OTListIt.txt :
OTListIt logfile created on: 2/9/2009 3:10:43 PM - Run
OTListIt2 by OldTimer - Version 2.0.0.10 Folder = C:\EXE & ZIP\HijackThis
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
478.48 Mb Total Physical Memory | 107.17 Mb Available Physical Memory | 22.40% Memory free
1.10 Gb Paging File | 0.87 Gb Available in Paging File | 79.52% Paging File free
Paging file location(s): C:\pagefile.sys 720 1440;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 152.66 Gb Total Space | 115.23 Gb Free Space | 75.48% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 76.33 Gb Total Space | 53.86 Gb Free Space | 70.57% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: N-F6908F5DF7D04
Current User Name: Kate
Logged in as Administrator.
Current Boot Mode: SafeMode with Networking
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Mozilla Firefox 3 Beta 3\firefox.exe (Mozilla Corporation)
PRC - C:\EXE & ZIP\HijackThis\OTListIt22.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (Apple Mobile Device [Auto | Stopped]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (aswUpdSv [Auto | Stopped]) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (Ati HotKey Poller [Auto | Stopped]) – C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
SRV - (ATI Smart [Auto | Stopped]) – C:\WINDOWS\system32\ati2sgag.exe ()
SRV - (avast! Antivirus [Auto | Stopped]) – C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner [On_Demand | Stopped]) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner [On_Demand | Stopped]) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (Bonjour Service [Auto | Stopped]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (iPod Service [On_Demand | Stopped]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Stopped]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (WudfSvc [On_Demand | Stopped]) – C:\WINDOWS\system32\WudfSvc.dll (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (Aavmker4 [System | Stopped]) – C:\WINDOWS\system32\drivers\aavmker4.sys (ALWIL Software)
DRV - (ALCXWDM [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (aswFsBlk [Auto | Stopped]) – C:\WINDOWS\system32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (aswMon2 [Auto | Stopped]) – C:\WINDOWS\system32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswRdr [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswSP [System | Stopped]) – C:\WINDOWS\system32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswTdi [System | Running]) – C:\WINDOWS\system32\drivers\aswTdi.sys (ALWIL Software)
DRV - (ati2mtag [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (L6TPortGX [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\L6TPortGX.sys (Line 6)
DRV - (motmodem [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\motmodem.sys (Motorola)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (rtl8139 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (Secdrv [Auto | Stopped]) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SilverLink [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\SilvrLnk.sys (Texas Instruments Incorporated)
DRV - (USBAAPL [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\usbaapl.sys (Apple, Inc.)
DRV - (Wdf01000 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\wdf01000.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - URLSearchHook: {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
O1 HOSTS File: (293398 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 127.0.0.1 www.163ns.com
O1 - Hosts: 127.0.0.1 163ns.com
O1 - Hosts: 10102 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {3541147A-29C4-40E8-BAAE-30D71529C686} - Reg Error: Key error. File not found
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - Reg Error: Key error. File not found
O2 - BHO: (no name) - {AC071477-43ED-4A48-A96C-698D4FEBD1C0} - C:\WINDOWS\system32\pmnoNHBQ.dll File not found
O2 - BHO: (no name) - {E3C16394-5010-4B4C-BCC2-CE63B6A92F24} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe File not found
O4 - HKLM..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" (ATI Technologies, Inc.)
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" (Hewlett-Packard Company)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe (HP)
O4 - HKLM..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 (Microsoft Corporation)
O4 - HKLM..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe (America Online, Inc.)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC (Microsoft Corporation)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SoundMan] SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - Startup: C:\Documents and Settings\Kate\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowLegacyWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowUnhashedWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra Button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Sites: line6.net ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: 55 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/download/5/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_10)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_10)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E473A65C-8087-49A3-AFFD-C5BC4A10669B} http://mvnet.xlontech.net/qm/fox/06101102/qsp2ie06101001.cab (Quantum Streaming IE Player Class)
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (wbsys.dll) - C:\WINDOWS\system32\wbsys.dll (Stardock.Net, Inc)
O20 - AppInit_DLLs: (yijzch.dll) - C:\WINDOWS\system32\yijzch.dll ()
O20 - AppInit_DLLs: (gmmaxq.dll) - C:\WINDOWS\system32\gmmaxq.dll ()
O20 - AppInit_DLLs: (rsrjon.dll sdbgyy.dll lqunfg.dll) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\pmnkHyVn: DllName - pmnkHyVn.dll - File not found
O20 - Winlogon\Notify\WBSrv: DllName - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll - C:\Program Files\Stardock\Object Desktop\WindowBlinds\WbSrv.dll (Stardock)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O29 - HKLM SecurityProviders - ( digeste.dll) - File not found
O30 - LSA: Authentication Packages - (C:\WINDOWS\system32\pmnoNHBQ) - File not found
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O33 - MountPoints2\{5790b52e-e98f-11dc-a99f-00142a8ea364}\Shell\AutoRun\command - "" = F:\system\viewer\FlipVideoforPC.exe – File not found
O33 - MountPoints2\{5790b52e-e98f-11dc-a99f-00142a8ea364}\Shell\Flip Video for PC\command - "" = F:\system\viewer\FlipVideoforPC.exe – File not found
========== Files/Folders - Created Within 30 Days ==========
[4 C:\WINDOWS\*.tmp files]
[2009/02/04 20:18:51 | 00,000,552 | —- | C] () – C:\WINDOWS\System32\d3d8caps.dat
[2009/02/04 20:14:46 | 00,000,000 | -HSD | C] – C:\WINDOWS\CSC
[2009/02/04 18:02:52 | 00,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2009/02/04 17:57:12 | 00,000,000 | —D | C] – C:\_OTListIt
[2009/02/04 15:27:20 | 00,001,734 | —- | C] () – C:\Documents and Settings\Kate\Desktop\HijackThis.lnk
[2009/02/04 15:27:20 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/02/04 15:25:53 | 00,000,000 | —D | C] – C:\WINDOWS\Backup
[2009/02/04 15:25:20 | 00,000,767 | —- | C] () – C:\Documents and Settings\Kate\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/02/04 15:25:05 | 00,000,592 | —- | C] () – C:\Documents and Settings\Kate\Desktop\ERUNT.lnk
[2009/02/04 15:25:04 | 00,000,000 | —D | C] – C:\Program Files\ERUNT
[2009/02/03 23:39:31 | 00,000,120 | -HS- | C] () – C:\WINDOWS\System32\djnldfnu.ini
[2009/02/03 23:39:30 | 00,072,704 | —- | C] () – C:\WINDOWS\System32\unfdlnjd.dll
[2009/02/03 23:36:32 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\lqunfg.dll
[2009/02/03 23:36:31 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\hjjalfxi.dll
[2009/02/03 23:06:38 | 00,000,120 | -HS- | C] () – C:\WINDOWS\System32\lfepeomv.ini
[2009/02/03 23:03:37 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\sdbgyy.dll
[2009/02/03 23:03:35 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\jxgqeqdh.dll
[2009/02/02 23:14:02 | 00,001,709 | —- | C] () – C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/02/02 23:14:01 | 00,023,152 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2009/02/02 23:13:59 | 00,050,864 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswTdi.sys
[2009/02/02 23:13:56 | 00,026,944 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aavmker4.sys
[2009/02/02 23:13:48 | 00,097,480 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\AvastSS.scr
[2009/02/02 23:13:37 | 00,111,184 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2009/02/02 23:13:37 | 00,020,560 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2009/02/02 23:13:35 | 00,094,032 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon2.sys
[2009/02/02 23:13:35 | 00,093,296 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon.sys
[2009/02/02 23:13:16 | 01,236,208 | —- | C] (ALWIL Software) – C:\WINDOWS\System32\aswBoot.exe
[2009/02/02 23:13:16 | 01,060,864 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\MFC71.dll
[2009/02/02 23:13:16 | 00,380,928 | —- | C] () – C:\WINDOWS\System32\actskin4.ocx
[2009/02/02 23:13:14 | 00,000,000 | —D | C] – C:\Program Files\Alwil Software
[2009/02/02 23:03:12 | 00,000,120 | -HS- | C] () – C:\WINDOWS\System32\cyxlcxjg.ini
[2009/02/02 23:03:09 | 00,072,704 | —- | C] () – C:\WINDOWS\System32\gjxclxyc.dll
[2009/02/02 23:00:53 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\yeagxa.dll
[2009/02/02 23:00:52 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\omkpkfjq.dll
[2009/02/02 15:43:42 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\rsrjon.dll
[2009/02/02 15:43:40 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\xhbkrflg.dll
[2009/02/02 15:41:05 | 00,000,120 | -HS- | C] () – C:\WINDOWS\System32\uyymbjdo.ini
[2009/02/02 15:40:59 | 00,072,704 | —- | C] () – C:\WINDOWS\System32\odjbmyyu.dll
[2009/01/30 10:26:21 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\duictg.dll
[2009/01/30 10:26:19 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\swdtmcsb.dll
[2009/01/30 08:04:38 | 00,072,704 | —- | C] () – C:\WINDOWS\System32\eepcfmpr.dll
[2009/01/30 08:01:42 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\gmmaxq.dll
[2009/01/30 08:01:40 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\egunlrtl.dll
[2009/01/28 21:24:04 | 00,072,704 | —- | C] () – C:\WINDOWS\System32\anljcqem.dll
[2009/01/28 21:22:10 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\tminnq.dll
[2009/01/28 21:22:07 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\heojtrfw.dll
[2009/01/27 21:40:44 | 00,228,520 | —- | C] () – C:\Documents and Settings\Kate\My Documents\WoWScrnShot_012709_213936.jpg
[2009/01/27 21:09:07 | 00,072,704 | —- | C] () – C:\WINDOWS\System32\khgqcspi.dll
[2009/01/27 21:07:34 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\yijzch.dll
[2009/01/27 21:07:32 | 00,129,024 | —- | C] () – C:\WINDOWS\System32\ovelebdv.dll
[2009/01/25 21:36:49 | 00,002,509 | —- | C] () – C:\Documents and Settings\Kate\Desktop\MS Word.lnk
[2009/01/24 21:03:49 | 00,000,000 | —D | C] – C:\Documents and Settings\Kate\Application Data\cogad
[2009/01/24 21:02:02 | 00,198,730 | —- | C] () – C:\WINDOWS\System32\wpv761232809034.cpx
[2009/01/20 00:38:22 | 00,000,000 | —D | C] – C:\Documents and Settings\Kate\Local Settings\Application Data\WMTools Downloaded Files
========== Files - Modified Within 30 Days ==========
[2 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[2009/02/09 14:45:50 | 00,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/02/09 14:44:59 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/02/09 06:51:40 | 04,254,480 | -H– | M] () – C:\Documents and Settings\Kate\Local Settings\Application Data\IconCache.db
[2009/02/08 22:46:41 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/02/07 09:25:50 | 00,002,626 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2009/02/04 20:18:51 | 00,000,552 | —- | M] () – C:\WINDOWS\System32\d3d8caps.dat
[2009/02/04 15:27:20 | 00,001,734 | —- | M] () – C:\Documents and Settings\Kate\Desktop\HijackThis.lnk
[2009/02/04 15:25:20 | 00,000,767 | —- | M] () – C:\Documents and Settings\Kate\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/02/04 15:25:05 | 00,000,592 | —- | M] () – C:\Documents and Settings\Kate\Desktop\ERUNT.lnk
[2009/02/04 14:32:41 | 00,293,398 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/02/04 14:32:29 | 00,293,398 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090204-143241.backup
[2009/02/04 12:09:18 | 00,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/02/03 23:39:35 | 00,000,120 | -HS- | M] () – C:\WINDOWS\System32\djnldfnu.ini
[2009/02/03 23:39:30 | 00,072,704 | —- | M] () – C:\WINDOWS\System32\unfdlnjd.dll
[2009/02/03 23:36:31 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\lqunfg.dll
[2009/02/03 23:36:31 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\hjjalfxi.dll
[2009/02/03 23:06:38 | 00,000,120 | -HS- | M] () – C:\WINDOWS\System32\lfepeomv.ini
[2009/02/03 23:03:36 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\sdbgyy.dll
[2009/02/03 23:03:36 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\jxgqeqdh.dll
[2009/02/03 20:20:00 | 00,248,320 | -HS- | M] () – C:\Documents and Settings\Kate\My Documents\Thumbs.db
[2009/02/02 23:14:02 | 00,001,709 | —- | M] () – C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/02/02 23:03:12 | 00,000,120 | -HS- | M] () – C:\WINDOWS\System32\cyxlcxjg.ini
[2009/02/02 23:03:10 | 00,072,704 | —- | M] () – C:\WINDOWS\System32\gjxclxyc.dll
[2009/02/02 23:00:53 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\yeagxa.dll
[2009/02/02 23:00:53 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\omkpkfjq.dll
[2009/02/02 15:43:40 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\xhbkrflg.dll
[2009/02/02 15:43:40 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\rsrjon.dll
[2009/02/02 15:41:05 | 00,000,120 | -HS- | M] () – C:\WINDOWS\System32\uyymbjdo.ini
[2009/02/02 15:40:59 | 00,072,704 | —- | M] () – C:\WINDOWS\System32\odjbmyyu.dll
[2009/01/30 14:58:16 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/01/30 11:45:12 | 00,000,093 | —- | M] () – C:\WINDOWS\wininit.ini
[2009/01/30 10:46:38 | 00,293,256 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090204-143228.backup
[2009/01/30 10:46:16 | 00,293,256 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090130-104638.backup
[2009/01/30 10:45:37 | 00,293,256 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090130-104616.backup
[2009/01/30 10:26:20 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\swdtmcsb.dll
[2009/01/30 10:26:20 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\duictg.dll
[2009/01/30 08:04:39 | 00,072,704 | —- | M] () – C:\WINDOWS\System32\eepcfmpr.dll
[2009/01/30 08:01:41 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\gmmaxq.dll
[2009/01/30 08:01:41 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\egunlrtl.dll
[2009/01/28 21:24:05 | 00,072,704 | —- | M] () – C:\WINDOWS\System32\anljcqem.dll
[2009/01/28 21:22:08 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\tminnq.dll
[2009/01/28 21:22:08 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\heojtrfw.dll
[2009/01/27 21:39:37 | 00,228,520 | —- | M] () – C:\Documents and Settings\Kate\My Documents\WoWScrnShot_012709_213936.jpg
[2009/01/27 21:09:08 | 00,072,704 | —- | M] () – C:\WINDOWS\System32\khgqcspi.dll
[2009/01/27 21:07:33 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\yijzch.dll
[2009/01/27 21:07:33 | 00,129,024 | —- | M] () – C:\WINDOWS\System32\ovelebdv.dll
[2009/01/25 21:36:49 | 00,002,509 | —- | M] () – C:\Documents and Settings\Kate\Desktop\MS Word.lnk
[2009/01/24 21:02:03 | 00,198,730 | —- | M] () – C:\WINDOWS\System32\wpv761232809034.cpx
[2009/01/20 15:00:34 | 00,091,648 | —- | M] () – C:\Documents and Settings\Kate\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/01/14 22:26:17 | 00,231,184 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
========== LOP Check ==========
[2009/02/02 22:57:40 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/12/25 12:34:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2008/08/07 00:36:01 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2007/05/23 22:14:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2007/12/20 20:25:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2008/02/16 21:46:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL Downloads
[2006/12/09 16:23:09 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL OCP
[2007/06/30 23:31:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2006/10/01 23:44:57 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/02/02 22:57:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg8
[2007/08/24 23:55:01 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2008/05/11 23:53:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2007/12/25 12:34:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Line 6
[2008/02/11 23:29:40 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2006/12/07 22:41:49 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Move Networks
[2009/02/02 15:40:58 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/02/04 12:46:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/11/08 06:26:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2006/06/28 18:51:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2009/02/02 22:33:21 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Kate\Application Data
[2007/12/20 20:27:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\acccore
[2008/11/20 21:01:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\Adobe
[2008/05/06 19:14:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\AdobeUM
[2007/12/20 20:10:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\Aim
[2008/12/25 19:27:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\Apple Computer
[2007/04/02 20:57:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\ArcSoft
[2009/02/02 23:40:18 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\cogad
[2008/03/20 19:59:09 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\FastStone
[2009/01/20 04:06:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\FrostWire
[2006/07/12 11:04:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\Google
[2007/04/02 17:54:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\gtk-2.0
[2006/06/20 15:45:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\Help
[2006/05/10 20:42:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\Identities
[2007/12/25 12:34:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\Line 6
[2006/10/16 22:35:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\Macromedia
[2009/02/02 22:55:22 | 00,000,000 | –SD | M] – C:\Documents and Settings\Kate\Application Data\Microsoft
[2008/02/16 21:42:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\Mozilla
[2007/10/27 14:15:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\Nvu
[2008/11/08 06:24:28 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\Real
[2006/07/01 10:21:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\Sun
[2008/02/11 23:32:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\Template
[2008/11/08 06:26:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Kate\Application Data\Viewpoint
[2009/01/30 14:58:16 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2008/11/19 18:00:00 | 00,000,286 | —- | M] () – C:\WINDOWS\Tasks\AVG Free Edition Test Center.job
[2004/08/04 07:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/02/08 22:46:41 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 0 bytes -> C:\Documents and Settings\Kate\My Documents\Thumbs.db:encryptable
< End of report >
Extras.txt :
OTListIt Extras logfile created on: 2/9/2009 3:10:43 PM - Run
OTListIt2 by OldTimer - Version 2.0.0.10 Folder = C:\EXE & ZIP\HijackThis
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
478.48 Mb Total Physical Memory | 107.17 Mb Available Physical Memory | 22.40% Memory free
1.10 Gb Paging File | 0.87 Gb Available in Paging File | 79.52% Paging File free
Paging file location(s): C:\pagefile.sys 720 1440;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 152.66 Gb Total Space | 115.23 Gb Free Space | 75.48% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 76.33 Gb Total Space | 53.86 Gb Free Space | 70.57% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: N-F6908F5DF7D04
Current User Name: Kate
Logged in as Administrator.
Current Boot Mode: SafeMode with Networking
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.chm [@ = chm.file] – C:\WINDOWS\hh.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\WINDOWS\system32\winhlp32.exe (Microsoft Corporation)
.hta [@ = htafile] – C:\WINDOWS\system32\mshta.exe (Microsoft Corporation)
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox 3 Beta 3\firefox.exe (Mozilla Corporation)
.inf [@ = inffile] – C:\WINDOWS\system32\notepad.exe (Microsoft Corporation)
.ini [@ = inifile] – C:\WINDOWS\system32\notepad.exe (Microsoft Corporation)
.js [@ = JSFile] – C:\WINDOWS\system32\wscript.exe (Microsoft Corporation)
.jse [@ = JSEFile] – C:\WINDOWS\system32\wscript.exe (Microsoft Corporation)
.reg [@ = regfile] – C:\WINDOWS\regedit.exe (Microsoft Corporation)
.txt [@ = txtfile] – C:\WINDOWS\system32\notepad.exe (Microsoft Corporation)
.vbe [@ = VBEFile] – C:\WINDOWS\system32\wscript.exe (Microsoft Corporation)
.vbs [@ = VBSFile] – C:\WINDOWS\system32\wscript.exe (Microsoft Corporation)
.wsf [@ = WSFFile] – C:\WINDOWS\system32\wscript.exe (Microsoft Corporation)
.wsh [@ = WSHFile] – C:\WINDOWS\system32\wscript.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger (America Online, Inc.)
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox (Mozilla Corporation)
C:\StubInstaller.exe:*:Enabled:LimeWire swarmed installer File not found
C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire File not found
C:\Program Files\Java\jre1.5.0_08\bin\javaw.exe:*:Enabled:Java™ 2 Platform Standard Edition binary File not found
C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader (AOL LLC)
C:\Program Files\Common Files\AOL\1159050899\ee\aolsoftware.exe:*:Enabled:AOL Services File not found
C:\Program Files\Common Files\AOL\1159050899\ee\aim6.exe:*:Enabled:AIM File not found
C:\Program Files\Java\jre1.5.0_09\bin\javaw.exe:*:Enabled:Java™ 2 Platform Standard Edition binary File not found
C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger (America Online, Inc.)
C:\Program Files\Java\jre1.5.0_10\bin\javaw.exe:*:Enabled:Java™ 2 Platform Standard Edition binary File not found
C:\Program Files\Common Files\AOL\1166939575\ee\aolsoftware.exe:*:Enabled:AOL Services (America Online, Inc.)
C:\Program Files\Common Files\AOL\1166939575\ee\aim6.exe:*:Enabled:AIM (America Online, Inc.)
C:\Program Files\Java\jre1.5.0_11\bin\javaw.exe:*:Enabled:Java™ 2 Platform Standard Edition binary File not found
C:\Program Files\FrostWire\FrostWire.exe:*:Enabled:LimeWire File not found
E:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire File not found
E:\Program Files\FrostWire\FrostWire.exe:*:Enabled:LimeWire (FrostWire Group)
C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM (AOL LLC)
C:\Program Files\Mozilla Firefox 3 Beta 3\firefox.exe:*:Enabled:Firefox (Mozilla Corporation)
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\WINDOWS\system32\mmc.exe:*:Enabled:Microsoft Management Console (Microsoft Corporation)
C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour (Apple Inc.)
C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes (Apple Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{26A24AE4-039D-4CA4-87B4-2F83216010FF}" = Java™ 6 Update 10
"{318AB667-3230-41B5-A617-CB3BF748D371}" = iTunes
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3D047C15-C859-45F7-81CE-F2681778069B}" = iPod for Windows 2006-01-10
"{43602F34-1AA3-44FB-AEB2-D08C2C73743F}" = Paint.NET v3.36
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{764D06D8-D8DE-411E-A1C8-D9E9380F8A84}" = Microsoft Works 7.0
"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}" = Bonjour
"{8DC42D05-680B-41B0-8878-6C14D24602DB}" = QuickTime
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{9A00D1BA-D03A-44E5-AF28-86A1F377DF61}" = The Sims Makin' Magic
"{A8B94669-8654-4126-BD28-D0D2412CDED6}" = TI Connect 1.6
"{AC76BA86-7AD7-1033-7B44-A70900000002}" = Adobe Reader 7.0.9
"{B1591C79-1C35-4E09-AA15-F7D6923AFB96}" = HP Deskjet 3840
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}" = HP Update
"{EC4455AB-F155-4CC1-A4C5-88F3777F9886}" = Apple Mobile Device Support
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"3ivx MPEG-4 5.0.1 Decoder" = 3ivx MPEG-4 5.0.1 Decoder (remove only)
"Adobe Flash Player Plugin" = Adobe Flash Player Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"AdobeESD" = Adobe Download Manager 2.2 (Remove Only)
"AIM_6" = AIM 6
"All ATI Software" = ATI - Software Uninstall Utility
"AOL Uninstaller" = AOL Uninstaller (Choose which Products to Remove)
"ATI Display Driver" = ATI Display Driver
"avast!" = avast! Antivirus
"ERUNT_is1" = ERUNT 1.1j
"FrostWire" = FrostWire 4.17.2
"HijackThis" = HijackThis 1.99.1
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{3D047C15-C859-45F7-81CE-F2681778069B}" = iPod for Windows 2006-01-10
"Mozilla Firefox (3.0.6)" = Mozilla Firefox (3.0.6)
"Network Play System (Patching)" = Network Play System (Patching)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"SpywareBlaster_is1" = SpywareBlaster 4.0
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"WIC" = Windows Imaging Component
"WindowBlinds" = WindowBlinds
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0 (Beta2)
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 1/27/2009 10:45:42 PM | Computer Name = N-F6908F5DF7D04 | Source = Application Hang | ID = 1002
Description = Hanging application TeaTimer.exe, version 1.5.2.16, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 1/27/2009 10:45:48 PM | Computer Name = N-F6908F5DF7D04 | Source = Application Hang | ID = 1002
Description = Hanging application TeaTimer.exe, version 1.5.2.16, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 2/3/2009 3:55:17 PM | Computer Name = N-F6908F5DF7D04 | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.0.3306, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 2/4/2009 6:59:31 PM | Computer Name = N-F6908F5DF7D04 | Source = Application Hang | ID = 1002
Description = Hanging application OTListIt22.exe, version 2.0.0.5, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 2/4/2009 8:31:50 PM | Computer Name = N-F6908F5DF7D04 | Source = Application Hang | ID = 1002
Description = Hanging application OTListIt22.exe, version 2.0.0.5, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 2/4/2009 8:42:53 PM | Computer Name = N-F6908F5DF7D04 | Source = Application Hang | ID = 1002
Description = Hanging application OTListIt22.exe, version 2.0.0.5, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 2/5/2009 8:12:55 PM | Computer Name = N-F6908F5DF7D04 | Source = Application Hang | ID = 1002
Description = Hanging application aim6.exe, version 1.4.9.1, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 2/5/2009 8:12:57 PM | Computer Name = N-F6908F5DF7D04 | Source = Application Hang | ID = 1002
Description = Hanging application aim6.exe, version 1.4.9.1, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 2/7/2009 10:24:20 AM | Computer Name = N-F6908F5DF7D04 | Source = Application Hang | ID = 1002
Description = Hanging application OTListIt22.exe, version 2.0.0.5, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 2/7/2009 10:31:44 AM | Computer Name = N-F6908F5DF7D04 | Source = Application Hang | ID = 1002
Description = Hanging application OTListIt22.exe, version 2.0.0.5, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
[ System Events ]
Error - 2/8/2009 11:48:49 PM | Computer Name = N-F6908F5DF7D04 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 2/8/2009 11:50:00 PM | Computer Name = N-F6908F5DF7D04 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Aavmker4 aswSP Fips Processor
Error - 2/9/2009 7:47:45 AM | Computer Name = N-F6908F5DF7D04 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 2/9/2009 7:48:44 AM | Computer Name = N-F6908F5DF7D04 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Aavmker4 aswSP Fips Processor
Error - 2/9/2009 7:51:45 AM | Computer Name = N-F6908F5DF7D04 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 2/9/2009 3:46:07 PM | Computer Name = N-F6908F5DF7D04 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 2/9/2009 3:46:44 PM | Computer Name = N-F6908F5DF7D04 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Aavmker4 aswSP Fips Processor
Error - 2/9/2009 3:51:06 PM | Computer Name = N-F6908F5DF7D04 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 2/9/2009 3:51:24 PM | Computer Name = N-F6908F5DF7D04 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 2/9/2009 4:09:51 PM | Computer Name = N-F6908F5DF7D04 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
< End of report >