This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Virus/Spyware problems, plz help

82 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello! So I logged onto my laptop and got a bunch of alerts that my PC was being infected by some spyware. My spyware program (MS 2009) took care of it and also my Viruse program (AVG) kicked in. But after I rebooted (I'm pretty sure that was a bad Idea) It wouldn't let me log into my account anymore. Instead of going to the normal XP loging screen it took me to this weird "School" like login screen (A small window that asks for user name and login password) and when I tried logging in there it would bring me to my background but wouldn't load any of my programs so it was useless. After a while it would sometime let me log in normally and when it did I would try to find the viruses and delete them. I deleted some like CSRSSC.EXE, 4.TMP, B.TMP, which were located in my C:\windows\prefects file but my virus scanner was picking up a lot of activity in my C:\windows\system32 folder and luckly was preventing them from doing anything… i think. When I am able to log on the problems I face are that it brings up a window saying that my Windows NT Multiple Provider Notification has to be closed and another window that will pop up about 20-40 sec. saying that Win 32 Services has to close down. I Just downloaded the HijackThis v2.0.2 so let me know what it is I need to do to provide all the information for this problem, THANKS!!

Here is a system scan from HJT:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:49:30 PM, on 2/3/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\TEMP\winlognn.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\DOCUME~1\Bret\LOCALS~1\Temp\csrssc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\DOCUME~1\Bret\LOCALS~1\Temp\csrssc.exe
C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\msas2009.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=3070206
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=3070206
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\Documents and Settings\Bret\fpxlnac.exe \s
O3 - Toolbar: ALOT Toolbar - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [services] C:\WINDOWS\services.exe
O4 - HKLM\..\Run: [jsf8uiw3jnjgffght] C:\WINDOWS\TEMP\winlognn.exe
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [jsf8uiw3jnjgffght] C:\WINDOWS\TEMP\winlognn.exe
O4 - HKCU\..\Run: [tezrtsjhfr84iusjfo84f] C:\DOCUME~1\Bret\LOCALS~1\Temp\csrssc.exe
O4 - HKCU\..\Run: [MS AntiSpyware 2009] "C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\msas2009.exe" /autorun
O4 - HKLM\..\Policies\Explorer\Run: [services] C:\WINDOWS\services.exe
O4 - HKUS\S-1-5-18\..\Run: [jsf8uiw3jnjgffght] C:\WINDOWS\TEMP\winlognn.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [tezrtsjhfr84iusjfo84f] C:\WINDOWS\TEMP\csrssc.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [jrfgxjvk.exe] C:\WINDOWS\jrfgxjvk.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [services] C:\WINDOWS\services.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [rveobljz.exe] C:\WINDOWS\rveobljz.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [services] C:\WINDOWS\services.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [jsf8uiw3jnjgffght] C:\WINDOWS\TEMP\winlognn.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [services] C:\WINDOWS\services.exe (User 'Default user')
O4 - Startup: ClearPlay Easy Updates.lnk = C:\Program Files\ClearPlay\ClearPlay Easy Updates\ClearPlayEasyUpdates.exe
O4 - Startup: MostFun.lnk = C:\Program Files\MostFun\Bin\MostFun.exe
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-_UNO/GAME_UNO1.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://www.gamehouse.com/games/SproutLauncher.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O22 - SharedTaskScheduler: jgzfkj9w38rksndfi7r4 - {C5BF49A2-94F3-42BD-F434-3604812C8955} - (no file)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
O23 - Service: GoogleDesktopManager - Unknown owner - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 9335 bytes
hello

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Standard Registry box change it to All.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
Hello!! Thanks for replying! So I'm stuck at that weird login screen… I was on a little while ago so I could follow your instructions but it disabled my internet so I was hoping to that it would let me use the internet if I restarted it… that didn't work. Any advice? Can I download that link and run the necessary programs/diagnostics in safe mode? (I'm not too familiar with safe mode)
I was able to get through and log on. I have to be quick and stop the programs "7.tmp" and "csrssc.tmp" from running or it won't let me get on the internet. I just downloaded what you asked for so i'll post the log shortly.
OTListIt logfile created on: 2/4/2009 6:30:42 PM - Run
OTListIt2 by OldTimer - Version 2.0.0.5 Folder = C:\Documents and Settings\Bret\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1014.37 Mb Total Physical Memory | 533.91 Mb Available Physical Memory | 52.64% Memory free
1.63 Gb Paging File | 1.21 Gb Available in Paging File | 73.86% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.83 Gb Total Space | 17.56 Gb Free Space | 31.45% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DDRHQHC1
Current User Name: Bret
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

C:\WINDOWS\system32\WLTRYSVC.EXE ()
C:\WINDOWS\system32\BCMWLTRY.EXE (Dell Inc.)
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe (Juniper Networks)
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
C:\Program Files\Dell\QuickSet\NicConfigSvc.exe (Dell Inc.)
C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
C:\WINDOWS\system32\igfxsrvc.exe (Intel Corporation)
C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe (Sun Microsystems, Inc.)
C:\WINDOWS\system32\WLTRAY.EXE (Dell Inc.)
C:\Program Files\Apoint\ApntEx.exe (Alps Electric Co., Ltd.)
C:\Program Files\Apoint\hidfind.exe (Alps Electric Co., Ltd.)
C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe (CyberLink Corp.)
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe (Adobe Systems Incorporated)
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
C:\Program Files\NetWaiting\netwaiting.exe ()
C:\Program Files\Dell Support\DSAgnt.exe (Gteko Ltd.)
C:\Program Files\MSN Messenger\msnmsgr.exe (Microsoft Corporation)
C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\msas2009.exe ()
C:\WINDOWS\system32\cmd.exe (Microsoft Corporation)
C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
C:\WINDOWS\system32\wuauclt.exe (Microsoft Corporation)
C:\WINDOWS\system32\taskmgr.exe (Microsoft Corporation)
C:\WINDOWS\services.exe (XRAVJE Corporation)
C:\WINDOWS\system32\rundll32.exe (Microsoft Corporation)
C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
C:\WINDOWS\system32\wuauclt.exe (Microsoft Corporation)
C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
C:\Documents and Settings\Bret\Desktop\OTListIt22.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (avg8emc [Auto | Running]) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd [Auto | Running]) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (dsNcService [Auto | Running]) – C:\Program Files\Juniper Networks\Common Files\dsNcService.exe (Juniper Networks)
SRV - (GoogleDesktopManager [On_Demand | Stopped]) – File not found
SRV - (gusvc [Auto | Running]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll (Microsoft Corporation)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (NICCONFIGSVC [Auto | Running]) – C:\Program Files\Dell\QuickSet\NicConfigSvc.exe (Dell Inc.)
SRV - (usnjsvc [On_Demand | Stopped]) – C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (wltrysvc [Auto | Running]) – C:\WINDOWS\system32\WLTRYSVC.EXE ()
SRV - (WMPNetworkSvc [Auto | Running]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (WudfSvc [Auto | Running]) – C:\WINDOWS\system32\WudfSvc.dll (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (AliIde [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\AMDAGP.SYS (Advanced Micro Devices, Inc.)
DRV - (ApfiltrService [On_Demand | Running]) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (APPDRV [System | Running]) – C:\WINDOWS\system32\drivers\APPDRV.SYS (Dell Inc)
DRV - (asc [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\asc3550.sys (Advanced System Products, Inc.)
DRV - (AvgLdx86 [System | Running]) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (BCM43XX [On_Demand | Running]) – C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corporation)
DRV - (bcm4sbxp [On_Demand | Running]) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (CmdIde [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (dac2w2k [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\dac2w2k.sys (Mylex Corporation)
DRV - (dsNcAdpt [On_Demand | Running]) – C:\WINDOWS\system32\drivers\dsNcAdpt.sys (Juniper Networks)
DRV - (DSproct [On_Demand | Running]) – C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys (GTek Technologies Ltd.)
DRV - (E100B [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\e100b325.sys (Intel Corporation)
DRV - (efpnolmo [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\efpnolmo.sys ()
DRV - (egnpsmiu [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\egnpsmiu.sys ()
DRV - (ethbotjf [System | Stopped]) – C:\WINDOWS\system32\drivers\ethbotjf.sys ()
DRV - (ethegmgt [System | Stopped]) – C:\WINDOWS\system32\drivers\ethegmgt.sys ()
DRV - (etherhmk [System | Stopped]) – C:\WINDOWS\system32\drivers\etherhmk.sys ()
DRV - (ethfbqvx [System | Stopped]) – C:\WINDOWS\system32\drivers\ethfbqvx.sys ()
DRV - (ethimbtt [System | Stopped]) – C:\WINDOWS\system32\drivers\ethimbtt.sys ()
DRV - (ethjenqu [System | Stopped]) – C:\WINDOWS\system32\drivers\ethjenqu.sys ()
DRV - (ethnwqjl [System | Stopped]) – C:\WINDOWS\system32\drivers\ethnwqjl.sys ()
DRV - (ethpdprv [System | Stopped]) – C:\WINDOWS\system32\drivers\ethpdprv.sys ()
DRV - (ethqovij [System | Stopped]) – C:\WINDOWS\system32\drivers\ethqovij.sys ()
DRV - (ethqsyoe [System | Stopped]) – C:\WINDOWS\system32\drivers\ethqsyoe.sys ()
DRV - (ethrnqxg [System | Stopped]) – C:\WINDOWS\system32\drivers\ethrnqxg.sys ()
DRV - (ethrsxjj [System | Stopped]) – C:\WINDOWS\system32\drivers\ethrsxjj.sys ()
DRV - (ethtgprm [System | Stopped]) – C:\WINDOWS\system32\drivers\ethtgprm.sys ()
DRV - (ethxkdvi [System | Stopped]) – C:\WINDOWS\system32\drivers\ethxkdvi.sys ()
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HDAudBus [On_Demand | Running]) – C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (HSF_DPV [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (ialm [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ialmnt5.sys (Intel Corporation)
DRV - (mdmxsdk [Auto | Running]) – C:\WINDOWS\system32\drivers\mdmxsdk.sys (Conexant)
DRV - (motmodem [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\motmodem.sys (Motorola)
DRV - (mraid35x [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\mraid35x.sys (American Megatrends Inc.)
DRV - (NEOFLTR_550_11965 [System | Running]) – C:\WINDOWS\system32\drivers\NEOFLTR_550_11965.sys (Juniper Networks)
DRV - (NEOFLTR_620_13525 [System | Running]) – C:\WINDOWS\system32\drivers\NEOFLTR_620_13525.sys (Juniper Networks)
DRV - (nv [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (Passthru [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ndisio.sys ()
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (ql1080 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\ql1080.sys (QLogic Corporation)
DRV - (ql12160 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\ql12160.sys (QLogic Corporation)
DRV - (ql1280 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\ql1280.sys (QLogic Corporation)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sisagp [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\SISAGP.SYS (Silicon Integrated Systems Corporation)
DRV - (Sparrow [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\sparrow.sys (Adaptec, Inc.)
DRV - (STHDA [On_Demand | Running]) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (symc810 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\symc810.sys (Symbios Logic Inc.)
DRV - (symc8xx [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (sym_hi [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (sym_u3 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (tsdtagpg [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\tsdtagpg.sys ()
DRV - (ultra [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\ultra.sys (Promise Technology, Inc.)
DRV - (USBAAPL [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\usbaapl.sys (Apple, Inc.)
DRV - (Wdf01000 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wdf01000.sys (Microsoft Corporation)
DRV - (winachsf [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (WinUSB [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\winusb.sys (Microsoft Corporation)
DRV - (WmiAcpi [System | Running]) – C:\WINDOWS\system32\drivers\wmiacpi.sys (Microsoft Corporation)

========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=3070206
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=3070206

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=3070206
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 ZieF.pl
O1 - Hosts: 127.0.0.1 localhost
O3 - HKLM\..\Toolbar: (&Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKLM\..\Toolbar: (ALOT Toolbar) - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll (Miva)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O4 - HKLM..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe (Dell Inc.)
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
O4 - HKLM..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [jsf8uiw3jnjgffght] C:\WINDOWS\TEMP\winlognn.exe File not found
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [services] C:\WINDOWS\services.exe (XRAVJE Corporation)
O4 - HKLM..\Run: [SigmatelSysTrayApp] stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup (Gteko Ltd.)
O4 - HKCU..\Run: [jsf8uiw3jnjgffght] C:\WINDOWS\TEMP\winlognn.exe File not found
O4 - HKCU..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe ()
O4 - HKCU..\Run: [MS AntiSpyware 2009] "C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\msas2009.exe" /autorun ()
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [services] C:\WINDOWS\services.exe (XRAVJE Corporation)
O4 - HKCU..\Run: [tezrtsjhfr84iusjfo84f] C:\DOCUME~1\Bret\LOCALS~1\Temp\csrssc.exe ()
O4 - HKCU..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe" File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
O4 - Startup: C:\Documents and Settings\Bret\Start Menu\Programs\Startup\ClearPlay Easy Updates.lnk = C:\Program Files\ClearPlay\ClearPlay Easy Updates\ClearPlayEasyUpdates.exe File not found
O4 - Startup: C:\Documents and Settings\Bret\Start Menu\Programs\Startup\MostFun.lnk = C:\Program Files\MostFun\Bin\MostFun.exe File not found
O4 - Startup: C:\Documents and Settings\Bret\Start Menu\Programs\Startup\Xfire.lnk = C:\Program Files\Xfire\Xfire.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\NPJPI150_06.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [NTDS] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [Juniper Secure DNS (Top)] - C:\Program Files\Juniper Networks\Secure Application Manager\samnsp.dll (Juniper Networks)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [Tcpip] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [Network Location Awareness (NLA) Namespace] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [Juniper Secure DNS (Bottom)] - C:\Program Files\Juniper Networks\Secure Application Manager\samnsp.dll (Juniper Networks)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/EN-US/a-_UNO/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key does not exist or could not be opened.)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} http://www.gamehouse.com/games/SproutLauncher.cab (SproutLauncherCtrl Class)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://www.popcap.com/games/popcaploader_v6.cab (PopCapLoader Object)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab (Minesweeper Flags Class)
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/octet-stream - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-complus - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-msdownload - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - Class Install Handler - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - deflate - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - gzip - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - lzdhtml - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/webviewhtml - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\system32\logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\system32\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\system32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\system32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\system32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\system32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\system32\WgaLogon.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {C5BF49A2-94F3-42BD-F434-3604812C8955} - jgzfkj9w38rksndfi7r4 - Reg Error: Key does not exist or could not be opened. File not found
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O27 - HKLM IFEO\Your Image File Name Here without a path: Debugger - C:\WINDOWS\system32\ntsd.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\system32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - ( schannel.dll) - C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - ( digest.dll) - C:\WINDOWS\system32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - ( msnsspc.dll) - C:\WINDOWS\system32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\system32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\system32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\system32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\system32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O33 - MountPoints2\{643e37d2-c42a-11db-b99b-001a9248dca8}\Shell\AutoRun\command - "" = E:\setupSNK.exe – File not found
O33 - MountPoints2\{e96a4e98-f88e-11dc-bcb3-001a9248dca8}\Shell - "" = AutoRun
O33 - MountPoints2\{e96a4e98-f88e-11dc-bcb3-001a9248dca8}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{e96a4e98-f88e-11dc-bcb3-001a9248dca8}\Shell\AutoRun\command - "" = E:\LaunchU3.exe – File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/02/04 18:29:42 | 00,506,368 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Bret\Desktop\OTListIt22.exe
[2009/02/04 18:27:13 | 00,000,695 | —- | C] () – C:\WINDOWS\System32\netsf_m.inf
[2009/02/04 18:27:12 | 00,001,748 | —- | C] () – C:\WINDOWS\System32\netsf.inf
[2009/02/04 18:27:10 | 00,040,448 | —- | C] () – C:\WINDOWS\Snakefedahe.dll
[2009/02/03 23:47:36 | 00,001,323 | —- | C] () – C:\Documents and Settings\Bret\Desktop\HijackThis.lnk
[2009/02/03 23:47:20 | 00,000,000 | —D | C] – C:\HJT
[2009/02/03 23:47:01 | 00,812,344 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Bret\Desktop\HJTsetup.exe
[2009/02/03 23:31:51 | 00,000,005 | —- | C] () – C:\WINDOWS\_id.dat
[2009/02/03 23:31:45 | 00,000,128 | —- | C] () – C:\WINDOWS\adobe.bat
[2009/02/03 23:05:11 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\ethxkdvi.sys
[2009/02/03 23:05:09 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\ethtgprm.sys
[2009/02/03 23:05:07 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\ethrsxjj.sys
[2009/02/03 23:05:05 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\ethrnqxg.sys
[2009/02/03 23:05:03 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\ethqsyoe.sys
[2009/02/03 23:05:01 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\ethqovij.sys
[2009/02/03 23:04:59 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\ethpdprv.sys
[2009/02/03 23:04:57 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\ethnwqjl.sys
[2009/02/03 23:04:55 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\ethjenqu.sys
[2009/02/03 23:04:53 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\ethimbtt.sys
[2009/02/03 23:04:51 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\ethfbqvx.sys
[2009/02/03 23:04:49 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\etherhmk.sys
[2009/02/03 23:04:47 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\ethegmgt.sys
[2009/02/03 23:04:45 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\ethbotjf.sys
[2009/02/03 23:04:43 | 00,137,280 | —- | C] () – C:\WINDOWS\System32\drivers\egnpsmiu.sys
[2009/02/03 23:04:41 | 00,137,280 | —- | C] () – C:\WINDOWS\System32\drivers\efpnolmo.sys
[2009/02/03 21:53:32 | 00,033,920 | —- | C] () – C:\WINDOWS\System32\drivers\tsdtagpg.sys
[2009/02/03 21:18:29 | 00,066,560 | -H– | C] () – C:\WINDOWS\System32\secupdat.dat
[2009/02/03 16:20:56 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\drivers\ndisio.sys
[2009/02/02 22:38:08 | 00,015,000 | —- | C] () – C:\WINDOWS\System32\_hnsf983ind.dll
[2009/02/02 22:21:31 | 00,037,888 | —- | C] (XRAVJE Corporation) – C:\WINDOWS\services.exe
[2009/02/02 22:18:49 | 00,040,448 | —- | C] () – C:\WINDOWS\kernel32.exe
[2009/02/02 22:18:00 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd
[2009/01/18 12:28:08 | 00,000,000 | -HSD | C] – C:\Config.Msi
[2009/01/09 21:15:35 | 00,000,000 | —D | C] – C:\Documents and Settings\Bret\Local Settings\Application Data\WMTools Downloaded Files
[2009/01/09 09:02:57 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Juniper Networks

