Symantec Corporation)
(SYMTDI) SYMTDI [Kernel | System | Running] -> %SystemRoot%\system32\drivers\symtdi.sys -> [2008/06/13 14:13:40 | 00,184,240 | ---- | M] (Symantec Corporation)
(uagp35) Microsoft AGPv3.5 Filter [Kernel | Boot | Running] -> %SystemRoot%\system32\drivers\uagp35.sys -> [2008/04/13 14:36:40 | 00,044,672 | ---- | M] (Microsoft Corporation)
(usbaudio) USB Audio Driver (WDM) [Kernel | On_Demand | Running] -> %SystemRoot%\system32\drivers\usbaudio.sys -> [2008/04/13 14:45:12 | 00,060,032 | ---- | M] (Microsoft Corporation)
(vaxscsi) vaxscsi [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\vaxscsi.sys -> [2007/02/06 15:36:06 | 00,223,128 | ---- | M] (Alcohol Soft Co., Ltd.)
(viagfx) viagfx [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\vtmini.sys -> [2005/03/08 11:50:16 | 00,172,544 | ---- | M] (Copyright © VIA/S3 Graphics Co, Ltd.)
(X4HSX32) X4HSX32 [Kernel | Auto | Running] -> %ProgramFiles%\GameTap\bin\Release\X4HSX32.sys -> [2008/09/13 23:20:35 | 00,024,576 | ---- | M] (Exent Technologies Ltd.)
(ZD1211U(ZyDAS)) ZyDAS ZD1211 IEEE 802.11b+g Wireless LAN Driver (USB)(ZyDAS) [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\drivers\ZD1211U.sys -> [2004/07/05 22:38:06 | 00,233,472 | ---- | M] (ZyDAS Technology Corporation)
(ZDPNDIS5) ZDPNDIS5 NDIS Protocol Driver [Kernel | On_Demand | Stopped] -> %SystemRoot%\system32\ZDPNDIS5.sys -> [2004/01/14 11:30:00 | 00,017,151 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA))
(GTNDIS5) GTNDIS5 NDIS Protocol Driver [Kernel | On_Demand | Running] -> %SystemRoot%\system32\GTNDIS5.sys -> [2003/09/25 22:15:32 | 00,015,872 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA))

[Registry - Safe List]
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://www.yahoo.com ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" -> http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Secondary_Page_URL" -> ->
HKEY_LOCAL_MACHINE\: Main\\"Extensions Off Page" -> about:NoAdd-ons ->
HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> %SystemRoot%\system32\blank.htm ->
HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com ->
HKEY_LOCAL_MACHINE\: Main\\"Secondary Start Pages" -> ->
HKEY_LOCAL_MACHINE\: Main\\"Security Risk Page" -> about:SecurityRisk ->
HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://www.yahoo.com ->
HKEY_LOCAL_MACHINE\: Search\\"CustomizeSearch" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm ->
HKEY_LOCAL_MACHINE\: Search\\"CustomSearch" -> http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html ->
HKEY_LOCAL_MACHINE\: Search\\"SearchAssistant" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm ->
< Internet Explorer Settings [HKEY_CURRENT_USER\] > -> ->
HKEY_CURRENT_USER\: Main\\"Default_Page_URL" -> http://www.yahoo.com ->
HKEY_CURRENT_USER\: Main\\"Default_Secondary_Page_URL" -> ->
HKEY_CURRENT_USER\: Main\\"Local Page" -> C:\WINDOWS\system32\blank.htm ->
HKEY_CURRENT_USER\: Main\\"Search Page" -> http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com ->
HKEY_CURRENT_USER\: Main\\"SearchDefaultBranded" -> ->
HKEY_CURRENT_USER\: Main\\"Start Page" -> http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome ->
HKEY_CURRENT_USER\: SearchURL\\"" -> http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.com ->
HKEY_CURRENT_USER\: URLSearchHooks\\"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" [HKLM] -> %ProgramFiles%\Yahoo!\Companion\Installs\cpn\yt.dll [Yahoo! Toolbar] -> [2006/10/26 10:28:40 | 00,440,384 | ---- | M] (Yahoo! Inc.)
HKEY_CURRENT_USER\: "ProxyEnable" -> 0 ->
< HOSTS File > (686 bytes and 19 lines) -> C:\WINDOWS\System32\drivers\etc\Hosts ->
127.0.0.1 localhost
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{02478D38-C3F9-4EFB-9B51-7695ECA05670} [HKLM] -> %ProgramFiles%\Yahoo!\Companion\Installs\cpn\yt.dll [Yahoo! Toolbar Helper] -> [2006/10/26 10:28:40 | 00,440,384 | ---- | M] (Yahoo! Inc.)
{07dd1779-5a1c-4db8-ae7c-be36daae3f0c} [HKLM] -> %SystemRoot%\system32\yndkyu.dll [Reg Error: Value does not exist or could not be read.] -> [2008/10/15 22:12:42 | 00,109,056 | ---- | M] ()
{3049C3E9-B461-4BC5-8870-4C09146192CA} [HKLM] -> %ProgramFiles%\Real\RealPlayer\rpbrowserrecordplugin.dll [RealPlayer Download and Record Plugin for Internet Explorer] -> [2008/09/02 23:35:17 | 00,308,856 | ---- | M] (RealPlayer)
{4AEB25BE-964A-3E1F-BA33-E2D186D44BDB} [HKLM] -> %SystemRoot%\system32\mwb34530.dll [D] -> [2008/10/15 19:22:43 | 00,167,936 | ---- | M] (Microsoft Corporation)
{6c3ed2b4-635d-4e17-9f2f-c5f73cc42dfd} [HKLM] -> %SystemRoot%\system32\dlmwvo.dll [Reg Error: Value does not exist or could not be read.] -> [2008/10/16 00:14:18 | 00,109,056 | ---- | M] ()
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_05\bin\ssv.dll [SSVHelper Class] -> [2008/02/22 04:25:19 | 00,509,328 | ---- | M] (Sun Microsystems, Inc.)
{CDC83A40-7693-4192-9DE1-CD8F8811B16B} [HKLM] -> %SystemRoot%\system32\geBqQIAR.dll [Reg Error: Value does not exist or could not be read.] -> [2008/10/15 19:03:02 | 00,267,776 | ---- | M] ()
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar ->
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" [HKLM] -> %ProgramFiles%\Yahoo!\Companion\Installs\cpn\yt.dll [Yahoo! Toolbar] -> [2006/10/26 10:28:40 | 00,440,384 | ---- | M] (Yahoo! Inc.)
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ ->
ShellBrowser\\"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.] -> File not found
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"541ac234" -> %SystemRoot%\system32\cxrxcwae.dll [rundll32.exe "C:\WINDOWS\system32\cxrxcwae.dll",b] -> [2008/10/16 00:12:03 | 00,071,168 | ---- | M] ()
"ccApp" -> %CommonProgramFiles%\Symantec Shared\ccApp.exe ["C:\Program Files\Common Files\Symantec Shared\ccApp.exe"] -> [2008/01/25 21:47:22 | 00,051,048 | ---- | M] (Symantec Corporation)
"HP Software Update" -> %ProgramFiles%\HP\HP Software Update\hpwuSchd2.exe ["C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"] -> [2005/02/16 23:11:42 | 00,049,152 | ---- | M] (Hewlett-Packard Co.)
"iTunesHelper" -> %ProgramFiles%\iTunes\iTunesHelper.exe ["C:\Program Files\iTunes\iTunesHelper.exe"] -> [2008/10/01 18:57:12 | 00,289,576 | ---- | M] (Apple Inc.)
"NvCplDaemon" -> %SystemRoot%\system32\nvcpl.dll [RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup] -> [2006/08/12 00:43:02 | 07,630,848 | ---- | M] (NVIDIA Corporation)
"osCheck" -> %ProgramFiles%\Norton AntiVirus\osCheck.exe ["C:\Program Files\Norton AntiVirus\osCheck.exe"] -> [2008/02/07 02:49:38 | 00,718,704 | ---- | M] (Symantec Corporation)
"QuickTime Task" -> %ProgramFiles%\QuickTime\QTTask.exe ["C:\Program Files\QuickTime\QTTask.exe" -atboottime] -> [2008/09/06 15:09:14 | 00,413,696 | ---- | M] (Apple Inc.)
"StxTrayMenu" -> %ProgramFiles%\Seagate\SystemTray\StxMenuMgr.exe ["C:\Program Files\Seagate\SystemTray\StxMenuMgr.exe"] -> [2007/01/18 13:20:26 | 00,190,008 | ---- | M] (Seagate LLC)
"TkBellExe" -> %CommonProgramFiles%\Real\Update_OB\realsched.exe ["C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot] -> [2008/09/02 23:34:41 | 00,185,896 | ---- | M] (RealNetworks, Inc.)
< All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup ->
%AllUsersProfile%\Start Menu\Programs\Startup\Compaq Connections.lnk -> %ProgramFiles%\Compaq Connections\6750491\Program\Compaq Connections.exe -> [2004/08/09 04:59:57 | 00,016,423 | ---- | M] ()
%AllUsersProfile%\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk -> %ProgramFiles%\HP\Digital Imaging\bin\hpqtra08.exe -> [2004/11/04 19:28:24 | 00,258,048 | ---- | M] (Hewlett-Packard Co.)
%AllUsersProfile%\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk -> %ProgramFiles%\HP\Digital Imaging\bin\hpqthb08.exe -> [2004/11/04 19:50:52 | 00,053,248 | ---- | M] (Hewlett-Packard Co.)
< nick petrotto Startup Folder > -> C:\Documents and Settings\nick petrotto\Start Menu\Programs\Startup ->
< Software Policy Settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer ->
< Software Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Internet Explorer ->
< CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"dontdisplaylastusername" -> [0] -> File not found
\\"legalnoticecaption" -> [] -> File not found
\\"legalnoticetext" -> [] -> File not found
\\"shutdownwithoutlogon" -> [1] -> File not found
\\"undockwithoutlogon" -> [1] -> File not found
< CurrentVersion Policy Settings - Explorer [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [145] -> File not found
\\"NoDrives" -> [0] -> File not found
< CurrentVersion Policy Settings - System [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
< Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ ->
E&xport to Microsoft Excel -> %SystemDrive%\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE [res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000] -> File not found
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}:{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_05\bin\npjpi160_05.dll [Menu: Sun Java Console] -> [2008/02/22 04:25:19 | 00,132,496 | ---- | M] (Sun Microsystems, Inc.)
{92780B25-18CC-41C8-B9BE-3C9C571A8263}:{FF059E31-CC5A-4E2E-BF3B-96E929D65503} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Button: Research] -> [2007/04/19 14:10:18 | 00,063,840 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Button: Messenger] -> [2008/04/13 20:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Menu: Windows Messenger] -> [2008/04/13 20:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ ->
CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> %ProgramFiles%\Java\jre1.6.0_05\bin\npjpi160_05.dll [Sun Java Console] -> [2008/02/22 04:25:19 | 00,132,496 | ---- | M] (Sun Microsystems, Inc.)
CmdMapping\\"{92780B25-18CC-41C8-B9BE-3C9C571A8263}" [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2007/04/19 14:10:18 | 00,063,840 | ---- | M] (Microsoft Corporation)
CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 20:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ ->
PluginsPageFriendlyName -> Microsoft ActiveX Gallery ->
PluginsPage -> http://activex.microsoft.com/controls/find...=%s&mime=%s ->
< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 4510 domain(s) found. ->
33 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 77 range(s) found. ->
< Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 4509 domain(s) found. ->
32 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 77 range(s) found. ->
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{01010200-5E80-11D8-9E86-0007E96C65AE} [HKLM] -> http://supportcenter.adelphia.net/sdccommo...ad/tgctlins.cab[SupportSoft Installer] ->
{01111F00-3E00-11D2-8470-0060089874ED} [HKLM] -> http://supportsoft.adelphia.net/sdccommon/...ad/tgctlins.cab[Support.com Installer] ->
{166B1BCA-3F9C-11CF-8075-444553540000} [HKLM] -> http://download.macromedia.com/pub/shockwa...director/sw.cab[Shockwave ActiveX Control] ->
{30528230-99f7-4bb4-88d8-fa1d4f56a2ab} [HKLM] -> C:\Program Files\Yahoo!\Common\yinsthelper.dll[YInstStarter Class] ->
{3334504D-9980-0010-8000-00AA00389B71} [HKLM] -> http://download.microsoft.com/download/0/C...C4D/mp43dmo.CAB[Reg Error: Key does not exist or could not be opened.] ->
{6A060448-60F9-11D5-A6CD-0002B31F7455} [HKLM] -> [ExentInf Class] ->
{8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab[Java Plug-in 1.6.0_05] ->
{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/products/plugin/autodl...indows-i586.cab[Java Plug-in 1.4.2_03] ->
{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab[Java Plug-in 1.5.0_06] ->
{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab[Java Plug-in 1.5.0_10] ->
{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab[Java Plug-in 1.5.0_11] ->
{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab[Java Plug-in 1.6.0_01] ->
{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab[Java Plug-in 1.6.0_03] ->
{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab[Java Plug-in 1.6.0_05] ->
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab[Java Plug-in 1.6.0_05] ->
{D27CDB6E-AE6D-11CF-96B8-444553540000} [HKLM] -> http://fpdownload.macromedia.com/pub/shock...ash/swflash.cab[Shockwave Flash Object] ->
{DF780F87-FF2B-4DF8-92D0-73DB16A1543A} [HKLM] -> http://download.games.yahoo.com/games/web_...aploader_v6.cab[PopCapLoader Object] ->
{E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} [HKLM] -> http://chat.yahoo.com/cab/yvwrctl.cab[Yahoo! Webcam Viewer Wrapper] ->
< DNS Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->
{19FF9990-6B37-4319-9577-7F6CE0556C60} -> (1394 Net Adapter) ->
{39F0655E-9D92-466F-8476-46FF44E146B8} -> (Compact Wireless-G USB Adapter) ->
{913C3971-ABB5-4A65-B85D-2A6CFB477B0C} -> () ->
{C8397028-6231-4375-97CD-138640ADBA1F} -> (VIA Rhine II Fast Ethernet Adapter) ->
{FC2C37BD-39F1-4862-9D3D-6E75D5BD6EE1} -> (Compact Wireless-G USB Adapter) ->
< AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs ->
*AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls ->
yndkyu.dll -> %SystemRoot%\system32\yndkyu.dll -> [2008/10/15 22:12:42 | 00,109,056 | ---- | M] ()
dlmwvo.dll -> %SystemRoot%\system32\dlmwvo.dll -> [2008/10/16 00:14:18 | 00,109,056 | ---- | M] ()
*MultiFile Done* -> ->
< SSODL [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad ->
"{fbeb8a05-beee-4442-804e-409d6c4515e9}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [CDBurn] -> File not found
< LSA Authentication Packages [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages ->
*LSA Authentication Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages ->
C:\WINDOWS\system32\geBqQIAR -> %SystemRoot%\system32\geBqQIAR.dll -> [2008/10/15 19:03:02 | 00,267,776 | ---- | M] ()
*MultiFile Done* -> ->
< Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List ->
"%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008/04/13 20:12:34 | 00,141,312 | ---- | M] (Microsoft Corporation)
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List ->
"%windir%\system32\sessmgr.exe" -> C:\WINDOWS\system32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008/04/13 20:12:34 | 00,141,312 | ---- | M] (Microsoft Corporation)
"C:\Program Files\AIM6\aim6.exe" -> C:\Program Files\AIM6\aim6.exe [C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM] -> [2008/08/06 11:21:06 | 00,050,472 | ---- | M] (AOL LLC)
"C:\Program Files\Bonjour\mDNSResponder.exe" -> C:\Program Files\Bonjour\mDNSResponder.exe [C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour] -> [2008/08/29 10:18:44 | 00,238,888 | ---- | M] (Apple Inc.)
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" -> C:\Program Files\Common Files\AOL\Loader\aolload.exe [C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader] -> [2006/11/03 03:17:27 | 00,010,800 | ---- | M] (AOL LLC)
"C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe" -> C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe [C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe:*:Enabled:Compaq Connections] -> [2004/08/09 04:59:57 | 00,016,423 | ---- | M] ()
"C:\Program Files\iTunes\iTunes.exe" -> C:\Program Files\iTunes\iTunes.exe [C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes] -> [2008/10/01 18:57:04 | 14,258,472 | ---- | M] (Apple Inc.)
"C:\Program Files\MySpace\IM\MySpaceIM.exe" -> C:\Program Files\MySpace\IM\MySpaceIM.exe [C:\Program Files\MySpace\IM\MySpaceIM.exe:*:Enabled:MySpace Instant Messenger] -> [2008/04/17 19:27:00 | 09,117,696 | ---- | M] ()
"C:\Program Files\Paltalk Messenger\paltalk.exe" -> C:\Program Files\Paltalk Messenger\paltalk.exe [C:\Program Files\Paltalk Messenger\paltalk.exe:*:Enabled:PaltalkScene] -> File not found
"C:\Program Files\uTorrent\uTorrent.exe" -> C:\Program Files\uTorrent\uTorrent.exe [C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent] -> [2008/10/09 20:21:01 | 00,270,128 | ---- | M] (BitTorrent, Inc.)
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot ->
"AlternateShell" -> cmd.exe ->
< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom ->
"AutoRun" -> 1 ->
"DisplayName" -> CD-ROM Driver ->
"ImagePath" -> %SystemRoot%\system32\drivers\cdrom.sys [system32\DRIVERS\cdrom.sys] -> [2008/04/13 14:40:46 | 00,062,976 | ---- | M] (Microsoft Corporation)
< Drives with AutoRun files > -> ->
C:\autoAlbum.log [-i="C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\HP\Digital Imaging\tmpAlb_3\tmpAlb_3_0.txt" -o="C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\HP\Digital Imaging\tmpAlb_3\tmpAlb_3_0_out.txt" -g -b -s=4 -f="text"input text file: C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\HP\Digital Imaging\tmpAlb_3\tmpAlb_3_0.txt | output file: C:\Documents and Settings\Compaq_Owner\Local Settings\Application Data\HP\Digital Imaging\tmpAlb_3\tmpAlb_3_0_out.txt | | Value of width is 1129 and ht is 1715creating book layout ... | layout is complete, writing output file of type 1... | ] -> %SystemDrive%\autoAlbum.log [ NTFS ] -> [2007/04/13 19:03:00 | 00,000,647 | ---- | M] ()
C:\AUTOEXEC.BAT [] -> %SystemDrive%\AUTOEXEC.BAT [ NTFS ] -> [2004/08/09 01:45:44 | 00,000,000 | ---- | M] ()
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c5803e0b-70aa-11dd-b2ca-00112fbf7319}\Shell\AutoRun\command
\{c5803e0b-70aa-11dd-b2ca-00112fbf7319}\Shell\AutoRun\command\\"" -> G:\Install FreeAgent Tools.exe ["G:\Install FreeAgent Tools.exe" /run] -> File not found

[Registry - Additional Scans - Safe List]
< App Paths [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ ->
AcroRd32.exe -> %ProgramFiles%\Adobe\Reader 8.0\Reader\AcroRd32.exe [C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe] -> [2007/05/11 03:06:38 | 00,341,616 | ---- | M] (Adobe Systems Incorporated)
audconv.exe -> %ProgramFiles%\Audio Converter\audconv.exe [C:\Program Files\Audio Converter\audconv.exe] -> File not found
bckgzm.exe -> %ProgramFiles%\MSN Gaming Zone\Windows\bckgzm.exe [C:\Program Files\MSN Gaming Zone\Windows\bckgzm.exe] -> [2004/08/04 08:00:00 | 00,042,577 | ---- | M] (Microsoft Corporation)
CamWizrd.exe -> %CommonProgramFiles%\Logitech\QCDRV\BIN\CamWizrd.exe [C:\Program Files\Common Files\Logitech\QCDRV\BIN\CamWizrd.exe] -> [2004/12/15 07:01:43 | 00,122,880 | R--- | M] (Logitech Inc.)
ccApp.exe -> %CommonProgramFiles%\Symantec Shared\ccApp.exe [C:\Program Files\Common Files\Symantec Shared\ccApp.exe] -> [2008/01/25 21:47:22 | 00,051,048 | ---- | M] (Symantec Corporation)
ccleaner.exe -> %ProgramFiles%\CCleaner\CCleaner.exe [C:\Program Files\CCleaner\ccleaner.exe] -> [2008/09/29 11:11:54 | 01,279,216 | ---- | M] (Piriform Ltd)
CDGrab.exe -> %ProgramFiles%\Illustrate\dBpowerAMP\CDGrab.exe [C:\Program Files\Illustrate\dBpowerAMP\CDGrab.exe] -> [2008/08/03 12:16:55 | 01,585,152 | ---- | M] (Illustrate)
chkrzm.exe -> %ProgramFiles%\MSN Gaming Zone\Windows\chkrzm.exe [C:\Program Files\MSN Gaming Zone\Windows\chkrzm.exe] -> [2004/08/04 08:00:00 | 00,042,575 | ---- | M] (Microsoft Corporation)
cmmgr32.exe -> %SystemRoot%\system32\cmmgr32.exe [C:\WINDOWS\system32\cmmgr32.exe] -> File not found
CONF.EXE -> %ProgramFiles%\NetMeeting\conf.exe [C:\Program Files\NetMeeting\conf.exe] -> [2008/04/13 20:12:15 | 01,032,192 | ---- | M] (Microsoft Corporation)
CoreConverter.exe -> %ProgramFiles%\Illustrate\dBpowerAMP\CoreConverter.exe [C:\Program Files\Illustrate\dBpowerAMP\CoreConverter.exe] -> [2008/08/03 12:16:54 | 00,225,280 | ---- | M] (Illustrate)
dBConfig.exe -> %ProgramFiles%\Illustrate\dBpowerAMP\dBConfig.exe [C:\Program Files\Illustrate\dBpowerAMP\dBConfig.exe] -> [2008/08/03 12:16:51 | 00,413,048 | ---- | M] (Illustrate)
dialer.exe -> %ProgramFiles%\Windows NT\dialer.exe [C:\Program Files\Windows NT\dialer.exe] -> [2008/04/13 20:12:17 | 00,539,136 | ---- | M] (Microsoft Corporation)
DMCFileSelector.exe -> %ProgramFiles%\Illustrate\dBpowerAMP\DMCFileSelector.exe [C:\Program Files\Illustrate\dBpowerAMP\DMCFileSelector.exe] -> [2008/08/03 12:16:57 | 00,364,544 | ---- | M] (Illustrate)
dwwin.exe -> %ProgramFiles%\DiscWizard for Windows\dwwin.exe [C:\Program Files\DiscWizard for Windows\dwwin.exe] -> [2004/03/31 10:19:52 | 00,552,960 | ---- | M] (Kroll Ontrack Inc)
DXDIAG.EXE -> %SystemRoot%\system32\dxdiag.exe [C:\WINDOWS\system32\dxdiag.exe] -> [2008/04/13 20:12:18 | 01,298,432 | ---- | M] (Microsoft Corporation)
easycdda.exe -> %ProgramFiles%\Audio Converter\easycdda.exe [C:\Program Files\Audio Converter\easycdda.exe] -> File not found
Episode 204 - Chariots of the Dogs -> %ProgramFiles%\Telltale Games\Sam and Max - Season Two\SamMax204.exe [C:\Program Files\Telltale Games\Sam and Max - Season Two\SamMax204.exe] -> File not found
Episode 205 - What's New, Beelzebub? -> %ProgramFiles%\Telltale Games\Sam and Max - Season Two\SamMax205.exe [C:\Program Files\Telltale Games\Sam and Max - Season Two\SamMax205.exe] -> File not found
excel.exe -> %ProgramFiles%\Microsoft Office\OFFICE11\EXCEL.EXE [C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE] -> [2008/05/15 15:42:26 | 10,354,176 | ---- | M] (Microsoft Corporation)
firefox.exe -> %ProgramFiles%\Mozilla Firefox\firefox.exe [C:\Program Files\Mozilla Firefox\firefox.exe] -> [2008/09/27 09:07:21 | 00,307,712 | ---- | M] (Mozilla Corporation)
GetPopupInfo.exe -> %ProgramFiles%\Illustrate\dBpowerAMP\GetPopupInfo.exe [C:\Program Files\Illustrate\dBpowerAMP\GetPopupInfo.exe] -> [2008/08/03 12:16:53 | 00,151,552 | ---- | M] (Illustrate)
HELPCTR.EXE -> %SystemRoot%\pchealth\helpctr\binaries\helpctr.exe [C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpCtr.exe] -> [2008/04/13 20:12:21 | 00,769,024 | ---- | M] (Microsoft Corporation)
HijackThis.exe -> %UserProfile%\Desktop\hijackthis\HijackThis.exe [C:\Documents and Settings\nick petrotto\Desktop\hijackthis\hijackthis.exe] -> [2005/02/16 11:06:16 | 00,218,112 | ---- | M] (Soeperman Enterprises Ltd.)
HpApp.exe -> %ProgramFiles%\HP Design Studio\HPapp.exe [C:\Program Files\HP Design Studio\HpApp.exe] -> [2004/06/30 10:33:54 | 00,659,456 | ---- | M] (AmericanGreetings.com)
HpqApkil.exe -> %ProgramFiles%\HP\Digital Imaging\Unload\HpqApkil.exe [C:\Program Files\HP\Digital Imaging\Unload\HpqApkil.exe] -> [2004/10/08 09:43:10 | 00,022,528 | ---- | M] ()
hpqgalry.exe -> %ProgramFiles%\HP\Digital Imaging\bin\hpqgalry.exe [C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe] -> [2004/11/04 19:36:46 | 00,425,984 | ---- | M] (Hewlett-Packard Co.)
HpqPhUnl.exe -> %ProgramFiles%\HP\Digital Imaging\Unload\HpqPhUnl.exe [C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe] -> [2004/10/08 09:42:04 | 00,413,696 | ---- | M] ()
HpqPSmon.exe -> %ProgramFiles%\HP\Digital Imaging\Unload\HpqPSmon.exe [C:\Program Files\HP\Digital Imaging\Unload\HpqPSmon.exe] -> [2004/10/08 09:43:12 | 00,065,536 | ---- | M] ()
hpqthb08.exe -> %ProgramFiles%\HP\Digital Imaging\bin\hpqthb08.exe [C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe] -> [2004/11/04 19:50:52 | 00,053,248 | ---- | M] (Hewlett-Packard Co.)
HpqUnSet.exe -> %ProgramFiles%\HP\Digital Imaging\Unload\HpqUnSet.exe [C:\Program Files\HP\Digital Imaging\Unload\HpqUnSet.exe] -> [2004/10/08 09:42:04 | 00,053,248 | ---- | M] (TODO: )
HPSdpApp.exe -> %ProgramFiles%\Easy Internet signup\HPSdpApp.exe [C:\Program Files\Easy Internet signup\HPSdpApp.exe] -> File not found
hrtzzm.exe -> %ProgramFiles%\MSN Gaming Zone\Windows\hrtzzm.exe [C:\Program Files\MSN Gaming Zone\Windows\hrtzzm.exe] -> [2004/08/04 08:00:00 | 00,042,573 | ---- | M] (Microsoft Corporation)
hypertrm.exe -> %ProgramFiles%\Windows NT\hypertrm.exe ["C:\Program Files\Windows NT\hypertrm.exe"] -> [2004/08/04 08:00:00 | 00,028,160 | ---- | M] (Hilgraeve, Inc.)
ICWCONN1.EXE -> %ProgramFiles%\Internet Explorer\Connection Wizard\icwconn1.exe ["C:\Program Files\Internet Explorer\Connection Wizard\ICWCONN1.EXE"] -> [2008/04/13 20:12:22 | 00,214,528 | ---- | M] (Microsoft Corporation)
ICWCONN2.EXE -> %ProgramFiles%\Internet Explorer\Connection Wizard\icwconn2.exe ["C:\Program Files\Internet Explorer\Connection Wizard\ICWCONN2.EXE"] -> [2008/04/13 20:12:22 | 00,086,016 | ---- | M] (Microsoft Corporation)
IEXPLORE.EXE -> %ProgramFiles%\Internet Explorer\iexplore.exe [C:\Program Files\Internet Explorer\IEXPLORE.EXE] -> [2008/06/23 05:20:52 | 00,625,664 | ---- | M] (Microsoft Corporation)
INETWIZ.EXE -> %ProgramFiles%\Internet Explorer\Connection Wizard\inetwiz.exe ["C:\Program Files\Internet Explorer\Connection Wizard\INETWIZ.EXE"] -> [2008/04/13 20:12:22 | 00,020,480 | ---- | M] (Microsoft Corporation)
infopath.exe -> %ProgramFiles%\Microsoft Office\OFFICE11\INFOPATH.EXE [C:\Program Files\Microsoft Office\OFFICE11\INFOPATH.EXE] -> [2007/04/30 14:57:26 | 07,084,384 | ---- | M] (Microsoft Corporation)
install.exe -> Reg Error: Value does not exist or could not be read. [Reg Error: Value does not exist or could not be read.] -> File not found
InstallHelper.exe -> Reg Error: Value does not exist or could not be read. [Reg Error: Value does not exist or could not be read.] -> File not found
ISIGNUP.EXE -> %ProgramFiles%\Internet Explorer\Connection Wizard\isignup.exe ["C:\Program Files\Internet Explorer\Connection Wizard\ISIGNUP.EXE"] -> [2004/08/04 08:00:00 | 00,016,384 | ---- | M] (Microsoft Corporation)
isobuster.exe -> %ProgramFiles%\Smart Projects\IsoBuster\IsoBuster.exe [C:\Program Files\Smart Projects\IsoBuster\IsoBuster.exe] -> File not found
ISPSignup.exe -> %ProgramFiles%\Easy Internet signup\ISPSignup.exe [C:\Program Files\Easy Internet signup\ISPSignup.exe] -> File not found
iTunes.exe -> %ProgramFiles%\iTunes\iTunes.exe [C:\Program Files\iTunes\iTunes.exe] -> [2008/10/01 18:57:04 | 14,258,472 | ---- | M] (Apple Inc.)
javaws.exe -> %ProgramFiles%\Java\jre1.6.0_05\bin\javaws.exe [C:\Program Files\Java\jre1.6.0_05\bin\javaws.exe] -> [2008/02/22 02:33:32 | 00,139,264 | ---- | M] (Sun Microsystems, Inc.)
Logitray.exe -> %ProgramFiles%\Logitech\Video\LogiTray.exe [C:\Program Files\Logitech\Video\Logitray.exe] -> [2005/01/18 18:37:30 | 00,217,088 | ---- | M] (Logitech Inc.)
LUALL.EXE -> %ProgramFiles%\Symantec\LiveUpdate\LUALL.EXE [C:\Program Files\Symantec\LiveUpdate\LUALL.EXE] -> [2008/09/05 11:52:30 | 00,873,848 | ---- | M] (Symantec Corporation)
MCUI32.exe -> %CommonProgramFiles%\Symantec Shared\SecurityHistory\MCUI32.exe [C:\Program Files\Common Files\Symantec Shared\SecurityHistory\MCUI32.exe] -> [2008/02/07 02:49:36 | 00,443,760 | ---- | M] (Symantec Corporation)
migwiz.exe -> %SystemRoot%\system32\usmt\migwiz.exe [%SystemRoot%\system32\usmt\migwiz.exe] -> [2008/04/13 20:12:25 | 00,245,248 | ---- | M] (Microsoft Corporation)
moviemk.exe -> %ProgramFiles%\Movie Maker\moviemk.exe [C:\Program Files\Movie Maker\moviemk.exe] -> [2008/04/13 20:12:27 | 03,558,912 | ---- | M] (Microsoft Corporation)
mplayer2.exe -> %ProgramFiles%\Windows Media Player\mplayer2.exe [C:\Program Files\Windows Media Player\mplayer2.exe] -> [2008/04/13 20:12:27 | 00,004,639 | ---- | M] (Microsoft Corporation)
MSACCESS.EXE -> %ProgramFiles%\Microsoft Office\OFFICE11\MSACCESS.EXE [C:\PROGRA~1\MICROS~2\OFFICE11\MSACCESS.EXE] -> [2007/05/10 13:43:12 | 06,688,096 | ---- | M] (Microsoft Corporation)
MSCONFIG.EXE -> %SystemRoot%\pchealth\helpctr\binaries\msconfig.exe [C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe] -> [2008/04/13 20:12:27 | 00,169,984 | ---- | M] (Microsoft Corporation)
msimn.exe -> %ProgramFiles%\Outlook Express\msimn.exe [%ProgramFiles%\Outlook Express\msimn.exe] -> [2008/04/13 20:12:28 | 00,060,416 | ---- | M] (Microsoft Corporation)
msinfo32.exe -> %CommonProgramFiles%\Microsoft Shared\MSInfo\msinfo32.exe [C:\Program Files\Common Files\Microsoft Shared\MSInfo\MSInfo32.exe] -> [2004/08/04 08:00:00 | 00,039,936 | ---- | M] (Microsoft Corporation)
MSMSGS.EXE -> %ProgramFiles%\Messenger\msmsgs.exe [C:\Program Files\Messenger\msmsgs.exe] -> [2008/04/13 20:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)
MsoHtmEd.exe -> Reg Error: Value does not exist or could not be read. [Reg Error: Value does not exist or could not be read.] -> File not found
msoxmled.exe -> %CommonProgramFiles%\Microsoft Shared\OFFICE12\MSOXMLED.EXE [C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLED.EXE] -> [2006/10/26 21:41:50 | 00,059,152 | ---- | M] (Microsoft Corporation)
MSPUB.EXE -> %ProgramFiles%\Microsoft Office\Office12\MSPUB.EXE [C:\PROGRA~1\MICROS~2\Office12\MSPUB.EXE] -> [2008/03/22 18:03:02 | 09,586,720 | ---- | M] (Microsoft Corporation)
mspview.exe -> %CommonProgramFiles%\Microsoft Shared\MODI\11.0\MSPVIEW.EXE [C:\PROGRA~1\COMMON~1\MICROS~1\MODI\11.0\MSPVIEW.EXE] -> [2007/04/09 13:24:00 | 00,367,496 | ---- | M] (Microsoft Corporation)
msworks.exe -> %ProgramFiles%\Microsoft Works\msworks.exe [c:\Program Files\Microsoft Works\msworks.exe] -> [2002/07/11 07:04:26 | 00,094,276 | ---- | M] (Microsoft® Corporation)
MusicConverter.exe -> %ProgramFiles%\Illustrate\dBpowerAMP\MusicConverter.exe [C:\Program Files\Illustrate\dBpowerAMP\MusicConverter.exe] -> [2008/08/03 12:16:54 | 00,647,168 | ---- | M] (Illustrate)
NAVW32.EXE -> %ProgramFiles%\Norton AntiVirus\Navw32.exe [C:\PROGRA~1\NORTON~1\Navw32.exe] -> [2008/02/07 10:05:12 | 00,251,752 | ---- | M] (Symantec Corporation)
NAVWNT.EXE -> %ProgramFiles%\Norton AntiVirus\Navwnt.exe [C:\PROGRA~1\NORTON~1\Navwnt.exe] -> [2008/02/07 10:05:16 | 00,061,288 | ---- | M] (Symantec Corporation)
ois.exe -> %ProgramFiles%\Microsoft Office\Office12\OIS.EXE [C:\PROGRA~1\MICROS~2\Office12\OIS.EXE] -> [2007/08/24 04:06:28 | 00,277,384 | ---- | M] (Microsoft Corporation)
ORUN32.EXE -> %SystemRoot%\ORUN32.EXE [C:\WINDOWS\ORUN32.EXE] -> File not found
OUTLOOK.EXE -> %ProgramFiles%\Microsoft Office\OFFICE11\OUTLOOK.EXE [C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE] -> [2008/04/23 15:09:50 | 00,199,688 | ---- | M] (Microsoft Corporation)
pbrush.exe -> %SystemRoot%\system32\mspaint.exe [%SystemRoot%\system32\mspaint.exe] -> [2008/04/13 20:12:28 | 00,343,040 | ---- | M] (Microsoft Corporation)
Pcdrw32.exe -> %ProgramFiles%\PC-Doctor for Windows\Pcdrw32.exe [C:\Program Files\PC-Doctor for Windows\Pcdrw32.exe] -> [2004/04/23 22:43:52 | 00,036,864 | ---- | M] ()
PictureViewer.exe -> %ProgramFiles%\QuickTime\PictureViewer.exe [C:\Program Files\QuickTime\PictureViewer.exe] -> [2008/09/06 15:09:08 | 00,548,864 | ---- | M] (Apple Inc.)
pinball.exe -> %ProgramFiles%\Windows NT\Pinball\pinball.exe [C:\Program Files\Windows NT\Pinball\pinball.exe] -> [2008/04/13 20:12:31 | 00,281,088 | ---- | M] (Cinematronics)
powerpnt.exe -> %ProgramFiles%\Microsoft Office\OFFICE11\POWERPNT.EXE [C:\PROGRA~1\MICROS~2\OFFICE11\POWERPNT.EXE] -> [2008/07/03 18:33:40 | 06,421,512 | ---- | M] (Microsoft Corporation)
Python.exe -> %SystemDrive%\Python22\python.exe [C:\Python22\Python.exe] -> [2002/04/10 05:35:30 | 00,020,527 | ---- | M] ()
Pythonwin.exe -> %SystemDrive%\Python22\Lib\site-packages\Pythonwin\Pythonwin.exe [C:\Python22\lib\site-packages\Pythonwin\Pythonwin.exe] -> [2002/01/19 01:44:14 | 00,024,638 | ---- | M] ()
QuickCam.exe -> %ProgramFiles%\Logitech\Video\QuickCam.exe [C:\Program Files\Logitech\Video\QuickCam.exe] -> File not found
QuickTimePlayer.exe -> %ProgramFiles%\QuickTime\QuickTimePlayer.exe [C:\Program Files\QuickTime\QuickTimePlayer.exe] -> [2008/09/06 15:09:38 | 07,685,424 | ---- | M] (Apple Inc.)
realplay.exe -> %ProgramFiles%\Real\RealPlayer\realplay.exe [C:\Program Files\Real\RealPlayer\realplay.exe] -> [2008/09/02 23:34:48 | 00,214,560 | ---- | M] (RealNetworks, Inc.)
RecordNow.exe -> %ProgramFiles%\Sonic RecordNow!\RecordNow.exe [c:\Program Files\Sonic RecordNow!\RecordNow.exe] -> [2004/06/07 17:02:00 | 01,912,832 | ---- | M] ()
rnxproc.exe -> %CommonProgramFiles%\Real\Update_OB\rnxproc.exe [C:\Program Files\Common Files\Real\Update_OB\rnxproc.exe] -> [2008/09/02 23:34:42 | 00,058,952 | ---- | M] (RealNetworks, Inc.)
RogueRemover.exe -> %ProgramFiles%\RogueRemover FREE\RogueRemover.exe [C:\Program Files\RogueRemover FREE\RogueRemover.exe] -> [2008/02/24 14:53:10 | 00,266,240 | ---- | M] (Malwarebytes)
RoxioTarget.exe -> %ProgramFiles%\Logitech\Video\RoxioTarget.exe [C:\Program Files\Logitech\Video\RoxioTarget.exe] -> [2005/01/18 18:46:36 | 00,029,696 | ---- | M] (Logitech Inc.)
rvsezm.exe -> %ProgramFiles%\MSN Gaming Zone\Windows\Rvsezm.exe [C:\Program Files\MSN Gaming Zone\Windows\rvsezm.exe] -> [2004/08/04 08:00:00 | 00,042,574 | ---- | M] (Microsoft Corporation)
setup.exe -> Reg Error: Value does not exist or could not be read. [Reg Error: Value does not exist or could not be read.] -> File not found
shvlzm.exe -> %ProgramFiles%\MSN Gaming Zone\Windows\shvlzm.exe [C:\Program Files\MSN Gaming Zone\Windows\shvlzm.exe] -> [2004/08/04 08:00:00 | 00,042,573 | ---- | M] (Microsoft Corporation)
table30.exe -> Reg Error: Value does not exist or could not be read. [Reg Error: Value does not exist or could not be read.] -> File not found
uiStub2.exe -> %CommonProgramFiles%\Symantec Shared\NPC\2.0\uiStub2.exe [C:\PROGRA~1\COMMON~1\SYMANT~1\NPC\2.0\uiStub2.exe] -> [2008/02/06 17:11:22 | 00,104,312 | ---- | M] (Symantec Corporation)
UltimateAudioRecorder.exe -> %ProgramFiles%\Audio Converter\UltimateAudioRecorder.exe [C:\Program Files\Audio Converter\UltimateAudioRecorder.exe] -> File not found
Verizon Games on Demand Player -> [C:\Program Files\Verizon Games on Demand Player\Verizon Games on Demand Player] -> File not found
vstudio.exe -> %ProgramFiles%\Ulead Systems\Ulead VideoStudio 10\vstudio.exe [C:\Program Files\Ulead Systems\Ulead VideoStudio 10\vstudio.exe] -> [2006/04/06 11:40:00 | 01,789,952 | ---- | M] (Ulead Systems, Inc.)
wab.exe -> %ProgramFiles%\Outlook Express\wab.exe [%ProgramFiles%\Outlook Express\wab.exe] -> [2008/04/13 20:12:38 | 00,046,080 | ---- | M] (Microsoft Corporation)
wabmig.exe -> %ProgramFiles%\Outlook Express\wabmig.exe [%ProgramFiles%\Outlook Express\wabmig.exe] -> [2008/04/13 20:12:39 | 00,030,208 | ---- | M] (Microsoft Corporation)
WaveChk.exe -> %ProgramFiles%\Logitech\Video\WaveChk.exe [C:\Program Files\Logitech\Video\WaveChk.exe] -> [2005/01/18 18:10:32 | 00,131,072 | ---- | M] (Logitech Inc.)
WinDVD.exe -> %ProgramFiles%\InterVideo\WinDVD\WinDVD.exe [C:\Program Files\InterVideo\WinDVD\WinDVD.exe] -> [2004/06/26 11:40:02 | 00,110,592 | ---- | M] (InterVideo Inc.)
winnt32.exe -> Reg Error: Value does not exist or could not be read. [Reg Error: Value does not exist or could not be read.] -> File not found
WinRAR.exe -> %ProgramFiles%\WinRAR\WinRAR.exe [C:\Program Files\WinRAR\WinRAR.exe] -> [2006/09/14 01:19:52 | 00,916,992 | ---- | M] ()
Winword.exe -> %ProgramFiles%\Microsoft Office\OFFICE11\WINWORD.EXE [C:\PROGRA~1\MICROS~2\OFFICE11\WINWORD.EXE] -> [2008/07/03 18:36:56 | 12,313,096 | ---- | M] (Microsoft Corporation)
WKPLMSTP.EXE -> %ProgramFiles%\Microsoft Works\wkplmstp.exe [c:\Program Files\Microsoft Works\wkplmstp.exe] -> [2002/07/11 07:19:20 | 00,045,056 | ---- | M] (Microsoft Corporation)
WKSAB.EXE -> %ProgramFiles%\Microsoft Works\wksab.exe [c:\Program Files\Microsoft Works\WKSAB.exe] -> [2002/07/11 07:09:18 | 00,020,555 | ---- | M] (Microsoft® Corporation)
wkscal.exe -> %CommonProgramFiles%\Microsoft Shared\Works Shared\wkscal.exe [c:\Program Files\Common Files\Microsoft Shared\Works Shared\wkscal.exe] -> [2002/07/11 07:03:28 | 00,102,467 | ---- | M] (Microsoft® Corporation)
wksdb.exe -> %ProgramFiles%\Microsoft Works\wksdb.exe [c:\Program Files\Microsoft Works\wksdb.exe] -> [2002/07/11 07:17:36 | 02,228,282 | ---- | M] (Microsoft® Corporation)
WKSPROJ.EXE -> %ProgramFiles%\Microsoft Works\WksProj.exe [c:\Program Files\Microsoft Works\WksProj.exe] -> [2002/07/11 07:21:42 | 00,114,688 | ---- | M] (Microsoft® Corporation)
WKSSB.EXE -> %ProgramFiles%\Microsoft Works\wkssb.exe [c:\Program Files\Microsoft Works\WKSSB.exe] -> [2002/07/11 07:10:32 | 00,725,046 | ---- | M] (Microsoft® Corporation)
wksss.exe -> %ProgramFiles%\Microsoft Works\wksss.exe [c:\Program Files\Microsoft Works\wksss.exe] -> [2002/07/11 07:14:16 | 01,863,740 | ---- | M] (Microsoft® Corporation)
wkswp.exe -> %ProgramFiles%\Microsoft Works\WksWP.exe [c:\Program Files\Microsoft Works\wkswp.exe] -> [2002/07/11 06:55:42 | 00,106,556 | ---- | M] (Microsoft® Corporation)
WKWCESTP.EXE -> %ProgramFiles%\Microsoft Works\wkwcestp.exe [c:\Program Files\Microsoft Works\wkwcestp.exe] -> [2002/07/11 07:19:18 | 00,045,056 | ---- | M] ()
wmenc.exe -> %ProgramFiles%\Windows Media Components\Encoder\wmenc.exe [C:\Program Files\Windows Media Components\Encoder\WMEnc.exe] -> [2002/12/11 20:38:52 | 00,613,888 | ---- | M] (Microsoft Corporation)
wmplayer.exe -> %ProgramFiles%\Windows Media Player\wmplayer.exe [C:\Program Files\Windows Media Player\wmplayer.exe] -> [2006/10/18 22:46:20 | 00,064,000 | ---- | M] (Microsoft Corporation)
WORDPAD.EXE -> %ProgramFiles%\Windows NT\Accessories\wordpad.exe ["%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE"] -> [2008/04/13 20:12:40 | 00,214,528 | ---- | M] (Microsoft Corporation)
WRITE.EXE -> %ProgramFiles%\Windows NT\Accessories\wordpad.exe ["%ProgramFiles%\Windows NT\Accessories\WORDPAD.EXE"] -> [2008/04/13 20:12:40 | 00,214,528 | ---- | M] (Microsoft Corporation)
yourapp.Exe -> %ProgramFiles%\Compact Wireless-G USB Adapter Wireless Network Monitor\YourApp.exe [C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\YourApp.exe] -> File not found
< Desktop Components > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\ ->
0 -> [Key] ->
0 -> FriendlyName = My Current Home Page ->
0 -> Source = About:Home ->
0 -> SubscribedURL = About:Home ->
< Disabled MSConfig State [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state ->
"bootini" -> 0 ->
"services" -> 0 ->
"startup" -> 0 ->
"system.ini" -> 0 ->
"win.ini" -> 0 ->
< File Associations - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\ ->
.bat [@ = batfile] -> "%1" %* ->
.chm [@ = chm.file] -> %SystemRoot%\hh.exe -> [2008/04/13 20:12:21 | 00,010,752 | ---- | M] (Microsoft Corporation)
.cmd [@ = cmdfile] -> "%1" %* ->
.com [@ = comfile] -> "%1" %* ->
.exe [@ = exefile] -> "%1" %* ->
.hlp [@ = hlpfile] -> %SystemRoot%\system32\winhlp32.exe -> [2004/08/04 15:00:00 | 00,008,192 | ---- | M] (Microsoft Corporation)
.hta [@ = htafile] -> %SystemRoot%\system32\mshta.exe -> [2006/10/17 12:56:10 | 00,045,568 | ---- | M] (Microsoft Corporation)
.html [@ = htmlfile] -> %ProgramFiles%\Internet Explorer\iexplore.exe -> [2008/06/23 05:20:52 | 00,625,664 | ---- | M] (Microsoft Corporation)
.inf [@ = inffile] -> %SystemRoot%\system32\notepad.exe -> [2008/04/13 20:12:29 | 00,069,120 | ---- | M] (Microsoft Corporation)
.ini [@ = inifile] -> %SystemRoot%\system32\notepad.exe -> [2008/04/13 20:12:29 | 00,069,120 | ---- | M] (Microsoft Corporation)
.js [@ = JSFile] -> %SystemRoot%\system32\wscript.exe -> [2008/05/08 07:24:44 | 00,155,648 | ---- | M] (Microsoft Corporation)
.jse [@ = JSEFile] -> %SystemRoot%\system32\wscript.exe -> [2008/05/08 07:24:44 | 00,155,648 | ---- | M] (Microsoft Corporation)
.pif [@ = piffile] -> "%1" %* ->
.reg [@ = regfile] -> %SystemRoot%\regedit.exe -> [2008/04/13 20:12:32 | 00,146,432 | ---- | M] (Microsoft Corporation)
.scr [@ = scrfile] -> "%1" /S ->
.txt [@ = txtfile] -> %SystemRoot%\system32\notepad.exe -> [2008/04/13 20:12:29 | 00,069,120 | ---- | M] (Microsoft Corporation)
.vbe [@ = VBEFile] -> %SystemRoot%\system32\wscript.exe -> [2008/05/08 07:24:44 | 00,155,648 | ---- | M] (Microsoft Corporation)
.vbs [@ = VBSFile] -> %SystemRoot%\system32\wscript.exe -> [2008/05/08 07:24:44 | 00,155,648 | ---- | M] (Microsoft Corporation)
.wsf [@ = WSFFile] -> %SystemRoot%\system32\wscript.exe -> [2008/05/08 07:24:44 | 00,155,648 | ---- | M] (Microsoft Corporation)
.wsh [@ = WSHFile] -> %SystemRoot%\system32\wscript.exe -> [2008/05/08 07:24:44 | 00,155,648 | ---- | M] (Microsoft Corporation)
< EventViewer Logs - Last 10 Errors > -> Event Information -> Description
Application [ Error ] 9/12/2007 10:25:36 PM Computer Name = YOUR-22CA86D5C4 | Source = Application Error | ID = 1000 -> Description = Faulting application logitray.exe, version 8.4.6.1012, faulting module mfc71.dll, version 7.10.3077.0, fault address 0x00018bcd.
Application [ Error ] 10/7/2007 5:28:31 PM Computer Name = YOUR-22CA86D5C4 | Source = Application Error | ID = 1000 -> Description = Faulting application explorer.exe, version 6.0.2900.3156, faulting module qcui2.dll, version 8.4.6.1012, fault address 0x0001a33c.
Application [ Error ] 10/7/2007 5:28:36 PM Computer Name = YOUR-22CA86D5C4 | Source = Application Error | ID = 1000 -> Description = Faulting application explorer.exe, version 6.0.2900.3156, faulting module qcui2.dll, version 8.4.6.1012, fault address 0x0001a33c.
Application [ Error ] 11/4/2007 8:57:45 PM Computer Name = YOUR-22CA86D5C4 | Source = Application Hang | ID = 1002 -> Description = Hanging application iexplore.exe, version 7.0.6000.16544, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Application [ Error ] 11/4/2007 8:57:46 PM Computer Name = YOUR-22CA86D5C4 | Source = Application Hang | ID = 1002 -> Description = Hanging application iexplore.exe, version 7.0.6000.16544, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Application [ Error ] 11/4/2007 8:58:58 PM Computer Name = YOUR-22CA86D5C4 | Source = Application Hang | ID = 1002 -> Description = Hanging application iexplore.exe, version 7.0.6000.16544, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Application [ Error ] 12/16/2007 1:31:09 AM Computer Name = YOUR-22CA86D5C4 | Source = Application Error | ID = 1000 -> Description = Faulting application firefox.exe, version 1.8.20071.12718, faulting module ntdll.dll, version 5.1.2600.2180, fault address 0x00018fea.
Application [ Error ] 12/25/2007 10:29:12 AM Computer Name = YOUR-22CA86D5C4 | Source = MsiInstaller | ID = 1013 -> Description = Product: Adobe Reader 6.0.1 -- Setup has detected that you already have a more functional product installed. Setup will now terminate.
Application [ Error ] 12/31/2007 1:25:40 PM Computer Name = YOUR-22CA86D5C4 | Source = Application Error | ID = 1000 -> Description = Faulting application UbiAutorun.exe, version 0.0.0.0, faulting module MSVBVM60.DLL, version 0.0.0.0, fault address 0x000b0d95.
Application [ Error ] 1/9/2008 8:37:35 PM Computer Name = YOUR-22CA86D5C4 | Source = crypt32 | ID = 131080 -> Description = Failed auto update retrieval of third-party root list sequence number from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> with error: This operation returned because the timeout period expired.
System [ Error ] 10/16/2008 8:36:47 PM Computer Name = YOUR-22CA86D5C4 | Source = DCOM | ID = 10005 -> Description = DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
System [ Error ] 10/16/2008 8:37:05 PM Computer Name = YOUR-22CA86D5C4 | Source = DCOM | ID = 10005 -> Description = DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
System [ Error ] 10/16/2008 8:37:17 PM Computer Name = YOUR-22CA86D5C4 | Source = Service Control Manager | ID = 7001 -> Description = The DHCP Client service depends on the NetBT service which failed to start because of the following error: %%31
System [ Error ] 10/16/2008 8:37:17 PM Computer Name = YOUR-22CA86D5C4 | Source = Service Control Manager | ID = 7001 -> Description = The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: %%31
System [ Error ] 10/16/2008 8:37:17 PM Computer Name = YOUR-22CA86D5C4 | Source = Service Control Manager | ID = 7001 -> Description = The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: %%31
System [ Error ] 10/16/2008 8:37:17 PM Computer Name = YOUR-22CA86D5C4 | Source = Service Control Manager | ID = 7001 -> Description = The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: %%31
System [ Error ] 10/16/2008 8:37:17 PM Computer Name = YOUR-22CA86D5C4 | Source = Service Control Manager | ID = 7001 -> Description = The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: %%31
System [ Error ] 10/16/2008 8:37:17 PM Computer Name = YOUR-22CA86D5C4 | Source = Service Control Manager | ID = 7001 -> Description = The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: %%31
System [ Error ] 10/16/2008 8:37:17 PM Computer Name = YOUR-22CA86D5C4 | Source = Service Control Manager | ID = 7026 -> Description = The following boot-start or system-start driver(s) failed to load: AFD AmdK7 eeCtrl Fips IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss SRTSP SRTSPX SYMTDI Tcpip
System [ Error ] 10/16/2008 9:32:11 PM Computer Name = YOUR-22CA86D5C4 | Source = DCOM | ID = 10005 -> Description = DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}

[Files/Folders - Created Within 90 Days]
5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp ->
11 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp ->
WinRAR -> %AppData%\WinRAR -> [2008/10/16 21:10:33 | 00,000,000 | ---D | C]
user32.dll -> %SystemRoot%\System32\dllcache\user32.dll -> [2008/10/16 20:50:32 | 00,578,560 | ---- | C] (Microsoft Corporation)
ERUNT -> %SystemRoot%\ERUNT -> [2008/10/16 20:37:35 | 00,000,000 | ---D | C]
OTScanIt2 -> %UserProfile%\Desktop\OTScanIt2 -> [2008/10/16 20:31:38 | 00,000,000 | ---D | C]
SDFix -> %SystemDrive%\SDFix -> [2008/10/16 20:28:04 | 00,000,000 | ---D | C]
OTScanIt2.exe -> %UserProfile%\Desktop\OTScanIt2.exe -> [2008/10/16 20:12:39 | 00,587,283 | ---- | C] ()
SDFix.exe -> %UserProfile%\Desktop\SDFix.exe -> [2008/10/16 20:10:04 | 01,522,584 | ---- | C] ()
CCleaner.lnk -> %UserProfile%\Desktop\CCleaner.lnk -> [2008/10/16 07:53:15 | 00,001,556 | ---- | C] ()
Yahoo! Companion -> %AllUsersProfile%\Application Data\Yahoo! Companion -> [2008/10/16 00:18:45 | 00,000,000 | ---D | C]
dlmwvo.dll -> %SystemRoot%\System32\dlmwvo.dll -> [2008/10/16 00:14:24 | 00,109,056 | ---- | C] ()
ycvxguqt.dll -> %SystemRoot%\System32\ycvxguqt.dll -> [2008/10/16 00:14:15 | 00,109,056 | ---- | C] ()
eawcxrxc.ini -> %SystemRoot%\System32\eawcxrxc.ini -> [2008/10/16 00:12:07 | 01,358,676 | -HS- | C] ()
cxrxcwae.dll -> %SystemRoot%\System32\cxrxcwae.dll -> [2008/10/16 00:12:02 | 00,071,168 | ---- | C] ()
AntiXPVSTFix.exe -> %SystemRoot%\System32\AntiXPVSTFix.exe -> [2008/10/16 00:08:57 | 00,088,576 | ---- | C] (S!Ri.URZ)
VACFix.exe -> %SystemRoot%\System32\VACFix.exe -> [2008/10/16 00:08:49 | 00,087,552 | ---- | C] (S!Ri.URZ)
WS2Fix.exe -> %SystemRoot%\System32\WS2Fix.exe -> [2008/10/16 00:08:40 | 00,025,600 | ---- | C] ()
VCCLSID.exe -> %SystemRoot%\System32\VCCLSID.exe -> [2008/10/16 00:08:37 | 00,289,144 | ---- | C] (S!Ri)
swxcacls.exe -> %SystemRoot%\System32\swxcacls.exe -> [2008/10/16 00:08:35 | 00,079,360 | ---- | C] (SteelWerX)
dumphive.exe -> %SystemRoot%\System32\dumphive.exe -> [2008/10/16 00:08:34 | 00,051,200 | ---- | C] ()
SrchSTS.exe -> %SystemRoot%\System32\SrchSTS.exe -> [2008/10/16 00:08:32 | 00,288,417 | ---- | C] (S!Ri)
swsc.exe -> %SystemRoot%\System32\swsc.exe -> [2008/10/16 00:08:28 | 00,040,960 | ---- | C] ()
swreg.exe -> %SystemRoot%\System32\swreg.exe -> [2008/10/16 00:08:25 | 00,135,168 | ---- | C] (SteelWerX)
Process.exe -> %SystemRoot%\System32\Process.exe -> [2008/10/16 00:08:24 | 00,053,248 | ---- | C] (http://www.beyondlogic.org)
CCleaner -> %ProgramFiles%\CCleaner -> [2008/10/16 00:07:49 | 00,000,000 | ---D | C]
RogueRemover FREE.lnk -> %AllUsersProfile%\Desktop\RogueRemover FREE.lnk -> [2008/10/16 00:07:02 | 00,000,703 | ---- | C] ()
RogueRemover FREE -> %ProgramFiles%\RogueRemover FREE -> [2008/10/16 00:07:00 | 00,000,000 | ---D | C]
SmitfraudFix -> %UserProfile%\Desktop\SmitfraudFix -> [2008/10/16 00:06:23 | 00,000,000 | ---D | C]
hijackthis -> %UserProfile%\Desktop\hijackthis -> [2008/10/16 00:06:07 | 00,000,000 | ---D | C]
smitRem -> %UserProfile%\Desktop\smitRem -> [2008/10/16 00:05:09 | 00,000,000 | ---D | C]
TaskManagerFix.exe -> %UserProfile%\Desktop\TaskManagerFix.exe -> [2008/10/15 22:51:09 | 00,077,824 | ---- | C] (Task Manager Fix)
cxcyribc.ini -> %SystemRoot%\System32\cxcyribc.ini -> [2008/10/15 22:14:24 | 01,363,352 | -HS- | C] ()
cbirycxc.dll -> %SystemRoot%\System32\cbirycxc.dll -> [2008/10/15 22:14:21 | 00,071,168 | ---- | C] ()
yndkyu.dll -> %SystemRoot%\System32\yndkyu.dll -> [2008/10/15 22:12:43 | 00,109,056 | ---- | C] ()
wtisnkdt.dll -> %SystemRoot%\System32\wtisnkdt.dll -> [2008/10/15 22:12:39 | 00,109,056 | ---- | C] ()
Compaq Connections.lnk -> %AllUsersProfile%\Start Menu\Programs\Startup\Compaq Connections.lnk -> [2008/10/15 22:02:59 | 00,001,918 | ---- | C] ()
tuvTkiIA.dll -> %SystemRoot%\System32\tuvTkiIA.dll -> [2008/10/15 19:36:21 | 00,040,448 | ---- | C] ()
pmnmMdcb.dll -> %SystemRoot%\System32\pmnmMdcb.dll -> [2008/10/15 19:36:20 | 00,040,448 | ---- | C] ()
wvUkJdCU.dll -> %SystemRoot%\System32\wvUkJdCU.dll -> [2008/10/15 19:35:51 | 00,040,448 | ---- | C] ()
byXNdcBT.dll -> %SystemRoot%\System32\byXNdcBT.dll -> [2008/10/15 19:35:51 | 00,040,448 | ---- | C] ()
ddcBqOeB.dll -> %SystemRoot%\System32\ddcBqOeB.dll -> [2008/10/15 19:34:56 | 00,040,448 | ---- | C] ()
khfFYOHB.dll -> %SystemRoot%\System32\khfFYOHB.dll -> [2008/10/15 19:34:55 | 00,040,448 | ---- | C] ()
jkkLEVoM.dll -> %SystemRoot%\System32\jkkLEVoM.dll -> [2008/10/15 19:34:42 | 00,040,448 | ---- | C] ()
cbXQIYRi.dll -> %SystemRoot%\System32\cbXQIYRi.dll -> [2008/10/15 19:34:41 | 00,040,448 | ---- | C] ()
nnnmjgDT.dll -> %SystemRoot%\System32\nnnmjgDT.dll -> [2008/10/15 19:34:37 | 00,040,448 | ---- | C] ()
khfEUkKD.dll -> %SystemRoot%\System32\khfEUkKD.dll -> [2008/10/15 19:34:35 | 00,040,448 | ---- | C] ()
opnmKBQk.dll -> %SystemRoot%\System32\opnmKBQk.dll -> [2008/10/15 19:33:40 | 00,040,448 | ---- | C] ()
ddcCVOhe.dll -> %SystemRoot%\System32\ddcCVOhe.dll -> [2008/10/15 19:33:38 | 00,040,448 | ---- | C] ()
wb34530.dll -> %SystemRoot%\System32\wb34530.dll -> [2008/10/15 19:22:43 | 00,167,936 | ---- | C] (Microsoft Corporation)
mwb34530.dll -> %SystemRoot%\System32\mwb34530.dll -> [2008/10/15 19:22:43 | 00,167,936 | ---- | C] (Microsoft Corporation)
bkwkgmae.ini -> %SystemRoot%\System32\bkwkgmae.ini -> [2008/10/15 19:09:12 | 01,363,352 | -HS- | C] ()
mwrkuq.dll -> %SystemRoot%\System32\mwrkuq.dll -> [2008/10/15 19:07:01 | 00,109,056 | ---- | C] ()
jegkvnyt.dll -> %SystemRoot%\System32\jegkvnyt.dll -> [2008/10/15 19:06:52 | 00,109,056 | ---- | C] ()
RAIQqBeg.ini2 -> %SystemRoot%\System32\RAIQqBeg.ini2 -> [2008/10/15 19:03:07 | 00,874,885 | -HS- | C] ()
RAIQqBeg.ini -> %SystemRoot%\System32\RAIQqBeg.ini -> [2008/10/15 19:03:06 | 00,874,901 | -HS- | C] ()
geBqQIAR.dll -> %SystemRoot%\System32\geBqQIAR.dll -> [2008/10/15 19:02:52 | 00,267,776 | ---- | C] ()
qoMgfcyX.dll -> %SystemRoot%\System32\qoMgfcyX.dll -> [2008/10/15 18:57:48 | 00,040,448 | ---- | C] ()
qoMdDVml.dll -> %SystemRoot%\System32\qoMdDVml.dll -> [2008/10/15 18:57:48 | 00,040,448 | ---- | C] ()
pmnnLccc.dll -> %SystemRoot%\System32\pmnnLccc.dll -> [2008/10/15 18:57:33 | 00,040,448 | ---- | C] ()
TmpRecentIcons -> %AppData%\TmpRecentIcons -> [2008/10/15 18:57:22 | 00,000,000 | ---D | C]
pics-14-Oct-202818 -> %UserProfile%\Desktop\pics-14-Oct-202818 -> [2008/10/14 23:02:06 | 00,000,000 | ---D | C]
Symantec -> %UserProfile%\My Documents\Symantec -> [2008/10/14 18:33:09 | 00,000,000 | ---D | C]
Norton AntiVirus - Run Full System Scan - nick petrotto.job -> %SystemRoot%\tasks\Norton AntiVirus - Run Full System Scan - nick petrotto.job -> [2008/10/14 18:29:48 | 00,000,572 | ---- | C] ()
Norton AntiVirus.lnk -> %AllUsersProfile%\Desktop\Norton AntiVirus.lnk -> [2008/10/14 18:27:47 | 00,001,971 | ---- | C] ()
Windows Sidebar -> %ProgramFiles%\Windows Sidebar -> [2008/10/14 18:23:57 | 00,000,000 | ---D | C]
Norton AntiVirus -> %ProgramFiles%\Norton AntiVirus -> [2008/10/14 18:23:56 | 00,000,000 | ---D | C]
SYMEVENT.SYS -> %SystemRoot%\System32\drivers\SYMEVENT.SYS -> [2008/10/14 18:22:51 | 00,123,952 | ---- | C] (Symantec Corporation)
S32EVNT1.DLL -> %SystemRoot%\System32\S32EVNT1.DLL -> [2008/10/14 18:22:51 | 00,060,800 | ---- | C] (Symantec Corporation)
SYMEVENT.CAT -> %SystemRoot%\System32\drivers\SYMEVENT.CAT -> [2008/10/14 18:22:51 | 00,010,671 | ---- | C] ()
SYMEVENT.INF -> %SystemRoot%\System32\drivers\SYMEVENT.INF -> [2008/10/14 18:22:51 | 00,000,805 | ---- | C] ()
Symantec -> %ProgramFiles%\Symantec -> [2008/10/14 18:22:20 | 00,000,000 | ---D | C]
Avg8 -> %AllUsersProfile%\Application Data\Avg8 -> [2008/10/14 18:20:44 | 00,000,000 | ---D | C]
qtfryc.dll -> %SystemRoot%\System32\qtfryc.dll -> [2008/10/14 17:13:43 | 00,101,376 | ---- | C] ()
uxprvfqr.dll -> %SystemRoot%\System32\uxprvfqr.dll -> [2008/10/14 17:13:40 | 00,101,376 | ---- | C] ()
kgyruspa.ini -> %SystemRoot%\System32\kgyruspa.ini -> [2008/10/14 17:07:24 | 01,349,616 | -HS- | C] ()
glaskrod.ini -> %SystemRoot%\System32\glaskrod.ini -> [2008/10/13 10:24:45 | 01,090,007 | -HS- | C] ()
edlmnkur.ini -> %SystemRoot%\System32\edlmnkur.ini -> [2008/10/13 01:59:06 | 01,088,753 | -HS- | C] ()
SvxxIRqr.ini2 -> %SystemRoot%\System32\SvxxIRqr.ini2 -> [2008/10/13 01:56:38 | 00,952,013 | -HS- | C] ()
SvxxIRqr.ini -> %SystemRoot%\System32\SvxxIRqr.ini -> [2008/10/13 01:56:37 | 00,952,013 | -HS- | C] ()
keira at great pumpkin farm -> %UserProfile%\Desktop\keira at great pumpkin farm -> [2008/10/13 01:45:25 | 00,000,000 | ---D | C]
Nero -> %AllUsersProfile%\Application Data\Nero -> [2008/10/13 01:28:06 | 00,000,000 | ---D | C]
21.REPACK.DVDRip.XviD-FLAiTE.avi -> %UserProfile%\Desktop\21.REPACK.DVDRip.XviD-FLAiTE.avi -> [2008/10/12 18:02:51 | 73,329,9153 | ---- | C] ()
iTunes -> %ProgramFiles%\iTunes -> [2008/10/09 21:54:45 | 00,000,000 | ---D | C]
{3276BE95_AF08_429F_A64F_CA64CB79BCF6} -> %AllUsersProfile%\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6} -> [2008/10/09 21:54:45 | 00,000,000 | ---D | C]
Bonjour -> %ProgramFiles%\Bonjour -> [2008/10/09 21:53:13 | 00,000,000 | ---D | C]
AOL -> %ProgramFiles%\AOL -> [2008/10/06 20:09:36 | 00,000,000 | ---D | C]
acccore -> %AllUsersProfile%\Application Data\acccore -> [2008/10/06 20:09:23 | 00,000,000 | ---D | C]
cat.jpg -> %UserProfile%\Desktop\cat.jpg -> [2008/10/06 20:03:24 | 00,091,827 | ---- | C] ()
88 min.mpg -> %UserProfile%\Desktop\88 min.mpg -> [2008/10/06 00:37:24 | 36,229,120 | ---- | C] ()
Move Networks -> %AppData%\Move Networks -> [2008/10/05 19:36:39 | 00,000,000 | ---D | C]
sweeny todd.mpg -> %UserProfile%\Desktop\sweeny todd.mpg -> [2008/10/05 19:05:12 | 55,332,864 | ---- | C] ()
MySpaceIM.lnk -> %AllUsersProfile%\Desktop\MySpaceIM.lnk -> [2008/10/05 18:24:43 | 00,000,747 | ---- | C] ()
HVIIIa.jpg -> %UserProfile%\Desktop\HVIIIa.jpg -> [2008/10/05 12:09:48 | 00,150,856 | ---- | C] ()
rt73.sys -> %SystemRoot%\System32\rt73.sys -> [2008/10/04 19:33:29 | 00,245,248 | ---- | C] (Ralink Technology, Corp.)
GTW32N50.dll -> %SystemRoot%\System32\GTW32N50.dll -> [2008/10/04 19:33:29 | 00,094,208 | ---- | C] ()
GTNDIS3.VXD -> %SystemRoot%\System32\GTNDIS3.VXD -> [2008/10/04 19:33:29 | 00,031,930 | ---- | C] ()
rt73.cat -> %SystemRoot%\System32\rt73.cat -> [2008/10/04 19:33:29 | 00,007,846 | ---- | C] ()
rt73.sys -> %SystemRoot%\System32\drivers\rt73.sys -> [2008/10/04 19:33:28 | 00,245,248 | ---- | C] (Ralink Technology, Corp.)
GTNDIS5.sys -> %SystemRoot%\System32\GTNDIS5.sys -> [2008/10/04 19:33:28 | 00,015,872 | ---- | C] (Printing Communications Assoc., Inc. (PCAUSA))
GTGina.dll -> %SystemRoot%\System32\GTGina.dll -> [2008/10/04 19:33:26 | 00,032,768 | ---- | C] (Gemtek)
Compact Wireless-G USB Adapter Wireless Network Monitor -> %ProgramFiles%\Compact Wireless-G USB Adapter Wireless Network Monitor -> [2008/10/04 19:33:08 | 00,000,000 | ---D | C]
WLAN.INI -> %SystemRoot%\System32\WLAN.INI -> [2008/10/04 19:32:47 | 00,001,361 | ---- | C] ()
uTorrent -> %ProgramFiles%\uTorrent -> [2008/09/28 17:42:11 | 00,000,000 | ---D | C]
AnMing -> %ProgramFiles%\AnMing -> [2008/09/28 17:22:16 | 00,000,000 | ---D | C]
wstdecod.dll -> %SystemRoot%\System32\dllcache\wstdecod.dll -> [2008/09/18 00:20:24 | 00,047,104 | ---- | C] (Microsoft Corporation)
psisrndr.ax -> %SystemRoot%\System32\psisrndr.ax -> [2008/09/18 00:20:24 | 00,030,208 | ---- | C] ()
psisrndr.ax -> %SystemRoot%\System32\dllcache\psisrndr.ax -> [2008/09/18 00:20:24 | 00,030,208 | ---- | C] ()
msvidctl.dll -> %SystemRoot%\System32\dllcache\msvidctl.dll -> [2008/09/18 00:20:23 | 01,230,336 | ---- | C] (Microsoft Corporation)
psisdecd.dll -> %SystemRoot%\System32\psisdecd.dll -> [2008/09/18 00:20:23 | 00,354,816 | ---- | C] ()
psisdecd.dll -> %SystemRoot%\System32\dllcache\psisdecd.dll -> [2008/09/18 00:20:23 | 00,354,816 | ---- | C] ()
msdvbnp.ax -> %SystemRoot%\System32\msdvbnp.ax -> [2008/09/18 00:20:23 | 00,052,224 | ---- | C] ()
msdvbnp.ax -> %SystemRoot%\System32\dllcache\msdvbnp.ax -> [2008/09/18 00:20:23 | 00,052,224 | ---- | C] ()
msdv.sys -> %SystemRoot%\System32\drivers\msdv.sys -> [2008/09/18 00:20:22 | 00,052,096 | ---- | C] (Microsoft Corporation)
msdv.sys -> %SystemRoot%\System32\dllcache\msdv.sys -> [2008/09/18 00:20:22 | 00,052,096 | ---- | C] (Microsoft Corporation)
mpe.sys -> %SystemRoot%\System32\drivers\mpe.sys -> [2008/09/18 00:20:22 | 00,015,104 | ---- | C] (Microsoft Corporation)
mpe.sys -> %SystemRoot%\System32\dllcache\mpe.sys -> [2008/09/18 00:20:22 | 00,015,104 | ---- | C] (Microsoft Corporation)
bdasup.sys -> %SystemRoot%\System32\drivers\bdasup.sys -> [2008/09/18 00:20:22 | 00,011,392 | ---- | C] (Microsoft Corporation)
bdasup.sys -> %SystemRoot%\System32\dllcache\bdasup.sys -> [2008/09/18 00:20:22 | 00,011,392 | ---- | C] (Microsoft Corporation)
bdaplgin.ax -> %SystemRoot%\System32\dllcache\bdaplgin.ax -> [2008/09/18 00:20:21 | 00,016,896 | ---- | C] (Microsoft Corporation)
bdaplgin.ax -> %SystemRoot%\System32\bdaplgin.ax -> [2008/09/18 00:20:21 | 00,016,896 | ---- | C] (Microsoft Corporation)
ksolay.ax -> %SystemRoot%\System32\ksolay.ax -> [2008/09/18 00:20:19 | 00,012,288 | ---- | C] (Microsoft Corporation)
qedit.dll -> %SystemRoot%\System32\dllcache\qedit.dll -> [2008/09/18 00:20:18 | 01,798,144 | ---- | C] ()
qedwipes.dll -> %SystemRoot%\System32\dllcache\qedwipes.dll -> [2008/09/18 00:20:18 | 00,733,184 | ---- | C] ()
mswebdvd.dll -> %SystemRoot%\System32\dllcache\mswebdvd.dll -> [2008/09/18 00:20:18 | 00,324,096 | ---- | C] (Microsoft Corporation)
qdvd.dll -> %SystemRoot%\System32\dllcache\qdvd.dll -> [2008/09/18 00:20:17 | 00,470,528 | ---- | C] ()
qdv.dll -> %SystemRoot%\System32\dllcache\qdv.dll -> [2008/09/18 00:20:17 | 00,316,928 | ---- | C] ()
msdmo.dll -> %SystemRoot%\System32\dllcache\msdmo.dll -> [2008/09/18 00:20:17 | 00,013,312 | ---- | C] ()
qcap.dll -> %SystemRoot%\System32\dllcache\qcap.dll -> [2008/09/18 00:20:16 | 00,257,024 | ---- | C] ()
mpg2splt.ax -> %SystemRoot%\System32\dllcache\mpg2splt.ax -> [2008/09/18 00:20:16 | 00,136,192 | ---- | C] ()
devenum.dll -> %SystemRoot%\System32\dllcache\devenum.dll -> [2008/09/18 00:20:16 | 00,132,608 | ---- | C] ()
amstream.dll -> %SystemRoot%\System32\dllcache\amstream.dll -> [2008/09/18 00:20:16 | 00,064,512 | ---- | C] ()
mciqtz32.dll -> %SystemRoot%\System32\dllcache\mciqtz32.dll -> [2008/09/18 00:20:16 | 00,034,304 | ---- | C] ()
dmime.dll -> %SystemRoot%\System32\dllcache\dmime.dll -> [2008/09/18 00:20:13 | 00,181,248 | ---- | C] (Microsoft Corporation)
dmusic.dll -> %SystemRoot%\System32\dllcache\dmusic.dll -> [2008/09/18 00:20:13 | 00,122,880 | ---- | C] (Microsoft Corporation)
dmsynth.dll -> %SystemRoot%\System32\dllcache\dmsynth.dll -> [2008/09/18 00:20:13 | 00,100,864 | ---- | C] (Microsoft Corporation)
dmstyle.dll -> %SystemRoot%\System32\dllcache\dmstyle.dll -> [2008/09/18 00:20:13 | 00,098,816 | ---- | C] (Microsoft Corporation)
dmcompos.dll -> %SystemRoot%\System32\dllcache\dmcompos.dll -> [2008/09/18 00:20:13 | 00,058,368 | ---- | C] (Microsoft Corporation)
dmloader.dll -> %SystemRoot%\System32\dllcache\dmloader.dll -> [2008/09/18 00:20:13 | 00,033,280 | ---- | C] (Microsoft Corporation)
dmband.dll -> %SystemRoot%\System32\dllcache\dmband.dll -> [2008/09/18 00:20:13 | 00,027,136 | ---- | C] (Microsoft Corporation)
d3d8.dll -> %SystemRoot%\System32\dllcache\d3d8.dll -> [2008/09/18 00:20:12 | 01,201,152 | ---- | C] (Microsoft Corporation)
dinput8.dll -> %SystemRoot%\System32\dllcache\dinput8.dll -> [2008/09/18 00:20:12 | 00,667,648 | ---- | C] (Microsoft Corporation)
dmscript.dll -> %SystemRoot%\System32\dllcache\dmscript.dll -> [2008/09/18 00:20:12 | 00,076,800 | ---- | C] (Microsoft Corporation)
dswave.dll -> %SystemRoot%\System32\dllcache\dswave.dll -> [2008/09/18 00:20:12 | 00,018,432 | ---- | C] (Microsoft Corporation)
dxdiag.exe -> %SystemRoot%\System32\dllcache\dxdiag.exe -> [2008/09/18 00:20:09 | 00,974,848 | ---- | C] (Microsoft Corporation)
dxdllreg.exe -> %SystemRoot%\System32\dxdllreg.exe -> [2008/09/18 00:20:07 | 00,063,696 | ---- | C] (Microsoft Corporation)
dsdmoprp.dll -> %SystemRoot%\System32\dllcache\dsdmoprp.dll -> [2008/09/18 00:20:06 | 00,491,520 | ---- | C] (Microsoft Corporation)
dpvoice.dll -> %SystemRoot%\System32\dllcache\dpvoice.dll -> [2008/09/18 00:20:06 | 00,381,952 | ---- | C] (Microsoft Corporation)
dsdmo.dll -> %SystemRoot%\System32\dllcache\dsdmo.dll -> [2008/09/18 00:20:06 | 00,186,880 | ---- | C] (Microsoft Corporation)
dpvvox.dll -> %SystemRoot%\System32\dllcache\dpvvox.dll -> [2008/09/18 00:20:06 | 00,112,128 | ---- | C] (Microsoft Corporation)
dpvsetup.exe -> %SystemRoot%\System32\dllcache\dpvsetup.exe -> [2008/09/18 00:20:06 | 00,080,896 | ---- | C] (Microsoft Corporation)
dpvacm.dll -> %SystemRoot%\System32\dllcache\dpvacm.dll -> [2008/09/18 00:20:06 | 00,019,968 | ---- | C] (Microsoft Corporation)
dx8vb.dll -> %SystemRoot%\System32\dllcache\dx8vb.dll -> [2008/09/18 00:20:02 | 01,189,888 | ---- | C] (Microsoft Corporation)
dpnet.dll -> %SystemRoot%\System32\dllcache\dpnet.dll -> [2008/09/18 00:20:02 | 00,723,968 | ---- | C] (Microsoft Corporation)
dpnhupnp.dll -> %SystemRoot%\System32\dllcache\dpnhupnp.dll -> [2008/09/18 00:20:02 | 00,068,096 | ---- | C] (Microsoft Corporation)
dpnhpast.dll -> %SystemRoot%\System32\dllcache\dpnhpast.dll -> [2008/09/18 00:20:02 | 00,032,768 | ---- | C] (Microsoft Corporation)
dpnsvr.exe -> %SystemRoot%\System32\dllcache\dpnsvr.exe -> [2008/09/18 00:20:02 | 00,016,896 | ---- | C] (Microsoft Corporation)
dpnlobby.dll -> %SystemRoot%\System32\dllcache\dpnlobby.dll -> [2008/09/18 00:20:02 | 00,003,072 | ---- | C] (Microsoft Corporation)
dpnaddr.dll -> %SystemRoot%\System32\dllcache\dpnaddr.dll -> [2008/09/18 00:20:02 | 00,003,072 | ---- | C] (Microsoft Corporation)
joy.cpl -> %SystemRoot%\System32\dllcache\joy.cpl -> [2008/09/18 00:20:01 | 00,208,896 | ---- | C] (Microsoft Corporation)
pid.dll -> %SystemRoot%\System32\dllcache\pid.dll -> [2008/09/18 00:20:01 | 00,031,744 | ---- | C] (Microsoft Corporation)
d3d8thk.dll -> %SystemRoot%\System32\dllcache\d3d8thk.dll -> [2008/09/18 00:20:01 | 00,008,192 | ---- | C] (Microsoft Corporation)
dsound3d.dll -> %SystemRoot%\System32\dllcache\dsound3d.dll -> [2008/09/18 00:20:00 | 01,294,336 | ---- | C] (Microsoft Corporation)
dx7vb.dll -> %SystemRoot%\System32\dllcache\dx7vb.dll -> [2008/09/18 00:20:00 | 00,602,624 | ---- | C] (Microsoft Corporation)
dsound.dll -> %SystemRoot%\System32\dllcache\dsound.dll -> [2008/09/18 00:20:00 | 00,381,952 | ---- | C] (Microsoft Corporation)
dpwsockx.dll -> %SystemRoot%\System32\dllcache\dpwsockx.dll -> [2008/09/18 00:20:00 | 00,079,360 | ---- | C] (Microsoft Corporation)
dinput.dll -> %SystemRoot%\System32\dllcache\dinput.dll -> [2008/09/18 00:19:59 | 00,648,704 | ---- | C] (Microsoft Corporation)
dplayx.dll -> %SystemRoot%\System32\dllcache\dplayx.dll -> [2008/09/18 00:19:59 | 00,230,400 | ---- | C] (Microsoft Corporation)
dpmodemx.dll -> %SystemRoot%\System32\dllcache\dpmodemx.dll -> [2008/09/18 00:19:59 | 00,077,824 | ---- | C] (Microsoft Corporation)
dplaysvr.exe -> %SystemRoot%\System32\dllcache\dplaysvr.exe -> [2008/09/18 00:19:59 | 00,028,160 | ---- | C] (Microsoft Corporation)
ddrawex.dll -> %SystemRoot%\System32\dllcache\ddrawex.dll -> [2008/09/18 00:19:59 | 00,024,064 | ---- | C] (Microsoft Corporation)
d3dim700.dll -> %SystemRoot%\System32\dllcache\d3dim700.dll -> [2008/09/18 00:19:58 | 00,797,184 | ---- | C] (Microsoft Corporation)
ddraw.dll -> %SystemRoot%\System32\dllcache\ddraw.dll -> [2008/09/18 00:19:58 | 00,292,864 | ---- | C] (Microsoft Corporation)
WNASPINT.DLL -> %SystemRoot%\System32\WNASPINT.DLL -> [2008/09/15 19:55:24 | 00,057,344 | ---- | C] (NexiTech, Inc.)
eJay -> %SystemDrive%\eJay -> [2008/09/15 19:49:29 | 00,000,000 | ---D | C]
apartments.doc -> %UserProfile%\My Documents\apartments.doc -> [2008/09/15 18:20:24 | 00,035,840 | ---- | C] ()
IconCache.db -> %UserProfile%\Local Settings\Application Data\IconCache.db -> [2008/09/14 23:22:43 | 03,357,482 | -H-- | C] ()
My Received Files -> %UserProfile%\My Documents\My Received Files -> [2008/09/14 01:59:48 | 00,000,000 | ---D | C]
Paltalk -> %AppData%\Paltalk -> [2008/09/13 23:43:21 | 00,000,000 | ---D | C]
AppleSoftwareUpdate.job -> %SystemRoot%\tasks\AppleSoftwareUpdate.job -> [2008/09/13 02:30:07 | 00,000,284 | ---- | C] ()
QuickTime -> %ProgramFiles%\QuickTime -> [2008/09/13 02:23:12 | 00,000,000 | ---D | C]
vbSkinner -> %SystemRoot%\vbSkinner -> [2008/09/04 20:15:04 | 00,000,000 | ---D | C]
xing shared -> %CommonProgramFiles%\xing shared -> [2008/09/02 23:35:22 | 00,000,000 | ---D | C]
Prefetch -> %SystemRoot%\Prefetch -> [2008/08/31 09:57:23 | 00,000,000 | ---D | C]
scripting -> %SystemRoot%\System32\scripting -> [2008/08/31 09:39:17 | 00,000,000 | ---D | C]
l2schemas -> %SystemRoot%\l2schemas -> [2008/08/31 09:39:15 | 00,000,000 | ---D | C]
msn -> %ProgramFiles%\msn -> [2008/08/31 09:39:14 | 00,000,000 | ---D | C]
en -> %SystemRoot%\System32\en -> [2008/08/31 09:39:14 | 00,000,000 | ---D | C]
bits -> %SystemRoot%\System32\bits -> [2008/08/31 09:39:14 | 00,000,000 | ---D | C]
ServicePackFiles -> %SystemRoot%\ServicePackFiles -> [2008/08/31 09:36:07 | 00,000,000 | ---D | C]
$NtServicePackUninstall$ -> %SystemRoot%\$NtServicePackUninstall$ -> [2008/08/31 09:28:11 | 00,000,000 | -H-D | C]
EHome -> %SystemRoot%\EHome -> [2008/08/31 09:28:09 | 00,000,000 | ---D | C]
wmphoto.dll -> %SystemRoot%\System32\wmphoto.dll -> [2008/08/27 00:32:52 | 00,276,992 | ---- | C] (Microsoft Corporation)
wlanapi.dll -> %SystemRoot%\System32\wlanapi.dll -> [2008/08/27 00:32:49 | 00,069,120 | ---- | C] (Microsoft Corporation)
windowscodecs.dll -> %SystemRoot%\System32\windowscodecs.dll -> [2008/08/27 00:32:47 | 00,712,704 | ---- | C] (Microsoft Corporation)
windowscodecsext.dll -> %SystemRoot%\System32\windowscodecsext.dll -> [2008/08/27 00:32:47 | 00,346,112 | ---- | C] (Microsoft Corporation)
wacompen.sys -> %SystemRoot%\System32\drivers\wacompen.sys -> [2008/08/27 00:32:44 | 00,014,208 | ---- | C] (Microsoft Corporation)
viaagp.sys -> %SystemRoot%\System32\drivers\viaagp.sys -> [2008/08/27 00:32:43 | 00,042,240 | ---- | C] (Microsoft Corporation)
usbvideo.sys -> %SystemRoot%\System32\drivers\usbvideo.sys -> [2008/08/27 00:32:41 | 00,121,984 | ---- | C] (Microsoft Corporation)
usb8023x.sys -> %SystemRoot%\System32\drivers\usb8023x.sys -> [2008/08/27 00:32:40 | 00,012,800 | ---- | C] (Microsoft Corporation)
tspkg.dll -> %SystemRoot%\System32\tspkg.dll -> [2008/08/27 00:32:35 | 00,050,688 | ---- | C] (Microsoft Corporation)
tsgqec.dll -> %SystemRoot%\System32\tsgqec.dll -> [2008/08/27 00:32:34 | 00,053,248 | ---- | C] (Microsoft Corporation)
spupdwxp.exe -> %SystemRoot%\System32\spupdwxp.exe -> [2008/08/27 00:32:27 | 00,020,992 | ---- | C] (Microsoft Corporation)
spdwnwxp.exe -> %SystemRoot%\System32\spdwnwxp.exe -> [2008/08/27 00:32:25 | 00,007,680 | ---- | C] (Microsoft Corporation)
smbali.sys -> %SystemRoot%\System32\drivers\smbali.sys -> [2008/08/27 00:32:24 | 00,005,888 | ---- | C] (Microsoft Corporation)
setupn.exe -> %SystemRoot%\System32\setupn.exe -> [2008/08/27 00:32:18 | 00,032,768 | ---- | C] (Microsoft Corporation)
sffp_mmc.sys -> %SystemRoot%\System32\drivers\sffp_mmc.sys -> [2008/08/27 00:32:18 | 00,010,240 | ---- | C] (Microsoft Corporation)
rhttpaa.dll -> %SystemRoot%\System32\rhttpaa.dll -> [2008/08/27 00:32:13 | 00,290,304 | ---- | C] (Microsoft Corporation)
rndismpx.sys -> %SystemRoot%\System32\drivers\rndismpx.sys -> [2008/08/27 00:32:13 | 00,030,592 | ---- | C] (Microsoft Corporation)
rfcomm.sys -> %SystemRoot%\System32\drivers\rfcomm.sys -> [2008/08/27 00:32:12 | 00,059,136 | ---- | C] (Microsoft Corporation)
rasqec.dll -> %SystemRoot%\System32\rasqec.dll -> [2008/08/27 00:32:11 | 00,061,952 | ---- | C] (Microsoft Corporation)
qutil.dll -> %SystemRoot%\System32\qutil.dll -> [2008/08/27 00:32:09 | 00,076,800 | ---- | C] (Microsoft Corporation)
qagentrt.dll -> %SystemRoot%\System32\qagentrt.dll -> [2008/08/27 00:32:08 | 00,291,328 | ---- | C] (Microsoft Corporation)
qagent.dll -> %SystemRoot%\System32\qagent.dll -> [2008/08/27 00:32:08 | 00,150,528 | ---- | C] (Microsoft Corporation)
qcliprov.dll -> %SystemRoot%\System32\qcliprov.dll -> [2008/08/27 00:32:08 | 00,062,464 | ---- | C] (Microsoft Corporation)
photometadatahandler.dll -> %SystemRoot%\System32\photometadatahandler.dll -> [2008/08/27 00:32:06 | 00,412,160 | ---- | C] (Microsoft Corporation)
onex.dll -> %SystemRoot%\System32\onex.dll -> [2008/08/27 00:32:02 | 00,144,384 | ---- | C] (Microsoft Corporation)
netwlan5.img -> %SystemRoot%\System32\drivers\netwlan5.img -> [2008/08/27 00:31:53 | 00,067,866 | ---- | C] ()
napmontr.dll -> %SystemRoot%\System32\napmontr.dll -> [2008/08/27 00:31:51 | 00,193,024 | ---- | C] (Microsoft Corporation)
napstat.exe -> %SystemRoot%\System32\napstat.exe -> [2008/08/27 00:31:51 | 00,176,640 | ---- | C] (Microsoft Corporation)
napipsec.dll -> %SystemRoot%\System32\napipsec.dll -> [2008/08/27 00:31:51 | 00,030,208 | ---- | C] (Microsoft Corporation)
mutohpen.sys -> %SystemRoot%\System32\drivers\mutohpen.sys -> [2008/08/27 00:31:50 | 00,012,672 | ---- | C] (Microsoft Corporation)
msxml6.dll -> %SystemRoot%\System32\msxml6.dll -> [2008/08/27 00:31:49 | 01,306,624 | ---- | C] (Microsoft Corporation)
msxml6.dll -> %SystemRoot%\System32\dllcache\msxml6.dll -> [2008/08/27 00:31:49 | 01,306,624 | ---- | C] (Microsoft Corporation)
msxml6r.dll -> %SystemRoot%\System32\msxml6r.dll -> [2008/08/27 00:31:49 | 00,079,872 | ---- | C] (Microsoft Corporation)
msxml6r.dll -> %SystemRoot%\System32\dllcache\msxml6r.dll -> [2008/08/27 00:31:49 | 00,079,872 | ---- | C] (Microsoft Corporation)
mssha.dll -> %SystemRoot%\System32\mssha.dll -> [2008/08/27 00:31:46 | 00,155,136 | ---- | C] (Microsoft Corporation)
msshavmsg.dll -> %SystemRoot%\System32\msshavmsg.dll -> [2008/08/27 00:31:46 | 00,076,800 | ---- | C] (Microsoft Corporation)
mmcfxcommon.dll -> %SystemRoot%\System32\mmcfxcommon.dll -> [2008/08/27 00:31:27 | 00,106,496 | ---- | C] (Microsoft Corporation)
mmcperf.exe -> %SystemRoot%\System32\mmcperf.exe -> [2008/08/27 00:31:27 | 00,033,792 | ---- | C] (Microsoft Corporation)
mmcex.dll -> %SystemRoot%\System32\mmcex.dll -> [2008/08/27 00:31:26 | 00,397,312 | ---- | C] (Microsoft Corporation)
microsoft.managementconsole.dll -> %SystemRoot%\System32\microsoft.managementconsole.dll -> [2008/08/27 00:31:26 | 00,184,320 | ---- | C] (Microsoft Corporation)
l2gpstore.dll -> %SystemRoot%\System32\l2gpstore.dll -> [2008/08/27 00:31:11 | 00,037,376 | ---- | C] (Microsoft Corporation)
kmsvc.dll -> %SystemRoot%\System32\kmsvc.dll -> [2008/08/27 00:31:02 | 00,061,440 | ---- | C] (Microsoft Corporation)
kbdpash.dll -> %SystemRoot%\System32\kbdpash.dll -> [2008/08/27 00:31:01 | 00,006,144 | ---- | C] (Microsoft Corporation)
kbdnepr.dll -> %SystemRoot%\System32\kbdnepr.dll -> [2008/08/27 00:31:01 | 00,006,144 | ---- | C] (Microsoft Corporation)
kbdiultn.dll -> %SystemRoot%\System32\kbdiultn.dll -> [2008/08/27 00:31:00 | 00,006,144 | ---- | C] (Microsoft Corporation)
kbdbhc.dll -> %SystemRoot%\System32\kbdbhc.dll -> [2008/08/27 00:31:00 | 00,006,144 | ---- | C] (Microsoft Corporation)
pid.inf -> %SystemRoot%\System32\pid.inf -> [2008/08/27 00:30:42 | 00,001,261 | ---- | C] ()
hidbth.sys -> %SystemRoot%\System32\drivers\hidbth.sys -> [2008/08/27 00:30:36 | 00,025,600 | ---- | C] (Microsoft Corporation)
hidir.sys -> %SystemRoot%\System32\drivers\hidir.sys -> [2008/08/27 00:30:36 | 00,019,200 | ---- | C] (Microsoft Corporation)
gagp30kx.sys -> %SystemRoot%\System32\drivers\gagp30kx.sys -> [2008/08/27 00:30:34 | 00,046,464 | ---- | C] (Microsoft Corporation)
faxpatch.exe -> %SystemRoot%\System32\faxpatch.exe -> [2008/08/27 00:30:29 | 00,020,992 | ---- | C] (Microsoft Corporation)
eapp3hst.dll -> %SystemRoot%\System32\eapp3hst.dll -> [2008/08/27 00:30:27 | 00,184,832 | ---- | C] (Microsoft Corporation)
eapphost.dll -> %SystemRoot%\System32\eapphost.dll -> [2008/08/27 00:30:27 | 00,180,224 | ---- | C] (Microsoft Corporation)
eappcfg.dll -> %SystemRoot%\System32\eappcfg.dll -> [2008/08/27 00:30:27 | 00,126,976 | ---- | C] (Microsoft Corporation)
eappgnui.dll -> %SystemRoot%\System32\eappgnui.dll -> [2008/08/27 00:30:27 | 00,094,208 | ---- | C] (Microsoft Corporation)
eapqec.dll -> %SystemRoot%\System32\eapqec.dll -> [2008/08/27 00:30:27 | 00,059,392 | ---- | C] (Microsoft Corporation)
eappprxy.dll -> %SystemRoot%\System32\eappprxy.dll -> [2008/08/27 00:30:27 | 00,040,960 | ---- | C] (Microsoft Corporation)
eapsvc.dll -> %SystemRoot%\System32\eapsvc.dll -> [2008/08/27 00:30:27 | 00,033,792 | ---- | C] (Microsoft Corporation)
eapolqec.dll -> %SystemRoot%\System32\eapolqec.dll -> [2008/08/27 00:30:27 | 00,030,720 | ---- | C] (Microsoft Corporation)
dot3ui.dll -> %SystemRoot%\System32\dot3ui.dll -> [2008/08/27 00:30:23 | 00,650,752 | ---- | C] (Microsoft Corporation)
dot3svc.dll -> %SystemRoot%\System32\dot3svc.dll -> [2008/08/27 00:30:23 | 00,132,096 | ---- | C] (Microsoft Corporation)
dot3cfg.dll -> %SystemRoot%\System32\dot3cfg.dll -> [2008/08/27 00:30:23 | 00,057,856 | ---- | C] (Microsoft Corporation)
dot3msm.dll -> %SystemRoot%\System32\dot3msm.dll -> [2008/08/27 00:30:23 | 00,056,320 | ---- | C] (Microsoft Corporation)
dot3gpclnt.dll -> %SystemRoot%\System32\dot3gpclnt.dll -> [2008/08/27 00:30:23 | 00,039,936 | ---- | C] (Microsoft Corporation)
dot3api.dll -> %SystemRoot%\System32\dot3api.dll -> [2008/08/27 00:30:23 | 00,026,112 | ---- | C] (Microsoft Corporation)
dot3dlg.dll -> %SystemRoot%\System32\dot3dlg.dll -> [2008/08/27 00:30:23 | 00,009,216 | ---- | C] (Microsoft Corporation)
dimsroam.dll -> %SystemRoot%\System32\dimsroam.dll -> [2008/08/27 00:30:21 | 00,039,936 | ---- | C] (Microsoft Corporation)
dimsntfy.dll -> %SystemRoot%\System32\dimsntfy.dll -> [2008/08/27 00:30:21 | 00,019,456 | ---- | C] (Microsoft Corporation)
dhcpqec.dll -> %SystemRoot%\System32\dhcpqec.dll -> [2008/08/27 00:30:20 | 00,048,640 | ---- | C] (Microsoft Corporation)
cxthsfs2.cty -> %SystemRoot%\System32\drivers\cxthsfs2.cty -> [2008/08/27 00:30:18 | 00,129,045 | ---- | C] ()
credssp.dll -> %SystemRoot%\System32\credssp.dll -> [2008/08/27 00:30:17 | 00,012,800 | ---- | C] (Microsoft Corporation)
bthpan.sys -> %SystemRoot%\System32\drivers\bthpan.sys -> [2008/08/27 00:30:10 | 00,101,120 | ---- | C] (Microsoft Corporation)
bthmodem.sys -> %SystemRoot%\System32\drivers\bthmodem.sys -> [2008/08/27 00:30:10 | 00,037,888 | ---- | C] (Microsoft Corporation)
bthprint.sys -> %SystemRoot%\System32\drivers\bthprint.sys -> [2008/08/27 00:30:10 | 00,036,480 | ---- | C] (Microsoft Corporation)
bthusb.sys -> %SystemRoot%\System32\drivers\bthusb.sys -> [2008/08/27 00:30:10 | 00,018,944 | ---- | C] (Microsoft Corporation)
bthenum.sys -> %SystemRoot%\System32\drivers\bthenum.sys -> [2008/08/27 00:30:10 | 00,017,024 | ---- | C] (Microsoft Corporation)
azroles.dll -> %SystemRoot%\System32\azroles.dll -> [2008/08/27 00:30:09 | 00,233,472 | ---- | C] (Microsoft Corporation)
bitsprx4.dll -> %SystemRoot%\System32\bitsprx4.dll -> [2008/08/27 00:30:09 | 00,007,168 | ---- | C] (Microsoft Corporation)
ativmc20.cod -> %SystemRoot%\System32\drivers\ativmc20.cod -> [2008/08/27 00:30:07 | 00,064,352 | ---- | C] ()
alim1541.sys -> %SystemRoot%\System32\drivers\alim1541.sys -> [2008/08/27 00:30:02 | 00,042,752 | ---- | C] (Microsoft Corporation)
agpcpq.sys -> %SystemRoot%\System32\drivers\agpcpq.sys -> [2008/08/27 00:30:00 | 00,044,928 | ---- | C] (Microsoft Corporation)
agp440.sys -> %SystemRoot%\System32\drivers\agp440.sys -> [2008/08/27 00:30:00 | 00,042,368 | ---- | C] (Microsoft Corporation)
aaclient.dll -> %SystemRoot%\System32\aaclient.dll -> [2008/08/27 00:29:58 | 00,136,192 | ---- | C] (Microsoft Corporation)
Tanagra -> %UserProfile%\Local Settings\Application Data\Tanagra -> [2008/08/25 19:10:38 | 00,000,000 | ---D | C]
Tanagra -> %AllUsersProfile%\Application Data\Tanagra -> [2008/08/25 18:59:06 | 00,000,000 | ---D | C]
Memeo -> %ProgramFiles%\Memeo -> [2008/08/25 18:59:06 | 00,000,000 | ---D | C]
Downloaded Installations -> %UserProfile%\Local Settings\Application Data\Downloaded Installations -> [2008/08/25 18:58:18 | 00,000,000 | ---D | C]
Seagate -> %ProgramFiles%\Seagate -> [2008/08/25 18:57:15 | 00,000,000 | ---D | C]
setup.iss -> %SystemRoot%\setup.iss -> [2008/08/25 18:56:11 | 00,000,615 | ---- | C] ()
sbp2port.sys -> %SystemRoot%\System32\drivers\sbp2port.sys -> [2008/08/25 18:54:45 | 00,043,904 | ---- | C] (Microsoft Corporation)
Episode 205 - What's New, Beelzebub.lnk -> %AllUsersProfile%\Desktop\Episode 205 - What's New, Beelzebub.lnk -> [2008/08/25 18:50:01 | 00,001,256 | ---- | C] ()
Episode 204 - Chariots of the Dogs.lnk -> %AllUsersProfile%\Desktop\Episode 204 - Chariots of the Dogs.lnk -> [2008/08/25 18:43:26 | 00,001,249 | ---- | C] ()
Telltale Games -> %ProgramFiles%\Telltale Games -> [2008/08/24 23:11:38 | 00,000,000 | ---D | C]
GameTap -> %ProgramFiles%\GameTap -> [2008/08/24 22:59:22 | 00,000,000 | ---D | C]
GameTap -> %AllUsersProfile%\Application Data\GameTap -> [2008/08/24 22:59:22 | 00,000,000 | ---D | C]
InstallShield -> %AppData%\InstallShield -> [2008/08/24 22:58:51 | 00,000,000 | ---D | C]
inetcomm.dll -> %SystemRoot%\System32\dllcache\inetcomm.dll -> [2008/08/14 20:59:32 | 00,691,712 | ---- | C] (Microsoft Corporation)
Adobe -> %SystemRoot%\System32\Adobe -> [2008/08/11 17:55:46 | 00,000,000 | ---D | C]
funny stuff -> %UserProfile%\Desktop\funny stuff -> [2008/08/04 22:16:25 | 00,000,000 | ---D | C]
SpoonUninstall-dBpoweramp DSP Effects.bmp -> %SystemRoot%\System32\SpoonUninstall-dBpoweramp DSP Effects.bmp -> [2008/08/03 12:17:13 | 00,033,846 | ---- | C] ()
SpoonUninstall-dBpoweramp DSP Effects.dat -> %SystemRoot%\System32\SpoonUninstall-dBpoweramp DSP Effects.dat -> [2008/08/03 12:17:12 | 00,008,458 | ---- | C] ()
SpoonUninstall-dBpoweramp Music Converter.bmp -> %SystemRoot%\System32\SpoonUninstall-dBpoweramp Music Converter.bmp -> [2008/08/03 12:17:01 | 00,033,846 | ---- | C] ()
SpoonUninstall-dBpoweramp Music Converter.dat -> %SystemRoot%\System32\SpoonUninstall-dBpoweramp Music Converter.dat -> [2008/08/03 12:17:01 | 00,013,282 | ---- | C] ()
AccurateRip -> %AppData%\AccurateRip -> [2008/08/03 11:25:24 | 00,000,000 | ---D | C]
bbjack at langford jamboree 2008 -> %UserProfile%\Desktop\bbjack at langford jamboree 2008 -> [2008/08/03 10:16:08 | 00,000,000 | ---D | C]
Batch FLV -> %UserProfile%\Desktop\Batch FLV -> [2008/08/02 11:29:40 | 00,000,000 | ---D | C]
ImTOO -> %ProgramFiles%\ImTOO -> [2008/08/01 23:32:17 | 00,000,000 | ---D | C]
AVS4YOU -> %AppData%\AVS4YOU -> [2008/08/01 20:01:52 | 00,000,000 | ---D | C]
AVS4YOU -> %AllUsersProfile%\Application Data\AVS4YOU -> [2008/08/01 20:01:42 | 00,000,000 | ---D | C]
AVSMedia -> %CommonProgramFiles%\AVSMedia -> [2008/08/01 20:00:19 | 00,000,000 | ---D | C]
AVS4YOU -> %ProgramFiles%\AVS4YOU -> [2008/08/01 20:00:08 | 00,000,000 | ---D | C]
jill -> %UserProfile%\My Documents\jill -> [2008/07/31 22:35:22 | 00,000,000 | ---D | C]
Converted Video -> %SystemDrive%\Converted Video -> [2008/07/29 20:39:44 | 00,000,000 | ---D | C]
shctxex.vb -> %AllUsersProfile%\Application Data\shctxex.vb -> [2008/07/28 22:20:42 | 00,000,000 | ---D | C]
msvcp60d.dll -> %SystemRoot%\System32\msvcp60d.dll -> [2008/07/28 22:20:15 | 00,516,173 | ---- | C] (Microsoft Corporation)
MSVCRTD.DLL -> %SystemRoot%\System32\MSVCRTD.DLL -> [2008/07/28 22:20:15 | 00,385,100 | ---- | C] (Microsoft Corporation)
vzcontextmenu.dll -> %SystemRoot%\System32\vzcontextmenu.dll -> [2008/07/28 22:20:15 | 00,069,632 | ---- | C] ()
vbrun60.inf -> %SystemRoot%\System32\vbrun60.inf -> [2008/07/28 22:20:13 | 00,001,069 | ---- | C] ()
Template -> %AppData%\Template -> [2008/07/23 16:41:18 | 00,000,000 | ---D | C]
score report_files -> %UserProfile%\My Documents\score report_files -> [2008/07/23 16:37:56 | 00,000,000 | ---D | C]
score report.htm -> %UserProfile%\My Documents\score report.htm -> [2008/07/23 16:37:55 | 00,000,746 | ---- | C] ()
important stuff -> %UserProfile%\Desktop\important stuff -> [2008/07/22 15:55:06 | 00,000,000 | ---D | C]
hp stuff -> %UserProfile%\Desktop\hp stuff -> [2008/07/22 15:54:09 | 00,000,000 | ---D | C]
dBpoweramp -> %AppData%\dBpoweramp -> [2008/07/20 01:46:19 | 00,000,000 | ---D | C]

[Files/Folders - Modified Within 90 Days]
5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp ->
11 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp ->
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\ -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader -> [2008/10/16 21:07:33 | 00,000,000 | ---D | M]
qmgr0.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat -> [2008/10/16 21:25:05 | 00,004,096 | ---- | M] ()
qmgr1.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat -> [2008/10/16 21:25:05 | 00,004,096 | ---- | M] ()
C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\DATA\ -> C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\DATA -> [2008/05/07 01:36:37 | 00,000,000 | ---D | M]
opa11.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\DATA\opa11.dat -> [2006/06/09 10:55:32 | 00,008,206 | ---- | M] ()
opa12.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\DATA\opa12.dat -> [2008/05/07 01:36:37 | 00,008,206 | ---- | M] ()
C:\Documents and Settings\All Users\Application Data\Microsoft\Works\ -> C:\Documents and Settings\All Users\Application Data\Microsoft\Works -> [2007/11/21 04:08:42 | 00,000,000 | ---D | M]
wkcalcat.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Works\wkcalcat.dat -> [2006/01/19 14:13:32 | 00,016,384 | ---- | M] ()
wklntnts.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Works\wklntnts.dat -> [2006/02/15 16:16:24 | 00,519,096 | ---- | M] ()
wklntsk.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Works\wklntsk.dat -> [2006/02/15 16:16:24 | 00,519,096 | ---- | M] ()
C:\Documents and Settings\nick petrotto\Local Settings\Temp\ -> C:\Documents and Settings\nick petrotto\Local Settings\Temp -> [2008/10/16 21:34:42 | 00,000,000 | ---D | M]
IadHide5.dll -> C:\Documents and Settings\nick petrotto\Local Settings\Temp\IadHide5.dll -> [2004/08/09 04:59:57 | 00,024,613 | ---- | M] (BackWeb)
20 C:\Documents and Settings\nick petrotto\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\nick petrotto\Local Settings\Temp\*.tmp ->
C:\Documents and Settings\nick petrotto\Local Settings\Temp\{C2B6D5F4-EB96-43A8-A49C-D883407E9A3E}\ -> C:\Documents and Settings\nick petrotto\Local Settings\Temp\{C2B6D5F4-EB96-43A8-A49C-D883407E9A3E} -> [2008/10/16 21:05:55 | 00,000,000 | ---D | M]
ISSetup.dll -> C:\Documents and Settings\nick petrotto\Local Settings\Temp\{C2B6D5F4-EB96-43A8-A49C-D883407E9A3E}\ISSetup.dll -> [2007/09/12 17:10:28 | 00,552,214 | R--- | M] (Macrovision Corporation)
_Setup.dll -> C:\Documents and Settings\nick petrotto\Local Settings\Temp\{C2B6D5F4-EB96-43A8-A49C-D883407E9A3E}\_Setup.dll -> [2006/05/17 14:21:08 | 00,373,680 | R--- | M] (Macrovision Corporation)
RAIQqBeg.ini -> %SystemRoot%\System32\RAIQqBeg.ini -> [2008/10/16 21:38:43 | 00,874,901 | -HS- | M] ()
RAIQqBeg.ini2 -> %SystemRoot%\System32\RAIQqBeg.ini2 -> [2008/10/16 21:36:18 | 00,874,885 | -HS- | M] ()
wpa.dbl -> %SystemRoot%\System32\wpa.dbl -> [2008/10/16 21:30:04 | 00,001,158 | ---- | M] ()
nvapps.xml -> %SystemRoot%\System32\nvapps.xml -> [2008/10/16 21:27:43 | 00,081,191 | ---- | M] ()
SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [2008/10/16 21:27:05 | 00,000,006 | -H-- | M] ()
bootstat.dat -> %SystemRoot%\bootstat.dat -> [2008/10/16 21:26:35 | 00,002,048 | --S- | M] ()
AppleSoftwareUpdate.job -> %SystemRoot%\tasks\AppleSoftwareUpdate.job -> [2008/10/16 21:21:03 | 00,000,284 | ---- | M] ()
HOSTS -> %SystemRoot%\System32\drivers\etc\HOSTS -> [2008/10/16 20:58:51 | 00,000,686 | ---- | M] ()
user32.dll -> %SystemRoot%\System32\dllcache\user32.dll -> [2008/10/16 20:50:32 | 00,578,560 | ---- | M] (Microsoft Corporation)
OTScanIt2.exe -> %UserProfile%\Desktop\OTScanIt2.exe -> [2008/10/16 20:13:01 | 00,587,283 | ---- | M] ()
SDFix.exe -> %UserProfile%\Desktop\SDFix.exe -> [2008/10/16 20:10:58 | 01,522,584 | ---- | M] ()
CCleaner.lnk -> %UserProfile%\Desktop\CCleaner.lnk -> [2008/10/16 07:53:21 | 00,001,556 | ---- | M] ()
win.ini -> %SystemRoot%\win.ini -> [2008/10/16 07:48:14 | 00,000,691 | ---- | M] ()
BOOT.INI -> %SystemDrive%\BOOT.INI -> [2008/10/16 07:48:14 | 00,000,281 | RHS- | M] ()
system.ini -> %SystemRoot%\system.ini -> [2008/10/16 07:48:14 | 00,000,227 | ---- | M] ()
ycvxguqt.dll -> %SystemRoot%\System32\ycvxguqt.dll -> [2008/10/16 00:14:18 | 00,109,056 | ---- | M] ()
dlmwvo.dll -> %SystemRoot%\System32\dlmwvo.dll -> [2008/10/16 00:14:18 | 00,109,056 | ---- | M] ()
eawcxrxc.ini -> %SystemRoot%\System32\eawcxrxc.ini -> [2008/10/16 00:12:14 | 01,358,676 | -HS- | M] ()
cxrxcwae.dll -> %SystemRoot%\System32\cxrxcwae.dll -> [2008/10/16 00:12:03 | 00,071,168 | ---- | M] ()
RogueRemover FREE.lnk -> %AllUsersProfile%\Desktop\RogueRemover FREE.lnk -> [2008/10/16 00:07:02 | 00,000,703 | ---- | M] ()
TaskManagerFix.exe -> %UserProfile%\Desktop\TaskManagerFix.exe -> [2008/10/15 22:51:15 | 00,077,824 | ---- | M] (Task Manager Fix)
cxcyribc.ini -> %SystemRoot%\System32\cxcyribc.ini -> [2008/10/15 22:14:39 | 01,363,352 | -HS- | M] ()
cbirycxc.dll -> %SystemRoot%\System32\cbirycxc.dll -> [2008/10/15 22:14:23 | 00,071,168 | ---- | M] ()
yndkyu.dll -> %SystemRoot%\System32\yndkyu.dll -> [2008/10/15 22:12:42 | 00,109,056 | ---- | M] ()
wtisnkdt.dll -> %SystemRoot%\System32\wtisnkdt.dll -> [2008/10/15 22:12:42 | 00,109,056 | ---- | M] ()
tuvTkiIA.dll -> %SystemRoot%\System32\tuvTkiIA.dll -> [2008/10/15 19:36:20 | 00,040,448 | ---- | M] ()
pmnmMdcb.dll -> %SystemRoot%\System32\pmnmMdcb.dll -> [2008/10/15 19:36:20 | 00,040,448 | ---- | M] ()
wvUkJdCU.dll -> %SystemRoot%\System32\wvUkJdCU.dll -> [2008/10/15 19:35:51 | 00,040,448 | ---- | M] ()
byXNdcBT.dll -> %SystemRoot%\System32\byXNdcBT.dll -> [2008/10/15 19:35:51 | 00,040,448 | ---- | M] ()
khfFYOHB.dll -> %SystemRoot%\System32\khfFYOHB.dll -> [2008/10/15 19:34:55 | 00,040,448 | ---- | M] ()
ddcBqOeB.dll -> %SystemRoot%\System32\ddcBqOeB.dll -> [2008/10/15 19:34:55 | 00,040,448 | ---- | M] ()
jkkLEVoM.dll -> %SystemRoot%\System32\jkkLEVoM.dll -> [2008/10/15 19:34:42 | 00,040,448 | ---- | M] ()
cbXQIYRi.dll -> %SystemRoot%\System32\cbXQIYRi.dll -> [2008/10/15 19:34:42 | 00,040,448 | ---- | M] ()
nnnmjgDT.dll -> %SystemRoot%\System32\nnnmjgDT.dll -> [2008/10/15 19:34:36 | 00,040,448 | ---- | M] ()
khfEUkKD.dll -> %SystemRoot%\System32\khfEUkKD.dll -> [2008/10/15 19:34:36 | 00,040,448 | ---- | M] ()
opnmKBQk.dll -> %SystemRoot%\System32\opnmKBQk.dll -> [2008/10/15 19:33:39 | 00,040,448 | ---- | M] ()
ddcCVOhe.dll -> %SystemRoot%\System32\ddcCVOhe.dll -> [2008/10/15 19:33:39 | 00,040,448 | ---- | M] ()
wb34530.dll -> %SystemRoot%\System32\wb34530.dll -> [2008/10/15 19:22:43 | 00,167,936 | ---- | M] (Microsoft Corporation)
mwb34530.dll -> %SystemRoot%\System32\mwb34530.dll -> [2008/10/15 19:22:43 | 00,167,936 | ---- | M] (Microsoft Corporation)
bkwkgmae.ini -> %SystemRoot%\System32\bkwkgmae.ini -> [2008/10/15 19:09:56 | 01,363,352 | -HS- | M] ()
mwrkuq.dll -> %SystemRoot%\System32\mwrkuq.dll -> [2008/10/15 19:06:53 | 00,109,056 | ---- | M] ()
jegkvnyt.dll -> %SystemRoot%\System32\jegkvnyt.dll -> [2008/10/15 19:06:53 | 00,109,056 | ---- | M] ()
geBqQIAR.dll -> %SystemRoot%\System32\geBqQIAR.dll -> [2008/10/15 19:03:02 | 00,267,776 | ---- | M] ()
qoMgfcyX.dll -> %SystemRoot%\System32\qoMgfcyX.dll -> [2008/10/15 18:57:48 | 00,040,448 | ---- | M] ()
qoMdDVml.dll -> %SystemRoot%\System32\qoMdDVml.dll -> [2008/10/15 18:57:48 | 00,040,448 | ---- | M] ()
pmnnLccc.dll -> %SystemRoot%\System32\pmnnLccc.dll -> [2008/10/15 18:57:32 | 00,040,448 | ---- | M] ()
DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> %UserProfile%\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini -> [2008/10/14 21:03:30 | 00,241,664 | ---- | M] ()
Thumbs.db -> %UserProfile%\Desktop\Thumbs.db -> [2008/10/14 21:03:29 | 00,054,784 | -HS- | M] ()
Norton AntiVirus - Run Full System Scan - nick petrotto.job -> %SystemRoot%\tasks\Norton AntiVirus - Run Full System Scan - nick petrotto.job -> [2008/10/14 20:20:45 | 00,000,572 | ---- | M] ()
SvxxIRqr.ini -> %SystemRoot%\System32\SvxxIRqr.ini -> [2008/10/14 20:13:26 | 00,952,013 | -HS- | M] ()
SvxxIRqr.ini2 -> %SystemRoot%\System32\SvxxIRqr.ini2 -> [2008/10/14 20:10:55 | 00,952,013 | -HS- | M] ()
SYMEVENT.CAT -> %SystemRoot%\System32\drivers\SYMEVENT.CAT -> [2008/10/14 19:46:34 | 00,010,671 | ---- | M] ()
SYMEVENT.INF -> %SystemRoot%\System32\drivers\SYMEVENT.INF -> [2008/10/14 19:46:34 | 00,000,805 | ---- | M] ()
SYMEVENT.SYS -> %SystemRoot%\System32\drivers\SYMEVENT.SYS -> [2008/10/14 19:46:33 | 00,123,952 | ---- | M] (Symantec Corporation)
S32EVNT1.DLL -> %SystemRoot%\System32\S32EVNT1.DLL -> [2008/10/14 19:46:33 | 00,060,800 | ---- | M] (Symantec Corporation)
Norton AntiVirus.lnk -> %AllUsersProfile%\Desktop\Norton AntiVirus.lnk -> [2008/10/14 18:27:47 | 00,001,971 | ---- | M] ()
kgyruspa.ini -> %SystemRoot%\System32\kgyruspa.ini -> [2008/10/14 18:20:25 | 01,349,616 | -HS- | M] ()
uxprvfqr.dll -> %SystemRoot%\System32\uxprvfqr.dll -> [2008/10/14 17:13:42 | 00,101,376 | ---- | M] ()
qtfryc.dll -> %SystemRoot%\System32\qtfryc.dll -> [2008/10/14 17:13:42 | 00,101,376 | ---- | M] ()
glaskrod.ini -> %SystemRoot%\System32\glaskrod.ini -> [2008/10/13 22:02:22 | 01,090,007 | -HS- | M] ()
edlmnkur.ini -> %SystemRoot%\System32\edlmnkur.ini -> [2008/10/13 01:59:30 | 01,088,753 | -HS- | M] ()
NeroDigital.ini -> %SystemRoot%\NeroDigital.ini -> [2008/10/12 18:06:33 | 00,000,116 | ---- | M] ()
IPH.PH -> %SystemDrive%\IPH.PH -> [2008/10/06 20:10:07 | 00,002,810 | -H-- | M] ()
AIM 6.lnk -> %AllUsersProfile%\Desktop\AIM 6.lnk -> [2008/10/06 20:09:21 | 00,001,682 | ---- | M] ()
cat.jpg -> %UserProfile%\Desktop\cat.jpg -> [2008/10/06 20:03:26 | 00,091,827 | ---- | M] ()
IconCache.db -> %UserProfile%\Local Settings\Application Data\IconCache.db -> [2008/10/06 07:04:03 | 03,357,482 | -H-- | M] ()
88 min.mpg -> %UserProfile%\Desktop\88 min.mpg -> [2008/10/06 00:38:17 | 36,229,120 | ---- | M] ()
sweeny todd.mpg -> %UserProfile%\Desktop\sweeny todd.mpg -> [2008/10/05 19:06:40 | 55,332,864 | ---- | M] ()
MySpaceIM.lnk -> %AllUsersProfile%\Desktop\MySpaceIM.lnk -> [2008/10/05 18:24:43 | 00,000,747 | ---- | M] ()
HVIIIa.jpg -> %UserProfile%\Desktop\HVIIIa.jpg -> [2008/10/05 12:09:49 | 00,150,856 | ---- | M] ()
WLAN.INI -> %SystemRoot%\System32\WLAN.INI -> [2008/10/04 19:32:47 | 00,001,361 | ---- | M] ()
VACFix.exe -> %SystemRoot%\System32\VACFix.exe -> [2008/10/01 15:51:40 | 00,087,552 | ---- | M] (S!Ri.URZ)
apartments.doc -> %UserProfile%\My Documents\apartments.doc -> [2008/09/25 07:24:38 | 00,035,840 | ---- | M] ()
imsins.BAK -> %SystemRoot%\imsins.BAK -> [2008/09/11 05:01:18 | 00,001,374 | ---- | M] ()
AntiXPVSTFix.exe -> %SystemRoot%\System32\AntiXPVSTFix.exe -> [2008/09/08 23:38:55 | 00,088,576 | ---- | M] (S!Ri.URZ)
pncrt.dll -> %SystemRoot%\System32\pncrt.dll -> [2008/09/02 23:34:46 | 00,278,528 | ---- | M] (Real Networks, Inc)
PerfStringBackup.INI -> %SystemRoot%\System32\PerfStringBackup.INI -> [2008/09/01 05:02:53 | 00,459,570 | ---- | M] ()
perfh009.dat -> %SystemRoot%\System32\perfh009.dat -> [2008/09/01 05:02:53 | 00,405,310 | ---- | M] ()
perfc009.dat -> %SystemRoot%\System32\perfc009.dat -> [2008/09/01 05:02:53 | 00,063,860 | ---- | M] ()
GDIPFONTCACHEV1.DAT -> %UserProfile%\Local Settings\Application Data\GDIPFONTCACHEV1.DAT -> [2008/08/31 10:00:00 | 00,095,064 | ---- | M] ()
FNTCACHE.DAT -> %SystemRoot%\System32\FNTCACHE.DAT -> [2008/08/31 09:56:35 | 00,321,928 | ---- | M] ()
NTLDR -> %SystemDrive%\NTLDR -> [2008/08/31 09:33:00 | 00,250,048 | RHS- | M] ()
MRT.exe -> %SystemRoot%\System32\MRT.exe -> [2008/08/26 16:28:12 | 16,208,504 | ---- | M] (Microsoft Corporation)
setup.iss -> %SystemRoot%\setup.iss -> [2008/08/25 19:06:16 | 00,000,615 | ---- | M] ()
Episode 205 - What's New, Beelzebub.lnk -> %AllUsersProfile%\Desktop\Episode 205 - What's New, Beelzebub.lnk -> [2008/08/25 18:50:01 | 00,001,256 | ---- | M] ()
Episode 204 - Chariots of the Dogs.lnk -> %AllUsersProfile%\Desktop\Episode 204 - Chariots of the Dogs.lnk -> [2008/08/25 18:43:26 | 00,001,249 | ---- | M] ()
21.REPACK.DVDRip.XviD-FLAiTE.avi -> %UserProfile%\Desktop\21.REPACK.DVDRip.XviD-FLAiTE.avi -> [2008/08/18 02:03:52 | 73,329,9153 | ---- | M] ()
mozver.dat -> %SystemRoot%\mozver.dat -> [2008/08/11 17:56:09 | 00,005,184 | ---- | M] ()
SpoonUninstall-dBpoweramp DSP Effects.dat -> %SystemRoot%\System32\SpoonUninstall-dBpoweramp DSP Effects.dat -> [2008/08/03 12:17:12 | 00,008,458 | ---- | M] ()
SpoonUninstall-dBpoweramp DSP Effects.bmp -> %SystemRoot%\System32\SpoonUninstall-dBpoweramp DSP Effects.bmp -> [2008/08/03 12:17:05 | 00,033,846 | ---- | M] ()
SpoonUninstall.exe -> %SystemRoot%\System32\SpoonUninstall.exe -> [2008/08/03 12:17:02 | 02,433,400 | ---- | M] ()
SpoonUninstall-dBpoweramp Music Converter.dat -> %SystemRoot%\System32\SpoonUninstall-dBpoweramp Music Converter.dat -> [2008/08/03 12:17:01 | 00,013,282 | ---- | M] ()
SpoonUninstall-dBpoweramp Music Converter.bmp -> %SystemRoot%\System32\SpoonUninstall-dBpoweramp Music Converter.bmp -> [2008/08/03 12:16:43 | 00,033,846 | ---- | M] ()
COH_Mon.sys -> %SystemRoot%\System32\drivers\COH_Mon.sys -> [2008/07/30 17:42:12 | 00,023,888 | ---- | M] (Symantec Corporation)
coh_mon.cat -> %SystemRoot%\System32\drivers\coh_mon.cat -> [2008/07/30 17:28:04 | 00,010,537 | ---- | M] ()
COH_Mon.inf -> %SystemRoot%\System32\drivers\COH_Mon.inf -> [2008/07/30 17:28:04 | 00,000,706 | ---- | M] ()
score report.htm -> %UserProfile%\My Documents\score report.htm -> [2008/07/23 16:37:57 | 00,000,746 | ---- | M] ()
SpoonUninstall-dBpoweramp FLAC Codec.dat -> %SystemRoot%\System32\SpoonUninstall-dBpoweramp FLAC Codec.dat -> [2008/07/20 01:05:46 | 00,002,895 | ---- | M] ()
SpoonUninstall-dBpoweramp FLAC Codec.bmp -> %SystemRoot%\System32\SpoonUninstall-dBpoweramp FLAC Codec.bmp -> [2008/07/20 01:05:25 | 00,033,846 | ---- | M] ()
cdm.dll -> %SystemRoot%\System32\dllcache\cdm.dll -> [2008/07/18 22:10:48 | 00,094,920 | ---- | M] (Microsoft Corporation)
cdm.dll -> %SystemRoot%\System32\cdm.dll -> [2008/07/18 22:10:48 | 00,094,920 | ---- | M] (Microsoft Corporation)
wuauclt.exe -> %SystemRoot%\System32\wuauclt.exe -> [2008/07/18 22:10:42 | 00,053,448 | ---- | M] (Microsoft Corporation)
wuauclt.exe -> %SystemRoot%\System32\dllcache\wuauclt.exe -> [2008/07/18 22:10:42 | 00,053,448 | ---- | M] (Microsoft Corporation)
wups2.dll -> %SystemRoot%\System32\wups2.dll -> [2008/07/18 22:10:40 | 00,045,768 | ---- | M] (Microsoft Corporation)
wucltui.dll.mui -> %SystemRoot%\System32\wucltui.dll.mui -> [2008/07/18 22:10:24 | 00,033,992 | ---- | M] (Microsoft Corporation)
wups.dll -> %SystemRoot%\System32\wups.dll -> [2008/07/18 22:10:20 | 00,036,552 | ---- | M] (Microsoft Corporation)
wups.dll -> %SystemRoot%\System32\dllcache\wups.dll -> [2008/07/18 22:10:20 | 00,036,552 | ---- | M] (Microsoft Corporation)
wucltui.dll -> %SystemRoot%\System32\wucltui.dll -> [2008/07/18 22:09:46 | 00,325,832 | ---- | M] (Microsoft Corporation)
wucltui.dll -> %SystemRoot%\System32\dllcache\wucltui.dll -> [2008/07/18 22:09:46 | 00,325,832 | ---- | M] (Microsoft Corporation)
wuaucpl.cpl -> %SystemRoot%\System32\wuaucpl.cpl -> [2008/07/18 22:09:46 | 00,215,752 | ---- | M] (Microsoft Corporation)
wuaucpl.cpl -> %SystemRoot%\System32\dllcache\wuaucpl.cpl -> [2008/07/18 22:09:46 | 00,215,752 | ---- | M] (Microsoft Corporation)
wuapi.dll -> %SystemRoot%\System32\wuapi.dll -> [2008/07/18 22:09:44 | 00,563,912 | ---- | M] (Microsoft Corporation)
wuapi.dll -> %SystemRoot%\System32\dllcache\wuapi.dll -> [2008/07/18 22:09:44 | 00,563,912 | ---- | M] (Microsoft Corporation)
wuweb.dll -> %SystemRoot%\System32\wuweb.dll -> [2008/07/18 22:09:44 | 00,205,000 | ---- | M] (Microsoft Corporation)
wuweb.dll -> %SystemRoot%\System32\dllcache\wuweb.dll -> [2008/07/18 22:09:44 | 00,205,000 | ---- | M] (Microsoft Corporation)
wuaueng.dll -> %SystemRoot%\System32\wuaueng.dll -> [2008/07/18 22:09:42 | 01,811,656 | ---- | M] (Microsoft Corporation)
wuaueng.dll -> %SystemRoot%\System32\dllcache\wuaueng.dll -> [2008/07/18 22:09:42 | 01,811,656 | ---- | M] (Microsoft Corporation)
wuapi.dll.mui -> %SystemRoot%\System32\wuapi.dll.mui -> [2008/07/18 22:09:42 | 00,025,800 | ---- | M] (Microsoft Corporation)
wuaucpl.cpl.mui -> %SystemRoot%\System32\wuaucpl.cpl.mui -> [2008/07/18 22:09:36 | 00,025,800 | ---- | M] (Microsoft Corporation)
wuaueng.dll.mui -> %SystemRoot%\System32\wuaueng.dll.mui -> [2008/07/18 22:08:34 | 00,020,680 | ---- | M] (Microsoft Corporation)
mucltui.dll -> %SystemRoot%\System32\mucltui.dll -> [2008/07/18 22:07:34 | 00,270,880 | ---- | M] (Microsoft Corporation)
muweb.dll -> %SystemRoot%\System32\muweb.dll -> [2008/07/18 22:07:32 | 00,210,976 | ---- | M] (Microsoft Corporation)
mucltui.dll.mui -> %SystemRoot%\System32\mucltui.dll.mui -> [2008/07/18 22:07:32 | 00,029,728 | ---- | M] (Microsoft Corporation)
[File - Lop Check]
Application Data -> C:\Documents and Settings\All Users\Application Data -> [2008/10/16 00:18:45 | 00,000,000 | R--D | M]
{3276BE95_AF08_429F_A64F_CA64CB79BCF6} -> C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6} -> [2008/10/09 21:54:45 | 00,000,000 | ---D | M]
acccore -> C:\Documents and Settings\All Users\Application Data\acccore -> [2008/10/06 20:09:23 | 00,000,000 | ---D | M]
Adobe -> C:\Documents and Settings\All Users\Application Data\Adobe -> [2008/03/30 11:05:42 | 00,000,000 | ---D | M]
AOL -> C:\Documents and Settings\All Users\Application Data\AOL -> [2008/02/18 07:09:39 | 00,000,000 | ---D | M]
AOL Downloads -> C:\Documents and Settings\All Users\Application Data\AOL Downloads -> [2008/02/18 04:03:58 | 00,000,000 | ---D | M]
AOL OCP -> C:\Documents and Settings\All Users\Application Data\AOL OCP -> [2006/12/20 16:09:34 | 00,000,000 | ---D | M]
Apple -> C:\Documents and Settings\All Users\Application Data\Apple -> [2007/07/25 19:37:16 | 00,000,000 | ---D | M]
Apple Computer -> C:\Documents and Settings\All Users\Application Data\Apple Computer -> [2006/12/09 10:14:28 | 00,000,000 | ---D | M]
Avg8 -> C:\Documents and Settings\All Users\Application Data\Avg8 -> [2008/10/14 18:20:44 | 00,000,000 | ---D | M]
AVS4YOU -> C:\Documents and Settings\All Users\Application Data\AVS4YOU -> [2008/08/01 20:01:42 | 00,000,000 | ---D | M]
DVD Shrink -> C:\Documents and Settings\All Users\Application Data\DVD Shrink -> [2008/01/26 23:18:52 | 00,000,000 | ---D | M]
Exetender -> C:\Documents and Settings\All Users\Application Data\Exetender -> [2008/07/16 21:13:00 | 00,000,000 | ---D | M]
GameTap -> C:\Documents and Settings\All Users\Application Data\GameTap -> [2008/08/24 23:02:36 | 00,000,000 | ---D | M]
HipSoft -> C:\Documents and Settings\All Users\Application Data\HipSoft -> [2007/12/12 02:29:10 | 00,000,000 | ---D | M]
HP -> C:\Documents and Settings\All Users\Application Data\HP -> [2008/07/14 22:00:54 | 00,000,000 | ---D | M]
InstallShield -> C:\Documents and Settings\All Users\Application Data\InstallShield -> [2006/06/03 12:37:33 | 00,000,000 | ---D | M]
Lavasoft -> C:\Documents and Settings\All Users\Application Data\Lavasoft -> [2008/05/24 21:08:07 | 00,000,000 | ---D | M]
Macromedia -> C:\Documents and Settings\All Users\Application Data\Macromedia -> [2006/02/15 16:46:27 | 00,000,000 | ---D | M]
Macrovision -> C:\Documents and Settings\All Users\Application Data\Macrovision -> [2006/02/15 17:21:16 | 00,000,000 | ---D | M]
Microsoft -> C:\Documents and Settings\All Users\Application Data\Microsoft -> [2007/08/07 21:34:16 | 00,000,000 | --SD | M]
Microsoft Help -> C:\Documents and Settings\All Users\Application Data\Microsoft Help -> [2008/09/11 05:03:36 | 00,000,000 | ---D | M]
Motive -> C:\Documents and Settings\All Users\Application Data\Motive -> [2004/08/09 05:03:40 | 00,000,000 | ---D | M]
Nero -> C:\Documents and Settings\All Users\Application Data\Nero -> [2008/10/13 01:29:59 | 00,000,000 | ---D | M]
NVIDIA -> C:\Documents and Settings\All Users\Application Data\NVIDIA -> [2007/08/19 18:18:51 | 00,000,000 | ---D | M]
QuickTime -> C:\Documents and Settings\All Users\Application Data\QuickTime -> [2006/01/06 16:47:15 | 00,000,000 | ---D | M]
SBSI -> C:\Documents and Settings\All Users\Application Data\SBSI -> [2004/08/09 01:52:28 | 00,000,000 | ---D | M]
shctxex.vb -> C:\Documents and Settings\All Users\Application Data\shctxex.vb -> [2008/07/28 22:20:42 | 00,000,000 | ---D | M]
SmartSound Software Inc -> C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc -> [2007/01/21 21:58:38 | 00,000,000 | ---D | M]
SpinTop Games -> C:\Documents and Settings\All Users\Application Data\SpinTop Games -> [2007/08/06 23:34:13 | 00,000,000 | ---D | M]
Spybot - Search & Destroy -> C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy -> [2008/10/13 02:11:17 | 00,000,000 | ---D | M]
Symantec -> C:\Documents and Settings\All Users\Application Data\Symantec -> [2008/10/14 19:42:16 | 00,000,000 | ---D | M]
Tanagra -> C:\Documents and Settings\All Users\Application Data\Tanagra -> [2008/08/25 18:59:06 | 00,000,000 | ---D | M]
TEMP -> C:\Documents and Settings\All Users\Application Data\TEMP -> [2007/05/19 12:28:15 | 00,000,000 | ---D | M]
Trymedia -> C:\Documents and Settings\All Users\Application Data\Trymedia -> [2007/07/11 00:28:32 | 00,000,000 | ---D | M]
Ulead Systems -> C:\Documents and Settings\All Users\Application Data\Ulead Systems -> [2007/01/21 22:12:13 | 00,000,000 | ---D | M]
Verizon -> C:\Documents and Settings\All Users\Application Data\Verizon -> [2008/07/20 19:41:00 | 00,000,000 | ---D | M]
Viewpoint -> C:\Documents and Settings\All Users\Application Data\Viewpoint -> [2008/10/06 20:09:25 | 00,000,000 | ---D | M]
Windows Genuine Advantage -> C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage -> [2006/05/03 12:19:08 | 00,000,000 | ---D | M]
Yahoo! -> C:\Documents and Settings\All Users\Application Data\Yahoo! -> [2007/11/06 15:55:27 | 00,000,000 | ---D | M]
Yahoo! Companion -> C:\Documents and Settings\All Users\Application Data\Yahoo! Companion -> [2008/10/16 00:18:45 | 00,000,000 | ---D | M]
Application Data -> C:\Documents and Settings\nick petrotto\Application Data -> [2008/10/16 21:10:33 | 00,000,000 | R--D | M]
acccore -> C:\Documents and Settings\nick petrotto\Application Data\acccore -> [2007/09/02 20:21:15 | 00,000,000 | ---D | M]
AccurateRip -> C:\Documents and Settings\nick petrotto\Application Data\AccurateRip -> [2008/08/03 11:25:24 | 00,000,000 | ---D | M]
Adobe -> C:\Documents and Settings\nick petrotto\Application Data\Adobe -> [2008/08/11 17:56:58 | 00,000,000 | ---D | M]
Ahead -> C:\Documents and Settings\nick petrotto\Application Data\Ahead -> [2007/11/16 03:58:11 | 00,000,000 | ---D | M]
Apple Computer -> C:\Documents and Settings\nick petrotto\Application Data\Apple Computer -> [2008/01/25 04:19:24 | 00,000,000 | ---D | M]
AVS4YOU -> C:\Documents and Settings\nick petrotto\Application Data\AVS4YOU -> [2008/08/01 20:01:52 | 00,000,000 | ---D | M]
dBpoweramp -> C:\Documents and Settings\nick petrotto\Application Data\dBpoweramp -> [2008/07/20 01:55:46 | 00,000,000 | ---D | M]
Eidos -> C:\Documents and Settings\nick petrotto\Application Data\Eidos -> [2008/05/10 07:29:45 | 00,000,000 | ---D | M]
Identities -> C:\Documents and Settings\nick petrotto\Application Data\Identities -> [2004/08/09 01:45:53 | 00,000,000 | ---D | M]
InstallShield -> C:\Documents and Settings\nick petrotto\Application Data\InstallShield -> [2008/08/24 22:58:51 | 00,000,000 | ---D | M]
InterVideo -> C:\Documents and Settings\nick petrotto\Application Data\InterVideo -> [2007/12/15 11:38:51 | 00,000,000 | ---D | M]
iScreensaver -> C:\Documents and Settings\nick petrotto\Application Data\iScreensaver -> [2007/09/03 01:28:07 | 00,000,000 | ---D | M]
Jasc Software Inc -> C:\Documents and Settings\nick petrotto\Application Data\Jasc Software Inc -> [2007/09/02 19:36:05 | 00,000,000 | ---D | M]
Leadertech -> C:\Documents and Settings\nick petrotto\Application Data\Leadertech -> [2007/10/19 17:16:34 | 00,000,000 | ---D | M]
LimeWire -> C:\Documents and Settings\nick petrotto\Application Data\LimeWire -> [2008/05/02 23:17:29 | 00,000,000 | ---D | M]
Macromedia -> C:\Documents and Settings\nick petrotto\Application Data\Macromedia -> [2007/09/12 01:59:59 | 00,000,000 | ---D | M]
Microsoft -> C:\Documents and Settings\nick petrotto\Application Data\Microsoft -> [2008/10/14 18:20:35 | 00,000,000 | --SD | M]
Motive -> C:\Documents and Settings\nick petrotto\Application Data\Motive -> [2008/07/16 21:24:12 | 00,000,000 | ---D | M]
Move Networks -> C:\Documents and Settings\nick petrotto\Application Data\Move Networks -> [2008/10/08 20:49:36 | 00,000,000 | ---D | M]
Mozilla -> C:\Documents and Settings\nick petrotto\Application Data\Mozilla -> [2008/09/01 13:52:05 | 00,000,000 | ---D | M]
MySpace -> C:\Documents and Settings\nick petrotto\Application Data\MySpace -> [2007/09/02 19:10:23 | 00,000,000 | ---D | M]
Paltalk -> C:\Documents and Settings\nick petrotto\Application Data\Paltalk -> [2008/10/05 01:56:18 | 00,000,000 | ---D | M]
Real -> C:\Documents and Settings\nick petrotto\Application Data\Real -> [2008/04/10 19:33:02 | 00,000,000 | ---D | M]
SampleView -> C:\Documents and Settings\nick petrotto\Application Data\SampleView -> [2004/08/09 04:57:16 | 00,000,000 | ---D | M]
Sonic -> C:\Documents and Settings\nick petrotto\Application Data\Sonic -> [2007/10/19 17:16:36 | 00,000,000 | ---D | M]
Sun -> C:\Documents and Settings\nick petrotto\Application Data\Sun -> [2004/08/09 02:12:41 | 00,000,000 | ---D | M]
Symantec -> C:\Documents and Settings\nick petrotto\Application Data\Symantec -> [2004/08/10 19:45:33 | 00,000,000 | ---D | M]
Talkback -> C:\Documents and Settings\nick petrotto\Application Data\Talkback -> [2007/09/28 00:08:32 | 00,000,000 | ---D | M]
Template -> C:\Documents and Settings\nick petrotto\Application Data\Template -> [2008/07/23 16:41:18 | 00,000,000 | ---D | M]
TmpRecentIcons -> C:\Documents and Settings\nick petrotto\Application Data\TmpRecentIcons -> [2008/10/16 19:00:10 | 00,000,000 | ---D | M]
ubi.com -> C:\Documents and Settings\nick petrotto\Application Data\ubi.com -> [2007/12/25 10:28:55 | 00,000,000 | ---D | M]
Ulead Systems -> C:\Documents and Settings\nick petrotto\Application Data\Ulead Systems -> [2007/09/02 20:16:53 | 00,000,000 | ---D | M]
uTorrent -> C:\Documents and Settings\nick petrotto\Application Data\uTorrent -> [2008/10/15 19:25:58 | 00,000,000 | ---D | M]
Verizon -> C:\Documents and Settings\nick petrotto\Application Data\Verizon -> [2008/07/20 19:41:00 | 00,000,000 | ---D | M]
Viewpoint -> C:\Documents and Settings\nick petrotto\Application Data\Viewpoint -> [2007/09/24 23:37:18 | 00,000,000 | ---D | M]
vol_toolbar -> C:\Documents and Settings\nick petrotto\Application Data\vol_toolbar -> [2008/07/16 21:02:10 | 00,000,000 | ---D | M]
WinRAR -> C:\Documents and Settings\nick petrotto\Application Data\WinRAR -> [2008/10/16 21:10:33 | 00,000,000 | ---D | M]
C:\WINDOWS\Tasks\ -> C:\WINDOWS\Tasks -> [2008/10/14 18:29:48 | 00,000,000 | --SD | M]
AppleSoftwareUpdate.job -> C:\WINDOWS\Tasks\AppleSoftwareUpdate.job -> [2008/10/16 21:21:03 | 00,000,284 | ---- | M] ()
desktop.ini -> C:\WINDOWS\Tasks\desktop.ini -> [2004/08/04 15:00:00 | 00,000,065 | RH-- | M] ()
Norton AntiVirus - Run Full System Scan - nick petrotto.job -> C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - nick petrotto.job -> [2008/10/14 20:20:45 | 00,000,572 | ---- | M] ()
SA.DAT -> C:\WINDOWS\Tasks\SA.DAT -> [2008/10/16 21:27:05 | 00,000,006 | -H-- | M] ()
[File - Purity Scan]

[CatchMe Rootkit Scan by GMER]
< Windows folder & sub-folders >
scanning hidden processes ...
IPC error: 2 The system cannot find the file specified.
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000001
"ujdew"=hex:90,af,6a,6b,ae,e3,e6,3e,f4,68,5b,30,69,8e,48,f9,9f,85,ee,6d,d8,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:44,a6,ad,62,f7,88,c2,f8,b4,af,7b,ed,6c,12,17,ae,0f,0e,75,15,83,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"khjeh"=hex:5f,4f,11,f4,22,6c,16,28,f6,fc,50,c6,47,3a,e2,cc,62,8d,31,3c,95,..
"a0"=hex:20,01,00,00,6f,7f,42,84,94,6a,0e,da,83,85,0e,e7,11,81,a3,1c,f1,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:ff,49,00,8c,13,76,f1,71,57,ac,4f,31,87,0c,f9,62,16,96,43,d2,42,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:d9,e0,37,6f,69,84,4f,67,6b,57,da,71,02,f4,41,d0,ba,3d,91,3f,da,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000001
"ujdew"=hex:90,af,6a,6b,ae,e3,e6,3e,f4,68,5b,30,69,8e,48,f9,9f,85,ee,6d,d8,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:44,a6,ad,62,f7,88,c2,f8,b4,af,7b,ed,6c,12,17,ae,0f,0e,75,15,83,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"khjeh"=hex:5f,4f,11,f4,22,6c,16,28,f6,fc,50,c6,47,3a,e2,cc,62,8d,31,3c,95,..
"a0"=hex:20,01,00,00,6f,7f,42,84,94,6a,0e,da,83,85,0e,e7,11,81,a3,1c,f1,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:ff,49,00,8c,13,76,f1,71,57,ac,4f,31,87,0c,f9,62,16,96,43,d2,42,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:d9,e0,37,6f,69,84,4f,67,6b,57,da,71,02,f4,41,d0,ba,3d,91,3f,da,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000001
"ujdew"=hex:90,af,6a,6b,ae,e3,e6,3e,f4,68,5b,30,69,8e,48,f9,9f,85,ee,6d,d8,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:44,a6,ad,62,f7,88,c2,f8,b4,af,7b,ed,6c,12,17,ae,0f,0e,75,15,83,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"khjeh"=hex:5f,4f,11,f4,22,6c,16,28,f6,fc,50,c6,47,3a,e2,cc,62,8d,31,3c,95,..
"a0"=hex:20,01,00,00,6f,7f,42,84,94,6a,0e,da,83,85,0e,e7,11,81,a3,1c,f1,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:86,d0,20,51,f3,12,a5,d8,83,c0,0e,68,0d,5a,74,a0,ba,89,0d,80,be,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:d9,e0,37,6f,69,84,4f,67,6b,57,da,71,02,f4,41,d0,ba,3d,91,3f,da,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:8ada402a
"s2"=dword:e672222b
"h0"=dword:00000002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000001
"ujdew"=hex:90,af,6a,6b,ae,e3,e6,3e,f4,68,5b,30,69,8e,48,f9,9f,85,ee,6d,d8,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:44,a6,ad,62,f7,88,c2,f8,b4,af,7b,ed,6c,12,17,ae,0f,0e,75,15,83,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"khjeh"=hex:5f,4f,11,f4,22,6c,16,28,f6,fc,50,c6,47,3a,e2,cc,62,8d,31,3c,95,..
"a0"=hex:20,01,00,00,6f,7f,42,84,94,6a,0e,da,83,85,0e,e7,11,81,a3,1c,f1,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:ff,49,00,8c,13,76,f1,71,57,ac,4f,31,87,0c,f9,62,16,96,43,d2,42,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:d9,e0,37,6f,69,84,4f,67,6b,57,da,71,02,f4,41,d0,ba,3d,91,3f,da,..
scanning hidden registry entries ...
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{8F24E4A6-56B6-C2C0-E24D-A0F742676E03}]
"abpmhocodefbpbplohckeciglpmfehmffi"=hex:61,62,6e,6a,69,68,6f,66,64,6f,64,6c,64,62,6b,62,66,6a,6c,6f,6e,..
"bbpmhocodefbpbplohnjkbcebpkimpibdogc"=hex:61,62,63,69,65,6e,64,63,6a,6b,64,6a,64,64,64,66,66,69,6f,6a,6f,..
scanning hidden files ...
C:\WINDOWS\Thumbs.db:encryptable 0 bytes
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 1
< Document and Settings folder & sub folders >
scanning hidden files ...
IPC error: 2 The system cannot find the file specified.
C:\Documents and Settings\Administrator\My Documents\My Music\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Administrator\My Documents\My Pictures\My Logitech Pictures\Pictures and Videos\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\1A43EBD3.TMP 0 bytes
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\DF6C7A06.TMP 0 bytes
C:\Documents and Settings\All Users\Documents\My Music\Sample Music\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Compaq_Owner\.limewire\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Compaq_Owner\.limewire\xml\misc\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Compaq_Owner\Desktop\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Compaq_Owner\Desktop\pics dump\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Compaq_Owner\Favorites\State Government Offices, Local US Government, City Government and Federal Government.url:favicon 3638 bytes
C:\Documents and Settings\Compaq_Owner\Favorites\http--www.appraisercentral.com-TaxLiens.pdf.url:favicon 1406 bytes
C:\Documents and Settings\Compaq_Owner\Favorites\artists Norton and Florentine's Profile page on Super Deluxe.url:favicon 1150 bytes
C:\Documents and Settings\Compaq_Owner\Favorites\Food Network Cooking, Recipe Collections, Party Ideas, Quick & Easy Recipes, Cooking Videos.url:favicon 894 bytes
C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\WinAVI\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Compaq_Owner\My Documents\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Compaq_Owner\Shared\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Compaq_Owner\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\Default User\My Documents\My Music\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\file\New Folder\Desktop\edgefest\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\file\New Folder\Desktop\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\file\New Folder\My Documents\My Pictures\My Logitech Pictures\Pictures and Videos\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\file\New Folder\My Documents\My Scans\2006-05 (May)\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\file\New Folder\My Documents\Nicks Music\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\file\New Folder\My Documents\Nicks Pics\My Logitech Pictures\1234\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\file\New Folder\My Documents\Nicks Pics\My Logitech Pictures\Pictures and Videos\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\file\New Folder\My Documents\Nicks Pics\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\file\New Folder\My Documents\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\nick petrotto\Desktop\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\nick petrotto\Desktop\tmaxx\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\nick petrotto\Desktop\pics-14-Oct-202818\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\nick petrotto\Desktop\pics-25-Jan-31817\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\nick petrotto\Desktop\Batch FLV\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\nick petrotto\Desktop\bbjack at langford jamboree 2008\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\nick petrotto\Desktop\funny stuff\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\nick petrotto\Desktop\aunt karens pics of keiras first birthday\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\nick petrotto\Desktop\keira at great pumpkin farm\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\nick petrotto\Desktop\keira christmas and new years\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\nick petrotto\Desktop\keira thanksgiving\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\nick petrotto\Desktop\keiras first birthday\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\nick petrotto\Desktop\pics\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\nick petrotto\Desktop\pics-1-Nov-212246\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\nick petrotto\Favorites\109WLH - Online Classroom.url:favicon 3638 bytes
C:\Documents and Settings\nick petrotto\Favorites\House For Rent - 3 bedroom, large yard, garage, deck,.url:favicon 1150 bytes
C:\Documents and Settings\nick petrotto\Favorites\Older 3 Bedroom Farmhouse - Close to Canal!.url:favicon 1150 bytes
C:\Documents and Settings\nick petrotto\Favorites\poison ivy.url:favicon 1078 bytes
C:\Documents and Settings\nick petrotto\Favorites\SUNY Online Application SystemSubmit My Application Select Payment Type.url:favicon 1150 bytes
C:\Documents and Settings\nick petrotto\My Documents\My Pictures\keira\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\nick petrotto\My Documents\My Pictures\My Logitech Pictures\family pics\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\nick petrotto\My Documents\My Pictures\My Logitech Pictures\Pictures and Videos\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\nick petrotto\My Documents\My Pictures\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\nick petrotto\My Documents\My Scans\2006-12 (Dec)\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\nick petrotto\My Documents\My Scans\2007-04 (Apr)\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\nick petrotto\My Documents\My Videos\RealPlayer Downloads\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\nick petrotto\My Documents\MySpaceIM Pics\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\nick petrotto\My Documents\Downloads\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\nick petrotto\My Documents\pics\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\nick petrotto\My Documents\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\nick petrotto\My Documents\Ulead VideoStudio\10.0\Thumbs.db:encryptable 0 bytes
C:\Documents and Settings\nick petrotto\My Documents\My Music\Thumbs.db:encryptable 0 bytes
scan completed successfully
hidden files: 188

< End of report >
both reports are in the same message… they are separated by the ————————————————————- across the page. thanks!
Hello

Start OTScanIt2. Copy/Paste the information in the quotebox below into the panel where it says "Paste fix here" and then click the Run Fix button.

[Kill Explorer]
[Unregister Dlls]
[Driver Services - Safe List]
YY -> (oflpydin) oflpydin [Kernel | On_Demand | Stopped] -> %SystemDrive%\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\oflpydin.sys
[Registry - Safe List]
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
YY -> {07dd1779-5a1c-4db8-ae7c-be36daae3f0c} [HKLM] -> %SystemRoot%\system32\yndkyu.dll [Reg Error: Value does not exist or could not be read.]
YY -> {4AEB25BE-964A-3E1F-BA33-E2D186D44BDB} [HKLM] -> %SystemRoot%\system32\mwb34530.dll [D]
YY -> {6c3ed2b4-635d-4e17-9f2f-c5f73cc42dfd} [HKLM] -> %SystemRoot%\system32\dlmwvo.dll [Reg Error: Value does not exist or could not be read.]
YY -> {CDC83A40-7693-4192-9DE1-CD8F8811B16B} [HKLM] -> %SystemRoot%\system32\geBqQIAR.dll [Reg Error: Value does not exist or could not be read.]
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\
YN -> ShellBrowser\\"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YY -> "541ac234" -> %SystemRoot%\system32\cxrxcwae.dll [rundll32.exe "C:\WINDOWS\system32\cxrxcwae.dll",b]
< AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
*AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls
YY -> yndkyu.dll -> %SystemRoot%\system32\yndkyu.dll
YY -> dlmwvo.dll -> %SystemRoot%\system32\dlmwvo.dll
< AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
< SSODL [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
YN -> "{fbeb8a05-beee-4442-804e-409d6c4515e9}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [CDBurn]
< LSA Authentication Packages [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages
*LSA Authentication Packages* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages
YY -> C:\WINDOWS\system32\geBqQIAR -> %SystemRoot%\system32\geBqQIAR.dll
< LSA Authentication Packages [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages
[Files/Folders - Created Within 90 Days]
NY -> 5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp
NY -> 11 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp
NY -> SDFix -> %SystemDrive%\SDFix
NY -> SDFix.exe -> %UserProfile%\Desktop\SDFix.exe
NY -> dlmwvo.dll -> %SystemRoot%\System32\dlmwvo.dll
NY -> ycvxguqt.dll -> %SystemRoot%\System32\ycvxguqt.dll
NY -> eawcxrxc.ini -> %SystemRoot%\System32\eawcxrxc.ini
NY -> cxrxcwae.dll -> %SystemRoot%\System32\cxrxcwae.dll
NY -> AntiXPVSTFix.exe -> %SystemRoot%\System32\AntiXPVSTFix.exe
NY -> VACFix.exe -> %SystemRoot%\System32\VACFix.exe
NY -> WS2Fix.exe -> %SystemRoot%\System32\WS2Fix.exe
NY -> VCCLSID.exe -> %SystemRoot%\System32\VCCLSID.exe
NY -> swxcacls.exe -> %SystemRoot%\System32\swxcacls.exe
NY -> dumphive.exe -> %SystemRoot%\System32\dumphive.exe
NY -> SrchSTS.exe -> %SystemRoot%\System32\SrchSTS.exe
NY -> swsc.exe -> %SystemRoot%\System32\swsc.exe
NY -> swreg.exe -> %SystemRoot%\System32\swreg.exe
NY -> Process.exe -> %SystemRoot%\System32\Process.exe
NY -> TaskManagerFix.exe -> %UserProfile%\Desktop\TaskManagerFix.exe
NY -> cxcyribc.ini -> %SystemRoot%\System32\cxcyribc.ini
NY -> cbirycxc.dll -> %SystemRoot%\System32\cbirycxc.dll
NY -> yndkyu.dll -> %SystemRoot%\System32\yndkyu.dll
NY -> wtisnkdt.dll -> %SystemRoot%\System32\wtisnkdt.dll
NY -> tuvTkiIA.dll -> %SystemRoot%\System32\tuvTkiIA.dll
NY -> pmnmMdcb.dll -> %SystemRoot%\System32\pmnmMdcb.dll
NY -> wvUkJdCU.dll -> %SystemRoot%\System32\wvUkJdCU.dll
NY -> byXNdcBT.dll -> %SystemRoot%\System32\byXNdcBT.dll
NY -> ddcBqOeB.dll -> %SystemRoot%\System32\ddcBqOeB.dll
NY -> khfFYOHB.dll -> %SystemRoot%\System32\khfFYOHB.dll
NY -> jkkLEVoM.dll -> %SystemRoot%\System32\jkkLEVoM.dll
NY -> cbXQIYRi.dll -> %SystemRoot%\System32\cbXQIYRi.dll
NY -> nnnmjgDT.dll -> %SystemRoot%\System32\nnnmjgDT.dll
NY -> khfEUkKD.dll -> %SystemRoot%\System32\khfEUkKD.dll
NY -> opnmKBQk.dll -> %SystemRoot%\System32\opnmKBQk.dll
NY -> ddcCVOhe.dll -> %SystemRoot%\System32\ddcCVOhe.dll
NY -> wb34530.dll -> %SystemRoot%\System32\wb34530.dll
NY -> mwb34530.dll -> %SystemRoot%\System32\mwb34530.dll
NY -> bkwkgmae.ini -> %SystemRoot%\System32\bkwkgmae.ini
NY -> mwrkuq.dll -> %SystemRoot%\System32\mwrkuq.dll
NY -> jegkvnyt.dll -> %SystemRoot%\System32\jegkvnyt.dll
NY -> RAIQqBeg.ini2 -> %SystemRoot%\System32\RAIQqBeg.ini2
NY -> RAIQqBeg.ini -> %SystemRoot%\System32\RAIQqBeg.ini
NY -> geBqQIAR.dll -> %SystemRoot%\System32\geBqQIAR.dll
NY -> qoMgfcyX.dll -> %SystemRoot%\System32\qoMgfcyX.dll
NY -> qoMdDVml.dll -> %SystemRoot%\System32\qoMdDVml.dll
NY -> pmnnLccc.dll -> %SystemRoot%\System32\pmnnLccc.dll
NY -> qtfryc.dll -> %SystemRoot%\System32\qtfryc.dll
NY -> uxprvfqr.dll -> %SystemRoot%\System32\uxprvfqr.dll
NY -> kgyruspa.ini -> %SystemRoot%\System32\kgyruspa.ini
NY -> glaskrod.ini -> %SystemRoot%\System32\glaskrod.ini
NY -> edlmnkur.ini -> %SystemRoot%\System32\edlmnkur.ini
NY -> SvxxIRqr.ini2 -> %SystemRoot%\System32\SvxxIRqr.ini2
NY -> SvxxIRqr.ini -> %SystemRoot%\System32\SvxxIRqr.ini
[Files/Folders - Modified Within 90 Days]
NY -> 5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp
NY -> 11 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp
[Empty Temp Folders]
[Start Explorer]
[Reboot]


The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here

I will review the information when it comes back in.




Also post a new HJT log
Explorer killed successfully [Driver Services - Safe List] Service oflpydin stopped successfully. Service oflpydin deleted successfully. File C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\oflpydin.sys not found. [Registry - Safe List] Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07dd1779-5a1c-4db8-ae7c-be36daae3f0c}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{07dd1779-5a1c-4db8-ae7c-be36daae3f0c}\ not found. File C:\WINDOWS\system32\yndkyu.dll not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4AEB25BE-964A-3E1F-BA33-E2D186D44BDB}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4AEB25BE-964A-3E1F-BA33-E2D186D44BDB}\ deleted successfully. LoadLibrary failed for C:\WINDOWS\system32\mwb34530.dll C:\WINDOWS\system32\mwb34530.dll NOT unregistered. C:\WINDOWS\system32\mwb34530.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6c3ed2b4-635d-4e17-9f2f-c5f73cc42dfd}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6c3ed2b4-635d-4e17-9f2f-c5f73cc42dfd}\ not found. File C:\WINDOWS\system32\dlmwvo.dll not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CDC83A40-7693-4192-9DE1-CD8F8811B16B}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CDC83A40-7693-4192-9DE1-CD8F8811B16B}\ not found. DllUnregisterServer procedure not found in C:\WINDOWS\system32\geBqQIAR.dll C:\WINDOWS\system32\geBqQIAR.dll NOT unregistered. C:\WINDOWS\system32\geBqQIAR.dll moved successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\541ac234 deleted successfully. File C:\WINDOWS\system32\cxrxcwae.dll not found. Unable to delete registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:yndkyu.dll . File C:\WINDOWS\system32\yndkyu.dll not found. Unable to delete registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:dlmwvo.dll . File C:\WINDOWS\system32\dlmwvo.dll not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\CDBurn deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\"{fbeb8a05-beee-4442-804e-409d6c4515e9}"\ not found. Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages:C:\WINDOWS\system32\geBqQIAR deleted successfully. File C:\WINDOWS\system32\geBqQIAR.dll not found. [Files/Folders - Created Within 90 Days] C:\WINDOWS\msdownld.tmp folder deleted successfully. C:\SDFix\backups folder moved successfully. C:\SDFix\apps\Replace\xp folder moved successfully. C:\SDFix\apps\Replace\w2k folder moved successfully. C:\SDFix\apps\Replace folder moved successfully. C:\SDFix\apps folder moved successfully. C:\SDFix folder moved successfully. File C:\Documents and Settings\nick\Desktop\SDFix.exe not found! File C:\WINDOWS\System32\dlmwvo.dll not found! File C:\WINDOWS\System32\ycvxguqt.dll not found! C:\WINDOWS\System32\eawcxrxc.ini moved successfully. File C:\WINDOWS\System32\cxrxcwae.dll not found! C:\WINDOWS\System32\AntiXPVSTFix.exe moved successfully. C:\WINDOWS\System32\VACFix.exe moved successfully. C:\WINDOWS\System32\WS2Fix.exe moved successfully. C:\WINDOWS\System32\VCCLSID.exe moved successfully. C:\WINDOWS\System32\swxcacls.exe moved successfully. C:\WINDOWS\System32\dumphive.exe moved successfully. C:\WINDOWS\System32\SrchSTS.exe moved successfully. C:\WINDOWS\System32\swsc.exe moved successfully. C:\WINDOWS\System32\swreg.exe moved successfully. C:\WINDOWS\System32\Process.exe moved successfully. File C:\Documents and Settings\nick\Desktop\TaskManagerFix.exe not found! C:\WINDOWS\System32\cxcyribc.ini moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\System32\cbirycxc.dll C:\WINDOWS\System32\cbirycxc.dll NOT unregistered. C:\WINDOWS\System32\cbirycxc.dll moved successfully. File C:\WINDOWS\System32\yndkyu.dll not found! LoadLibrary failed for C:\WINDOWS\System32\wtisnkdt.dll C:\WINDOWS\System32\wtisnkdt.dll NOT unregistered. File move failed. C:\WINDOWS\System32\wtisnkdt.dll scheduled to be moved on reboot. LoadLibrary failed for C:\WINDOWS\System32\tuvTkiIA.dll C:\WINDOWS\System32\tuvTkiIA.dll NOT unregistered. File move failed. C:\WINDOWS\System32\tuvTkiIA.dll scheduled to be moved on reboot. LoadLibrary failed for C:\WINDOWS\System32\pmnmMdcb.dll C:\WINDOWS\System32\pmnmMdcb.dll NOT unregistered. File move failed. C:\WINDOWS\System32\pmnmMdcb.dll scheduled to be moved on reboot. LoadLibrary failed for C:\WINDOWS\System32\wvUkJdCU.dll C:\WINDOWS\System32\wvUkJdCU.dll NOT unregistered. File move failed. C:\WINDOWS\System32\wvUkJdCU.dll scheduled to be moved on reboot. File C:\WINDOWS\System32\byXNdcBT.dll not found! LoadLibrary failed for C:\WINDOWS\System32\ddcBqOeB.dll C:\WINDOWS\System32\ddcBqOeB.dll NOT unregistered. File move failed. C:\WINDOWS\System32\ddcBqOeB.dll scheduled to be moved on reboot. LoadLibrary failed for C:\WINDOWS\System32\khfFYOHB.dll C:\WINDOWS\System32\khfFYOHB.dll NOT unregistered. File move failed. C:\WINDOWS\System32\khfFYOHB.dll scheduled to be moved on reboot. LoadLibrary failed for C:\WINDOWS\System32\jkkLEVoM.dll C:\WINDOWS\System32\jkkLEVoM.dll NOT unregistered. File move failed. C:\WINDOWS\System32\jkkLEVoM.dll scheduled to be moved on reboot. File C:\WINDOWS\System32\cbXQIYRi.dll not found! LoadLibrary failed for C:\WINDOWS\System32\nnnmjgDT.dll C:\WINDOWS\System32\nnnmjgDT.dll NOT unregistered. File move failed. C:\WINDOWS\System32\nnnmjgDT.dll scheduled to be moved on reboot. LoadLibrary failed for C:\WINDOWS\System32\khfEUkKD.dll C:\WINDOWS\System32\khfEUkKD.dll NOT unregistered. File move failed. C:\WINDOWS\System32\khfEUkKD.dll scheduled to be moved on reboot. LoadLibrary failed for C:\WINDOWS\System32\opnmKBQk.dll C:\WINDOWS\System32\opnmKBQk.dll NOT unregistered. File move failed. C:\WINDOWS\System32\opnmKBQk.dll scheduled to be moved on reboot. LoadLibrary failed for C:\WINDOWS\System32\ddcCVOhe.dll C:\WINDOWS\System32\ddcCVOhe.dll NOT unregistered. File move failed. C:\WINDOWS\System32\ddcCVOhe.dll scheduled to be moved on reboot. LoadLibrary failed for C:\WINDOWS\System32\wb34530.dll C:\WINDOWS\System32\wb34530.dll NOT unregistered. C:\WINDOWS\System32\wb34530.dll moved successfully. File C:\WINDOWS\System32\mwb34530.dll not found! C:\WINDOWS\System32\bkwkgmae.ini moved successfully. File C:\WINDOWS\System32\mwrkuq.dll not found! LoadLibrary failed for C:\WINDOWS\System32\jegkvnyt.dll C:\WINDOWS\System32\jegkvnyt.dll NOT unregistered. File move failed. C:\WINDOWS\System32\jegkvnyt.dll scheduled to be moved on reboot. C:\WINDOWS\System32\RAIQqBeg.ini2 moved successfully. C:\WINDOWS\System32\RAIQqBeg.ini moved successfully. File C:\WINDOWS\System32\geBqQIAR.dll not found! LoadLibrary failed for C:\WINDOWS\System32\qoMgfcyX.dll C:\WINDOWS\System32\qoMgfcyX.dll NOT unregistered. File move failed. C:\WINDOWS\System32\qoMgfcyX.dll scheduled to be moved on reboot. LoadLibrary failed for C:\WINDOWS\System32\qoMdDVml.dll C:\WINDOWS\System32\qoMdDVml.dll NOT unregistered. File move failed. C:\WINDOWS\System32\qoMdDVml.dll scheduled to be moved on reboot. LoadLibrary failed for C:\WINDOWS\System32\pmnnLccc.dll C:\WINDOWS\System32\pmnnLccc.dll NOT unregistered. File move failed. C:\WINDOWS\System32\pmnnLccc.dll scheduled to be moved on reboot. DllUnregisterServer procedure not found in C:\WINDOWS\System32\qtfryc.dll C:\WINDOWS\System32\qtfryc.dll NOT unregistered. C:\WINDOWS\System32\qtfryc.dll moved successfully. DllUnregisterServer procedure not found in C:\WINDOWS\System32\uxprvfqr.dll C:\WINDOWS\System32\uxprvfqr.dll NOT unregistered. C:\WINDOWS\System32\uxprvfqr.dll moved successfully. C:\WINDOWS\System32\kgyruspa.ini moved successfully. C:\WINDOWS\System32\glaskrod.ini moved successfully. C:\WINDOWS\System32\edlmnkur.ini moved successfully. C:\WINDOWS\System32\SvxxIRqr.ini2 moved successfully. C:\WINDOWS\System32\SvxxIRqr.ini moved successfully. [Files/Folders - Modified Within 90 Days] [Empty Temp Folders] File delete failed. C:\Documents and Settings\nick\Local Settings\Temp\etilqs_Dee6hsNXUqPlJvG8bH8l scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\nick\Local Settings\Temp\hpodvd09.log scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\nick\Local Settings\Temp\IadHide5.dll scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\nick\Local Settings\Temp\~DF6E9B.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot. Local Service Temp folder emptied. Local Service Temporary Internet Files folder emptied. Windows Temp folder emptied. File delete failed. C:\Documents and Settings\nick\Local Settings\Application Data\Mozilla\Firefox\Profiles\fij47kw0.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\nick\Local Settings\Application Data\Mozilla\Firefox\Profiles\fij47kw0.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\nick\Local Settings\Application Data\Mozilla\Firefox\Profiles\fij47kw0.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\nick\Local Settings\Application Data\Mozilla\Firefox\Profiles\fij47kw0.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\nick\Local Settings\Application Data\Mozilla\Firefox\Profiles\fij47kw0.default\urlclassifier3.sqlite scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\nick\Local Settings\Application Data\Mozilla\Firefox\Profiles\fij47kw0.default\XUL.mfl scheduled to be deleted on reboot. FireFox cache emptied. RecycleBin -> emptied. Explorer started successfully < End of fix log > OTScanIt2 by OldTimer - Version 1.0.0.17b fix logfile created on 10192008_004349 Files moved on Reboot… File C:\WINDOWS\System32\wtisnkdt.dll not found! File C:\WINDOWS\System32\tuvTkiIA.dll not found! File C:\WINDOWS\System32\pmnmMdcb.dll not found! File C:\WINDOWS\System32\wvUkJdCU.dll not found! File C:\WINDOWS\System32\ddcBqOeB.dll not found! File C:\WINDOWS\System32\khfFYOHB.dll not found! File C:\WINDOWS\System32\jkkLEVoM.dll not found! File C:\WINDOWS\System32\nnnmjgDT.dll not found! File C:\WINDOWS\System32\khfEUkKD.dll not found! File C:\WINDOWS\System32\opnmKBQk.dll not found! File C:\WINDOWS\System32\ddcCVOhe.dll not found! File C:\WINDOWS\System32\jegkvnyt.dll not found! File C:\WINDOWS\System32\qoMgfcyX.dll not found! File C:\WINDOWS\System32\qoMdDVml.dll not found! File C:\WINDOWS\System32\pmnnLccc.dll not found! File C:\Documents and Settings\nick\Local Settings\Temp\etilqs_Dee6hsNXUqPlJvG8bH8l not found! C:\Documents and Settings\nick\Local Settings\Temp\hpodvd09.log moved successfully. C:\Documents and Settings\nick\Local Settings\Temp\IadHide5.dll moved successfully. File C:\Documents and Settings\nick\Local Settings\Temp\~DF6E9B.tmp not found! C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat moved successfully. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat moved successfully. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat moved successfully. C:\Documents and Settings\nick\Local Settings\Application Data\Mozilla\Firefox\Profiles\fij47kw0.default\Cache\_CACHE_001_ moved successfully. C:\Documents and Settings\nick\Local Settings\Application Data\Mozilla\Firefox\Profiles\fij47kw0.default\Cache\_CACHE_002_ moved successfully. C:\Documents and Settings\nick\Local Settings\Application Data\Mozilla\Firefox\Profiles\fij47kw0.default\Cache\_CACHE_003_ moved successfully. C:\Documents and Settings\nick\Local Settings\Application Data\Mozilla\Firefox\Profiles\fij47kw0.default\Cache\_CACHE_MAP_ moved successfully. C:\Documents and Settings\nick\Local Settings\Application Data\Mozilla\Firefox\Profiles\fij47kw0.default\urlclassifier3.sqlite moved successfully. C:\Documents and Settings\nick\Local Settings\Application Data\Mozilla\Firefox\Profiles\fij47kw0.default\XUL.mfl moved successfully.
Logfile of HijackThis v1.99.1
Scan saved at 12:53:37 AM, on 10/19/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Memeo\AutoBackup\MemeoService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\HP\hpcoretech\comp\hpdarc.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://downloads.yahoo.com/internetexplorer/welcome.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [StxTrayMenu] "C:\Program Files\Seagate\SystemTray\StxMenuMgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [541ac234] rundll32.exe "C:\WINDOWS\system32\hjohrvnh.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01010200-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Installer) - http://supportcenter.adelphia.net/sdccommo…ad/tgctlins.cab
O16 - DPF: {01111F00-3E00-11D2-8470-0060089874ED} (Support.com Installer) - http://supportsoft.adelphia.net/sdccommon/…ad/tgctlins.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class) -
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_…aploader_v6.cab
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - AppInit_DLLs: thngvf.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: AutoBackup (BMUService) - Memeo - C:\Program Files\Memeo\AutoBackup\MemeoService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WUSB54GCSVC - Unknown owner - C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe" "WUSB54GC.exe (file missing)
Hello

Disable resident protections (Antivirus…); you'll re-enable them after the scan

Download Lop S&D < here

Double-click Lop S&D.exe
Choose the language, then choose Option 1 (Search)
Wait till the end of the scan
Post the log which is created: (%SystemDrive%\lopR.txt)
ok so i ran across another problem while trying to run the most recent program. my security center is disabled so i cannot stop norton. also i tried to go on microsoft.com which directed me to run—–>services.msc and i could not enable automatic updates either. i will try to find out which processes are linked to norton antivirus and try to end the program that way.
——————–\\ Lop S&D 4.2.4-5 XP/Vista

Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : AMD Athlon™ XP 3200+ )
BIOS : Rev. 3.11
USER : nick ( Administrator )
BOOT : Normal boot
Antivirus : Norton AntiVirus 15.5.0.23 (Not Activated)
Firewall : Norton AntiVirus 15.5.0.23 (Activated)
C:\ (Local Disk) - NTFS - Total : 149 Go Free : 59 Go
D:\ (CD or DVD)
E:\ (CD or DVD)
F:\ (Local Disk) - NTFS - Total : 149 Go Free : 50 Go
H:\ (CD or DVD)
I:\ (USB)
J:\ (USB)
K:\ (USB)
L:\ (USB)
N:\ (CD or DVD)
O:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 02-10-2008|23:42 )
Option : [1] ( Sun 10/19/2008|13:39 )

——————–\\ Listing folders in APPLIC~1

[08/25/2007|09:33] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Adobe
[08/09/2004|01:45] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Identities
[08/25/2007|09:35] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Jasc Software Inc
[10/14/2008|06:20] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Microsoft
[08/09/2004|04:57] C:\DOCUME~1\ADMINI~1\APPLIC~1\ SampleView
[08/09/2004|02:12] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Sun
[08/10/2004|07:45] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Symantec

[10/09/2008|09:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ {3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[10/06/2008|08:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ acccore
[03/30/2008|11:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Adobe
[02/18/2008|07:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ AOL
[02/18/2008|04:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ AOL Downloads
[12/20/2006|04:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ AOL OCP
[07/25/2007|07:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple
[12/09/2006|10:14] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple Computer
[10/14/2008|06:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Avg8
[08/01/2008|08:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ AVS4YOU
[01/26/2008|11:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ DVD Shrink
[07/16/2008|09:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Exetender
[08/24/2008|11:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ GameTap
[12/12/2007|02:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ HipSoft
[07/14/2008|10:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ HP
[06/03/2006|12:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ InstallShield
[05/24/2008|09:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Lavasoft
[02/15/2006|04:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Macromedia
[02/15/2006|05:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Macrovision
[08/07/2007|09:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Microsoft
[09/11/2008|05:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Microsoft Help
[08/09/2004|05:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Motive
[10/18/2008|01:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Nero
[08/19/2007|06:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ NVIDIA
[01/06/2006|04:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ QuickTime
[08/09/2004|01:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SBSI
[07/28/2008|10:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ shctxex.vb
[01/21/2007|09:58] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SmartSound Software Inc
[08/06/2007|11:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SpinTop Games
[10/13/2008|02:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Spybot - Search & Destroy
[10/17/2008|10:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Symantec
[08/25/2008|06:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Tanagra
[05/19/2007|12:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ TEMP
[07/11/2007|12:28] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Trymedia
[01/21/2007|10:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Ulead Systems
[07/20/2008|07:41] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Verizon
[10/06/2008|08:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Viewpoint
[05/03/2006|12:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Windows Genuine Advantage
[11/06/2007|03:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Yahoo!
[10/16/2008|12:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Yahoo! Companion

[02/07/2007|12:17] C:\DOCUME~1\APPLIC~1\APPLIC~1\ Microsoft

[12/20/2006|04:09] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ acccore
[08/22/2007|05:33] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Ace
[01/15/2007|05:17] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Adobe
[12/22/2006|12:14] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ AdobeUM
[10/03/2006|11:44] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Ahead
[12/21/2006|08:09] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Aim
[07/26/2007|04:26] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Apple Computer
[08/20/2007|04:26] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Eidos
[12/04/2006|10:59] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ FotoWire
[02/22/2007|01:19] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Help
[08/09/2004|01:45] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Identities
[12/09/2006|12:43] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ InterVideo
[08/18/2007|04:00] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ iScreensaver
[10/04/2006|03:02] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Jasc Software Inc
[11/03/2006|09:08] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Leadertech
[07/28/2007|02:52] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Macromedia
[08/20/2007|04:23] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Microsoft
[02/07/2007|12:17] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ MySpace
[10/02/2006|12:45] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Real
[08/09/2004|04:57] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ SampleView
[02/06/2007|08:45] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ SecuROM
[11/03/2006|09:08] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Sonic
[08/09/2004|02:12] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Sun
[08/10/2004|07:45] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Symantec
[02/10/2007|03:32] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ U3
[01/21/2007|10:30] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Ulead Systems
[09/12/2008|07:15] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ uTorrent
[01/18/2007|05:48] C:\DOCUME~1\COMPAQ~1\APPLIC~1\ Viewpoint

[08/09/2004|01:45] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Identities
[08/10/2004|08:33] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Microsoft
[08/09/2004|04:57] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ SampleView
[08/09/2004|02:12] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Sun
[08/10/2004|07:45] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Symantec

[01/05/2006|12:08] C:\DOCUME~1\file\APPLIC~1\ Aim
[02/21/2006|10:45] C:\DOCUME~1\file\APPLIC~1\ Alien Skin
[01/30/2006|08:00] C:\DOCUME~1\file\APPLIC~1\ Apple Computer
[03/23/2006|07:06] C:\DOCUME~1\file\APPLIC~1\ AVG7
[09/02/2006|09:23] C:\DOCUME~1\file\APPLIC~1\ FotoWire
[03/12/2006|01:22] C:\DOCUME~1\file\APPLIC~1\ Help
[08/09/2004|01:45] C:\DOCUME~1\file\APPLIC~1\ Identities
[01/08/2006|05:49] C:\DOCUME~1\file\APPLIC~1\ InterVideo
[02/07/2007|12:17] C:\DOCUME~1\file\APPLIC~1\ Microsoft

[03/28/2008|09:27] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Adobe
[10/14/2008|06:20] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Microsoft

[10/14/2008|06:20] C:\DOCUME~1\NETWOR~1\APPLIC~1\ Microsoft

[10/18/2008|12:46] C:\DOCUME~1\nick\APPLIC~1\ acccore
[10/18/2008|12:00] C:\DOCUME~1\nick\APPLIC~1\ Adobe
[10/18/2008|06:00] C:\DOCUME~1\nick\APPLIC~1\ AVS4YOU
[08/09/2004|01:45] C:\DOCUME~1\nick\APPLIC~1\ Identities
[10/18/2008|12:03] C:\DOCUME~1\nick\APPLIC~1\ Macromedia
[10/19/2008|12:27] C:\DOCUME~1\nick\APPLIC~1\ Microsoft
[10/18/2008|12:07] C:\DOCUME~1\nick\APPLIC~1\ Mozilla
[10/18/2008|11:55] C:\DOCUME~1\nick\APPLIC~1\ MySpace
[10/18/2008|08:11] C:\DOCUME~1\nick\APPLIC~1\ Nero
[10/18/2008|12:43] C:\DOCUME~1\nick\APPLIC~1\ Real
[08/09/2004|04:57] C:\DOCUME~1\nick\APPLIC~1\ SampleView
[08/09/2004|02:12] C:\DOCUME~1\nick\APPLIC~1\ Sun
[08/10/2004|07:45] C:\DOCUME~1\nick\APPLIC~1\ Symantec
[10/18/2008|06:26] C:\DOCUME~1\nick\APPLIC~1\ Ulead Systems
[10/18/2008|08:14] C:\DOCUME~1\nick\APPLIC~1\ uTorrent

[09/02/2007|08:21] C:\DOCUME~1\NICKPE~1\APPLIC~1\ acccore
[08/03/2008|11:25] C:\DOCUME~1\NICKPE~1\APPLIC~1\ AccurateRip
[08/11/2008|05:56] C:\DOCUME~1\NICKPE~1\APPLIC~1\ Adobe
[11/16/2007|03:58] C:\DOCUME~1\NICKPE~1\APPLIC~1\ Ahead
[01/25/2008|04:19] C:\DOCUME~1\NICKPE~1\APPLIC~1\ Apple Computer
[08/01/2008|08:01] C:\DOCUME~1\NICKPE~1\APPLIC~1\ AVS4YOU
[07/20/2008|01:55] C:\DOCUME~1\NICKPE~1\APPLIC~1\ dBpoweramp
[05/10/2008|07:29] C:\DOCUME~1\NICKPE~1\APPLIC~1\ Eidos
[08/09/2004|01:45] C:\DOCUME~1\NICKPE~1\APPLIC~1\ Identities
[08/24/2008|10:58] C:\DOCUME~1\NICKPE~1\APPLIC~1\ InstallShield
[12/15/2007|11:38] C:\DOCUME~1\NICKPE~1\APPLIC~1\ InterVideo
[09/03/2007|01:28] C:\DOCUME~1\NICKPE~1\APPLIC~1\ iScreensaver
[09/02/2007|07:36] C:\DOCUME~1\NICKPE~1\APPLIC~1\ Jasc Software Inc
[10/19/2007|05:16] C:\DOCUME~1\NICKPE~1\APPLIC~1\ Leadertech
[05/02/2008|11:17] C:\DOCUME~1\NICKPE~1\APPLIC~1\ LimeWire
[09/12/2007|01:59] C:\DOCUME~1\NICKPE~1\APPLIC~1\ Macromedia
[10/14/2008|06:20] C:\DOCUME~1\NICKPE~1\APPLIC~1\ Microsoft
[07/16/2008|09:24] C:\DOCUME~1\NICKPE~1\APPLIC~1\ Motive
[10/08/2008|08:49] C:\DOCUME~1\NICKPE~1\APPLIC~1\ Move Networks
[09/01/2008|01:52] C:\DOCUME~1\NICKPE~1\APPLIC~1\ Mozilla
[09/02/2007|07:10] C:\DOCUME~1\NICKPE~1\APPLIC~1\ MySpace
[10/05/2008|01:56] C:\DOCUME~1\NICKPE~1\APPLIC~1\ Paltalk
[04/10/2008|07:33] C:\DOCUME~1\NICKPE~1\APPLIC~1\ Real
[08/09/2004|04:57] C:\DOCUME~1\NICKPE~1\APPLIC~1\ SampleView
[10/19/2007|05:16] C:\DOCUME~1\NICKPE~1\APPLIC~1\ Sonic
[08/09/2004|02:12] C:\DOCUME~1\NICKPE~1\APPLIC~1\ Sun
[08/10/2004|07:45] C:\DOCUME~1\NICKPE~1\APPLIC~1\ Symantec
[09/28/2007|12:08] C:\DOCUME~1\NICKPE~1\APPLIC~1\ Talkback
[07/23/2008|04:41] C:\DOCUME~1\NICKPE~1\APPLIC~1\ Template
[10/16/2008|07:00] C:\DOCUME~1\NICKPE~1\APPLIC~1\ TmpRecentIcons
[12/25/2007|10:28] C:\DOCUME~1\NICKPE~1\APPLIC~1\ ubi.com
[09/02/2007|08:16] C:\DOCUME~1\NICKPE~1\APPLIC~1\ Ulead Systems
[10/18/2008|11:31] C:\DOCUME~1\NICKPE~1\APPLIC~1\ uTorrent
[07/20/2008|07:41] C:\DOCUME~1\NICKPE~1\APPLIC~1\ Verizon
[09/24/2007|11:37] C:\DOCUME~1\NICKPE~1\APPLIC~1\ Viewpoint
[07/16/2008|09:02] C:\DOCUME~1\NICKPE~1\APPLIC~1\ vol_toolbar
[10/16/2008|09:10] C:\DOCUME~1\NICKPE~1\APPLIC~1\ WinRAR

——————–\\ Scheduled Tasks located in C:\WINDOWS\Tasks

[10/14/2008 08:20 PM][–a——] C:\WINDOWS\tasks\Norton AntiVirus - Run Full System Scan - nick petrotto.job
[10/16/2008 09:21 PM][–a——] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[10/19/2008 12:47 PM][–ah—–] C:\WINDOWS\tasks\SA.DAT
[08/04/2004 03:00 PM][-rah—–] C:\WINDOWS\tasks\desktop.ini

——————–\\ Listing Folders in C:\Program Files

[04/06/2007|07:14] C:\Program Files\ 802.11 Wireless LAN
[03/30/2008|11:05] C:\Program Files\ Adobe
[12/21/2006|08:10] C:\Program Files\ AIM
[10/06/2008|08:10] C:\Program Files\ AIM6
[09/28/2008|05:35] C:\Program Files\ AnMing
[12/21/2006|08:08] C:\Program Files\ AOD
[10/14/2008|07:25] C:\Program Files\ AOL
[09/13/2008|02:32] C:\Program Files\ Apple Software Update
[05/08/2008|05:42] C:\Program Files\ AVG
[10/18/2008|06:26] C:\Program Files\ AVS4YOU
[08/09/2004|04:59] C:\Program Files\ BackWeb
[07/07/2008|06:35] C:\Program Files\ Belkin
[10/09/2008|09:53] C:\Program Files\ Bonjour
[10/18/2008|10:45] C:\Program Files\ Common Files
[10/04/2008|07:33] C:\Program Files\ Compact Wireless-G USB Adapter Wireless Network Monitor
[08/09/2004|04:59] C:\Program Files\ Compaq Connections
[02/10/2007|05:06] C:\Program Files\ Crazy Machines - New Challenges
[02/05/2007|01:39] C:\Program Files\ DAEMON Tools
[09/01/2007|07:41] C:\Program Files\ dayam NFO Viewer
[05/30/2006|07:30] C:\Program Files\ Deskshare
[02/06/2007|12:32] C:\Program Files\ directx
[01/04/2006|04:33] C:\Program Files\ DiscWizard for Windows
[01/07/2006|12:46] C:\Program Files\ DivX
[04/09/2006|05:16] C:\Program Files\ DVD Shrink
[01/16/2007|10:11] C:\Program Files\ EO Video
[06/24/2008|07:00] C:\Program Files\ FILES
[08/24/2008|11:00] C:\Program Files\ GameTap
[08/09/2004|05:03] C:\Program Files\ Help and Support Additions
[07/14/2008|09:51] C:\Program Files\ Hewlett-Packard
[10/19/2008|12:53] C:\Program Files\ Hijackthis
[10/19/2008|12:44] C:\Program Files\ HP
[12/08/2006|08:40] C:\Program Files\ HP Design Studio
[01/14/2006|05:30] C:\Program Files\ Illustrate
[05/19/2007|02:11] C:\Program Files\ IMSI
[08/01/2008|11:32] C:\Program Files\ ImTOO
[10/12/2008|07:20] C:\Program Files\ InstallShield Installation Information
[10/18/2008|02:58] C:\Program Files\ Internet Explorer
[12/31/2005|06:55] C:\Program Files\ InterVideo
[10/09/2008|09:54] C:\Program Files\ iPod
[10/09/2008|09:55] C:\Program Files\ iTunes
[03/01/2006|08:56] C:\Program Files\ Jasc Software Inc
[04/08/2008|05:21] C:\Program Files\ Java
[12/04/2006|10:59] C:\Program Files\ Logitech
[05/16/2006|12:26] C:\Program Files\ Macromedia
[02/04/2008|06:51] C:\Program Files\ Mafia
[05/19/2007|06:25] C:\Program Files\ MagicDisc
[08/25/2008|06:59] C:\Program Files\ Memeo
[08/31/2008|09:44] C:\Program Files\ Messenger
[06/09/2006|10:52] C:\Program Files\ Microsoft ActiveSync
[05/07/2008|04:43] C:\Program Files\ Microsoft CAPICOM 2.1.0.2
[08/09/2004|01:45] C:\Program Files\ microsoft frontpage
[05/07/2008|01:24] C:\Program Files\ Microsoft Office
[08/09/2004|02:48] C:\Program Files\ Microsoft Visual Studio
[05/07/2008|01:24] C:\Program Files\ Microsoft Works
[06/09/2006|10:50] C:\Program Files\ Microsoft.NET
[08/31/2008|09:39] C:\Program Files\ Movie Maker
[10/19/2008|12:49] C:\Program Files\ Mozilla Firefox
[06/03/2006|01:07] C:\Program Files\ Mpeg2Decoder
[10/18/2008|03:02] C:\Program Files\ MSBuild
[08/31/2008|09:39] C:\Program Files\ msn
[09/28/2006|06:14] C:\Program Files\ MSN Games
[08/09/2004|01:42] C:\Program Files\ MSN Gaming Zone
[12/08/2006|04:07] C:\Program Files\ MSXML 4.0
[02/07/2007|12:17] C:\Program Files\ MySpace
[10/18/2008|01:18] C:\Program Files\ Nero
[08/31/2008|09:35] C:\Program Files\ NetMeeting
[10/14/2008|06:30] C:\Program Files\ Norton AntiVirus
[07/22/2007|01:29] C:\Program Files\ Oberon Media
[08/31/2008|09:35] C:\Program Files\ Outlook Express
[08/09/2004|05:04] C:\Program Files\ PC-Doctor for Windows
[07/22/2007|01:46] C:\Program Files\ PopCap Games
[01/22/2006|12:12] C:\Program Files\ Qualcomm
[09/13/2008|02:24] C:\Program Files\ QuickTime
[02/13/2006|07:16] C:\Program Files\ Real
[10/18/2008|03:02] C:\Program Files\ Reference Assemblies
[08/19/2007|06:27] C:\Program Files\ ResChanger 2005
[07/18/2007|07:19] C:\Program Files\ Rocknor's Donut Factory - Full
[10/18/2008|11:37] C:\Program Files\ RogueRemover FREE
[08/25/2008|06:57] C:\Program Files\ Seagate
[01/21/2007|09:58] C:\Program Files\ SmartSound Software
[05/01/2008|05:26] C:\Program Files\ SocratesMedia
[08/09/2004|02:39] C:\Program Files\ Sonic
[08/09/2004|02:39] C:\Program Files\ Sonic RecordNow!
[10/14/2008|07:46] C:\Program Files\ Symantec
[08/24/2008|11:11] C:\Program Files\ Telltale Games
[05/10/2008|07:23] C:\Program Files\ Ubisoft
[01/21/2007|09:55] C:\Program Files\ Ulead Systems
[01/22/2007|12:45] C:\Program Files\ Undisker
[08/09/2004|01:49] C:\Program Files\ Uninstall Information
[09/28/2008|05:42] C:\Program Files\ uTorrent
[10/04/2008|07:41] C:\Program Files\ Verizon
[10/23/2007|07:22] C:\Program Files\ Viewpoint
[01/21/2007|09:57] C:\Program Files\ Windows Media Components
[12/08/2006|10:10] C:\Program Files\ Windows Media Connect 2
[10/18/2008|11:54] C:\Program Files\ Windows Media Player
[08/31/2008|09:35] C:\Program Files\ Windows NT
[10/14/2008|06:23] C:\Program Files\ Windows Sidebar
[08/09/2004|01:43] C:\Program Files\ WindowsUpdate
[07/19/2007|09:03] C:\Program Files\ WinRAR
[08/09/2004|01:45] C:\Program Files\ xerox
[01/05/2006|02:35] C:\Program Files\ XviD
[11/06/2007|03:55] C:\Program Files\ Yahoo!
[07/22/2007|01:44] C:\Program Files\ Yahoo! Games

——————–\\ Listing Folders in C:\Program Files\Common Files

[06/12/2007|12:42] C:\Program Files\Common Files\ Adobe
[12/20/2006|04:09] C:\Program Files\Common Files\ AOL
[07/25/2007|07:37] C:\Program Files\Common Files\ Apple
[10/18/2008|06:26] C:\Program Files\Common Files\ AVSMedia
[03/10/2006|07:28] C:\Program Files\Common Files\ Bcgsoft
[06/09/2006|10:51] C:\Program Files\Common Files\ DESIGNER
[02/09/2007|05:48] C:\Program Files\Common Files\ DirectX
[12/04/2006|10:59] C:\Program Files\Common Files\ FotoWire
[01/04/2006|09:31] C:\Program Files\Common Files\ Hewlett-Packard
[07/14/2008|09:55] C:\Program Files\Common Files\ HP
[03/01/2006|08:56] C:\Program Files\Common Files\ InstallShield
[03/01/2006|08:57] C:\Program Files\Common Files\ Jasc Software Inc
[08/09/2004|02:12] C:\Program Files\Common Files\ Java
[12/04/2006|10:58] C:\Program Files\Common Files\ Logitech
[05/16/2006|12:26] C:\Program Files\Common Files\ Macromedia
[10/13/2008|09:40] C:\Program Files\Common Files\ Microsoft Shared
[07/16/2008|09:03] C:\Program Files\Common Files\ Motive
[08/09/2004|01:43] C:\Program Files\Common Files\ MSSoap
[10/18/2008|01:49] C:\Program Files\Common Files\ Nero
[12/20/2006|04:09] C:\Program Files\Common Files\ Nullsoft
[08/08/2004|06:37] C:\Program Files\Common Files\ ODBC
[09/02/2008|11:35] C:\Program Files\Common Files\ Real
[08/08/2004|06:37] C:\Program Files\Common Files\ SpeechEngines
[07/16/2008|08:54] C:\Program Files\Common Files\ SupportSoft
[08/09/2004|02:39] C:\Program Files\Common Files\ SureThing Shared
[10/16/2008|09:23] C:\Program Files\Common Files\ Symantec Shared
[08/31/2008|09:35] C:\Program Files\Common Files\ System
[01/21/2007|09:55] C:\Program Files\Common Files\ Ulead Systems
[09/12/2008|08:21] C:\Program Files\Common Files\ Wise Installation Wizard
[09/02/2008|11:35] C:\Program Files\Common Files\ xing shared

——————–\\ Process

( 46 Processes )

… OK !

——————–\\ Searching with S_Lop

No Lop folder found !

——————–\\ Searching for Lop Files - Folders

C:\DOCUME~1\nick\Cookies\nick@advertising[2].txt

——————–\\ Searching within the Registry

….. OK !

——————–\\ Checking the Hosts file

Hosts file CLEAN


——————–\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-19 13:43:41
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden files …
scan completed successfully
hidden processes: 0
hidden files: 0

——————–\\ Searching for other infections

C:\WINDOWS\system32\RYHilnmp.ini
C:\WINDOWS\system32\RYHilnmp.ini2
==> VUNDO <==

——————–\\ Cracks & Keygens ..

C:\DOCUME~1\nick\My Documents\Downloads\Nero_9_Key_Generator\Nero 9 KeyGen.exe
C:\DOCUME~1\nick\Recent\Crack.lnk
C:\DOCUME~1\ALLUSE~1\Application Data\GameTap\appdata\cache\gtPlayer\data\catalogmedia\CrackDown_GEN_Sega_243b0.dds
C:\DOCUME~1\ALLUSE~1\Application Data\GameTap\appdata\cache\gtPlayer\data\catalogmedia\Crackpots_2600_Act_265f3.dds


[F:50][D:4]-> C:\DOCUME~1\nick\LOCALS~1\Temp
[F:21][D:0]-> C:\DOCUME~1\nick\Cookies
[F:279][D:4]-> C:\DOCUME~1\nick\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - Sun 10/19/2008|13:46 - Option : [1]

——————–\\ Scan completed at 13:46:31
You got infected because you downloaded cracks

Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :Files
    C:\DOCUME~1\ALLUSE~1\APPLIC~1\shctxex.vb
    C:\WINDOWS\system32\RYHilnmp.ini
    C:\WINDOWS\system32\RYHilnmp.ini2
    C:\DOCUME~1\nick\My Documents\Downloads\Nero_9_Key_Generator
    C:\DOCUME~1\nick\Recent\Crack.lnk
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.




  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<info.txt (<

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI