hello, sorry it took so long for a response. This is the result of the OTListIt scan (It only opened 1 notepad window) Thank you so much:
OTListIt logfile created on: 2/9/2009 2:11:46 AM - Run 3
OTListIt2 by OldTimer - Version 2.0.0.9 Folder = C:\Documents and Settings\Lane 8\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
511.37 Mb Total Physical Memory | 54.77 Mb Available Physical Memory | 10.71% Memory free
1.22 Gb Paging File | 0.65 Gb Available in Paging File | 52.99% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 51.67 Gb Total Space | 16.74 Gb Free Space | 32.40% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: CHRIS
Current User Name: Lane 8
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
PRC - C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
PRC - C:\WINDOWS\system32\LEXBCES.EXE (Lexmark International, Inc.)
PRC - C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (America Online, Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\AskBarDis\bar\bin\AskService.exe ()
PRC - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe ()
PRC - C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
PRC - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
PRC - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
PRC - C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe (Dell Inc.)
PRC - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
PRC - C:\Program Files\Dantz\Retrospect Express HD\retrorun.exe (Dantz Development Corporation)
PRC - C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe (Symantec Corporation)
PRC - C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\wuauclt.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\1XConfig.exe (Intel)
PRC - C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (Intel Corporation)
PRC - C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
PRC - C:\Program Files\Dell\Media Experience\PCMService.exe (CyberLink Corp.)
PRC - C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe (CyberLink Corp.)
PRC - C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe (Musicmatch Inc.)
PRC - C:\WINDOWS\system32\dla\tfswctrl.exe (Sonic Solutions)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\Symantec Client Security\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
PRC - C:\Program Files\Apoint\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Symantec Client Security\Symantec AntiVirus\DoScan.exe (Symantec Corporation)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\Maxtor\OneTouch\Utils\OneTouch.exe (Maxtor Corporation)
PRC - C:\Documents and Settings\Lane 8\Local Settings\Temp\{231F68F4-70E4-41A6-BEDA-7E7934169B54}\mxoaldr.exe (Cypress Semiconductor)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\frmwrk32.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\LEXPPS.EXE (Lexmark International, Inc.)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Documents and Settings\Lane 8\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (Google Inc.)
PRC - C:\Program Files\Dell Photo Printer 720\dlbcserv.exe ()
PRC - C:\WINDOWS\system32\regsvr32.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MpCmdRun.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Lane 8\Desktop\OTListIt22.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (AOL ACS [Auto | Running]) – C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (America Online, Inc.)
SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (ASKService [Auto | Running]) – C:\Program Files\AskBarDis\bar\bin\AskService.exe ()
SRV - (ASKUpgrade [Auto | Running]) – C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe ()
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Running]) – C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
SRV - (ccEvtMgr [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
SRV - (ccProxy [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\ccProxy.exe (Symantec Corporation)
SRV - (ccPwdSvc [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (Symantec Corporation)
SRV - (ccSetMgr [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (DefWatch [Auto | Running]) – C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
SRV - (dlbu_device [On_Demand | Stopped]) – C:\WINDOWS\system32\dlbucoms.exe (Dell)
SRV - (DSBrokerService [On_Demand | Stopped]) – C:\Program Files\DellSupport\brkrsvc.exe ()
SRV - (EvtEng [Auto | Running]) – C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
SRV - (gusvc [Auto | Running]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (ISSVC [Auto | Running]) – C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe (Symantec Corporation)
SRV - (LexBceS [Auto | Running]) – C:\WINDOWS\system32\LEXBCES.EXE (Lexmark International, Inc.)
SRV - (MDM [Auto | Running]) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (NICCONFIGSVC [Auto | Running]) – C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe (Dell Inc.)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (RegSrvc [Auto | Running]) – C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
SRV - (RetroExpLauncher [Auto | Running]) – C:\Program Files\Dantz\Retrospect Express HD\retrorun.exe (Dantz Development Corporation)
SRV - (S24EventMonitor [Auto | Running]) – C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
SRV - (SavRoam [On_Demand | Stopped]) – C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe (symantec)
SRV - (SNDSrvc [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (SPBBCSvc [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
SRV - (Symantec AntiVirus [Auto | Running]) – C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (SymSecurePort [Auto | Running]) – C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe (Symantec Corporation)
SRV - (UMWdf [Auto | Running]) – C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
SRV - (WinDefend [Auto | Running]) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (WLANKEEPER [Auto | Running]) – C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
========== Driver Services (SafeList) ==========
DRV - (AegisP [Auto | Running]) – C:\WINDOWS\system32\drivers\AegisP.sys (Meetinghouse Data Communications)
DRV - (AliIde [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\AMDAGP.SYS (Advanced Micro Devices, Inc.)
DRV - (ApfiltrService [On_Demand | Running]) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (APPDRV [System | Running]) – C:\WINDOWS\system32\drivers\APPDRV.SYS (Dell Inc)
DRV - (asc [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\asc3550.sys (Advanced System Products, Inc.)
DRV - (ati2mtag [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (bcm4sbxp [On_Demand | Running]) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (BVRPMPR5 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\BVRPMPR5.SYS (Avanquest Software)
DRV - (CmdIde [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (dac2w2k [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\dac2w2k.sys (Mylex Corporation)
DRV - (drvmcdb [Boot | Running]) – C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (drvnddm [Auto | Running]) – C:\WINDOWS\system32\drivers\drvnddm.sys (Sonic Solutions)
DRV - (DSproct [On_Demand | Stopped]) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (dsunidrv [Auto | Running]) – C:\WINDOWS\system32\drivers\dsunidrv.sys (Gteko Ltd.)
DRV - (E100B [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\e100b325.sys (Intel Corporation)
DRV - (eeCtrl [System | Running]) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HSFHWICH [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HSFHWICH.sys (Conexant Systems, Inc.)
DRV - (HSF_DP [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (IWCA [On_Demand | Running]) – C:\WINDOWS\system32\drivers\iwca.sys (Intel Corporation)
DRV - (mdmxsdk [Auto | Running]) – C:\WINDOWS\system32\drivers\mdmxsdk.sys (Conexant)
DRV - (mraid35x [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\mraid35x.sys (American Megatrends Inc.)
DRV - (MXOFX [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\MXOFX.SYS (Cypress Semiconductor)
DRV - (MXOPSWD [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\mxopswd.sys (Maxtor Corp.)
DRV - (NAVENG [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090208.016\naveng.sys (Symantec Corporation)
DRV - (NAVEX15 [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090208.016\navex15.sys (Symantec Corporation)
DRV - (nv [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (omci [System | Running]) – C:\WINDOWS\system32\drivers\omci.sys (Dell Inc)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\system32\drivers\pxhelp20.sys (Sonic Solutions)
DRV - (ql1080 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\ql1080.sys (QLogic Corporation)
DRV - (ql12160 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\ql12160.sys (QLogic Corporation)
DRV - (ql1280 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\ql1280.sys (QLogic Corporation)
DRV - (s24trans [Auto | Running]) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (SAVRT [System | Running]) – C:\Program Files\Symantec Client Security\Symantec AntiVirus\savrt.sys (Symantec Corporation)
DRV - (SAVRTPEL [System | Running]) – C:\Program Files\Symantec Client Security\Symantec AntiVirus\Savrtpel.sys (Symantec Corporation)
DRV - (sdbus [On_Demand | Running]) – C:\WINDOWS\system32\drivers\sdbus.sys (Microsoft Corporation)
DRV - (Secdrv [Auto | Running]) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sisagp [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\SISAGP.SYS (Silicon Integrated Systems Corporation)
DRV - (SONYPVU1 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\SONYPVU1.SYS (Sony Corporation)
DRV - (Sparrow [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\sparrow.sys (Adaptec, Inc.)
DRV - (SPBBCDrv [On_Demand | Stopped]) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (sscdbhk5 [System | Running]) – C:\WINDOWS\system32\drivers\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln [System | Running]) – C:\WINDOWS\system32\drivers\ssrtln.sys (Sonic Solutions)
DRV - (STAC97 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\STAC97.sys (SigmaTel, Inc.)
DRV - (symc810 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\symc810.sys (Symbios Logic Inc.)
DRV - (symc8xx [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (SYMDNS [On_Demand | Running]) – C:\WINDOWS\system32\drivers\symdns.sys (Symantec Corporation)
DRV - (SymEvent [On_Demand | Running]) – C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
DRV - (SYMFW [On_Demand | Running]) – C:\WINDOWS\system32\drivers\symfw.sys (Symantec Corporation)
DRV - (SYMIDS [On_Demand | Running]) – C:\WINDOWS\system32\drivers\symids.sys (Symantec Corporation)
DRV - (SYMIDSCO [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\SymcData\scfidsdefs\20090129.001\SymIDSCo.sys (Symantec Corporation)
DRV - (SYMNDIS [On_Demand | Running]) – C:\WINDOWS\system32\drivers\symndis.sys (Symantec Corporation)
DRV - (SYMREDRV [On_Demand | Running]) – C:\WINDOWS\system32\drivers\symredrv.sys (Symantec Corporation)
DRV - (SYMTDI [System | Running]) – C:\WINDOWS\system32\drivers\symtdi.sys (Symantec Corporation)
DRV - (sym_hi [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (sym_u3 [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (tfsnboio [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsncofs [Auto | Running]) – C:\WINDOWS\system32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsndrct [Auto | Running]) – C:\WINDOWS\system32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres [Auto | Running]) – C:\WINDOWS\system32\dla\tfsndres.sys (Sonic Solutions)
DRV - (tfsnifs [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsnopio [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsnudf [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnudfa [Auto | Running]) – C:\WINDOWS\system32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (ultra [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\ultra.sys (Promise Technology, Inc.)
DRV - (USBAAPL [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\usbaapl.sys (Apple, Inc.)
DRV - (usbaudio [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (usbvideo [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\usbvideo.sys (Microsoft Corporation)
DRV - (w29n51 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\w29n51.sys (Intel® Corporation)
DRV - (wanatw [On_Demand | Running]) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (winachsf [On_Demand | Running]) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (WS2IFSL [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\ws2ifsl.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.microsoft.com/isapi/redir.dll?p…ER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
IE - URLSearchHook: {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: () - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll (MyWay.com)
O2 - BHO: (TBSB05288 Class) - {6714ADBD-C6C1-42A8-BD84-9C9339059421} - C:\Program Files\IEToolbar\ECO Bar\ecobar.dll ()
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll (Google Inc.)
O2 - BHO: (no name) - {C0D38F0E-BFF2-4229-B046-0BBDA652E70E} - C:\WINDOWS\system\gvayss.dll File not found
O2 - BHO: (adsoftinc browser enhancer) - {C5784472-D42E-72C7-08FA-C41D78C8EF85} - C:\WINDOWS\system32\oqrjoisockpwi.dll ()
O3 - HKLM\..\Toolbar: (ECO Bar) - {10000000-1000-1000-1000-100000000000} - C:\Program Files\IEToolbar\ECO Bar\ecobar.dll ()
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (Radio) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {10000000-1000-1000-1000-100000000000} - C:\Program Files\IEToolbar\ECO Bar\ecobar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {F0993251-2512-4710-AF6E-0A13EA199D02} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" (Symantec Corporation)
O4 - HKLM..\Run: [DeadAIM] rundll32.exe "C:\Program Files\AIM\\DeadAIM.ocm",ExportedCheckODLs (Microsoft Corporation)
O4 - HKLM..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe" (Dell Computer Corporation)
O4 - HKLM..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe (Sonic Solutions)
O4 - HKLM..\Run: [DLBUCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBUtime.dll,_RunDLLEntry@16 ()
O4 - HKLM..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [fjysdhttvrn] C:\WINDOWS\System32\regsvr32.exe /s "C:\WINDOWS\system32\oqrjoisockpwi.dll" (Microsoft Corporation)
O4 - HKLM..\Run: [Framework Windows] frmwrk32.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless (Intel Corporation)
O4 - HKLM..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start (InstallShield Software Corporation)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [MaxtorOneTouch] C:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe (Maxtor Corporation)
O4 - HKLM..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe (Musicmatch Inc.)
O4 - HKLM..\Run: [MXOBG] C:\Documents and Settings\Lane 8\Local Settings\Temp\{231F68F4-70E4-41A6-BEDA-7E7934169B54}\MXOALDR.EXE (Cypress Semiconductor)
O4 - HKLM..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [RetroExpress] C:\PROGRA~1\Dantz\RETROS~1\RetroExpress.exe /h (Dantz Development Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)
O4 - HKLM..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe (Symantec Corporation)
O4 - HKLM..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide (Microsoft Corporation)
O4 - HKCU..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h File not found
O4 - HKCU..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup (Gteko Ltd.)
O4 - HKCU..\Run: [Google Update] "C:\Documents and Settings\Lane 8\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c (Google Inc.)
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKLM..\RunServices: [Microsoft Windows DLL Services Configuration] windir32.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe (America Online, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\dlbcserv.lnk = C:\Program Files\Dell Photo Printer 720\dlbcserv.exe ()
O4 - Startup: C:\Documents and Settings\Lane 8\Start Menu\Programs\Startup\Clean Access Agent.lnk = C:\Program Files\Cisco Systems\Clean Access Agent\CCAAgentLauncher.exe (Cisco Systems, Inc.)
O4 - Startup: C:\Documents and Settings\Lane 8\Start Menu\Programs\Startup\p2pmax.lnk = C:\Program Files\p2pmax\p2pmax.exe (BB Inc)
O4 - Startup: C:\Documents and Settings\Lane 8\Start Menu\Programs\Startup\ppcb_32.lnk = C:\Program Files\ppcbooster\ppcb_32.exe ()
O4 - Startup: C:\Documents and Settings\Lane 8\Start Menu\Programs\Startup\runit_32.lnk = C:\Program Files\runit\runit_32.exe (BB Inc)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetActiveDesktop = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 0
O8 - Extra context menu item: &AOL Toolbar Search - res://c:\program files\aol\aol toolbar 2.0\aoltbhtml.dll/search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O9 - Extra Button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (America Online, Inc.)
O9 - Extra Button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe File not found
O9 - Extra 'Tools' menuitem : EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (America Online, Inc.)
O9 - Extra Button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - File not found
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YPager.exe ()
O9 - Extra 'Tools' menuitem : Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YPager.exe ()
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 71 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {001EE746-A1F9-460E-80AD-269E088D6A01}
http://site.ebrary.com.avoserv.library.for…s/ebraryRdr.cab (Infotl Control)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} http://www.musicnotes.com/download/mnviewer.cab (Musicnotes Viewer)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537}
http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase6662.cab (Windows Live Safety Center Base Module)
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3}
http://www.shockwave.com/content/dinerdash…h2.1.0.0.67.cab (CPlayFirstDinerDash2Control Object)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://go.divx.com/plugin/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429}
http://www.sibelius.com/download/software/…tiveXPlugin.cab (ScorchPlugin Class)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://www.popcap.com/games/popcaploader_v6.cab (PopCapLoader Object)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\gvayss: DllName - C:\WINDOWS\system\gvayss.dll - C:\WINDOWS\system\gvayss.dll File not found
O20 - Winlogon\Notify\IntelWireless: DllName - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll (Intel Corporation)
O20 - Winlogon\Notify\mljjh: DllName - C:\WINDOWS\system32\mljjh.dll - C:\WINDOWS\system32\mljjh.dll File not found
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
O20 - Winlogon\Notify\raswave: DllName - C:\WINDOWS\Help\SBSI\raswave.dll - C:\WINDOWS\Help\SBSI\raswave.dll File not found
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O33 - MountPoints2\{22a92702-5b94-11dd-985f-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{22a92702-5b94-11dd-985f-00038a000015}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{22a92702-5b94-11dd-985f-00038a000015}\Shell\AutoRun\command - "" = E:\ONSPCLCK.exe – File not found
O33 - MountPoints2\{58221e37-67bd-11dd-9866-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{58221e37-67bd-11dd-9866-00038a000015}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{58221e37-67bd-11dd-9866-00038a000015}\Shell\AutoRun\command - "" = E:\LaunchU3.exe – File not found
========== Files/Folders - Created Within 30 Days ==========
[4 C:\WINDOWS\System32\*.tmp files]
[2009/02/09 01:55:12 | 00,487,424 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Lane 8\Desktop\OTListIt22.exe
[2009/02/09 01:30:26 | 00,000,000 | —D | C] – C:\Documents and Settings\Lane 8\Desktop\bfu
[2009/02/05 19:39:19 | 00,001,734 | —- | C] () – C:\Documents and Settings\Lane 8\Desktop\HijackThis.lnk
[2009/02/05 19:39:16 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/02/05 19:38:41 | 00,812,344 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Lane 8\My Documents\HJTInstall.exe
[2009/02/05 19:07:22 | 00,000,000 | —D | C] – C:\Program Files\Hijackthis
[2009/02/05 19:06:18 | 00,488,144 | —- | C] (Soeperman Enterprises Ltd ) – C:\Documents and Settings\Lane 8\My Documents\HJTsetup.exe
[2009/02/05 17:06:24 | 00,000,000 | —D | C] – C:\Documents and Settings\Lane 8\Desktop\SmitfraudFix
[2009/02/05 11:12:34 | 53,628,1088 | -HS- | C] () – C:\hiberfil.sys
[2009/02/05 10:58:37 | 00,000,000 | —D | C] – C:\Documents and Settings\Lane 8\My Documents\SmitfraudFix
[2009/02/05 10:22:03 | 00,005,418 | —- | C] () – C:\WINDOWS\System32\tmp.reg
[2009/02/05 10:21:38 | 00,078,336 | —- | C] (S!Ri.URZ) – C:\WINDOWS\System32\Agent.OMZ.Fix.exe
[2009/02/05 10:21:37 | 00,080,384 | —- | C] (S!Ri.URZ) – C:\WINDOWS\System32\o4Patch.exe
[2009/02/05 10:21:36 | 00,087,552 | —- | C] (S!Ri.URZ) – C:\WINDOWS\System32\VACFix.exe
[2009/02/05 10:21:35 | 00,025,600 | —- | C] () – C:\WINDOWS\System32\WS2Fix.exe
[2009/02/05 10:21:34 | 00,289,144 | —- | C] (S!Ri) – C:\WINDOWS\System32\VCCLSID.exe
[2009/02/05 10:21:34 | 00,288,417 | —- | C] (S!Ri) – C:\WINDOWS\System32\SrchSTS.exe
[2009/02/05 10:21:34 | 00,079,360 | —- | C] (SteelWerX) – C:\WINDOWS\System32\swxcacls.exe
[2009/02/05 10:21:34 | 00,051,200 | —- | C] () – C:\WINDOWS\System32\dumphive.exe
[2009/02/05 10:21:33 | 00,135,168 | —- | C] (SteelWerX) – C:\WINDOWS\System32\swreg.exe
[2009/02/05 10:21:33 | 00,053,248 | —- | C] (http://www.beyondlogic.org) – C:\WINDOWS\System32\Process.exe
[2009/02/05 10:21:33 | 00,040,960 | —- | C] () – C:\WINDOWS\System32\swsc.exe
[2009/02/05 10:20:41 | 01,661,611 | —- | C] () – C:\Documents and Settings\Lane 8\My Documents\SmitfraudFix.exe
[2009/02/04 23:55:10 | 00,000,000 | —D | C] – C:\Program Files\Windows Live Safety Center
[2009/02/04 19:45:01 | 00,024,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\userinit.exe
[2009/02/04 19:44:23 | 00,000,001 | —- | C] () – C:\WINDOWS\System32\uniq.tll
[2009/02/04 19:43:58 | 00,024,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\frmwrk32.exe
[2009/01/22 09:53:25 | 00,050,375 | —- | C] () – C:\Documents and Settings\Lane 8\Desktop\l_6c9a8731e1b525d086f42ff4c16a707a.jpg
[2009/01/21 08:35:29 | 00,000,000 | —D | C] – C:\WINDOWS\ie7updates
[2009/01/21 08:33:13 | 00,000,000 | —D | C] – C:\WINDOWS\WBEM
[2009/01/21 08:33:11 | 00,000,000 | —D | C] – C:\WINDOWS\System32\en-US
[2009/01/21 08:31:14 | 00,000,000 | -H-D | C] – C:\WINDOWS\ie7
[2009/01/21 08:30:39 | 00,000,000 | -H-D | C] – C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$
[2009/01/21 08:29:22 | 00,000,000 | -H-D | C] – C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$
[2009/01/21 08:27:05 | 00,121,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xmllite.dll
[2009/01/21 08:20:58 | 00,000,000 | —D | C] – C:\WINDOWS\network diagnostic
[2009/01/21 08:19:14 | 00,459,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeeds.dll
[2009/01/21 08:19:13 | 00,267,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iertutil.dll
[2009/01/21 08:19:13 | 00,052,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2009/01/21 08:19:12 | 00,383,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieapfltr.dll
[2009/01/21 08:19:12 | 00,063,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\icardie.dll
[2009/01/21 08:19:12 | 00,013,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieudinit.exe
[2009/01/21 08:19:11 | 02,455,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieapfltr.dat
[2009/01/21 08:19:11 | 00,991,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll.mui
[2009/01/21 08:19:09 | 06,066,176 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll
[2009/01/21 08:17:01 | 00,000,000 | —D | C] – C:\59251d4b9db2c7c0fbab
[2009/01/21 08:16:49 | 15,452,536 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Lane 8\My Documents\IE7-WindowsXP-x86-enu.exe
[2009/01/16 18:42:12 | 00,001,200 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-4154990965-559821465-4190246901-1007.job
[2009/01/16 18:20:33 | 00,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2009/01/16 18:20:29 | 00,000,000 | —D | C] – C:\Documents and Settings\Lane 8\Application Data\skypePM
[2009/01/16 18:10:13 | 00,000,000 | R–D | C] – C:\Program Files\Skype
[2009/01/16 18:10:01 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Skype
[2009/01/15 13:17:58 | 00,035,328 | —- | C] () – C:\WINDOWS\System32\ztLib.dll
========== Files - Modified Within 30 Days ==========
[4 C:\WINDOWS\System32\*.tmp files]
[2009/02/09 02:06:24 | 00,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/02/09 01:55:33 | 00,487,424 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Lane 8\Desktop\OTListIt22.exe
[2009/02/09 01:47:40 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/02/09 01:45:07 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/02/09 01:44:52 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/02/09 01:44:44 | 53,628,1088 | -HS- | M] () – C:\hiberfil.sys
[2009/02/09 01:41:25 | 00,000,000 | —- | M] () – C:\WINDOWS\dsww06562.exe
[2009/02/09 01:41:21 | 00,000,000 | —- | M] () – C:\WINDOWS\acnq35580.exe
[2009/02/09 01:40:09 | 05,897,174 | -H– | M] () – C:\Documents and Settings\Lane 8\Local Settings\Application Data\IconCache.db
[2009/02/06 08:49:08 | 00,000,040 | —- | M] () – C:\WINDOWS\System32\profile.dat
[2009/02/06 08:34:44 | 00,001,200 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-4154990965-559821465-4190246901-1007.job
[2009/02/05 19:39:19 | 00,001,734 | —- | M] () – C:\Documents and Settings\Lane 8\Desktop\HijackThis.lnk
[2009/02/05 19:39:11 | 00,812,344 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Lane 8\My Documents\HJTInstall.exe
[2009/02/05 19:06:33 | 00,488,144 | —- | M] (Soeperman Enterprises Ltd ) – C:\Documents and Settings\Lane 8\My Documents\HJTsetup.exe
[2009/02/05 17:18:42 | 00,382,260 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/02/05 17:18:42 | 00,053,838 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/02/05 17:18:41 | 00,441,626 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/02/05 10:59:41 | 00,005,418 | —- | M] () – C:\WINDOWS\System32\tmp.reg
[2009/02/05 10:21:10 | 01,661,611 | —- | M] () – C:\Documents and Settings\Lane 8\My Documents\SmitfraudFix.exe
[2009/02/04 19:44:23 | 00,000,001 | —- | M] () – C:\WINDOWS\System32\uniq.tll
[2009/02/04 19:43:51 | 00,024,064 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\frmwrk32.exe
[2009/02/01 16:30:23 | 00,000,000 | —- | M] () – C:\WINDOWS\echp00265.exe
[2009/01/27 18:39:27 | 00,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/01/27 06:32:19 | 00,048,267 | —- | M] () – C:\WINDOWS\System32\wjslqojcykb.exe
[2009/01/23 23:04:04 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/01/23 18:27:44 | 00,302,080 | —- | M] () – C:\WINDOWS\System32\oqrjoisockpwi.dll
[2009/01/22 03:02:05 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/01/21 22:31:29 | 00,050,375 | —- | M] () – C:\Documents and Settings\Lane 8\Desktop\l_6c9a8731e1b525d086f42ff4c16a707a.jpg
[2009/01/21 08:50:40 | 00,000,077 | -HS- | M] () – C:\Documents and Settings\Lane 8\My Documents\desktop.ini
[2009/01/21 08:17:00 | 15,452,536 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Lane 8\My Documents\IE7-WindowsXP-x86-enu.exe
[2009/01/16 18:20:33 | 00,000,056 | -H– | M] () – C:\WINDOWS\System32\ezsidmv.dat
[2009/01/15 13:17:58 | 00,035,328 | —- | M] () – C:\WINDOWS\System32\ztLib.dll
========== LOP Check ==========
[2009/01/16 18:10:01 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/10/17 16:20:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2007/02/11 22:15:49 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2007/02/08 13:22:19 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Age of Empires 3
[2007/04/07 12:16:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ahead
[2006/09/30 23:04:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2007/11/17 10:50:40 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2007/11/17 10:53:55 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/01/01 14:50:03 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Azureus
[2007/06/21 16:27:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BVRP Software
[2005/07/13 11:04:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2008/01/13 11:04:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Dell
[2005/08/29 15:30:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Dell Photo Printer 720
[2009/02/05 00:05:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2009/02/09 01:23:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google Updater
[2005/07/13 11:13:17 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\GTek
[2005/07/13 11:14:05 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InstallShield
[2005/07/13 11:01:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intel
[2005/07/13 11:18:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intuit
[2005/08/28 12:17:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com
[2008/09/04 17:43:40 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2006/12/12 15:23:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2005/09/01 13:47:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2005/07/13 11:17:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2009/02/09 01:29:58 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RetroExp
[2006/11/30 22:35:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2004/08/10 13:13:06 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2009/01/16 18:44:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Skype
[2005/08/17 23:55:12 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2005/07/26 12:04:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Support.com
[2005/08/28 11:45:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2007/04/20 15:16:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2006/10/11 21:09:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Trymedia
[2007/04/20 16:17:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2006/01/15 12:15:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2005/10/21 21:13:54 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2009/02/05 10:59:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data
[2008/10/23 19:10:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\Adobe
[2007/02/11 22:16:35 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\AdobeUM
[2007/04/07 12:26:28 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\Ahead
[2005/10/03 22:40:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\Aim
[2008/07/27 21:44:13 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\Apple Computer
[2009/01/01 21:34:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\Azureus
[2007/02/05 19:49:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\CiscoCAA
[2005/07/19 23:57:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\CyberLink
[2006/12/07 17:25:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\Google
[2008/01/13 11:03:33 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Lane 8\Application Data\Gtek
[2007/10/12 16:04:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\Help
[2004/08/10 13:08:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\Identities
[2005/07/13 11:02:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\Intel
[2005/08/29 15:28:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\Jasc Software Inc
[2005/08/17 23:57:45 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\Lavasoft
[2006/11/26 13:18:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\Leadertech
[2006/10/27 16:08:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\Macromedia
[2008/12/31 15:56:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\MalwareRemoval
[2005/08/17 23:47:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\McAfee.com
[2005/07/28 11:52:51 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\McAfee.com Personal Firewall
[2008/02/02 17:52:47 | 00,000,000 | –SD | M] – C:\Documents and Settings\Lane 8\Application Data\Microsoft
[2009/01/01 15:30:07 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Lane 8\Application Data\Move Networks
[2009/01/20 19:30:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\Mozilla
[2007/08/23 11:45:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\Netscape
[2006/12/12 15:23:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\PlayFirst
[2008/03/21 08:56:59 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\Real
[2008/12/31 15:56:17 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\SetupMalwareRemoval
[2009/01/16 18:20:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\skypePM
[2006/11/26 13:20:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\Sonic
[2005/07/13 11:00:40 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\Sun
[2005/11/29 18:16:55 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\Thunderbird
[2008/08/14 22:23:55 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\U3
[2007/02/24 03:41:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Lane 8\Application Data\Viewpoint
[2009/01/23 23:04:04 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2004/08/04 05:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/02/06 08:34:44 | 00,001,200 | —- | M] () – C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-4154990965-559821465-4190246901-1007.job
[2009/02/09 02:06:24 | 00,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2009/02/09 01:45:07 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
[2005/08/28 12:12:02 | 00,000,366 | —- | M] () – C:\WINDOWS\Tasks\Symantec NetDetect.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 104 bytes -> %AllUsersProfile%\Application Data\TEMP:4295826C
< End of report >