========== Files - Modified Within 30 Days ==========

[11 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009/02/04 18:30:34 | 00,479,920 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/02/04 18:30:34 | 00,408,238 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/02/04 18:30:34 | 00,064,602 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/02/04 18:29:55 | 00,506,368 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Bret\Desktop\OTListIt22.exe
[2009/02/04 18:27:16 | 00,053,248 | —- | M] () – C:\WINDOWS\System32\drivers\ndisio.sys
[2009/02/04 18:27:13 | 00,000,695 | —- | M] () – C:\WINDOWS\System32\netsf_m.inf
[2009/02/04 18:27:12 | 00,001,748 | —- | M] () – C:\WINDOWS\System32\netsf.inf
[2009/02/04 18:27:10 | 00,040,448 | —- | M] () – C:\WINDOWS\Snakefedahe.dll
[2009/02/04 18:27:08 | 00,000,128 | —- | M] () – C:\WINDOWS\adobe.bat
[2009/02/04 18:26:34 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/02/04 18:26:20 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/02/04 18:26:18 | 10,637,14816 | -HS- | M] () – C:\hiberfil.sys
[2009/02/04 18:26:18 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/02/04 18:20:16 | 00,000,005 | —- | M] () – C:\WINDOWS\_id.dat
[2009/02/04 11:19:36 | 32,763,955 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/02/04 11:16:31 | 00,138,080 | —- | M] () – C:\WINDOWS\System32\drivers\ethxkdvi.sys
[2009/02/04 11:16:31 | 00,138,080 | —- | M] () – C:\WINDOWS\System32\drivers\ethtgprm.sys
[2009/02/04 11:16:31 | 00,138,080 | —- | M] () – C:\WINDOWS\System32\drivers\ethrsxjj.sys
[2009/02/04 11:16:31 | 00,138,080 | —- | M] () – C:\WINDOWS\System32\drivers\ethrnqxg.sys
[2009/02/04 11:16:31 | 00,138,080 | —- | M] () – C:\WINDOWS\System32\drivers\ethqsyoe.sys
[2009/02/04 11:16:31 | 00,138,080 | —- | M] () – C:\WINDOWS\System32\drivers\ethqovij.sys
[2009/02/04 11:16:31 | 00,138,080 | —- | M] () – C:\WINDOWS\System32\drivers\ethpdprv.sys
[2009/02/04 11:16:31 | 00,138,080 | —- | M] () – C:\WINDOWS\System32\drivers\ethnwqjl.sys
[2009/02/04 11:16:31 | 00,138,080 | —- | M] () – C:\WINDOWS\System32\drivers\ethjenqu.sys
[2009/02/04 11:16:31 | 00,138,080 | —- | M] () – C:\WINDOWS\System32\drivers\ethimbtt.sys
[2009/02/04 11:16:31 | 00,138,080 | —- | M] () – C:\WINDOWS\System32\drivers\ethfbqvx.sys
[2009/02/04 11:16:31 | 00,138,080 | —- | M] () – C:\WINDOWS\System32\drivers\etherhmk.sys
[2009/02/04 11:16:31 | 00,138,080 | —- | M] () – C:\WINDOWS\System32\drivers\ethegmgt.sys
[2009/02/04 11:16:30 | 00,138,080 | —- | M] () – C:\WINDOWS\System32\drivers\ethbotjf.sys
[2009/02/03 23:47:36 | 00,001,323 | —- | M] () – C:\Documents and Settings\Bret\Desktop\HijackThis.lnk
[2009/02/03 23:47:01 | 00,812,344 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Bret\Desktop\HJTsetup.exe
[2009/02/03 23:31:42 | 00,037,888 | —- | M] (XRAVJE Corporation) – C:\WINDOWS\services.exe
[2009/02/03 23:04:43 | 00,137,280 | —- | M] () – C:\WINDOWS\System32\drivers\egnpsmiu.sys
[2009/02/03 23:04:41 | 00,137,280 | —- | M] () – C:\WINDOWS\System32\drivers\efpnolmo.sys
[2009/02/03 21:53:32 | 00,033,920 | —- | M] () – C:\WINDOWS\System32\drivers\tsdtagpg.sys
[2009/02/03 21:20:45 | 00,066,560 | -H– | M] () – C:\WINDOWS\System32\secupdat.dat
[2009/02/02 23:36:36 | 00,000,561 | —- | M] () – C:\Documents and Settings\Bret\My Documents\My Sharing Folders.lnk
[2009/02/02 22:38:08 | 00,015,000 | —- | M] () – C:\WINDOWS\System32\_hnsf983ind.dll
[2009/02/02 22:36:58 | 00,085,942 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/02/02 22:18:51 | 00,040,448 | —- | M] () – C:\WINDOWS\kernel32.exe
[2009/02/01 00:19:52 | 00,000,268 | -H– | M] () – C:\sqmdata02.sqm
[2009/02/01 00:19:52 | 00,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2009/01/31 17:55:16 | 00,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/01/31 09:31:33 | 00,010,520 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/01/31 09:31:32 | 00,325,128 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/01/31 09:31:32 | 00,027,656 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/01/31 09:31:29 | 00,107,272 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/01/29 23:14:42 | 00,000,268 | -H– | M] () – C:\sqmdata01.sqm
[2009/01/29 23:14:42 | 00,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2009/01/29 23:14:31 | 00,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2009/01/29 23:14:31 | 00,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2009/01/25 22:59:02 | 00,000,268 | -H– | M] () – C:\sqmdata19.sqm
[2009/01/25 22:59:02 | 00,000,244 | -H– | M] () – C:\sqmnoopt19.sqm
[2009/01/25 15:01:09 | 00,000,268 | -H– | M] () – C:\sqmdata18.sqm
[2009/01/25 15:01:08 | 00,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2009/01/23 00:00:43 | 00,000,268 | -H– | M] () – C:\sqmdata17.sqm
[2009/01/23 00:00:43 | 00,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2009/01/20 16:49:09 | 00,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2009/01/20 16:49:09 | 00,000,232 | -H– | M] () – C:\sqmdata16.sqm
[2009/01/20 10:05:44 | 00,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2009/01/20 10:05:44 | 00,000,232 | -H– | M] () – C:\sqmdata15.sqm
[2009/01/18 23:13:12 | 00,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2009/01/18 23:13:12 | 00,000,232 | -H– | M] () – C:\sqmdata14.sqm
[2009/01/18 16:36:34 | 00,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2009/01/18 16:36:34 | 00,000,232 | -H– | M] () – C:\sqmdata13.sqm
[2009/01/18 12:40:42 | 00,010,752 | —- | M] () – C:\Documents and Settings\Bret\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/01/17 18:08:19 | 00,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2009/01/17 18:08:19 | 00,000,232 | -H– | M] () – C:\sqmdata12.sqm
[2009/01/17 02:28:11 | 00,000,268 | -H– | M] () – C:\sqmdata11.sqm
[2009/01/17 02:28:11 | 00,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2009/01/16 18:29:03 | 00,000,268 | -H– | M] () – C:\sqmdata10.sqm
[2009/01/16 18:29:03 | 00,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2009/01/16 18:28:52 | 00,000,268 | -H– | M] () – C:\sqmdata09.sqm
[2009/01/16 18:28:52 | 00,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2009/01/16 02:25:10 | 00,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2009/01/16 02:25:10 | 00,000,232 | -H– | M] () – C:\sqmdata08.sqm
[2009/01/15 15:00:15 | 00,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2009/01/15 15:00:15 | 00,000,232 | -H– | M] () – C:\sqmdata07.sqm
[2009/01/15 02:03:12 | 00,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2009/01/15 02:03:12 | 00,000,232 | -H– | M] () – C:\sqmdata06.sqm
[2009/01/14 11:14:03 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/01/12 18:00:10 | 00,000,268 | -H– | M] () – C:\sqmdata05.sqm
[2009/01/12 18:00:10 | 00,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2009/01/12 17:59:58 | 00,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2009/01/12 17:59:58 | 00,000,232 | -H– | M] () – C:\sqmdata04.sqm
[2009/01/11 20:28:59 | 00,000,268 | -H– | M] () – C:\sqmdata03.sqm
[2009/01/11 20:28:59 | 00,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2009/01/08 14:55:38 | 05,864,900 | -H– | M] () – C:\Documents and Settings\Bret\Local Settings\Application Data\IconCache.db

========== LOP Check ==========

[2009/02/02 22:18:00 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/12/21 15:28:05 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2008/03/29 16:54:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2008/01/22 21:15:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2008/10/27 18:12:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2008/08/17 15:23:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG7
[2009/02/03 21:42:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg8
[2009/02/02 22:18:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd
[2007/07/20 16:07:37 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GameHouse
[2009/01/06 18:39:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2009/02/03 23:44:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google Updater
[2007/02/16 08:35:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2007/02/06 19:29:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GTek
[2008/04/07 18:58:46 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intuit
[2009/01/09 09:03:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Juniper Networks
[2008/08/23 10:57:26 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2007/06/04 10:53:40 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MostFun
[2007/07/20 13:17:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2004/08/10 12:13:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2007/03/20 15:06:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/12/16 19:51:00 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Bret\Application Data
[2007/12/09 22:00:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\Adobe
[2008/03/24 14:56:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\alot
[2008/10/27 19:20:12 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\Apple Computer
[2008/04/15 16:56:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\ClearPlay Inc
[2007/02/25 18:15:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\CyberLink
[2008/04/01 21:25:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\Google
[2007/02/06 19:29:31 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Bret\Application Data\Gtek
[2007/02/25 20:21:30 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\Help
[2008/04/21 20:03:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\ICAClient
[2004/08/10 12:08:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\Identities
[2007/04/13 22:02:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\InstallShield
[2008/04/21 20:17:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\Juniper Networks
[2007/12/28 18:19:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\Leadertech
[2007/05/05 20:33:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\LimeWire Music
[2007/04/25 09:07:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\Macromedia
[2007/04/16 20:21:55 | 00,000,000 | –SD | M] – C:\Documents and Settings\Bret\Application Data\Microsoft
[2008/01/27 21:57:43 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Bret\Application Data\Move Networks
[2008/08/17 13:41:57 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\Mozilla
[2007/02/18 15:28:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\Sun
[2007/04/22 09:03:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\Talkback
[2008/12/16 21:12:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\Tibia
[2008/01/08 21:18:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\Xfire
[2007/06/10 08:56:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\yoclient
[2009/01/14 11:14:03 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2004/08/04 04:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/02/04 18:26:20 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 263719 bytes -> %SystemRoot%\Temp:temp
< End of report >



OTListIt Extras logfile created on: 2/4/2009 6:30:42 PM - Run
OTListIt2 by OldTimer - Version 2.0.0.5 Folder = C:\Documents and Settings\Bret\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1014.37 Mb Total Physical Memory | 533.91 Mb Available Physical Memory | 52.64% Memory free
1.63 Gb Paging File | 1.21 Gb Available in Paging File | 73.86% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.83 Gb Total Space | 17.56 Gb Free Space | 31.45% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DDRHQHC1
Current User Name: Bret
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1 (Microsoft Corporation)
C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\World of Warcraft\WoW-1.12.x-to-2.0.1-enUS-patch-downloader.exe:*:Enabled:Blizzard Downloader File not found
C:\Program Files\World of Warcraft\WoW-2.0.3-enUS-downloader.exe:*:Enabled:Blizzard Downloader File not found
C:\Program Files\World of Warcraft\WoW-2.0.3.6299-to-2.0.7.6383-enUS-downloader.exe:*:Enabled:Blizzard Downloader File not found
C:\Program Files\World of Warcraft\WoW-2.0.7.6383-to-2.0.8.6403-enUS-downloader.exe:*:Enabled:Blizzard Downloader File not found
C:\Program Files\Grisoft\AVG7\avginet.exe:*:Enabled:avginet.exe File not found
C:\Program Files\Grisoft\AVG7\avgamsvr.exe:*:Enabled:avgamsvr.exe File not found
C:\Program Files\Grisoft\AVG7\avgcc.exe:*:Enabled:avgcc.exe File not found
C:\Program Files\World of Warcraft\WoW-2.0.8.6403-to-2.0.10.6448-enUS-downloader.exe:*:Enabled:Blizzard Downloader File not found
C:\Program Files\World of Warcraft\WoW-2.0.3.6299-to-2.0.10.6448-enUS-downloader.exe:*:Enabled:Blizzard Downloader File not found
C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger (Microsoft Corporation)
C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1 (Microsoft Corporation)
C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) (Microsoft Corporation)
C:\Program Files\World of Warcraft\WoW-2.0.10.6448-to-2.0.12.6546-enUS-downloader.exe:*:Enabled:Blizzard Downloader File not found
C:\WINDOWS\system32\fxsclnt.exe:*:Disabled:Microsoft Fax Console (Microsoft Corporation)
C:\Program Files\World of Warcraft\BackgroundDownloader.exe:*:Enabled:Blizzard Downloader File not found
C:\Program Files\Warcraft III\Frozen Throne.exe:*:Enabled:Warcraft III - The Frozen Throne File not found
C:\Program Files\MostFun\Bin\MostFun.exe:*:Disabled:MostFun File not found
C:\Program Files\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III File not found
C:\Program Files\Microsoft Games\Halo Trial\halo.exe:*:Enabled:Halo File not found
C:\Program Files\Xfire\Xfire.exe:*:Enabled:Xfire File not found
C:\Program Files\THQ\DarkCrusade\DarkCrusade.exe:*:Enabled:DarkCrusade File not found
C:\Program Files\Warcraft III\War3.exe:*:Enabled:Warcraft III File not found
C:\Program Files\Tremulous\tremulous.exe:*:Enabled:tremulous File not found
C:\Program Files\TurboTax\Deluxe 2007\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax File not found
C:\Program Files\TurboTax\Deluxe 2007\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager File not found
C:\Program Files\Team17\Worms 2\Frontend.exe:*:Enabled:Worms 2 Frontend File not found
C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper (Microsoft Corporation)
C:\Program Files\Team17\Worms Armageddon\Landgen.exe:*:Enabled:Landgen File not found
C:\Program Files\Team17\Worms Armageddon\WA.exe:*:Enabled:Worms Armageddon File not found
C:\Program Files\Juniper Networks\Secure Application Manager\dsSamProxy.exe:*:Enabled:Secure Application Manager Proxy (Juniper Networks)
C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour (Apple Inc.)
C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes (Apple Inc.)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{178BAABD-0C95-4EB6-9E12-29A039EA27F6}" = Qwest eChat Support Tools
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{23E8D2D6-F7C8-4A35-816C-6C914EE0A601}" = Citrix Presentation Server Client - Web Only
"{26E1BFB0-E87E-4696-9F89-B467F01F81E5}" = Broadcom Management Programs
"{27DC856A-0916-4988-8198-8714DDD3183D}" = AGEIA PhysX v7.05.17
"{2BD2069A-A865-432A-86B8-1151BB0526CC}" = MostFun Game Player
"{318AB667-3230-41B5-A617-CB3BF748D371}" = iTunes
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3EE33958-7381-4E7B-A4F3-6E43098E9E9C}" = URL Assistant
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{49672EC2-171B-47B4-8CE7-50D7806360D7}" = Windows Live Sign-in Assistant
"{4998FF95-709A-430A-B104-92A009ABB848}" = QuickConnect
"{4CCD7A06-1C0E-4C6D-BBB9-1472A9685AF8}" = EZT
"{52D56C42-8C69-4882-A661-39695537C9CF}" = DellConnect
"{571700F0-DB9D-4B3A-B03D-35A14BB5939F}" = Windows Live Messenger
"{58762801-BA53-42B3-890B-C6B9CC8CFE26}" = QuickConnect
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.7
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{7DD9A065-2C86-4A9F-A5FF-796EC1B99DCA}" = AnswerWorks 4.0 Runtime - English
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{8A62A068-3FD6-495A-9F66-26FE94F32EC9}" = Rhapsody Player Engine
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver
"{8DC42D05-680B-41B0-8878-6C14D24602DB}" = QuickTime
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9579E862-5FC7-4337-B1CC-5E37451524C5}" = Motorola Driver Installation
"{9692FD03-6662-4E62-B08C-30DFF51651E1}" = Actiontec Gateway
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = ALPS Touch Pad Driver
"{A654A805-41D9-40C7-AA46-4AF04F044D61}" = Adobe® Photoshop® Album Starter Edition 3.2
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{BCE72AED-3332-4863-9567-C5DCB9052CA2}" = Netflix Movie Viewer
"{C5074CC4-0E26-4716-A307-960272A90040}" = QuickSet
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CEE2252C-4035-4B27-8EC6-0B085DD3A413}" = Dell Support 3.2.1
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{EC4455AB-F155-4CC1-A4C5-88F3777F9886}" = Apple Mobile Device Support
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"Adobe® Photoshop® Album Starter Edition 3.2" = Adobe® Photoshop® Album Starter Edition 3.2
"alotToolbar" = ALOT Toolbar
"AVG8Uninstall" = AVG Free 8.0
"Broadcom 802.11b Network Adapter" = Dell Wireless WLAN Card
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_14F100C3" = Conexant HDA D110 MDC V.92 Modem
"GameSpy Arcade" = GameSpy Arcade
"Google Updater" = Google Updater
"HijackThis" = HijackThis 2.0.2
"Juniper Network Connect 5.5.0" = Juniper Networks Network Connect 5.5.0
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Mozilla Firefox (3.0.5)" = Mozilla Firefox (3.0.5)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"Neoteris_Secure_Application_Manager" = Juniper Networks Secure Application Manager
"SearchAssist" = SearchAssist
"Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2
"Tibia_is1" = Tibia
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Wdf01007" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"winusb0100" = Microsoft WinUsb 1.0
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01007" = Microsoft User-Mode Driver Framework Feature Pack 1.7

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
"MS AntiSpyware 2009 5.7" = MS AntiSpyware 2009
"Neoteris_Host_Checker" = Juniper Networks Host Checker

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/4/2009 9:22:31 PM | Computer Name = DDRHQHC1 | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.2180, faulting
module unknown, version 0.0.0.0, fault address 0x09909382.

Error - 2/4/2009 9:23:33 PM | Computer Name = DDRHQHC1 | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.2180, faulting
module unknown, version 0.0.0.0, fault address 0x09909382.

Error - 2/4/2009 9:24:31 PM | Computer Name = DDRHQHC1 | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.2180, faulting
module unknown, version 0.0.0.0, fault address 0x09909382.

Error - 2/4/2009 9:25:31 PM | Computer Name = DDRHQHC1 | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.2180, faulting
module unknown, version 0.0.0.0, fault address 0x09909382.

Error - 2/4/2009 9:30:57 PM | Computer Name = DDRHQHC1 | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.2180, faulting
module unknown, version 0.0.0.0, fault address 0x09909382.

Error - 2/4/2009 9:31:19 PM | Computer Name = DDRHQHC1 | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.2180, faulting
module unknown, version 0.0.0.0, fault address 0x09909382.

Error - 2/4/2009 9:32:19 PM | Computer Name = DDRHQHC1 | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.2180, faulting
module unknown, version 0.0.0.0, fault address 0x09909382.

Error - 2/4/2009 9:33:21 PM | Computer Name = DDRHQHC1 | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.2180, faulting
module unknown, version 0.0.0.0, fault address 0x09909382.

Error - 2/4/2009 9:34:20 PM | Computer Name = DDRHQHC1 | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.2180, faulting
module unknown, version 0.0.0.0, fault address 0x09909382.

Error - 2/4/2009 9:35:19 PM | Computer Name = DDRHQHC1 | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 5.1.2600.2180, faulting
module unknown, version 0.0.0.0, fault address 0x09909382.

[ System Events ]
Error - 2/4/2009 11:03:18 AM | Computer Name = DDRHQHC1 | Source = Srv | ID = 2019
Description = The server was unable to allocate from the system nonpaged pool because
the pool was empty.

Error - 2/4/2009 2:15:57 PM | Computer Name = DDRHQHC1 | Source = Service Control Manager | ID = 7000
Description = The Zune Bus Enumerator Driver service failed to start due to the
following error: %%2

Error - 2/4/2009 2:16:06 PM | Computer Name = DDRHQHC1 | Source = NetBT | ID = 4307
Description = Initialization failed because the transport refused to open initial
Addresses.

Error - 2/4/2009 2:17:39 PM | Computer Name = DDRHQHC1 | Source = Service Control Manager | ID = 7000
Description = The Zune Bus Enumerator Driver service failed to start due to the
following error: %%2

Error - 2/4/2009 2:17:52 PM | Computer Name = DDRHQHC1 | Source = NetBT | ID = 4307
Description = Initialization failed because the transport refused to open initial
Addresses.

Error - 2/4/2009 2:22:36 PM | Computer Name = DDRHQHC1 | Source = Service Control Manager | ID = 7023
Description = The Computer Browser service terminated with the following error:
%%1460

Error - 2/4/2009 9:00:46 PM | Computer Name = DDRHQHC1 | Source = Service Control Manager | ID = 7000
Description = The Zune Bus Enumerator Driver service failed to start due to the
following error: %%2

Error - 2/4/2009 9:05:42 PM | Computer Name = DDRHQHC1 | Source = Service Control Manager | ID = 7023
Description = The Computer Browser service terminated with the following error:
%%1460

Error - 2/4/2009 9:26:31 PM | Computer Name = DDRHQHC1 | Source = Service Control Manager | ID = 7000
Description = The Zune Bus Enumerator Driver service failed to start due to the
following error: %%2

Error - 2/4/2009 9:31:27 PM | Computer Name = DDRHQHC1 | Source = Service Control Manager | ID = 7023
Description = The Computer Browser service terminated with the following error:
%%1460


< End of report >
Also here is another HJ, just in case it helps.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:38:51 PM, on 2/4/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\svchost.exe
C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\msas2009.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\services.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Bret\Desktop\OTListIt22.exe
C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=3070206
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=3070206
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O3 - Toolbar: ALOT Toolbar - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [services] C:\WINDOWS\services.exe
O4 - HKLM\..\Run: [jsf8uiw3jnjgffght] C:\WINDOWS\TEMP\winlognn.exe
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [jsf8uiw3jnjgffght] C:\WINDOWS\TEMP\winlognn.exe
O4 - HKCU\..\Run: [tezrtsjhfr84iusjfo84f] C:\DOCUME~1\Bret\LOCALS~1\Temp\csrssc.exe
O4 - HKCU\..\Run: [services] C:\WINDOWS\services.exe
O4 - HKCU\..\Run: [MS AntiSpyware 2009] "C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\msas2009.exe" /autorun
O4 - HKLM\..\Policies\Explorer\Run: [services] C:\WINDOWS\services.exe
O4 - HKCU\..\Policies\Explorer\Run: [services] C:\WINDOWS\services.exe
O4 - HKUS\S-1-5-18\..\Run: [tezrtsjhfr84iusjfo84f] C:\WINDOWS\TEMP\csrssc.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [services] C:\WINDOWS\services.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [services] C:\WINDOWS\services.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [tezrtsjhfr84iusjfo84f] C:\WINDOWS\TEMP\csrssc.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [services] C:\WINDOWS\services.exe (User 'Default user')
O4 - Startup: ClearPlay Easy Updates.lnk = C:\Program Files\ClearPlay\ClearPlay Easy Updates\ClearPlayEasyUpdates.exe
O4 - Startup: MostFun.lnk = C:\Program Files\MostFun\Bin\MostFun.exe
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-_UNO/GAME_UNO1.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://www.gamehouse.com/games/SproutLauncher.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O22 - SharedTaskScheduler: jgzfkj9w38rksndfi7r4 - {C5BF49A2-94F3-42BD-F434-3604812C8955} - (no file)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
O23 - Service: GoogleDesktopManager - Unknown owner - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 9253 bytes
hello

Run OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :Processes
    explorer.exe
    
    :OTLI
    DRV - (efpnolmo [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\efpnolmo.sys ()
    DRV - (egnpsmiu [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\egnpsmiu.sys ()
    DRV - (ethbotjf [System | Stopped]) – C:\WINDOWS\system32\drivers\ethbotjf.sys ()
    DRV - (ethegmgt [System | Stopped]) – C:\WINDOWS\system32\drivers\ethegmgt.sys ()
    DRV - (etherhmk [System | Stopped]) – C:\WINDOWS\system32\drivers\etherhmk.sys ()
    DRV - (ethfbqvx [System | Stopped]) – C:\WINDOWS\system32\drivers\ethfbqvx.sys ()
    DRV - (ethimbtt [System | Stopped]) – C:\WINDOWS\system32\drivers\ethimbtt.sys ()
    DRV - (ethjenqu [System | Stopped]) – C:\WINDOWS\system32\drivers\ethjenqu.sys ()
    DRV - (ethnwqjl [System | Stopped]) – C:\WINDOWS\system32\drivers\ethnwqjl.sys ()
    DRV - (ethpdprv [System | Stopped]) – C:\WINDOWS\system32\drivers\ethpdprv.sys ()
    DRV - (ethqovij [System | Stopped]) – C:\WINDOWS\system32\drivers\ethqovij.sys ()
    DRV - (ethqsyoe [System | Stopped]) – C:\WINDOWS\system32\drivers\ethqsyoe.sys ()
    DRV - (ethrnqxg [System | Stopped]) – C:\WINDOWS\system32\drivers\ethrnqxg.sys ()
    DRV - (ethrsxjj [System | Stopped]) – C:\WINDOWS\system32\drivers\ethrsxjj.sys ()
    DRV - (ethtgprm [System | Stopped]) – C:\WINDOWS\system32\drivers\ethtgprm.sys ()
    DRV - (ethxkdvi [System | Stopped]) – C:\WINDOWS\system32\drivers\ethxkdvi.sys ()
    O3 - HKLM\..\Toolbar: (ALOT Toolbar) - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll (Miva)
    O4 - HKLM..\Run: [jsf8uiw3jnjgffght] C:\WINDOWS\TEMP\winlognn.exe File not found
    O4 - HKLM..\Run: [services] C:\WINDOWS\services.exe (XRAVJE Corporation)
    O4 - HKCU..\Run: [jsf8uiw3jnjgffght] C:\WINDOWS\TEMP\winlognn.exe File not found
    O4 - HKCU..\Run: [MS AntiSpyware 2009] "C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\msas2009.exe" /autorun ()
    O4 - HKCU..\Run: [services] C:\WINDOWS\services.exe (XRAVJE Corporation)
    O4 - HKCU..\Run: [tezrtsjhfr84iusjfo84f] C:\DOCUME~1\Bret\LOCALS~1\Temp\csrssc.exe ()
    O4 - HKCU..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe" File not found
    O22 - SharedTaskScheduler: {C5BF49A2-94F3-42BD-F434-3604812C8955} - jgzfkj9w38rksndfi7r4 - Reg Error: Key does not exist or could not be opened. File not found
    O33 - MountPoints2\{643e37d2-c42a-11db-b99b-001a9248dca8}\Shell\AutoRun\command - "" = E:\setupSNK.exe – File not found
    O33 - MountPoints2\{e96a4e98-f88e-11dc-bcb3-001a9248dca8}\Shell\AutoRun\command - "" = E:\LaunchU3.exe – File not found
    [2009/02/04 18:27:13 | 00,000,695 | —- | C] () – C:\WINDOWS\System32\netsf_m.inf
    [2009/02/04 18:27:12 | 00,001,748 | —- | C] () – C:\WINDOWS\System32\netsf.inf
    [2009/02/04 18:27:10 | 00,040,448 | —- | C] () – C:\WINDOWS\Snakefedahe.dll
    [2009/02/03 23:31:51 | 00,000,005 | —- | C] () – C:\WINDOWS\_id.dat
    [2009/02/03 23:31:45 | 00,000,128 | —- | C] () – C:\WINDOWS\adobe.bat
    [2009/02/03 23:05:11 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\ethxkdvi.sys
    [2009/02/03 23:05:09 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\ethtgprm.sys
    [2009/02/03 23:05:07 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\ethrsxjj.sys
    [2009/02/03 23:05:05 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\ethrnqxg.sys
    [2009/02/03 23:05:03 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\ethqsyoe.sys
    [2009/02/03 23:05:01 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\ethqovij.sys
    [2009/02/03 23:04:59 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\ethpdprv.sys
    [2009/02/03 23:04:57 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\ethnwqjl.sys
    [2009/02/03 23:04:55 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\ethjenqu.sys
    [2009/02/03 23:04:53 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\ethimbtt.sys
    [2009/02/03 23:04:51 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\ethfbqvx.sys
    [2009/02/03 23:04:49 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\etherhmk.sys
    [2009/02/03 23:04:47 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\ethegmgt.sys
    [2009/02/03 23:04:45 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\ethbotjf.sys
    [2009/02/03 23:04:43 | 00,137,280 | —- | C] () – C:\WINDOWS\System32\drivers\egnpsmiu.sys
    [2009/02/03 23:04:41 | 00,137,280 | —- | C] () – C:\WINDOWS\System32\drivers\efpnolmo.sys
    [2009/02/03 21:53:32 | 00,033,920 | —- | C] () – C:\WINDOWS\System32\drivers\tsdtagpg.sys
    [2009/02/02 22:38:08 | 00,015,000 | —- | C] () – C:\WINDOWS\System32\_hnsf983ind.dll
    [2009/02/02 22:21:31 | 00,037,888 | —- | C] (XRAVJE Corporation) – C:\WINDOWS\services.exe
    [2009/02/02 22:18:49 | 00,040,448 | —- | C] () – C:\WINDOWS\kernel32.exe
    [2009/02/02 22:18:00 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd
    
    :Services
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL2 log ( don't check the boxes beside LOP Check or Purity this time )
Hello

Um… I've let OTListIt2 run for over 2 hours and It looks like it's not responding anymore. Stuck on "Stopping Process explorer.exe…"

I also just tried running it in Safe Mode but it still end up saying it's "Not Responding"

Here is a new Hijack log and OTL2 log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:14:19 PM, on 2/5/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\msas2009.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\services.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Bret\Desktop\OTListIt22.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\E.tmp
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=3070206
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=3070206
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\pdbcopy.exe,C:\WINDOWS\system32\gcc.exe,C:\WINDOWS\system32\actcontroller.exe,
O3 - Toolbar: ALOT Toolbar - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [services] C:\WINDOWS\services.exe
O4 - HKLM\..\Run: [jsf8uiw3jnjgffght] C:\WINDOWS\TEMP\winlognn.exe
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [jsf8uiw3jnjgffght] C:\WINDOWS\TEMP\winlognn.exe
O4 - HKCU\..\Run: [tezrtsjhfr84iusjfo84f] C:\DOCUME~1\Bret\LOCALS~1\Temp\csrssc.exe
O4 - HKCU\..\Run: [services] C:\WINDOWS\services.exe
O4 - HKCU\..\Run: [MS AntiSpyware 2009] "C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\msas2009.exe" /autorun
O4 - HKLM\..\Policies\Explorer\Run: [services] C:\WINDOWS\services.exe
O4 - HKCU\..\Policies\Explorer\Run: [services] C:\WINDOWS\services.exe
O4 - HKUS\S-1-5-18\..\Run: [tezrtsjhfr84iusjfo84f] C:\WINDOWS\TEMP\csrssc.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [services] C:\WINDOWS\services.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [nttakbit.exe] C:\WINDOWS\nttakbit.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [services] C:\WINDOWS\services.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [tezrtsjhfr84iusjfo84f] C:\WINDOWS\TEMP\csrssc.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [services] C:\WINDOWS\services.exe (User 'Default user')
O4 - Startup: ClearPlay Easy Updates.lnk = C:\Program Files\ClearPlay\ClearPlay Easy Updates\ClearPlayEasyUpdates.exe
O4 - Startup: MostFun.lnk = C:\Program Files\MostFun\Bin\MostFun.exe
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\Xfire.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-_UNO/GAME_UNO1.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://www.gamehouse.com/games/SproutLauncher.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O22 - SharedTaskScheduler: jgzfkj9w38rksndfi7r4 - {C5BF49A2-94F3-42BD-F434-3604812C8955} - (no file)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
O23 - Service: GoogleDesktopManager - Unknown owner - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 9429 bytes






OTListIt logfile created on: 2/5/2009 12:06:38 PM - Run 7
OTListIt2 by OldTimer - Version 2.0.0.5 Folder = C:\Documents and Settings\Bret\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1014.37 Mb Total Physical Memory | 542.86 Mb Available Physical Memory | 53.52% Memory free
1.63 Gb Paging File | 1.18 Gb Available in Paging File | 72.26% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.83 Gb Total Space | 17.45 Gb Free Space | 31.26% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DDRHQHC1
Current User Name: Bret
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

C:\WINDOWS\system32\WLTRYSVC.EXE ()
C:\WINDOWS\system32\BCMWLTRY.EXE (Dell Inc.)
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe (Juniper Networks)
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
C:\Program Files\Dell\QuickSet\NicConfigSvc.exe (Dell Inc.)
C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe (Sun Microsystems, Inc.)
C:\WINDOWS\system32\WLTRAY.EXE (Dell Inc.)
C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe (CyberLink Corp.)
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe (Adobe Systems Incorporated)
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
C:\WINDOWS\system32\igfxsrvc.exe (Intel Corporation)
C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
C:\Program Files\NetWaiting\netwaiting.exe ()
C:\Program Files\Dell Support\DSAgnt.exe (Gteko Ltd.)
C:\Program Files\Apoint\hidfind.exe (Alps Electric Co., Ltd.)
C:\Program Files\MSN Messenger\msnmsgr.exe (Microsoft Corporation)
C:\Program Files\Apoint\ApntEx.exe (Alps Electric Co., Ltd.)
C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\msas2009.exe ()
C:\WINDOWS\system32\cmd.exe (Microsoft Corporation)
C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
C:\WINDOWS\services.exe ()
C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
C:\WINDOWS\system32\wuauclt.exe (Microsoft Corporation)
C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
C:\WINDOWS\system32\wuauclt.exe (Microsoft Corporation)
C:\Program Files\AVG\AVG8\avgupd.exe (AVG Technologies CZ, s.r.o.)
C:\Documents and Settings\Bret\Desktop\OTListIt22.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (avg8emc [Auto | Running]) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd [Auto | Running]) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (dsNcService [Auto | Running]) – C:\Program Files\Juniper Networks\Common Files\dsNcService.exe (Juniper Networks)
SRV - (GoogleDesktopManager [On_Demand | Stopped]) – File not found
SRV - (gusvc [Auto | Running]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll (Microsoft Corporation)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (NICCONFIGSVC [Auto | Running]) – C:\Program Files\Dell\QuickSet\NicConfigSvc.exe (Dell Inc.)
SRV - (usnjsvc [On_Demand | Stopped]) – C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (wltrysvc [Auto | Running]) – C:\WINDOWS\system32\WLTRYSVC.EXE ()
SRV - (WMPNetworkSvc [Auto | Running]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (WudfSvc [Auto | Running]) – C:\WINDOWS\system32\WudfSvc.dll (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (AliIde [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\AMDAGP.SYS (Advanced Micro Devices, Inc.)
DRV - (ApfiltrService [On_Demand | Running]) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (APPDRV [System | Running]) – C:\WINDOWS\system32\drivers\APPDRV.SYS (Dell Inc)
DRV - (asc [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\asc3550.sys (Advanced System Products, Inc.)
DRV - (AvgLdx86 [System | Running]) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (BCM43XX [On_Demand | Running]) – C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corporation)
DRV - (bcm4sbxp [On_Demand | Running]) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (CmdIde [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (dac2w2k [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\dac2w2k.sys (Mylex Corporation)
DRV - (dsNcAdpt [On_Demand | Running]) – C:\WINDOWS\system32\drivers\dsNcAdpt.sys (Juniper Networks)
DRV - (DSproct [On_Demand | Running]) – C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys (GTek Technologies Ltd.)
DRV - (E100B [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\e100b325.sys (Intel Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HDAudBus [On_Demand | Running]) – C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (HSF_DPV [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (ialm [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ialmnt5.sys (Intel Corporation)
DRV - (mdmxsdk [Auto | Running]) – C:\WINDOWS\system32\drivers\mdmxsdk.sys (Conexant)
DRV - (motmodem [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\motmodem.sys (Motorola)
DRV - (mraid35x [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\mraid35x.sys (American Megatrends Inc.)
DRV - (NEOFLTR_550_11965 [System | Running]) – C:\WINDOWS\system32\drivers\NEOFLTR_550_11965.sys (Juniper Networks)
DRV - (NEOFLTR_620_13525 [System | Running]) – C:\WINDOWS\system32\drivers\NEOFLTR_620_13525.sys (Juniper Networks)
DRV - (nv [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (Passthru [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ndisio.sys ()
DRV - (protect [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\protect.sys ()
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (ql1080 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\ql1080.sys (QLogic Corporation)
DRV - (ql12160 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\ql12160.sys (QLogic Corporation)
DRV - (ql1280 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\ql1280.sys (QLogic Corporation)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sisagp [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\SISAGP.SYS (Silicon Integrated Systems Corporation)
DRV - (Sparrow [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\sparrow.sys (Adaptec, Inc.)
DRV - (STHDA [On_Demand | Running]) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (symc810 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\symc810.sys (Symbios Logic Inc.)
DRV - (symc8xx [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (sym_hi [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (sym_u3 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (ultra [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\ultra.sys (Promise Technology, Inc.)
DRV - (USBAAPL [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\usbaapl.sys (Apple, Inc.)
DRV - (Wdf01000 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wdf01000.sys (Microsoft Corporation)
DRV - (winachsf [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (WinUSB [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\winusb.sys (Microsoft Corporation)
DRV - (WmiAcpi [System | Running]) – C:\WINDOWS\system32\drivers\wmiacpi.sys (Microsoft Corporation)

========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=3070206
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=3070206

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=3070206
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 ZieF.pl
O1 - Hosts: 127.0.0.1 localhost
O3 - HKLM\..\Toolbar: (&Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKLM\..\Toolbar: (ALOT Toolbar) - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll (Miva)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O4 - HKLM..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe (Dell Inc.)
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
O4 - HKLM..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [jsf8uiw3jnjgffght] C:\WINDOWS\TEMP\winlognn.exe File not found
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [services] C:\WINDOWS\services.exe ()
O4 - HKLM..\Run: [SigmatelSysTrayApp] stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup (Gteko Ltd.)
O4 - HKCU..\Run: [jsf8uiw3jnjgffght] C:\WINDOWS\TEMP\winlognn.exe File not found
O4 - HKCU..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe ()
O4 - HKCU..\Run: [MS AntiSpyware 2009] "C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\msas2009.exe" /autorun ()
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [services] C:\WINDOWS\services.exe ()
O4 - HKCU..\Run: [tezrtsjhfr84iusjfo84f] C:\DOCUME~1\Bret\LOCALS~1\Temp\csrssc.exe ()
O4 - HKCU..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe" File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
O4 - Startup: C:\Documents and Settings\Bret\Start Menu\Programs\Startup\ClearPlay Easy Updates.lnk = C:\Program Files\ClearPlay\ClearPlay Easy Updates\ClearPlayEasyUpdates.exe File not found
O4 - Startup: C:\Documents and Settings\Bret\Start Menu\Programs\Startup\MostFun.lnk = C:\Program Files\MostFun\Bin\MostFun.exe File not found
O4 - Startup: C:\Documents and Settings\Bret\Start Menu\Programs\Startup\Xfire.lnk = C:\Program Files\Xfire\Xfire.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\NPJPI150_06.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [NTDS] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [Juniper Secure DNS (Top)] - C:\Program Files\Juniper Networks\Secure Application Manager\samnsp.dll (Juniper Networks)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [Tcpip] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [Network Location Awareness (NLA) Namespace] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [Juniper Secure DNS (Bottom)] - C:\Program Files\Juniper Networks\Secure Application Manager\samnsp.dll (Juniper Networks)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/EN-US/a-_UNO/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key does not exist or could not be opened.)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} http://www.gamehouse.com/games/SproutLauncher.cab (SproutLauncherCtrl Class)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://www.popcap.com/games/popcaploader_v6.cab (PopCapLoader Object)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab (Minesweeper Flags Class)
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/octet-stream - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-complus - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-msdownload - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - Class Install Handler - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - deflate - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - gzip - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - lzdhtml - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/webviewhtml - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\pdbcopy.exe) - C:\WINDOWS\system32\pdbcopy.exe ()
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\gcc.exe) - C:\WINDOWS\system32\gcc.exe ()
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\system32\logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\system32\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\system32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\system32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\system32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\system32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\system32\WgaLogon.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {C5BF49A2-94F3-42BD-F434-3604812C8955} - jgzfkj9w38rksndfi7r4 - Reg Error: Key does not exist or could not be opened. File not found
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O27 - HKLM IFEO\Your Image File Name Here without a path: Debugger - C:\WINDOWS\system32\ntsd.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\system32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - ( schannel.dll) - C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - ( digest.dll) - C:\WINDOWS\system32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - ( msnsspc.dll) - C:\WINDOWS\system32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\system32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\system32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\system32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\system32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O33 - MountPoints2\{643e37d2-c42a-11db-b99b-001a9248dca8}\Shell\AutoRun\command - "" = E:\setupSNK.exe – File not found
O33 - MountPoints2\{e96a4e98-f88e-11dc-bcb3-001a9248dca8}\Shell - "" = AutoRun
O33 - MountPoints2\{e96a4e98-f88e-11dc-bcb3-001a9248dca8}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{e96a4e98-f88e-11dc-bcb3-001a9248dca8}\Shell\AutoRun\command - "" = E:\LaunchU3.exe – File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/02/05 12:07:33 | 00,046,080 | —- | C] () – C:\WINDOWS\System32\actcontroller.exe
[2009/02/05 12:06:45 | 00,046,080 | —- | C] () – C:\WINDOWS\System32\gcc.exe
[2009/02/05 12:06:42 | 00,003,584 | —- | C] () – C:\WINDOWS\nttakbit.exe
[2009/02/05 12:04:39 | 10,637,14816 | -HS- | C] () – C:\hiberfil.sys
[2009/02/05 11:57:23 | 00,018,944 | -H– | C] () – C:\WINDOWS\System32\drivers\protect.sys
[2009/02/05 11:53:38 | 00,005,715 | —- | C] () – C:\Documents and Settings\Bret\Desktop\Document.rtf
[2009/02/05 08:54:47 | 00,000,000 | —D | C] – C:\_OTListIt
[2009/02/05 08:52:19 | 00,064,512 | —- | C] () – C:\WINDOWS\System32\pdbcopy.exe
[2009/02/05 08:52:18 | 00,038,400 | —- | C] () – C:\WINDOWS\System32\mlJCRKeE.dll
[2009/02/04 18:29:42 | 00,506,368 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Bret\Desktop\OTListIt22.exe
[2009/02/04 18:27:13 | 00,000,695 | —- | C] () – C:\WINDOWS\System32\netsf_m.inf
[2009/02/04 18:27:12 | 00,001,748 | —- | C] () – C:\WINDOWS\System32\netsf.inf
[2009/02/03 23:47:36 | 00,001,323 | —- | C] () – C:\Documents and Settings\Bret\Desktop\HijackThis.lnk
[2009/02/03 23:47:20 | 00,000,000 | —D | C] – C:\HJT
[2009/02/03 23:47:01 | 00,812,344 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Bret\Desktop\HJTsetup.exe
[2009/02/03 23:31:51 | 00,000,005 | —- | C] () – C:\WINDOWS\_id.dat
[2009/02/03 23:31:45 | 00,000,128 | —- | C] () – C:\WINDOWS\adobe.bat
[2009/02/03 21:18:29 | 00,066,560 | -H– | C] () – C:\WINDOWS\System32\secupdat.dat
[2009/02/03 16:20:56 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\drivers\ndisio.sys
[2009/02/02 22:38:08 | 00,015,000 | —- | C] () – C:\WINDOWS\System32\_hnsf983ind.dll
[2009/02/02 22:21:31 | 00,040,961 | —- | C] () – C:\WINDOWS\services.exe
[2009/02/02 22:18:49 | 00,040,448 | —- | C] () – C:\WINDOWS\kernel32.exe
[2009/02/02 22:18:00 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd
[2009/01/18 12:28:08 | 00,000,000 | -HSD | C] – C:\Config.Msi
[2009/01/09 21:15:35 | 00,000,000 | —D | C] – C:\Documents and Settings\Bret\Local Settings\Application Data\WMTools Downloaded Files
[2009/01/09 09:02:57 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Juniper Networks

========== Files - Modified Within 30 Days ==========

[24 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[2009/02/05 12:08:52 | 00,479,920 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/02/05 12:08:52 | 00,408,238 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/02/05 12:08:52 | 00,064,602 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/02/05 12:07:33 | 00,046,080 | —- | M] () – C:\WINDOWS\System32\actcontroller.exe
[2009/02/05 12:06:45 | 00,046,080 | —- | M] () – C:\WINDOWS\System32\gcc.exe
[2009/02/05 12:06:42 | 00,003,584 | —- | M] () – C:\WINDOWS\nttakbit.exe
[2009/02/05 12:06:32 | 32,820,251 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/02/05 12:06:32 | 00,086,834 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/02/05 12:05:15 | 00,000,128 | —- | M] () – C:\WINDOWS\adobe.bat
[2009/02/05 12:04:59 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/02/05 12:04:41 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/02/05 12:04:40 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/02/05 12:04:39 | 10,637,14816 | -HS- | M] () – C:\hiberfil.sys
[2009/02/05 12:03:53 | 03,184,656 | -H– | M] () – C:\Documents and Settings\Bret\Local Settings\Application Data\IconCache.db
[2009/02/05 11:57:24 | 00,018,944 | -H– | M] () – C:\WINDOWS\System32\drivers\protect.sys
[2009/02/05 11:53:58 | 00,000,232 | -H– | M] () – C:\sqmdata05.sqm
[2009/02/05 11:53:57 | 00,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2009/02/05 11:53:38 | 00,005,715 | —- | M] () – C:\Documents and Settings\Bret\Desktop\Document.rtf
[2009/02/05 08:52:20 | 00,040,961 | —- | M] () – C:\WINDOWS\services.exe
[2009/02/05 08:52:19 | 00,064,512 | —- | M] () – C:\WINDOWS\System32\pdbcopy.exe
[2009/02/05 08:52:18 | 00,038,400 | —- | M] () – C:\WINDOWS\System32\mlJCRKeE.dll
[2009/02/04 21:23:43 | 00,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2009/02/04 21:23:43 | 00,000,232 | -H– | M] () – C:\sqmdata04.sqm
[2009/02/04 20:32:18 | 00,053,248 | —- | M] () – C:\WINDOWS\System32\drivers\ndisio.sys
[2009/02/04 20:32:15 | 00,000,695 | —- | M] () – C:\WINDOWS\System32\netsf_m.inf
[2009/02/04 20:32:13 | 00,001,748 | —- | M] () – C:\WINDOWS\System32\netsf.inf
[2009/02/04 20:29:53 | 00,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2009/02/04 20:29:53 | 00,000,232 | -H– | M] () – C:\sqmdata03.sqm
[2009/02/04 18:29:55 | 00,506,368 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Bret\Desktop\OTListIt22.exe
[2009/02/04 18:20:16 | 00,000,005 | —- | M] () – C:\WINDOWS\_id.dat
[2009/02/03 23:47:36 | 00,001,323 | —- | M] () – C:\Documents and Settings\Bret\Desktop\HijackThis.lnk
[2009/02/03 23:47:01 | 00,812,344 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Bret\Desktop\HJTsetup.exe
[2009/02/03 21:20:45 | 00,066,560 | -H– | M] () – C:\WINDOWS\System32\secupdat.dat
[2009/02/02 23:36:36 | 00,000,561 | —- | M] () – C:\Documents and Settings\Bret\My Documents\My Sharing Folders.lnk
[2009/02/02 22:38:08 | 00,015,000 | —- | M] () – C:\WINDOWS\System32\_hnsf983ind.dll
[2009/02/02 22:18:51 | 00,040,448 | —- | M] () – C:\WINDOWS\kernel32.exe
[2009/02/01 00:19:52 | 00,000,268 | -H– | M] () – C:\sqmdata02.sqm
[2009/02/01 00:19:52 | 00,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2009/01/31 17:55:16 | 00,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/01/31 09:31:33 | 00,010,520 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/01/31 09:31:32 | 00,325,128 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/01/31 09:31:32 | 00,027,656 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/01/31 09:31:29 | 00,107,272 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/01/29 23:14:42 | 00,000,268 | -H– | M] () – C:\sqmdata01.sqm
[2009/01/29 23:14:42 | 00,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2009/01/29 23:14:31 | 00,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2009/01/29 23:14:31 | 00,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2009/01/25 22:59:02 | 00,000,268 | -H– | M] () – C:\sqmdata19.sqm
[2009/01/25 22:59:02 | 00,000,244 | -H– | M] () – C:\sqmnoopt19.sqm
[2009/01/25 15:01:09 | 00,000,268 | -H– | M] () – C:\sqmdata18.sqm
[2009/01/25 15:01:08 | 00,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2009/01/23 00:00:43 | 00,000,268 | -H– | M] () – C:\sqmdata17.sqm
[2009/01/23 00:00:43 | 00,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2009/01/20 16:49:09 | 00,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2009/01/20 16:49:09 | 00,000,232 | -H– | M] () – C:\sqmdata16.sqm
[2009/01/20 10:05:44 | 00,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2009/01/20 10:05:44 | 00,000,232 | -H– | M] () – C:\sqmdata15.sqm
[2009/01/18 23:13:12 | 00,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2009/01/18 23:13:12 | 00,000,232 | -H– | M] () – C:\sqmdata14.sqm
[2009/01/18 16:36:34 | 00,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2009/01/18 16:36:34 | 00,000,232 | -H– | M] () – C:\sqmdata13.sqm
[2009/01/18 12:40:42 | 00,010,752 | —- | M] () – C:\Documents and Settings\Bret\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/01/17 18:08:19 | 00,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2009/01/17 18:08:19 | 00,000,232 | -H– | M] () – C:\sqmdata12.sqm
[2009/01/17 02:28:11 | 00,000,268 | -H– | M] () – C:\sqmdata11.sqm
[2009/01/17 02:28:11 | 00,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2009/01/16 18:29:03 | 00,000,268 | -H– | M] () – C:\sqmdata10.sqm
[2009/01/16 18:29:03 | 00,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2009/01/16 18:28:52 | 00,000,268 | -H– | M] () – C:\sqmdata09.sqm
[2009/01/16 18:28:52 | 00,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2009/01/16 02:25:10 | 00,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2009/01/16 02:25:10 | 00,000,232 | -H– | M] () – C:\sqmdata08.sqm
[2009/01/15 15:00:15 | 00,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2009/01/15 15:00:15 | 00,000,232 | -H– | M] () – C:\sqmdata07.sqm
[2009/01/15 02:03:12 | 00,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2009/01/15 02:03:12 | 00,000,232 | -H– | M] () – C:\sqmdata06.sqm
[2009/01/14 11:14:03 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job

========== LOP Check ==========

[2009/02/02 22:18:00 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/12/21 15:28:05 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2008/03/29 16:54:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2008/01/22 21:15:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2008/10/27 18:12:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2008/08/17 15:23:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG7
[2009/02/03 21:42:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg8
[2009/02/02 22:18:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd
[2007/07/20 16:07:37 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GameHouse
[2009/01/06 18:39:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2009/02/05 09:02:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google Updater
[2007/02/16 08:35:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2007/02/06 19:29:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GTek
[2008/04/07 18:58:46 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intuit
[2009/01/09 09:03:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Juniper Networks
[2008/08/23 10:57:26 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2007/06/04 10:53:40 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MostFun
[2007/07/20 13:17:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2004/08/10 12:13:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2007/03/20 15:06:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/12/16 19:51:00 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Bret\Application Data
[2007/12/09 22:00:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\Adobe
[2008/03/24 14:56:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\alot
[2008/10/27 19:20:12 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\Apple Computer
[2008/04/15 16:56:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\ClearPlay Inc
[2007/02/25 18:15:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\CyberLink
[2008/04/01 21:25:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\Google
[2007/02/06 19:29:31 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Bret\Application Data\Gtek
[2007/02/25 20:21:30 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\Help
[2008/04/21 20:03:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\ICAClient
[2004/08/10 12:08:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\Identities
[2007/04/13 22:02:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\InstallShield
[2008/04/21 20:17:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\Juniper Networks
[2007/12/28 18:19:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\Leadertech
[2007/05/05 20:33:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\LimeWire Music
[2007/04/25 09:07:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\Macromedia
[2007/04/16 20:21:55 | 00,000,000 | –SD | M] – C:\Documents and Settings\Bret\Application Data\Microsoft
[2008/01/27 21:57:43 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Bret\Application Data\Move Networks
[2008/08/17 13:41:57 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\Mozilla
[2007/02/18 15:28:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\Sun
[2007/04/22 09:03:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\Talkback
[2008/12/16 21:12:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\Tibia
[2008/01/08 21:18:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\Xfire
[2007/06/10 08:56:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\yoclient
[2009/01/14 11:14:03 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2004/08/04 04:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/02/05 12:04:41 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 263749 bytes -> %SystemRoot%\Temp:temp
< End of report >
Do this please


Run OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTLI
    DRV - (efpnolmo [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\efpnolmo.sys ()
    DRV - (egnpsmiu [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\egnpsmiu.sys ()
    DRV - (ethbotjf [System | Stopped]) – C:\WINDOWS\system32\drivers\ethbotjf.sys ()
    DRV - (ethegmgt [System | Stopped]) – C:\WINDOWS\system32\drivers\ethegmgt.sys ()
    DRV - (etherhmk [System | Stopped]) – C:\WINDOWS\system32\drivers\etherhmk.sys ()
    DRV - (ethfbqvx [System | Stopped]) – C:\WINDOWS\system32\drivers\ethfbqvx.sys ()
    DRV - (ethimbtt [System | Stopped]) – C:\WINDOWS\system32\drivers\ethimbtt.sys ()
    DRV - (ethjenqu [System | Stopped]) – C:\WINDOWS\system32\drivers\ethjenqu.sys ()
    DRV - (ethnwqjl [System | Stopped]) – C:\WINDOWS\system32\drivers\ethnwqjl.sys ()
    DRV - (ethpdprv [System | Stopped]) – C:\WINDOWS\system32\drivers\ethpdprv.sys ()
    DRV - (ethqovij [System | Stopped]) – C:\WINDOWS\system32\drivers\ethqovij.sys ()
    DRV - (ethqsyoe [System | Stopped]) – C:\WINDOWS\system32\drivers\ethqsyoe.sys ()
    DRV - (ethrnqxg [System | Stopped]) – C:\WINDOWS\system32\drivers\ethrnqxg.sys ()
    DRV - (ethrsxjj [System | Stopped]) – C:\WINDOWS\system32\drivers\ethrsxjj.sys ()
    DRV - (ethtgprm [System | Stopped]) – C:\WINDOWS\system32\drivers\ethtgprm.sys ()
    DRV - (ethxkdvi [System | Stopped]) – C:\WINDOWS\system32\drivers\ethxkdvi.sys ()
    O3 - HKLM\..\Toolbar: (ALOT Toolbar) - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll (Miva)
    O4 - HKLM..\Run: [jsf8uiw3jnjgffght] C:\WINDOWS\TEMP\winlognn.exe File not found
    O4 - HKLM..\Run: [services] C:\WINDOWS\services.exe (XRAVJE Corporation)
    O4 - HKCU..\Run: [jsf8uiw3jnjgffght] C:\WINDOWS\TEMP\winlognn.exe File not found
    O4 - HKCU..\Run: [MS AntiSpyware 2009] "C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\msas2009.exe" /autorun ()
    O4 - HKCU..\Run: [services] C:\WINDOWS\services.exe (XRAVJE Corporation)
    O4 - HKCU..\Run: [tezrtsjhfr84iusjfo84f] C:\DOCUME~1\Bret\LOCALS~1\Temp\csrssc.exe ()
    O4 - HKCU..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe" File not found
    O22 - SharedTaskScheduler: {C5BF49A2-94F3-42BD-F434-3604812C8955} - jgzfkj9w38rksndfi7r4 - Reg Error: Key does not exist or could not be opened. File not found
    O33 - MountPoints2\{643e37d2-c42a-11db-b99b-001a9248dca8}\Shell\AutoRun\command - "" = E:\setupSNK.exe – File not found
    O33 - MountPoints2\{e96a4e98-f88e-11dc-bcb3-001a9248dca8}\Shell\AutoRun\command - "" = E:\LaunchU3.exe – File not found
    [2009/02/04 18:27:13 | 00,000,695 | —- | C] () – C:\WINDOWS\System32\netsf_m.inf
    [2009/02/04 18:27:12 | 00,001,748 | —- | C] () – C:\WINDOWS\System32\netsf.inf
    [2009/02/04 18:27:10 | 00,040,448 | —- | C] () – C:\WINDOWS\Snakefedahe.dll
    [2009/02/03 23:31:51 | 00,000,005 | —- | C] () – C:\WINDOWS\_id.dat
    [2009/02/03 23:31:45 | 00,000,128 | —- | C] () – C:\WINDOWS\adobe.bat
    [2009/02/03 23:05:11 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\ethxkdvi.sys
    [2009/02/03 23:05:09 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\ethtgprm.sys
    [2009/02/03 23:05:07 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\ethrsxjj.sys
    [2009/02/03 23:05:05 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\ethrnqxg.sys
    [2009/02/03 23:05:03 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\ethqsyoe.sys
    [2009/02/03 23:05:01 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\ethqovij.sys
    [2009/02/03 23:04:59 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\ethpdprv.sys
    [2009/02/03 23:04:57 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\ethnwqjl.sys
    [2009/02/03 23:04:55 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\ethjenqu.sys
    [2009/02/03 23:04:53 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\ethimbtt.sys
    [2009/02/03 23:04:51 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\ethfbqvx.sys
    [2009/02/03 23:04:49 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\etherhmk.sys
    [2009/02/03 23:04:47 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\ethegmgt.sys
    [2009/02/03 23:04:45 | 00,138,080 | —- | C] () – C:\WINDOWS\System32\drivers\ethbotjf.sys
    [2009/02/03 23:04:43 | 00,137,280 | —- | C] () – C:\WINDOWS\System32\drivers\egnpsmiu.sys
    [2009/02/03 23:04:41 | 00,137,280 | —- | C] () – C:\WINDOWS\System32\drivers\efpnolmo.sys
    [2009/02/03 21:53:32 | 00,033,920 | —- | C] () – C:\WINDOWS\System32\drivers\tsdtagpg.sys
    [2009/02/02 22:38:08 | 00,015,000 | —- | C] () – C:\WINDOWS\System32\_hnsf983ind.dll
    [2009/02/02 22:21:31 | 00,037,888 | —- | C] (XRAVJE Corporation) – C:\WINDOWS\services.exe
    [2009/02/02 22:18:49 | 00,040,448 | —- | C] () – C:\WINDOWS\kernel32.exe
    [2009/02/02 22:18:00 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd
    
    :Services
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
    
    :Services
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL2 log ( don't check the boxes beside LOP Check or Purity this time )
========== OTLISTIT ========== Service\Driver efpnolmo deleted successfully. Service\Driver egnpsmiu deleted successfully. Service\Driver ethbotjf deleted successfully. Service\Driver ethegmgt deleted successfully. Service\Driver etherhmk deleted successfully. Service\Driver ethfbqvx deleted successfully. Service\Driver ethimbtt deleted successfully. Service\Driver ethjenqu deleted successfully. Service\Driver ethnwqjl deleted successfully. Service\Driver ethpdprv deleted successfully. Service\Driver ethqovij deleted successfully. Service\Driver ethqsyoe deleted successfully. Service\Driver ethrnqxg deleted successfully. Service\Driver ethrsxjj deleted successfully. Service\Driver ethtgprm deleted successfully. Service\Driver ethxkdvi deleted successfully. C:\Program Files\alot\bin\alot.dll NOT unregistered. C:\Program Files\alot\bin\alot.dll moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5AA2BA46-9913-4dc7-9620-69AB0FA17AE7}\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\jsf8uiw3jnjgffght deleted successfully. C:\WINDOWS\services.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\services deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\jsf8uiw3jnjgffght deleted successfully. C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\msas2009.exe moved successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\MS AntiSpyware 2009 deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\services deleted successfully. C:\Documents and Settings\Bret\Local Settings\Temp\csrssc.exe moved successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\tezrtsjhfr84iusjfo84f deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\WhenUSave deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\\{C5BF49A2 not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C5BF49A2\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\94F3-42BD-F434-3604812C8955}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{643e37d2-c42a-11db-b99b-001a9248dca8}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e96a4e98-f88e-11dc-bcb3-001a9248dca8}\ deleted successfully. C:\WINDOWS\System32\netsf_m.inf moved successfully. C:\WINDOWS\System32\netsf.inf moved successfully. LoadLibrary failed for C:\WINDOWS\Snakefedahe.dll C:\WINDOWS\Snakefedahe.dll NOT unregistered. File move failed. C:\WINDOWS\Snakefedahe.dll scheduled to be moved on reboot. C:\WINDOWS\_id.dat moved successfully. C:\WINDOWS\adobe.bat moved successfully. File move failed. C:\WINDOWS\System32\drivers\ethxkdvi.sys scheduled to be moved on reboot. File move failed. C:\WINDOWS\System32\drivers\ethtgprm.sys scheduled to be moved on reboot. File move failed. C:\WINDOWS\System32\drivers\ethrsxjj.sys scheduled to be moved on reboot. File move failed. C:\WINDOWS\System32\drivers\ethrnqxg.sys scheduled to be moved on reboot. File move failed. C:\WINDOWS\System32\drivers\ethqsyoe.sys scheduled to be moved on reboot. File move failed. C:\WINDOWS\System32\drivers\ethqovij.sys scheduled to be moved on reboot. File move failed. C:\WINDOWS\System32\drivers\ethpdprv.sys scheduled to be moved on reboot. File move failed. C:\WINDOWS\System32\drivers\ethnwqjl.sys scheduled to be moved on reboot. File move failed. C:\WINDOWS\System32\drivers\ethjenqu.sys scheduled to be moved on reboot. File move failed. C:\WINDOWS\System32\drivers\ethimbtt.sys scheduled to be moved on reboot. File move failed. C:\WINDOWS\System32\drivers\ethfbqvx.sys scheduled to be moved on reboot. File move failed. C:\WINDOWS\System32\drivers\etherhmk.sys scheduled to be moved on reboot. File move failed. C:\WINDOWS\System32\drivers\ethegmgt.sys scheduled to be moved on reboot. File move failed. C:\WINDOWS\System32\drivers\ethbotjf.sys scheduled to be moved on reboot. File move failed. C:\WINDOWS\System32\drivers\egnpsmiu.sys scheduled to be moved on reboot. File move failed. C:\WINDOWS\System32\drivers\efpnolmo.sys scheduled to be moved on reboot. File move failed. C:\WINDOWS\System32\drivers\tsdtagpg.sys scheduled to be moved on reboot. C:\WINDOWS\System32\_hnsf983ind.dll NOT unregistered. C:\WINDOWS\System32\_hnsf983ind.dll moved successfully. File move failed. C:\WINDOWS\services.exe scheduled to be moved on reboot. C:\WINDOWS\kernel32.exe moved successfully. C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\SAVED moved successfully. C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\LOG moved successfully. C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\DELETED moved successfully. C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\BASE moved successfully. C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009 moved successfully. C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd moved successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== ========== COMMANDS ========== File delete failed. C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\RTZGMZC1\6r%3Dh%26rnd%3DbaqaxR%2CbdmchtieIrql%26bg1%3D%26bg2%3D%26bg3%3D%26fid%3D214544621%26sp%3D0%26cat%3D%26tvvid%3D%26tvch%3D%26tvcat%3D%26tvmcat%3D%26nwcat%3D%26nwvert%3D%26dwcat%3D&r=0 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\RTZGMZC1\6r%3Dh%26rnd%3Dleqtsd%2CbdmckqWmytkn%26bg1%3D%26bg2%3D%26bg3%3D%26fid%3D167366962%26sp%3D0%26cat%3D%26tvvid%3D%26tvch%3D%26tvcat%3D%26tvmcat%3D%26nwcat%3D%26nwvert%3D%26dwcat%3D&r=0 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\RTZGMZC1\a0mNnApdIo5mM05VYcTGJdWVJ7SAnyWdvVTFn15berWaMpTTQ6PqZbZdRGZbARr6wSdfaWVbS4U PqmHArXTXp2tUASGJZa2AUJmdAyTWfeYrf8Ybj90EeqSrQAWUv5TdJ5nFjuRb7p1TUy5TBh4av3nTJFYb BfYq79mp5DZb2[1].gif scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\RTZGMZC1\click,AgAAAL5CAwC9XAMAB2wBAAAAKX0AAAsAAgACFgIABgIuawEAdUoCAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAH8hwUYAAAAA,,http%3A%2F%2Ffriends[2].viewfriends%26friendid%3D143987247,;ord=1187062143 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\RTZGMZC1\click,AgAAALVCAwCKVQMAHFQBAAIAHXwAAP8AAAACFAIABgIuawEABCQCAAAAAAAAAAAAAAAAA AAAAAAA[2].read%26messageid%3D4109635884%26mytoken%3D12d6993f-4777-4b30-a4c3-92212b67abfb,;ord=1187055041 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\RTZGMZC1\click,bg8AAMFCAwD7FAMAGjgCAAAAaXwAAAcAAgACFwIABgIuawEA7oUDAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAK0qwUYAAAAA,,http%3A%2F%2Fprofile[2].viewprofile%26friendid%3D44982507,;ord=1187064493 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\RTZGMZC1\d%26r%3Dh%26rnd%3DeIyRwp%2CbdmcgyojtWox%26bg1%3D%26bg2%3D%26bg3%3D%26fid%3D228472269%26sp%3D0%26cat%3D%26tvvid%3D%26tvch%3D%26tvcat%3D%26tvmcat%3D%26nwcat%3D%26nwvert%3D%26dwcat&r=0 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\RTZGMZC1\d%26r%3Dh%26rnd%3DeoqpWc%2CbdmcgyKbmdf%26bg1%3D%26bg2%3D%26bg3%3D%26fid%3D172834952%26sp%3D0%26cat%3D%26tvvid%3D%26tvch%3D%26tvcat%3D%26tvmcat%3D%26nwcat%3D%26nwvert%3D%26dwcat%&r=0 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\RTZGMZC1\scraper%26r%3Dh%26rnd%3Dfeieab%2CbdmchodjhgbK%26bg1%3D%26bg2%3D%26bg3%3D%26fid%3D%26sp%3D0%26cat%3D%26tvvid%3D%26tvch%3D%26tvcat%3D%26tvmcat%3D%26nwcat%3D%26nwvert%3D%26dwcat%3D&r=0 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\RTZGMZC1\styles%3Dleaderboard%26page%3D11021002%26rand%3D900294807%26friendid%3D175744361%26acnt%3D1%26schoolpage%3D0%26bg1%3D34%26bandgenre%3D34%26bg2%3D0%26bandgenre%3D0%26,;ord=1187064020 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\MV8IFQJL\CAO9ST4J.styles%3Dleaderboard%26page%3D11021002%26rand%3D821901193%26friendid%3D175744361%26acnt%3D1%26schoolpage%3D0%26bg1%3D34%26bandgenre%3D34%26bg2%3D0%26bandgenre%3D0%26&r=0 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\MV8IFQJL\CAOPOJCV.styles%3Dleaderboard%26page%3D11021002%26rand%3D284209936%26friendid%3D218871464%26acnt%3D1%26schoolpage%3D0%26bg1%3D34%26bandgenre%3D34%26bg2%3D0%26bandgenre%3D0%26&r=0 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\MV8IFQJL\CAQJYNI1.styles%3Dleaderboard%26page%3D11021002%26rand%3D907052274%26friendid%3D18842010%26acnt%3D1%26schoolpage%3D0%26bg1%3D28%26bandgenre%3D28%26bg2%3D38%26bandgenre%3D38%2&r=0 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\MV8IFQJL\click,BAAAALhCAwCY4AQASVsCAAIAbXwAAP8AAAACFQIABgLkdQEAwrgDAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAFkWwUYAAAAA,,http%3A[2].viewpicture%26friendid%3D62589564%26albumid%3D0,;ord=1187059289 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\MV8IFQJL\click,BAAAALlCAwBxlwYASVsCAAIAdXwAAP8AAAACFQIABgLkdQEAwrgD[2].editalbumphot o%26albumid%3D326019%26imageid%3D2049226%26mytoken%3D3e02067d-44d2-44dd-a113-42734e9cba71,;ord=1187059292 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\MV8IFQJL\click,cA8AAL9CAwCKVQMAHFQBAAAARX0AAAsABAACFgIABgIuawEABCQCAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAOkhwUYAAAAA[2].interests%26mytoken%3D14f86dc4-be36-4f41-974e-a57f2fffc4b7,;ord=1187062249 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\MV8IFQJL\d%26r%3Dh%26rnd%3DdiauoR%2CbdmcgAvhgmrs%26bg1%3D%26bg2%3D%26bg3%3D%26fid%3D56896652%26sp%3D0%26cat%3D%26tvvid%3D%26tvch%3D%26tvcat%3D%26tvmcat%3D%26nwcat%3D%26nwvert%3D%26dwcat%&r=0 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\JYQDLVT8\3Dh%26rnd%3Dehanhg%2Cbdmcbbyfbgkx%26bg1%3D%26bg2%3D%26bg3%3D%26fid%3D%26sp%3D0%26cat%3D%26tvvid%3D%26tvch%3D%26tvcat%3D%26tvmcat%3D%26nwcat%3D%26nwvert%3D%26dwcat%3D,;ord=1187054649 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\JYQDLVT8\click,AwAAALdCAwC9XAMAB2wBAAIARXwAAP8AAAACFQIABgIuawEAdUoCAAAAAAAAAAAAAAAAA [2].styles%3Dleaderboard%26page%3D14000009%26rand%3D639239522%26acnt%3D1%26schoolpage%3D0,;ord=1187058400 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\JYQDLVT8\click,AwAAAMFCAwCSVQMAC2wBAAIAkX0AAP8AAAACFgIABgIuawEAeUoCAAAAAAAAAAAAAAAAA [2].styles%3Dleaderboard%26page%3D21000002%26rand%3D058552571%26acnt%3D1%26schoolpage%3D0,;ord=1187062922 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\JYQDLVT8\click,BAAAALhCAwCKVQMAHFQBAAAAZXwAAAsAAgACFQIABgIuawEABCQCAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAANITwUYAAAAA,,http%3A[2].viewpicture%26friendid%3D62589564%26albumid%3D0,;ord=1187058642 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\JYQDLVT8\click,BAAAAMFCAwCSVQMAC2wBAAAAcXwAAAkAAgACFwIABgIuawEAeUoCAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAcrwUYAAAAA,,http%3A%2F%2Fviewmorepi[2].viewalbums%26friendid%3D143987247,;ord=1187064583 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\2KNPPGGS\%3Dmrec%26r%3Dh%26rnd%3DkaiAks%2CbdmcisRmetrr%26bg1%3D%26bg2%3D%26bg3%3D%26fid%3D%26sp%3D0%26cat%3D%26tvvid%3D%26tvch%3D%26tvcat%3D%26tvmcat%3D%26nwcat%3D%26nwvert%3D%26dwcat%3D&r=0 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\2KNPPGGS\click,AgAAALVCAwDDXAMASlcBAAAAEXwAAAcAAgACFAIABgIuawEAAykCAAAAAAAAAAAAAAAAA AAAAAAA[2].read%26messageid%3D4192355904%26mytoken%3D80ac6102-26ca-4c68-8e24-b664bec529c8,;ord=1187055002 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\2KNPPGGS\click,rgcAALVCAwCOVQMAC2wBAAIAUXwAAP8AAAACFQIACgIuaw[2].ng%2Fsite%3Dmyspace%26position%3Dskyscraper%26page%3D14000009%26rand%3D747429011%26acnt%3D2%26schoolpage%3D0,;ord=1187058409 scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\2KNPPGGS\d%26r%3Dh%26rnd%3DgliRru%2Cbdmcgzshydww%26bg1%3D%26bg2%3D%26bg3%3D%26fid%3D44982507%26sp%3D0%26cat%3D%26tvvid%3D%26tvch%3D%26tvcat%3D%26tvmcat%3D%26nwcat%3D%26nwvert%3D%26dwcat%&r=0 scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. Windows Temp folder emptied. Java cache emptied. FireFox cache emptied. Temp folders emptied. Explorer started successfully ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== ========== COMMANDS ========== User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. Windows Temp folder emptied. Java cache emptied. FireFox cache emptied. Temp folders emptied. Explorer started successfully OTListIt2 by OldTimer - Version 2.0.0.5 log created on 02052009_131315 Files moved on Reboot… File C:\WINDOWS\Snakefedahe.dll not found! File C:\WINDOWS\System32\drivers\ethxkdvi.sys not found! File C:\WINDOWS\System32\drivers\ethtgprm.sys not found! File C:\WINDOWS\System32\drivers\ethrsxjj.sys not found! File C:\WINDOWS\System32\drivers\ethrnqxg.sys not found! File C:\WINDOWS\System32\drivers\ethqsyoe.sys not found! File C:\WINDOWS\System32\drivers\ethqovij.sys not found! File C:\WINDOWS\System32\drivers\ethpdprv.sys not found! File C:\WINDOWS\System32\drivers\ethnwqjl.sys not found! File C:\WINDOWS\System32\drivers\ethjenqu.sys not found! File C:\WINDOWS\System32\drivers\ethimbtt.sys not found! File C:\WINDOWS\System32\drivers\ethfbqvx.sys not found! File C:\WINDOWS\System32\drivers\etherhmk.sys not found! File C:\WINDOWS\System32\drivers\ethegmgt.sys not found! File C:\WINDOWS\System32\drivers\ethbotjf.sys not found! File C:\WINDOWS\System32\drivers\egnpsmiu.sys not found! File C:\WINDOWS\System32\drivers\efpnolmo.sys not found! File C:\WINDOWS\System32\drivers\tsdtagpg.sys not found! C:\WINDOWS\services.exe moved successfully. File C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\RTZGMZC1\6r%3Dh%26rnd%3DbaqaxR%2CbdmchtieIrql%26bg1%3D%26bg2%3D%26bg3%3D%26fid%3D214544621%26sp%3D0%26cat%3D%26tvvid%3D%26tvch%3D%26tvcat%3D%26tvmcat%3D%26nwcat%3D%26nwvert%3D%26dwcat%3D&r=0 not found! File C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\RTZGMZC1\6r%3Dh%26rnd%3Dleqtsd%2CbdmckqWmytkn%26bg1%3D%26bg2%3D%26bg3%3D%26fid%3D167366962%26sp%3D0%26cat%3D%26tvvid%3D%26tvch%3D%26tvcat%3D%26tvmcat%3D%26nwcat%3D%26nwvert%3D%26dwcat%3D&r=0 not found! File C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\RTZGMZC1\a0mNnApdIo5mM05VYcTGJdWVJ7SAnyWdvVTFn15berWaMpTTQ6PqZbZdRGZbARr6wSdfaWVbS4U PqmHArXTXp2tUASGJZa2AUJmdAyTWfeYrf8Ybj90EeqSrQAWUv5TdJ5nFjuRb7p1TUy5TBh4av3nTJFYb BfYq79mp5DZb2[1].gif not found! File C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\RTZGMZC1\click,AgAAAL5CAwC9XAMAB2wBAAAAKX0AAAsAAgACFgIABgIuawEAdUoCAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAH8hwUYAAAAA,,http%3A%2F%2Ffriends[2].viewfriends%26friendid%3D143987247,;ord=1187062143 not found! File C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\RTZGMZC1\click,AgAAALVCAwCKVQMAHFQBAAIAHXwAAP8AAAACFAIABgIuawEABCQCAAAAAAAAAAAAAAAAA AAAAAAA[2].read%26messageid%3D4109635884%26mytoken%3D12d6993f-4777-4b30-a4c3-92212b67abfb,;ord=1187055041 not found! File C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\RTZGMZC1\click,bg8AAMFCAwD7FAMAGjgCAAAAaXwAAAcAAgACFwIABgIuawEA7oUDAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAK0qwUYAAAAA,,http%3A%2F%2Fprofile[2].viewprofile%26friendid%3D44982507,;ord=1187064493 not found! File C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\RTZGMZC1\d%26r%3Dh%26rnd%3DeIyRwp%2CbdmcgyojtWox%26bg1%3D%26bg2%3D%26bg3%3D%26fid%3D228472269%26sp%3D0%26cat%3D%26tvvid%3D%26tvch%3D%26tvcat%3D%26tvmcat%3D%26nwcat%3D%26nwvert%3D%26dwcat&r=0 not found! File C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\RTZGMZC1\d%26r%3Dh%26rnd%3DeoqpWc%2CbdmcgyKbmdf%26bg1%3D%26bg2%3D%26bg3%3D%26fid%3D172834952%26sp%3D0%26cat%3D%26tvvid%3D%26tvch%3D%26tvcat%3D%26tvmcat%3D%26nwcat%3D%26nwvert%3D%26dwcat%&r=0 not found! File C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\RTZGMZC1\scraper%26r%3Dh%26rnd%3Dfeieab%2CbdmchodjhgbK%26bg1%3D%26bg2%3D%26bg3%3D%26fid%3D%26sp%3D0%26cat%3D%26tvvid%3D%26tvch%3D%26tvcat%3D%26tvmcat%3D%26nwcat%3D%26nwvert%3D%26dwcat%3D&r=0 not found! File C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\RTZGMZC1\styles%3Dleaderboard%26page%3D11021002%26rand%3D900294807%26friendid%3D175744361%26acnt%3D1%26schoolpage%3D0%26bg1%3D34%26bandgenre%3D34%26bg2%3D0%26bandgenre%3D0%26,;ord=1187064020 not found! File C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\MV8IFQJL\CAO9ST4J.styles%3Dleaderboard%26page%3D11021002%26rand%3D821901193%26friendid%3D175744361%26acnt%3D1%26schoolpage%3D0%26bg1%3D34%26bandgenre%3D34%26bg2%3D0%26bandgenre%3D0%26&r=0 not found! File C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\MV8IFQJL\CAOPOJCV.styles%3Dleaderboard%26page%3D11021002%26rand%3D284209936%26friendid%3D218871464%26acnt%3D1%26schoolpage%3D0%26bg1%3D34%26bandgenre%3D34%26bg2%3D0%26bandgenre%3D0%26&r=0 not found! File C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\MV8IFQJL\CAQJYNI1.styles%3Dleaderboard%26page%3D11021002%26rand%3D907052274%26friendid%3D18842010%26acnt%3D1%26schoolpage%3D0%26bg1%3D28%26bandgenre%3D28%26bg2%3D38%26bandgenre%3D38%2&r=0 not found! File C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\MV8IFQJL\click,BAAAALhCAwCY4AQASVsCAAIAbXwAAP8AAAACFQIABgLkdQEAwrgDAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAFkWwUYAAAAA,,http%3A[2].viewpicture%26friendid%3D62589564%26albumid%3D0,;ord=1187059289 not found! File C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\MV8IFQJL\click,BAAAALlCAwBxlwYASVsCAAIAdXwAAP8AAAACFQIABgLkdQEAwrgD[2].editalbumphot o%26albumid%3D326019%26imageid%3D2049226%26mytoken%3D3e02067d-44d2-44dd-a113-42734e9cba71,;ord=1187059292 not found! File C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\MV8IFQJL\click,cA8AAL9CAwCKVQMAHFQBAAAARX0AAAsABAACFgIABgIuawEABCQCAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAOkhwUYAAAAA[2].interests%26mytoken%3D14f86dc4-be36-4f41-974e-a57f2fffc4b7,;ord=1187062249 not found! File C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\MV8IFQJL\d%26r%3Dh%26rnd%3DdiauoR%2CbdmcgAvhgmrs%26bg1%3D%26bg2%3D%26bg3%3D%26fid%3D56896652%26sp%3D0%26cat%3D%26tvvid%3D%26tvch%3D%26tvcat%3D%26tvmcat%3D%26nwcat%3D%26nwvert%3D%26dwcat%&r=0 not found! File C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\JYQDLVT8\3Dh%26rnd%3Dehanhg%2Cbdmcbbyfbgkx%26bg1%3D%26bg2%3D%26bg3%3D%26fid%3D%26sp%3D0%26cat%3D%26tvvid%3D%26tvch%3D%26tvcat%3D%26tvmcat%3D%26nwcat%3D%26nwvert%3D%26dwcat%3D,;ord=1187054649 not found! File C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\JYQDLVT8\click,AwAAALdCAwC9XAMAB2wBAAIARXwAAP8AAAACFQIABgIuawEAdUoCAAAAAAAAAAAAAAAAA [2].styles%3Dleaderboard%26page%3D14000009%26rand%3D639239522%26acnt%3D1%26schoolpage%3D0,;ord=1187058400 not found! File C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\JYQDLVT8\click,AwAAAMFCAwCSVQMAC2wBAAIAkX0AAP8AAAACFgIABgIuawEAeUoCAAAAAAAAAAAAAAAAA [2].styles%3Dleaderboard%26page%3D21000002%26rand%3D058552571%26acnt%3D1%26schoolpage%3D0,;ord=1187062922 not found! File C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\JYQDLVT8\click,BAAAALhCAwCKVQMAHFQBAAAAZXwAAAsAAgACFQIABgIuawEABCQCAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAANITwUYAAAAA,,http%3A[2].viewpicture%26friendid%3D62589564%26albumid%3D0,;ord=1187058642 not found! File C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\JYQDLVT8\click,BAAAAMFCAwCSVQMAC2wBAAAAcXwAAAkAAgACFwIABgIuawEAeUoCAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAcrwUYAAAAA,,http%3A%2F%2Fviewmorepi[2].viewalbums%26friendid%3D143987247,;ord=1187064583 not found! File C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\2KNPPGGS\%3Dmrec%26r%3Dh%26rnd%3DkaiAks%2CbdmcisRmetrr%26bg1%3D%26bg2%3D%26bg3%3D%26fid%3D%26sp%3D0%26cat%3D%26tvvid%3D%26tvch%3D%26tvcat%3D%26tvmcat%3D%26nwcat%3D%26nwvert%3D%26dwcat%3D&r=0 not found! File C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\2KNPPGGS\click,AgAAALVCAwDDXAMASlcBAAAAEXwAAAcAAgACFAIABgIuawEAAykCAAAAAAAAAAAAAAAAA AAAAAAA[2].read%26messageid%3D4192355904%26mytoken%3D80ac6102-26ca-4c68-8e24-b664bec529c8,;ord=1187055002 not found! File C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\2KNPPGGS\click,rgcAALVCAwCOVQMAC2wBAAIAUXwAAP8AAAACFQIACgIuaw[2].ng%2Fsite%3Dmyspace%26position%3Dskyscraper%26page%3D14000009%26rand%3D747429011%26acnt%3D2%26schoolpage%3D0,;ord=1187058409 not found! File C:\Documents and Settings\Bret\Local Settings\Temp\Temporary Internet Files\Content.IE5\2KNPPGGS\d%26r%3Dh%26rnd%3DgliRru%2Cbdmcgzshydww%26bg1%3D%26bg2%3D%26bg3%3D%26fid%3D44982507%26sp%3D0%26cat%3D%26tvvid%3D%26tvch%3D%26tvcat%3D%26tvmcat%3D%26nwcat%3D%26nwvert%3D%26dwcat%&r=0 not found! File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot. Registry entries deleted on Reboot…
This is the OT log with LOP Check and Purity Check and Standard Tegistry to All. (I assumed that is what you wanted) :



OTListIt logfile created on: 2/5/2009 1:38:20 PM - Run 10
OTListIt2 by OldTimer - Version 2.0.0.5 Folder = C:\Documents and Settings\Bret\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1014.37 Mb Total Physical Memory | 597.03 Mb Available Physical Memory | 58.86% Memory free
1.63 Gb Paging File | 1.27 Gb Available in Paging File | 77.96% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.83 Gb Total Space | 19.45 Gb Free Space | 34.84% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DDRHQHC1
Current User Name: Bret
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

C:\WINDOWS\system32\WLTRYSVC.EXE ()
C:\WINDOWS\system32\BCMWLTRY.EXE (Dell Inc.)
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe (Juniper Networks)
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
C:\Program Files\Dell\QuickSet\NicConfigSvc.exe (Dell Inc.)
C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe (Sun Microsystems, Inc.)
C:\WINDOWS\system32\WLTRAY.EXE (Dell Inc.)
C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
C:\WINDOWS\system32\igfxsrvc.exe (Intel Corporation)
C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
C:\Program Files\Apoint\hidfind.exe (Alps Electric Co., Ltd.)
C:\Program Files\Apoint\ApntEx.exe (Alps Electric Co., Ltd.)
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe (CyberLink Corp.)
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe (Adobe Systems Incorporated)
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
C:\Program Files\NetWaiting\netwaiting.exe ()
C:\Program Files\Dell Support\DSAgnt.exe (Gteko Ltd.)
C:\Program Files\MSN Messenger\msnmsgr.exe (Microsoft Corporation)
C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
C:\WINDOWS\system32\wuauclt.exe (Microsoft Corporation)
C:\Documents and Settings\Bret\Desktop\OTListIt22.exe (OldTimer Tools)
C:\WINDOWS\system32\wuauclt.exe (Microsoft Corporation)

========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (avg8emc [Auto | Running]) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd [Auto | Running]) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (dsNcService [Auto | Running]) – C:\Program Files\Juniper Networks\Common Files\dsNcService.exe (Juniper Networks)
SRV - (GoogleDesktopManager [On_Demand | Stopped]) – File not found
SRV - (gusvc [Auto | Running]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll (Microsoft Corporation)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (NICCONFIGSVC [Auto | Running]) – C:\Program Files\Dell\QuickSet\NicConfigSvc.exe (Dell Inc.)
SRV - (usnjsvc [On_Demand | Stopped]) – C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (wltrysvc [Auto | Running]) – C:\WINDOWS\system32\WLTRYSVC.EXE ()
SRV - (WMPNetworkSvc [Auto | Running]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (WudfSvc [Auto | Running]) – C:\WINDOWS\system32\WudfSvc.dll (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (AliIde [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\AMDAGP.SYS (Advanced Micro Devices, Inc.)
DRV - (ApfiltrService [On_Demand | Running]) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (APPDRV [System | Running]) – C:\WINDOWS\system32\drivers\APPDRV.SYS (Dell Inc)
DRV - (asc [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\asc3550.sys (Advanced System Products, Inc.)
DRV - (AvgLdx86 [System | Running]) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (BCM43XX [On_Demand | Running]) – C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corporation)
DRV - (bcm4sbxp [On_Demand | Running]) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (CmdIde [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (dac2w2k [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\dac2w2k.sys (Mylex Corporation)
DRV - (dsNcAdpt [On_Demand | Running]) – C:\WINDOWS\system32\drivers\dsNcAdpt.sys (Juniper Networks)
DRV - (DSproct [On_Demand | Running]) – C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys (GTek Technologies Ltd.)
DRV - (E100B [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\e100b325.sys (Intel Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HDAudBus [On_Demand | Running]) – C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (HSF_DPV [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (ialm [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ialmnt5.sys (Intel Corporation)
DRV - (mdmxsdk [Auto | Running]) – C:\WINDOWS\system32\drivers\mdmxsdk.sys (Conexant)
DRV - (miegjyix [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\miegjyix.sys ()
DRV - (motmodem [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\motmodem.sys (Motorola)
DRV - (mraid35x [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\mraid35x.sys (American Megatrends Inc.)
DRV - (NEOFLTR_550_11965 [System | Running]) – C:\WINDOWS\system32\drivers\NEOFLTR_550_11965.sys (Juniper Networks)
DRV - (NEOFLTR_620_13525 [System | Running]) – C:\WINDOWS\system32\drivers\NEOFLTR_620_13525.sys (Juniper Networks)
DRV - (nv [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (Passthru [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ndisio.sys ()
DRV - (protect [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\protect.sys ()
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (ql1080 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\ql1080.sys (QLogic Corporation)
DRV - (ql12160 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\ql12160.sys (QLogic Corporation)
DRV - (ql1280 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\ql1280.sys (QLogic Corporation)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sisagp [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\SISAGP.SYS (Silicon Integrated Systems Corporation)
DRV - (Sparrow [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\sparrow.sys (Adaptec, Inc.)
DRV - (STHDA [On_Demand | Running]) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (symc810 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\symc810.sys (Symbios Logic Inc.)
DRV - (symc8xx [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (sym_hi [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (sym_u3 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (ultra [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\ultra.sys (Promise Technology, Inc.)
DRV - (USBAAPL [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\usbaapl.sys (Apple, Inc.)
DRV - (Wdf01000 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wdf01000.sys (Microsoft Corporation)
DRV - (winachsf [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (WinUSB [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\winusb.sys (Microsoft Corporation)
DRV - (WmiAcpi [System | Running]) – C:\WINDOWS\system32\drivers\wmiacpi.sys (Microsoft Corporation)

========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=3070206
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=3070206

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=3070206
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 ZieF.pl
O1 - Hosts: 127.0.0.1 localhost
O3 - HKLM\..\Toolbar: (&Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O4 - HKLM..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe (Dell Inc.)
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc)
O4 - HKLM..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [services] C:\WINDOWS\services.exe File not found
O4 - HKLM..\Run: [SigmatelSysTrayApp] stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup (Gteko Ltd.)
O4 - HKCU..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe ()
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
O4 - Startup: C:\Documents and Settings\Bret\Start Menu\Programs\Startup\ClearPlay Easy Updates.lnk = C:\Program Files\ClearPlay\ClearPlay Easy Updates\ClearPlayEasyUpdates.exe File not found
O4 - Startup: C:\Documents and Settings\Bret\Start Menu\Programs\Startup\MostFun.lnk = C:\Program Files\MostFun\Bin\MostFun.exe File not found
O4 - Startup: C:\Documents and Settings\Bret\Start Menu\Programs\Startup\Xfire.lnk = C:\Program Files\Xfire\Xfire.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\NPJPI150_06.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [NTDS] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [Juniper Secure DNS (Top)] - C:\Program Files\Juniper Networks\Secure Application Manager\samnsp.dll (Juniper Networks)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [Tcpip] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [Network Location Awareness (NLA) Namespace] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [Juniper Secure DNS (Bottom)] - C:\Program Files\Juniper Networks\Secure Application Manager\samnsp.dll (Juniper Networks)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/EN-US/a-_UNO/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key does not exist or could not be opened.)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} http://www.gamehouse.com/games/SproutLauncher.cab (SproutLauncherCtrl Class)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://www.popcap.com/games/popcaploader_v6.cab (PopCapLoader Object)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab (Minesweeper Flags Class)
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/octet-stream - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-complus - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-msdownload - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - Class Install Handler - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - deflate - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - gzip - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - lzdhtml - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/webviewhtml - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\pdbcopy.exe) - C:\WINDOWS\system32\pdbcopy.exe ()
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\gcc.exe) - C:\WINDOWS\system32\gcc.exe ()
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\actcontroller.exe) - C:\WINDOWS\system32\actcontroller.exe ()
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\c++.exe) - C:\WINDOWS\system32\c++.exe ()
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\system32\logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\system32\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\system32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\system32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\system32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\system32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\system32\WgaLogon.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {C5BF49A2-94F3-42BD-F434-3604812C8955} - jgzfkj9w38rksndfi7r4 - Reg Error: Key does not exist or could not be opened. File not found
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O27 - HKLM IFEO\Your Image File Name Here without a path: Debugger - C:\WINDOWS\system32\ntsd.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\system32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - ( schannel.dll) - C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - ( digest.dll) - C:\WINDOWS\system32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - ( msnsspc.dll) - C:\WINDOWS\system32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\system32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\system32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\system32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\system32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]

========== Files/Folders - Created Within 30 Days ==========

[2009/02/05 13:40:40 | 00,057,345 | —- | C] () – C:\WINDOWS\services.exe
[2009/02/05 13:40:37 | 00,003,584 | —- | C] () – C:\WINDOWS\lfzfweiu.exe
[2009/02/05 13:18:30 | 00,046,080 | —- | C] () – C:\WINDOWS\System32\c++.exe
[2009/02/05 12:14:36 | 00,033,920 | —- | C] () – C:\WINDOWS\System32\drivers\miegjyix.sys
[2009/02/05 12:07:33 | 00,046,080 | —- | C] () – C:\WINDOWS\System32\actcontroller.exe
[2009/02/05 12:06:45 | 00,046,080 | —- | C] () – C:\WINDOWS\System32\gcc.exe
[2009/02/05 12:06:42 | 00,003,584 | —- | C] () – C:\WINDOWS\nttakbit.exe
[2009/02/05 12:04:39 | 10,637,14816 | -HS- | C] () – C:\hiberfil.sys
[2009/02/05 11:57:23 | 00,018,944 | -H– | C] () – C:\WINDOWS\System32\drivers\protect.sys
[2009/02/05 11:53:38 | 00,005,715 | —- | C] () – C:\Documents and Settings\Bret\Desktop\Document.rtf
[2009/02/05 08:54:47 | 00,000,000 | —D | C] – C:\_OTListIt
[2009/02/05 08:52:19 | 00,046,080 | —- | C] () – C:\WINDOWS\System32\pdbcopy.exe
[2009/02/05 08:52:18 | 00,038,400 | —- | C] () – C:\WINDOWS\System32\mlJCRKeE.dll
[2009/02/04 18:29:42 | 00,506,368 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Bret\Desktop\OTListIt22.exe
[2009/02/03 23:47:36 | 00,001,323 | —- | C] () – C:\Documents and Settings\Bret\Desktop\HijackThis.lnk
[2009/02/03 23:47:20 | 00,000,000 | —D | C] – C:\HJT
[2009/02/03 23:47:01 | 00,812,344 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Bret\Desktop\HJTsetup.exe
[2009/02/03 21:18:29 | 00,066,560 | -H– | C] () – C:\WINDOWS\System32\secupdat.dat
[2009/02/03 16:20:56 | 00,053,248 | —- | C] () – C:\WINDOWS\System32\drivers\ndisio.sys
[2009/01/18 12:28:08 | 00,000,000 | -HSD | C] – C:\Config.Msi
[2009/01/09 21:15:35 | 00,000,000 | —D | C] – C:\Documents and Settings\Bret\Local Settings\Application Data\WMTools Downloaded Files
[2009/01/09 09:02:57 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Juniper Networks

========== Files - Modified Within 30 Days ==========

[32 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[2009/02/05 13:40:53 | 00,479,920 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/02/05 13:40:53 | 00,408,238 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/02/05 13:40:53 | 00,064,602 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/02/05 13:40:40 | 00,046,080 | —- | M] () – C:\WINDOWS\System32\pdbcopy.exe
[2009/02/05 13:40:39 | 00,057,345 | —- | M] () – C:\WINDOWS\services.exe
[2009/02/05 13:40:37 | 00,003,584 | —- | M] () – C:\WINDOWS\lfzfweiu.exe
[2009/02/05 13:36:54 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/02/05 13:36:42 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/02/05 13:36:38 | 10,637,14816 | -HS- | M] () – C:\hiberfil.sys
[2009/02/05 13:36:38 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/02/05 13:24:07 | 00,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2009/02/05 13:24:07 | 00,000,232 | -H– | M] () – C:\sqmdata08.sqm
[2009/02/05 13:18:30 | 00,046,080 | —- | M] () – C:\WINDOWS\System32\c++.exe
[2009/02/05 13:16:34 | 03,226,052 | -H– | M] () – C:\Documents and Settings\Bret\Local Settings\Application Data\IconCache.db
[2009/02/05 13:16:34 | 00,000,232 | -H– | M] () – C:\sqmdata07.sqm
[2009/02/05 13:16:33 | 00,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2009/02/05 12:27:36 | 00,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2009/02/05 12:27:36 | 00,000,232 | -H– | M] () – C:\sqmdata06.sqm
[2009/02/05 12:14:36 | 00,033,920 | —- | M] () – C:\WINDOWS\System32\drivers\miegjyix.sys
[2009/02/05 12:07:33 | 00,046,080 | —- | M] () – C:\WINDOWS\System32\actcontroller.exe
[2009/02/05 12:06:45 | 00,046,080 | —- | M] () – C:\WINDOWS\System32\gcc.exe
[2009/02/05 12:06:42 | 00,003,584 | —- | M] () – C:\WINDOWS\nttakbit.exe
[2009/02/05 12:06:32 | 32,820,251 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/02/05 12:06:32 | 00,086,834 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/02/05 11:57:24 | 00,018,944 | -H– | M] () – C:\WINDOWS\System32\drivers\protect.sys
[2009/02/05 11:53:58 | 00,000,232 | -H– | M] () – C:\sqmdata05.sqm
[2009/02/05 11:53:57 | 00,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2009/02/05 11:53:38 | 00,005,715 | —- | M] () – C:\Documents and Settings\Bret\Desktop\Document.rtf
[2009/02/05 08:52:18 | 00,038,400 | —- | M] () – C:\WINDOWS\System32\mlJCRKeE.dll
[2009/02/04 21:23:43 | 00,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2009/02/04 21:23:43 | 00,000,232 | -H– | M] () – C:\sqmdata04.sqm
[2009/02/04 20:32:18 | 00,053,248 | —- | M] () – C:\WINDOWS\System32\drivers\ndisio.sys
[2009/02/04 20:29:53 | 00,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2009/02/04 20:29:53 | 00,000,232 | -H– | M] () – C:\sqmdata03.sqm
[2009/02/04 18:29:55 | 00,506,368 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Bret\Desktop\OTListIt22.exe
[2009/02/03 23:47:36 | 00,001,323 | —- | M] () – C:\Documents and Settings\Bret\Desktop\HijackThis.lnk
[2009/02/03 23:47:01 | 00,812,344 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Bret\Desktop\HJTsetup.exe
[2009/02/03 21:20:45 | 00,066,560 | -H– | M] () – C:\WINDOWS\System32\secupdat.dat
[2009/02/02 23:36:36 | 00,000,561 | —- | M] () – C:\Documents and Settings\Bret\My Documents\My Sharing Folders.lnk
[2009/02/01 00:19:52 | 00,000,268 | -H– | M] () – C:\sqmdata02.sqm
[2009/02/01 00:19:52 | 00,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2009/01/31 17:55:16 | 00,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/01/31 09:31:33 | 00,010,520 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/01/31 09:31:32 | 00,325,128 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/01/31 09:31:32 | 00,027,656 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/01/31 09:31:29 | 00,107,272 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/01/29 23:14:42 | 00,000,268 | -H– | M] () – C:\sqmdata01.sqm
[2009/01/29 23:14:42 | 00,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2009/01/29 23:14:31 | 00,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2009/01/29 23:14:31 | 00,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2009/01/25 22:59:02 | 00,000,268 | -H– | M] () – C:\sqmdata19.sqm
[2009/01/25 22:59:02 | 00,000,244 | -H– | M] () – C:\sqmnoopt19.sqm
[2009/01/25 15:01:09 | 00,000,268 | -H– | M] () – C:\sqmdata18.sqm
[2009/01/25 15:01:08 | 00,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2009/01/23 00:00:43 | 00,000,268 | -H– | M] () – C:\sqmdata17.sqm
[2009/01/23 00:00:43 | 00,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2009/01/20 16:49:09 | 00,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2009/01/20 16:49:09 | 00,000,232 | -H– | M] () – C:\sqmdata16.sqm
[2009/01/20 10:05:44 | 00,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2009/01/20 10:05:44 | 00,000,232 | -H– | M] () – C:\sqmdata15.sqm
[2009/01/18 23:13:12 | 00,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2009/01/18 23:13:12 | 00,000,232 | -H– | M] () – C:\sqmdata14.sqm
[2009/01/18 16:36:34 | 00,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2009/01/18 16:36:34 | 00,000,232 | -H– | M] () – C:\sqmdata13.sqm
[2009/01/18 12:40:42 | 00,010,752 | —- | M] () – C:\Documents and Settings\Bret\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/01/17 18:08:19 | 00,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2009/01/17 18:08:19 | 00,000,232 | -H– | M] () – C:\sqmdata12.sqm
[2009/01/17 02:28:11 | 00,000,268 | -H– | M] () – C:\sqmdata11.sqm
[2009/01/17 02:28:11 | 00,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2009/01/16 18:29:03 | 00,000,268 | -H– | M] () – C:\sqmdata10.sqm
[2009/01/16 18:29:03 | 00,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2009/01/16 18:28:52 | 00,000,268 | -H– | M] () – C:\sqmdata09.sqm
[2009/01/16 18:28:52 | 00,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2009/01/14 11:14:03 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job

========== LOP Check ==========

[2009/02/05 13:13:20 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/12/21 15:28:05 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2008/03/29 16:54:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2008/01/22 21:15:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2008/10/27 18:12:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2008/08/17 15:23:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG7
[2009/02/03 21:42:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg8
[2007/07/20 16:07:37 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GameHouse
[2009/01/06 18:39:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2009/02/05 09:02:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google Updater
[2007/02/16 08:35:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2007/02/06 19:29:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\GTek
[2008/04/07 18:58:46 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intuit
[2009/01/09 09:03:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Juniper Networks
[2008/08/23 10:57:26 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2007/06/04 10:53:40 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MostFun
[2007/07/20 13:17:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2004/08/10 12:13:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2007/03/20 15:06:22 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/12/16 19:51:00 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Bret\Application Data
[2007/12/09 22:00:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\Adobe
[2008/03/24 14:56:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\alot
[2008/10/27 19:20:12 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\Apple Computer
[2008/04/15 16:56:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\ClearPlay Inc
[2007/02/25 18:15:05 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\CyberLink
[2008/04/01 21:25:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\Google
[2007/02/06 19:29:31 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Bret\Application Data\Gtek
[2007/02/25 20:21:30 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\Help
[2008/04/21 20:03:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\ICAClient
[2004/08/10 12:08:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\Identities
[2007/04/13 22:02:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\InstallShield
[2008/04/21 20:17:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\Juniper Networks
[2007/12/28 18:19:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\Leadertech
[2007/05/05 20:33:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\LimeWire Music
[2007/04/25 09:07:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\Macromedia
[2007/04/16 20:21:55 | 00,000,000 | –SD | M] – C:\Documents and Settings\Bret\Application Data\Microsoft
[2008/01/27 21:57:43 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Bret\Application Data\Move Networks
[2008/08/17 13:41:57 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\Mozilla
[2007/02/18 15:28:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\Sun
[2007/04/22 09:03:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\Talkback
[2008/12/16 21:12:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\Tibia
[2008/01/08 21:18:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\Xfire
[2007/06/10 08:56:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Bret\Application Data\yoclient
[2009/01/14 11:14:03 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2004/08/04 04:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/02/05 13:36:42 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 263749 bytes -> %SystemRoot%\Temp:temp
< End of report >
hello

Before we begin, you should save these instructions in Notepad to your desktop, or print them, for easy reference. Much of our fix will be done in Safe mode, and you will be unable to access this thread at that time. If you have questions at any point, or are unsure of the instructions, feel free to post here and ask for clarification before proceeding.


Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum.




Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt log in your next reply.
I'd give you the log but now it's not letting me even connect to the internet. It isn't even sending any packets for the internet. What happend?
you rebooted your PC ?

try this as well

ComboFix will disconnect the machine from the internet, this prevents fresh malware from coming in.
The connection shall be restored once ComboFix gets to the Find3M stage.
In the event that ComboFix terminates prematurely you can manually restore the connection by …
* Going to Control Panel > Network Connections.
* Right click on their Network icons & select "Repair"

[external image: Posted Image]

Alternately, if the Network icon appears in the notification area in the lower right corner of Desktop, right-click it, and then click Repair from the shortcut menu.

[external image: Posted Image]

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI