This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Myway.mywebsearch

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hello

1. Please download Brute Force Uninstaller to your desktop.
  • Right click the BFU folder on your desktop, and choose Extract All
  • Click "Next"
  • In the box to choose where to extract the files to,
  • Click "Browse"
  • Click on the + sign next to "My Computer"
  • Click on "Local Disk (C:) or whatever your primary drive is
  • Click "Make New Folder"
  • Type in BFU
  • Click "Next", and Uncheck the "Show Extracted Files" box and then click "Finish".

2. RIGHT-CLICK HERE and choose "Save As" (in IE it's "Save Target/Link As") in order to download MyWebSearch and FunWebProduct Remover .
Save it in the same folder you made earlier (on your desktop).


3. Then, please go to Start > My Computer and navigate to the BFU folder.
  • Start the Brute Force Uninstaller by doubleclicking BFU.exe
  • Behind the scriptline to execute field click the folder icon [external image: Posted Image] and select MyWebSearch.bfu
  • Press Execute and let it do it’s job. (You ought to see a progress bar if you did this correctly.)
  • Wait for the complete script execution box to pop up and press OK.
  • Press exit to terminate the BFU program.

hello

1. Please download Brute Force Uninstaller to your desktop.

  • Right click the BFU folder on your desktop, and choose Extract All
  • Click "Next"
  • In the box to choose where to extract the files to,
  • Click "Browse"
  • Click on the + sign next to "My Computer"
  • Click on "Local Disk (C:) or whatever your primary drive is
  • Click "Make New Folder"
  • Type in BFU
  • Click "Next", and Uncheck the "Show Extracted Files" box and then click "Finish".

2. RIGHT-CLICK HERE and choose "Save As" (in IE it's "Save Target/Link As") in order to download MyWebSearch and FunWebProduct Remover .
Save it in the same folder you made earlier (on your desktop).


3. Then, please go to Start > My Computer and navigate to the BFU folder.
  • Start the Brute Force Uninstaller by doubleclicking BFU.exe
  • Behind the scriptline to execute field click the folder icon [external image: Posted Image] and select MyWebSearch.bfu
  • Press Execute and let it do it’s job. (You ought to see a progress bar if you did this correctly.)
  • Wait for the complete script execution box to pop up and press OK.
  • Press exit to terminate the BFU program.


Thanks but it still seems to find it with spybot.
Hello

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txts will open.
  • Save both reports to your desktop.
—————————————————

Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.

Hello

Please download DDS and save it to your desktop.

  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txts will open.
  • Save both reports to your desktop.
—————————————————

Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


DDS (Ver_09-02-01.01) - NTFSx86
Run by [removed] at 18:18:06.85 on Sun 02/08/2009
Internet Explorer: 7.0.5730.11
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3071.2369 [GMT -5:00]

AV: avast! antivirus 4.8.1296 [VPS 090208-0] *On-access scanning enabled* (Updated)
FW: ZoneAlarm Firewall *enabled*

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Palm\Hotsync.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Webroot\Washer\wwDisp.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Vincenzo\Desktop\dds.pif

============== Pseudo HJT Report ===============

uStart Page = hxxp://sympatico.MSN.ca
uSearch Page =
uSearch Bar =
mStart Page = hxxp://www.sympatico.msn.ca
mSearch Bar =
uInternet Settings,ProxyOverride = *.local
uSearchAssistant =
uCustomizeSearch =
mURLSearchHooks: H - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: SpywareGuardDLBLOCK.CBrowserHelper: {4a368e80-174f-4872-96b5-0b27ddd11db2} - c:\program files\spywareguard\dlprotect.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: EpsonToolBandKicker Class: {e99421fb-68dd-40f0-b4ac-b7027cae2f1a} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
BHO: EWPP - No File
TB: EPSON Web-To-Page: {ee5d279f-081b-4404-994d-c6b60aaeba6d} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
TB: {F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA} - No File
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [EPSON Stylus Photo RX595 Series] c:\windows\system32\spool\drivers\w32x86\3\e_faticla.exe /fu "c:\windows\temp\E_S1DD.tmp" /EF "HKCU"
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil9f.exe
uRunOnce: [Index Washer] c:\program files\webroot\washer\WashIdx.exe "Vincenzo"
mRun: [Logitech Utility] Logi_MwX.Exe
mRun: [TCASUTIEXE] TCAUDIAG.exe -on
mRun: [LtcyCfgApply] "c:\documents and settings\vincenzo\desktop\latency tool pci\LtcyCfg.exe" /a
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
dRun: [Nokia.PCSync] c:\program files\nokia\nokia pc suite 6\PcSync2.exe /NoDialog
StartupFolder: c:\docume~1\vincenzo\startm~1\programs\startup\spywar~1.lnk - c:\program files\spywareguard\sgmain.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hotsyn~1.lnk - c:\program files\palm\Hotsync.exe
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office10\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: bmo.com\www1
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
DPF: {00B71CFB-6864-4346-A978-C0A14556272C} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} - hxxp://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} - hxxp://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} - hxxp://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} - hxxp://support.f-secure.com/ols/fscax.cab
DPF: {0DB074F0-617E-4EE9-912C-2965CF2AA5A4} - hxxp://download.microsoft.com/download/7/0/7/707a44ad-52ad-49af-b7ef-e21b6b0656e4/VirtualEarth3D.cab
DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} - hxxp://downloadcenter.samsung.com/content/common/cab/DjVuControlLite_EN.cab
DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} - hxxp://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - hxxp://www.symantec.com/techsupp/asa/LSSupCtl.cab
DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} - hxxp://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} - hxxp://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} - hxxp://download.yahoo.com/dl/installs/yinst0401.cab
DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} - hxxp://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://by121fd.bay121.hotmail.msn.com/resources/MsnPUpld.cab
DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} - hxxp://files.ea.com/downloads/rtpatch/v2/EARTPX.cab
DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} - hxxp://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1183322733905
DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - hxxp://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1183322725405
DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} - hxxp://chat.yahoo.com/cab/yacsui.cab
DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} - hxxp://download.zonelabs.com/bin/promotions/spywaredetector/ICSScanner37680.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} - hxxp://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} - hxxp://zone.msn.com/bingame/zpagames/zpa_txhe.cab60231.cab
DPF: {AFAB176A-0D25-436A-8555-286F6D7AA388} - hxxp://www.actualresearch.com/files/rfscanax.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - hxxp://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - hxxp://www.adobe.com/products/acrobat/nos/gp.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} - hxxp://zone.msn.com/binframework/v10/StProxy.cab55579.cab
DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - hxxp://driveragent.com/files/driveragent.cab
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SpywareGuard.Handler: {81559c35-8464-49f7-bb0e-07a383bef910} - c:\program files\spywareguard\spywareguard.dll
SEH: CShellExecuteHookImpl Object: {57b86673-276a-48b2-bae7-c6dbb3020eb8} - c:\program files\grisoft\avg anti-spyware 7.5\shellexecutehook.dll
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, xlibgfl254.dll

============= SERVICES / DRIVERS ===============

R0 BsStor;InCD Storage Helper Driver;c:\windows\system32\drivers\bsstor.sys [2003-11-29 9344]
R0 d346bus;d346bus;c:\windows\system32\drivers\d346bus.sys [2004-7-2 156800]
R0 d346prt;d346prt;c:\windows\system32\drivers\d346prt.sys [2004-7-2 5248]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-4-2 111184]
R1 AVG Anti-Spyware Driver;AVG Anti-Spyware Driver;c:\program files\grisoft\avg anti-spyware 7.5\guard.sys [2006-9-28 11000]
R1 AvgAsCln;AVG Anti-Spyware Clean Driver;c:\windows\system32\drivers\AvgAsCln.sys [2007-6-20 3968]
R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2006-3-8 353680]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-4-2 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2007-6-27 155160]
R2 TCAITDI;TCAITDI Protocol;c:\windows\system32\drivers\TCAITDI.SYS [2001-9-4 19534]
R2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service –> c:\windows\system32\zonelabs\vsmon.exe -service [?]
R2 wwEngineSvc;Window Washer Engine;c:\program files\webroot\washer\WasherSvc.exe [2007-9-6 598856]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2007-6-27 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2007-6-27 352920]
R3 chanalog;CH Analog Devices;c:\windows\system32\drivers\chanalog.sys [2007-9-9 30240]
S3 AVG Anti-Spyware Guard;AVG Anti-Spyware Guard;c:\program files\grisoft\avg anti-spyware 7.5\guard.exe [2006-9-28 312880]
S3 fsbl;fsbl; [x]
S4 BsUDF;InCD UDF Driver;c:\windows\system32\drivers\bsudf.sys [2003-11-29 448640]
S4 DeepsightExtractor;Deepsight Extractor;c:\program files\symantec\deepsight extractor\extractorservice.exe –> c:\program files\symantec\deepsight extractor\ExtractorService.exe [?]
S4 ExtractorServiceNPF03;DeepSight Extractor Service for NPF03;c:\program files\symantec\deepsight extractor\extractorservicenpf03.exe –> c:\program files\symantec\deepsight extractor\ExtractorServiceNPF03.exe [?]
S4 ExtractorServiceNPF04;DeepSight Extractor Service for NPF04;c:\program files\symantec\deepsight extractor\extractorservicenpf04.exe –> c:\program files\symantec\deepsight extractor\ExtractorServiceNPF04.exe [?]
S4 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2005-9-28 1174664]

=============== Created Last 30 ================

2009-02-05 00:10 –d—– c:\program files\Western Digital Technologies
2009-01-30 00:13 1,221,008 a——- c:\windows\system32\zpeng25.dll

==================== Find3M ====================

2009-01-31 12:05 19,640 a——- c:\docume~1\vincenzo\applic~1\GDIPFONTCACHEV1.DAT
2009-01-30 00:14 4,212 a—h— c:\windows\system32\zllictbl.dat
2008-12-11 05:57 333,952 a——- c:\windows\system32\drivers\srv.sys
2008-07-31 09:46 2,835 a——- c:\program files\INSTALL.LOG
2003-06-03 10:49 448,256 a——- c:\windows\inf\EL2K_N64.sys
2003-06-03 10:48 147,328 a——- c:\windows\inf\EL2K_XP.sys
2003-06-03 10:47 147,328 a——- c:\windows\inf\EL2K_2K.sys
2005-01-14 21:32 61 —sh— c:\windows\cnerolf.dat
2006-05-03 04:06 163,328 —shr– c:\windows\system32\flvDX.dll
2007-02-21 05:47 31,232 —shr– c:\windows\system32\msfDX.dll
2008-09-06 20:52 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008090620080907\index.dat

============= FINISH: 18:18:58.29 ===============
s for the other file there is alot of personal info, anyone can see this info is it absolutely necessary?
I wouldn't ask for it if it wasn't necessary

You can edit your logs after each of my replies if you want


Download Rooter.exe to your desktop
  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here

I wouldn't ask for it if it wasn't necessary

You can edit your logs after each of my replies if you want


Download Rooter.exe to your desktop

  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here


No problem sir I didn't mean about you just the net in general.
Here you go!

Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel® Pentium® 4 CPU 3.00GHz )
BIOS : BIOS Date: 06/11/03 16:46:02 Ver: 08.00.09
USER : Vincenzo ( Administrator )
BOOT : Normal boot

Antivirus : avast! antivirus 4.8.1296 [VPS 090209-0] 4.8.1296 (Activated)
Firewall : ZoneAlarm Firewall 8.0.065.000 (Activated)

C:\ (Local Disk) - NTFS - Total:74 Go (Free:32 Go)
D:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)


Mon 02/09/2009|12:29

———————-\\ Search..

No infections found !


1 - "C:\Rooter$\Rooter_1.txt" - Mon 02/09/2009|12:30

———————-\\ Scan completed at 12:30
hello

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.

hello

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.



OTListIt logfile created on: 2/9/2009 2:01:47 PM - Run
OTListIt2 by OldTimer - Version 2.0.0.10 Folder = C:\Documents and Settings\Vincenzo\Desktop\TOOLS\Myweb search removal
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 3.85 Gb Available in Paging File | 96.19% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 32.44 Gb Free Space | 43.53% Space Free | Partition Type: NTFS
Drive D: | 629.86 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 465.65 Gb Total Space | 449.04 Gb Free Space | 96.43% Space Free | Partition Type: FAT32
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ENZO
Current User Name: Vincenzo
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\CTSVCCDA.EXE (Creative Technology Ltd)
PRC - C:\Program Files\Common Files\Motive\McciCMService.exe (Motive Communications, Inc.)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
PRC - C:\WINDOWS\system32\MsPMSPSv.exe (Microsoft Corporation)
PRC - C:\Program Files\Webroot\Washer\WasherSvc.exe (Webroot Software, Inc.)
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Advanced Micro Devices Inc.)
PRC - C:\Program Files\Logitech\MouseWare\system\EM_EXEC.EXE (Logitech Inc.)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
PRC - C:\Program Files\Palm\Hotsync.exe (PalmSource, Inc)
PRC - C:\Program Files\SpywareGuard\sgmain.exe ()
PRC - C:\Program Files\SpywareGuard\sgbhp.exe ()
PRC - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Webroot\Washer\wwDisp.exe (Webroot Software, Inc.)
PRC - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
PRC - C:\Program Files\Windows NT\Accessories\wordpad.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Vincenzo\Desktop\TOOLS\Myweb search removal\OTListIt22.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (ACDaemon [Disabled | Stopped]) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (aswUpdSv [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (Ati HotKey Poller [Auto | Running]) – C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
SRV - (ATI Smart [Auto | Stopped]) – C:\WINDOWS\system32\ati2sgag.exe ()
SRV - (avast! Antivirus [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner [On_Demand | Running]) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner [On_Demand | Running]) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (AVG Anti-Spyware Guard [On_Demand | Stopped]) – C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe (GRISOFT s.r.o.)
SRV - (Bonjour Service [Disabled | Stopped]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (CLTNetCnService [Disabled | Stopped]) – File not found
SRV - (Creative Service for CDROM Access [Auto | Running]) – C:\WINDOWS\system32\CTSVCCDA.EXE (Creative Technology Ltd)
SRV - (DeepsightExtractor [Disabled | Stopped]) – File not found
SRV - (ExtractorServiceNPF03 [Disabled | Stopped]) – File not found
SRV - (ExtractorServiceNPF04 [Disabled | Stopped]) – File not found
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (iPod Service [On_Demand | Stopped]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (McciCMService [Auto | Running]) – C:\Program Files\Common Files\Motive\McciCMService.exe (Motive Communications, Inc.)
SRV - (ServiceLayer [On_Demand | Stopped]) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (SoundMAX Agent Service (default) [Auto | Running]) – C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
SRV - (Symantec Core LC [Disabled | Stopped]) – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (Symantec Corporation)
SRV - (usnjsvc [On_Demand | Stopped]) – C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (vsmon [Auto | Stopped]) – C:\WINDOWS\system32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (WMDM PMSP Service [Auto | Running]) – C:\WINDOWS\system32\MsPMSPSv.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (WudfSvc [On_Demand | Stopped]) – C:\WINDOWS\system32\WudfSvc.dll (Microsoft Corporation)
SRV - (wwEngineSvc [Auto | Running]) – C:\Program Files\Webroot\Washer\WasherSvc.exe (Webroot Software, Inc.)
SRV - (x10nets [On_Demand | Stopped]) – File not found

========== Driver Services (SafeList) ==========

DRV - (Aavmker4 [System | Running]) – C:\WINDOWS\system32\drivers\aavmker4.sys (ALWIL Software)
DRV - (aeaudio [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\aeaudio.sys (Andrea Electronics Corporation)
DRV - (Afc [On_Demand | Running]) – C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (aslm75 [Auto | Running]) – C:\WINDOWS\system32\drivers\ASLM75.SYS ()
DRV - (aswFsBlk [Auto | Running]) – C:\WINDOWS\system32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (aswMon2 [Auto | Running]) – C:\WINDOWS\system32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswRdr [On_Demand | Running]) – C:\WINDOWS\system32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswSP [System | Running]) – C:\WINDOWS\system32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswTdi [System | Running]) – C:\WINDOWS\system32\drivers\aswTdi.sys (ALWIL Software)
DRV - (atapi [Boot | Running]) – C:\WINDOWS\system32\drivers\atapi.sys ()
DRV - (ati2mtag [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (atinrvxx [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\atinrvxx.sys (ATI Technologies Inc.)
DRV - (ATITool [System | Running]) – C:\Program Files\ATITool\atitool.sys ()
DRV - (AVG Anti-Spyware Driver [System | Running]) – C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ()
DRV - (AvgAsCln [System | Running]) – C:\WINDOWS\system32\drivers\AvgAsCln.sys (GRISOFT, s.r.o.)
DRV - (BsStor [Boot | Running]) – C:\WINDOWS\system32\drivers\bsstor.sys (B.H.A Co.,Ltd.)
DRV - (BsUDF [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\bsudf.sys (ahead software)
DRV - (chanalog [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\chanalog.sys (CH Products)
DRV - (ctac32k [On_Demand | Running]) – C:\WINDOWS\system32\drivers\CTAC32K.SYS (Creative Technology Ltd)
DRV - (ctaud2k [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctljystk [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ctljystk.sys (Creative Technology Ltd.)
DRV - (ctprxy2k [On_Demand | Running]) – C:\WINDOWS\system32\drivers\CTPRXY2K.SYS (Creative Technology Ltd)
DRV - (ctsfm2k [On_Demand | Running]) – C:\WINDOWS\system32\drivers\CTSFM2K.SYS (Creative Technology Ltd)
DRV - (d346bus [Boot | Running]) – C:\WINDOWS\system32\drivers\d346bus.sys ( )
DRV - (d346prt [Boot | Running]) – C:\WINDOWS\system32\drivers\d346prt.sys ( )
DRV - (EL2000 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\EL2K_XP.sys (3Com Corporation)
DRV - (emupia [On_Demand | Running]) – C:\WINDOWS\system32\drivers\EMUPIA2K.SYS (Creative Technology Ltd)
DRV - (ENETHUSB [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\enethusb.sys (Efficient Networks, Inc.)
DRV - (gameenum [On_Demand | Running]) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (giveio [Boot | Running]) – C:\WINDOWS\system32\giveio.sys ()
DRV - (gmer [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\gmer.sys (GMER)
DRV - (ha10kx2k [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (hap16v2k [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\HAP16V2K.SYS (Creative Technology Ltd)
DRV - (hidgame [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\hidgame.sys (Microsoft Corporation)
DRV - (kbdhid [System | Stopped]) – C:\WINDOWS\system32\drivers\kbdhid.sys (Microsoft Corporation)
DRV - (L8042pr2 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\L8042pr2.Sys (Logitech, Inc.)
DRV - (LHidFlt2 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\LHIDFLT2.SYS (Logitech, Inc.)
DRV - (LHidUsb [On_Demand | Running]) – C:\WINDOWS\system32\drivers\LHIDUSB.SYS (Logitech, Inc.)
DRV - (LMouFlt2 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\LMouFlt2.Sys (Logitech, Inc.)
DRV - (MidiSyn [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\MidiSyn.sys (Analog Devices Inc)
DRV - (MREMP50 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRENDIS5 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MRENDIS5.sys (Motive, Inc.)
DRV - (MRESP50 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MVDCODEC [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\atinmdxx.sys (ATI Technologies Inc.)
DRV - (MxlW2k [On_Demand | Running]) – C:\WINDOWS\system32\drivers\MxlW2k.sys (MusicMatch, Inc.)
DRV - (ossrv [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (PalmUSBD [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\PalmUSBD.sys (PalmSource, Inc.)
DRV - (pfc [On_Demand | Running]) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (PfModNT [Auto | Running]) – C:\WINDOWS\system32\drivers\PFMODNT.SYS (Creative Technology Ltd.)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\system32\drivers\pxhelp20.sys (Sonic Solutions)
DRV - (Secdrv [Auto | Running]) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sfdrv01 [Boot | Running]) – C:\WINDOWS\system32\drivers\sfdrv01.sys (Protection Technology)
DRV - (sfhlp02 [Boot | Running]) – C:\WINDOWS\system32\drivers\sfhlp02.sys (Protection Technology)
DRV - (smwdm [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\smwdm.sys (Analog Devices, Inc.)
DRV - (speedfan [Boot | Running]) – C:\WINDOWS\system32\speedfan.sys (Windows ® 2000 DDK provider)
DRV - (srescan [Boot | Running]) – C:\WINDOWS\system32\ZoneLabs\srescan.sys (Check Point Software Technologies LTD)
DRV - (symlcbrd [Auto | Running]) – C:\WINDOWS\system32\drivers\symlcbrd.sys (Symantec Corporation)
DRV - (TCAITDI [Auto | Running]) – C:\WINDOWS\system32\drivers\TCAITDI.SYS (3Com Corporation)
DRV - (TVICHW32 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\TVICHW32.SYS (EnTech Taiwan)
DRV - (vsdatant [System | Running]) – C:\WINDOWS\system32\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (WBHWDOCT [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\WBHWDOCT.sys (Winbond Electronics Corp.)
DRV - (WmBEnum [On_Demand | Running]) – C:\WINDOWS\system32\drivers\WmBEnum.sys (Logitech Inc.)
DRV - (WmFilter [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\WmFilter.sys (Logitech Inc.)
DRV - (WmVirHid [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\WmVirHid.sys (Logitech Inc.)
DRV - (WmXlCore [On_Demand | Running]) – C:\WINDOWS\system32\drivers\WmXlCore.sys (Logitech Inc.)
DRV - (WS2IFSL [System | Running]) – C:\WINDOWS\system32\drivers\ws2ifsl.sys (Microsoft Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.sympatico.msn.ca
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - URLSearchHook: {50B48177-18A1-B9B0-E399-90C5E06199DA} - Reg Error: Key error. File not found

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.MSN.ca
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

O1 HOSTS File: (291440 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 127.0.0.1 www.163ns.com
O1 - Hosts: 10060 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - Reg Error: Key error. File not found
O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [Logitech Utility] Logi_MwX.Exe (Logitech Inc.)
O4 - HKLM..\Run: [LtcyCfgApply] "C:\Documents and Settings\Vincenzo\Desktop\latency tool pci\LtcyCfg.exe" /a ()
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TCASUTIEXE] TCAUDIAG.exe -on File not found
O4 - HKLM..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [EPSON Stylus Photo RX595 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICLA.EXE /FU "C:\WINDOWS\TEMP\E_S1DD.tmp" /EF "HKCU" (SEIKO EPSON CORPORATION)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9f.exe File not found
O4 - HKCU..\RunOnce: [Index Washer] C:\Program Files\Webroot\Washer\WashIdx.exe "Vincenzo" (Webroot Software, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe (PalmSource, Inc)
O4 - Startup: C:\Documents and Settings\Vincenzo\Start Menu\Programs\Startup\SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll (InterTrust Technologies Corporation, Inc.)
O15 - HKLM\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: bmo.com ([www1] https in Trusted sites)
O15 - HKCU\..Trusted Domains: 58 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab (Checkers Class)
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab (SupportSoft SmartIssue)
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab (SupportSoft Script Runner Class)
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab (StagingUI Object)
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} http://support.f-secure.com/ols/fscax.cab (F-Secure Online Scanner 3.1)
O16 - DPF: {0DB074F0-617E-4EE9-912C-2965CF2AA5A4} http://download.microsoft.com/download/7/0…tualEarth3D.cab (SentinelVE3D Class)
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} http://downloadcenter.samsung.com/content/…trolLite_EN.cab (DjVuCtl Class)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab (CKAVWebScan Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} http://www.symantec.com/techsupp/asa/LSSupCtl.cab (LSSupCtl Class)
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab (Yahoo! Audio Conferencing)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab (Symantec AntiVirus scanner)
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} http://download.yahoo.com/dl/installs/yinst0401.cab (YInstStarter Class)
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab (MSN Games – Buddy Invite)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://by121fd.bay121.hotmail.msn.com/resources/MsnPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} http://files.ea.com/downloads/rtpatch/v2/EARTPX.cab (EARTPatchX Class)
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab (ZonePAChat Object)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/microsoftu…b?1183322733905 (WUWebControl Class)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1183322725405 (MUWebControl Class)
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} http://chat.yahoo.com/cab/yacsui.cab (Yahoo! Audio UI1)
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} http://download.zonelabs.com/bin/promotion…canner37680.cab (ICSScanner Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab (MessengerStatsClient Class)
O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} http://zone.msn.com/bingame/zpagames/zpa_txhe.cab60231.cab (MSN Games – Texas Holdem Poker)
O16 - DPF: {AFAB176A-0D25-436A-8555-286F6D7AA388} http://www.actualresearch.com/files/rfscanax.cab (CRegFreezeScanModule Object)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab (ActiveDataInfo Class)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://www.adobe.com/products/acrobat/nos/gp.cab (get_atlcom Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} http://zone.msn.com/binframework/v10/StProxy.cab55579.cab (MSN Games – Game Communicator)
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} http://driveragent.com/files/driveragent.cab (Driver Agent ActiveX Control)
O16 - DPF: Microsoft XML Parser for Java file:///C:/WINDOWS/Java/classes/xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {57B86673-276A-48B2-BAE7-C6DBB3020EB8} - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll (GRISOFT s.r.o.)
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O29 - HKLM SecurityProviders - ( xlibgfl254.dll) - File not found
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - D:\AUTORUN.INF () - [ CDFS ]
O32 - Autorun File - G:\autorun.inf () - [ FAT32 ]
O32 - Autorun File - G:\autorun [2002/01/05 14:30:58 00,000,000 | —D | M] - [ FAT32 ]
O33 - MountPoints2\{c348e5dc-f33b-11dd-a240-000c6e7bf812}\Shell\AutoRun\command - "" = G:\wd_windows_tools\WDSetup.exe – [2008/06/19 12:46:02 | 01,760,476 | —- | M] (Western Digital Corporation )

========== Files/Folders - Created Within 30 Days ==========

[2009/02/09 12:56:55 | 00,001,215 | —- | C] () – C:\Documents and Settings\Vincenzo\Desktop\767-300 Configuration Manager.lnk
[2009/02/09 12:52:17 | 00,002,048 | —- | C] () – C:\WINDOWS\lvld67.lic
[2009/02/09 12:29:16 | 00,000,000 | —D | C] – C:\Rooter$
[2009/02/08 18:30:27 | 00,004,096 | —- | C] () – C:\WINDOWS\System32\crash
[2009/02/08 01:57:10 | 00,000,000 | —D | C] – C:\Documents and Settings\Vincenzo\Desktop\Level D 767 (FS9)
[2009/02/05 00:10:55 | 00,000,000 | —D | C] – C:\Program Files\Western Digital Technologies
[2009/02/01 14:11:04 | 00,030,208 | —- | C] () – C:\Documents and Settings\Vincenzo\My Documents\HEARTS.doc
[2009/01/31 13:49:20 | 00,065,536 | —- | C] () – C:\Documents and Settings\Vincenzo\My Documents\Enleo.doc
[2009/01/31 13:48:30 | 00,067,072 | —- | C] () – C:\Documents and Settings\Vincenzo\My Documents\Melea.doc
[2009/01/31 03:05:10 | 00,000,000 | —D | C] – C:\Documents and Settings\Vincenzo\Desktop\sounds
[2009/01/31 01:48:04 | 00,000,000 | —D | C] – C:\Documents and Settings\Vincenzo\Desktop\Load fs9 2
[2009/01/31 01:43:50 | 00,000,000 | —D | C] – C:\Documents and Settings\Vincenzo\Desktop\Load fs9
[2009/01/25 23:39:17 | 00,032,256 | —- | C] () – C:\Documents and Settings\Vincenzo\My Documents\VIDEO EDITING 2.doc
[2009/01/21 23:03:55 | 00,027,136 | —- | C] () – C:\Documents and Settings\Vincenzo\My Documents\You Found Me.doc
[2009/01/16 13:10:10 | 00,000,935 | —- | C] () – C:\Documents and Settings\Vincenzo\Desktop\rick email.rtf

========== Files - Modified Within 30 Days ==========

[5 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[2009/02/09 12:56:55 | 00,001,215 | —- | M] () – C:\Documents and Settings\Vincenzo\Desktop\767-300 Configuration Manager.lnk
[2009/02/09 12:52:17 | 00,002,048 | —- | M] () – C:\WINDOWS\lvld67.lic
[2009/02/09 12:42:32 | 00,482,444 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/02/09 12:42:32 | 00,413,244 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/02/09 12:42:32 | 00,061,356 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/02/09 12:39:28 | 00,348,376 | -H– | M] () – C:\WINDOWS\System32\vsconfig.xml
[2009/02/09 12:39:22 | 00,013,002 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/02/09 12:38:11 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/02/09 12:38:03 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/02/09 12:38:02 | 00,003,568 | —- | M] () – C:\WINDOWS\System32\ativvaxx.cap
[2009/02/09 12:36:47 | 00,024,144 | —- | M] () – C:\WINDOWS\System32\BMXCtrlState-{00000002-00000000-0000000D-00001102-00000002-80671102}.rfx
[2009/02/09 12:36:47 | 00,024,144 | —- | M] () – C:\WINDOWS\System32\BMXBkpCtrlState-{00000002-00000000-0000000D-00001102-00000002-80671102}.rfx
[2009/02/09 12:36:47 | 00,016,348 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000002-00000000-0000000D-00001102-00000002-80671102}.rfx
[2009/02/09 12:36:47 | 00,016,348 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000002-00000000-0000000D-00001102-00000002-80671102}.rfx
[2009/02/09 12:36:47 | 00,002,056 | —- | M] () – C:\WINDOWS\System32\settingsbkup.sfm
[2009/02/09 12:36:47 | 00,002,056 | —- | M] () – C:\WINDOWS\System32\settings.sfm
[2009/02/09 12:36:47 | 00,000,288 | —- | M] () – C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-0000000D-00001102-00000002-80671102}.dat
[2009/02/09 12:36:47 | 00,000,288 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000002-00000000-0000000D-00001102-00000002-80671102}.dat
[2009/02/09 10:59:12 | 00,002,626 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2009/02/08 18:30:27 | 00,004,096 | —- | M] () – C:\WINDOWS\System32\crash
[2009/02/07 15:59:01 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/02/07 15:37:41 | 00,291,440 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/02/05 16:11:35 | 01,256,296 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\aswBoot.exe
[2009/02/05 16:08:19 | 00,093,296 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon.sys
[2009/02/05 16:08:10 | 00,094,032 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon2.sys
[2009/02/05 16:07:23 | 00,114,768 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2009/02/05 16:07:12 | 00,020,560 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2009/02/05 16:06:20 | 00,051,376 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswTdi.sys
[2009/02/05 16:06:10 | 00,023,152 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2009/02/05 16:05:11 | 00,026,944 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aavmker4.sys
[2009/02/05 16:04:45 | 00,097,480 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\AVASTSS.scr
[2009/02/04 23:51:28 | 00,000,892 | —- | M] () – C:\WINDOWS\win.ini
[2009/02/04 23:51:28 | 00,000,254 | —- | M] () – C:\WINDOWS\system.ini
[2009/02/04 23:51:28 | 00,000,211 | RHS- | M] () – C:\boot.ini
[2009/02/01 14:11:05 | 00,030,208 | —- | M] () – C:\Documents and Settings\Vincenzo\My Documents\HEARTS.doc
[2009/01/31 13:49:20 | 00,065,536 | —- | M] () – C:\Documents and Settings\Vincenzo\My Documents\Enleo.doc
[2009/01/31 13:48:30 | 00,067,072 | —- | M] () – C:\Documents and Settings\Vincenzo\My Documents\Melea.doc
[2009/01/31 12:05:16 | 00,019,640 | —- | M] () – C:\Documents and Settings\Vincenzo\Application Data\GDIPFONTCACHEV1.DAT
[2009/01/31 10:54:56 | 00,019,640 | —- | M] () – C:\Documents and Settings\Vincenzo\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/01/31 10:53:49 | 00,119,744 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/01/31 01:49:10 | 00,000,056 | —- | M] () – C:\WINDOWS\fs9configurator.ini
[2009/01/30 00:14:06 | 00,004,212 | -H– | M] () – C:\WINDOWS\System32\zllictbl.dat
[2009/01/25 23:39:18 | 00,032,256 | —- | M] () – C:\Documents and Settings\Vincenzo\My Documents\VIDEO EDITING 2.doc
[2009/01/21 23:03:55 | 00,027,136 | —- | M] () – C:\Documents and Settings\Vincenzo\My Documents\You Found Me.doc
[2009/01/16 13:10:11 | 00,000,935 | —- | M] () – C:\Documents and Settings\Vincenzo\Desktop\rick email.rtf

========== LOP Check ==========

[2008/11/11 22:53:55 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/11/09 18:15:54 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2007/09/16 14:55:28 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2007/03/07 12:16:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2008/12/29 01:49:09 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ArcSoft
[2008/09/21 21:14:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ATI
[2003/11/12 02:30:19 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Creative
[2004/04/13 23:24:50 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2008/02/08 00:16:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EPSON
[2008/07/09 13:55:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Geek Squad
[2007/09/04 01:33:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2006/07/24 11:52:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HotSync
[2007/04/26 22:39:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Installations
[2007/09/20 00:29:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iolo
[2007/06/26 11:57:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
[2007/09/20 00:21:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MailFrontier
[2005/03/06 11:54:09 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee
[2005/03/06 11:53:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com
[2009/01/31 00:34:57 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2008/08/01 11:45:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Motive
[2007/08/06 13:50:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MotiveSysIDs
[2007/04/26 22:50:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Suite
[2003/12/21 23:08:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2009/02/09 13:03:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2007/06/18 13:55:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2009/02/07 22:48:58 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2007/09/06 13:12:19 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Webroot
[2006/02/08 13:31:01 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/12/06 13:58:27 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Vincenzo\Application Data
[2008/12/10 23:16:18 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Adobe
[2004/11/02 12:35:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Adorons
[2005/01/21 00:08:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\AISchedule
[2006/05/20 13:57:01 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Apple Computer
[2008/12/29 14:51:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\ArcSoft
[2008/08/28 01:15:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Atari
[2005/06/23 23:39:51 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\ATI
[2008/10/26 13:04:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Auslogics
[2003/11/12 02:49:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Creative
[2008/02/10 20:28:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\EPSON
[2005/02/18 13:20:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\FSAutoStart
[2008/12/06 13:58:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\GARMIN
[2006/12/30 17:24:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Help
[2006/07/24 11:49:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\HotSync
[2007/08/12 01:30:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Identities
[2008/07/29 22:22:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Image Zone Express
[2008/02/08 00:11:55 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\InstallShield
[2003/11/12 14:14:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\InterTrust
[2004/04/13 22:49:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\InterVideo
[2007/09/20 00:29:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\iolo
[2005/05/28 14:32:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Lavasoft
[2004/07/15 01:19:08 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Leadertech
[2008/02/10 21:34:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\LimeWire
[2004/11/07 16:53:45 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Macromedia
[2009/01/31 00:34:55 | 00,000,000 | –SD | M] – C:\Documents and Settings\Vincenzo\Application Data\Microsoft
[2008/08/01 11:48:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Motive
[2007/08/08 22:10:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Mozilla
[2007/04/27 00:13:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Nokia
[2008/02/11 14:49:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Nokia Multimedia Player
[2007/04/26 22:50:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\PC Suite
[2003/12/06 03:06:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Sun
[2005/02/17 02:12:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Symantec
[2006/08/31 23:58:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\teamspeak2
[2007/08/08 22:10:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Thunderbird
[2008/03/05 19:13:41 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\webex
[2008/07/09 13:58:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Webroot
[2005/06/24 01:13:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\X10 Commander
[2004/08/24 23:19:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Yahoo! Messenger
[2009/02/07 15:59:01 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2001/08/23 07:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/02/09 12:38:11 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34

< End of report >
OTListIt Extras logfile created on: 2/9/2009 2:01:47 PM - Run
OTListIt2 by OldTimer - Version 2.0.0.10 Folder = C:\Documents and Settings\Vincenzo\Desktop\TOOLS\Myweb search removal
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 3.85 Gb Available in Paging File | 96.19% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 32.44 Gb Free Space | 43.53% Space Free | Partition Type: NTFS
Drive D: | 629.86 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ENZO
Current User Name: Vincenzo
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.chm [@ = chm.file] – C:\WINDOWS\hh.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\WINDOWS\system32\winhlp32.exe (Microsoft Corporation)
.hta [@ = htafile] – C:\WINDOWS\system32\mshta.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.inf [@ = inffile] – C:\WINDOWS\system32\notepad.exe (Microsoft Corporation)
.ini [@ = inifile] – C:\WINDOWS\system32\notepad.exe (Microsoft Corporation)
.js [@ = JSFile] – C:\WINDOWS\system32\wscript.exe (Microsoft Corporation)
.jse [@ = JSEFile] – C:\WINDOWS\system32\wscript.exe (Microsoft Corporation)
.reg [@ = regfile] – C:\WINDOWS\regedit.exe (Microsoft Corporation)
.txt [@ = txtfile] – C:\WINDOWS\system32\notepad.exe (Microsoft Corporation)
.vbe [@ = VBEFile] – C:\WINDOWS\system32\wscript.exe (Microsoft Corporation)
.vbs [@ = VBSFile] – C:\WINDOWS\system32\wscript.exe (Microsoft Corporation)
.wsf [@ = WSFFile] – C:\WINDOWS\system32\wscript.exe (Microsoft Corporation)
.wsh [@ = WSHFile] – C:\WINDOWS\system32\wscript.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring" = 1

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1 (Microsoft Corporation)
C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger (Microsoft Corporation)
C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire File not found
C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour (Apple Inc.)
C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes (Apple Inc.)
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1 (Microsoft Corporation)
C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) (Microsoft Corporation)
C:\Program Files\Yahoo!\Messenger\YPager.exe:*:Enabled:Yahoo! Messenger (Yahoo! Inc.)
C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server (Yahoo! Inc.)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0030188A-533E-42EE-9837-E044F10E4369}" = Palm
"{007B37D9-0C45-4202-834B-DD5FAAE99D63}" = ArcSoft Print Creations - Slimline Card
"{01A1A019-E1D8-482A-BE17-5E118D17C0A0}" = ArcSoft Print Creations - Brochures & Flyers
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{066D65EA-ED53-44E4-A96A-F81B6E409D2E}" = PC Connectivity Solution
"{08C5815C-2C6E-44f8-8748-0E61BC9AFB68}" = Symantec KB-DocID:2003093015493306
"{08CA9554-B5FE-4313-938F-D4A417B81175}" = QuickTime
"{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics
"{11396328-AAFB-C592-B715-8D461CE7B495}" = Catalyst Control Center Graphics Previews Common
"{121634B0-2F4A-11D3-ADA3-00C04F52DD53}" = Windows Installer Clean Up
"{1A1F46B3-9B31-A93C-F5F9-2A3DBFC71BCC}" = Skins
"{1CA2E5E4-F4FE-44B4-95E9-77523FB95838}" = EPSON Stylus Photo RX595 Series Scanner Driver Update
"{1EC65D1D-3911-4F7D-8B6A-63C69EDBFC6E}" = EditVoicepack
"{2758F387-D016-4725-9D03-AB039364DF3D}" = PMDG_747-400_Sound_Update
"{286CB62B-0D03-4BF7-BEAC-AECA224C4FB7}" = ArcSoft Print Creations
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{366FFC89-C800-4366-B903-B9C4314109A5}" = Garmin WebUpdater
"{3CCB26F5-E2A7-4C91-8340-9149D7B7C2BE}" = Virtual Earth 3D (Beta)
"{3CE47E6B-AE27-4E40-AC54-329EED96B933}" = ArcSoft Print Creations - Funhouse II
"{3D047C15-C859-45F7-81CE-F2681778069B}" = iPod for Windows 2006-01-10
"{3DE0053C-FD9A-483E-B7C9-B06E4392206E}" = iTunes
"{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}" = Bonjour
"{49C88E44-1B38-4FC6-824E-2BDA3063B0E3}" = Apple Mobile Device Support
"{5023B3E9-6B73-471E-8BD9-DA4442AE357C}" = ArcSoft Print Creations - Quick Photo Book
"{56589DFE-0C29-4DFE-8E42-887B771ECD23}" = ArcSoft Print Creations - Photo Book
"{56CA5D3B-3002-4E7B-90FE-071D8FDF3814}" =
"{571700F0-DB9D-4B3A-B03D-35A14BB5939F}" = Windows Live Messenger
"{57A48477-92F0-4C1F-ADF9-4806C4EC3CF2}" = Nokia PC Suite
"{5809E7CF-4DCF-11D4-9875-00105ACE7734}" = Logitech MouseWare 9.76
"{5D1C82E7-7EC0-4404-A8AD-36C3B444BC34}" = ArcSoft Print Creations - Poster Creator
"{654F0312-CB3D-4FE2-962C-6BB9752E9146}" = iPod for Windows 2005-06-26
"{666E0B91-3FD3-43B7-B6A2-EB9012758982}" = FSAutoStart
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6A6E453A-24DE-3F26-E6AD-7C22A6440B93}" = CCC Help English
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{77DC8E20-5D4B-9563-3F36-BC481384AE9E}" = ccc-core-preinstall
"{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}" = EPSON Web-To-Page
"{7F34A21F-2DEB-4598-BB19-611D6BD24271}" = Managed DirectX (0900)
"{7FFD52E3-239B-4096-B1F5-6B1B5F2A72F8}" = FSBrowser
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E1DCD15-C9F1-49CE-807B-198C8241EB6B}" = ALi USB2.0 Driver
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{907B4640-266B-4A21-92FB-CD1A86CD0F63}" = RollerCoaster Tycoon 3 Platinum
"{9115E7DB-3B29-445A-802D-11E0AA945B7F}" = Sound Blaster Live!
"{9591C049-5CAE-4E89-A8D9-191F1899628B}" = ArcSoft Print Creations - Funhouse
"{95F875CC-1B85-43E6-B3E0-13EA04F3D995}" = ArcSoft Print Creations - Photo Prints
"{972B1D9B-0EAD-49E8-B7D6-3B83FD5665B1}" = Nokia Connectivity Cable Driver
"{97679567-0095-464E-B5F2-E218A1CF3421}" = PMDG747_400 Queen of the Skies
"{98E8A2EF-4EAE-43B8-A172-74842B764777}" = InterVideo WinDVD 4
"{9933F0EE-DFCD-4829-B979-3C56C367CB1A}" = InterVideo WinDVD Creator
"{A040AC77-C1AA-4CC9-8931-9F648AF178F6}" = VC 9.0 Runtime
"{A403D88E-ED7D-48E3-91FD-B8C8A720EDA1}" = Microsoft Speech SDK 5.1
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A4D7B764-4140-11D4-88EB-0050DA3579C0}" = Nero - Burning Rom
"{A6D7A411-7A86-F032-F2DF-470E28B2D835}" = ccc-utility
"{A96D3ED0-E7B3-41F6-8BB5-F3C63D80901D}" = SplashPhoto
"{AC696733-F8C5-4EAD-B165-AC8AB8C2A755}" = TTS_Technology
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.3
"{B0D83FCD-9D42-43ED-8315-250326AADA02}" = ArcSoft Print Creations - Scrapbook
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{B9242864-2841-4ADE-86E0-8F90F91B04DD}" = Logitech Gaming Software
"{B98DA566-F72B-5A7B-1992-DBB0243C5C23}" = Catalyst Control Center Graphics Full New
"{BD12C3FF-F520-4A9D-9B36-A7756466F1AA}" = ArcSoft MediaImpression
"{C176A8E4-FDAE-BFFB-AA04-CE75372C72B0}" = Catalyst Control Center Graphics Light
"{C51738A2-0FD3-49A0-8634-77D84842580D}" = My Active AirSource
"{CA9ED5E4-1548-485B-A293-417840060158}" = ArcSoft Print Creations - Photo Calendar
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D03E7B00-CA85-4684-9321-1888873C34BD}" = ArcSoft PhotoImpression 6
"{D32D4182-DE6C-457E-838C-8D7B9CE332BA}" = InterVideo WinRip
"{D4E22434-1BCE-4C91-A1E4-FC352DFD4B3B}" = aerosoft's - Mega Airport Frankfurt - FS2004
"{D72B7816-2616-4695-84BD-EB5D6DE75A83}" = ASRC
"{D8E00A2F-9CAE-47B1-BA09-C4A126D7DBA4}" = SquawkBox
"{D9F4A9F8-92C5-4289-9D04-F0F8F02D580A}" = iPod for Windows 2005-10-12
"{DB909A1C-B447-428F-8103-E8975BCB99F0}" = ArcSoft RAW Thumbnail Viewer
"{DDA85049-52FF-4CD0-B30D-9722508C6A01}" = AISchedule
"{DE2A8612-B454-62A6-BE86-2E9F2F830390}" = ccc-core-static
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = AusLogics Disk Defrag
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E3D521EB-AD0D-4184-9FF0-8321D88DCF0E}" = ActiveSky Version 6 and ActiveSky Graphics
"{E6B4117F-AC59-4B13-9274-EB136E8897EE}" = ArcSoft Print Creations - Album Page
"{EA01B804-60DA-41ED-80D3-4C7EBB62774A}" = ArcSoft Video Downloader
"{EA67A493-7B35-D0C1-ACC5-2F0A239D0FFB}" = Catalyst Control Center Graphics Full Existing
"{ED654F5D-5DC9-46EA-9D10-621231527F98}" = FS9 Configurator
"{ED8FF847-6705-4D71-B4E6-876A3FA2344A}" = DeepSight Extractor
"{F04F9557-81A9-4293-BC49-2C216FA325A7}" = ArcSoft Print Creations - Greeting Card
"{F0681859-D086-4384-B204-386FA7D80A5B}" = SplashShopper
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F36A2ADA-7106-8F06-9838-99299A8DC6AC}" = Catalyst Control Center Core Implementation
"{F51D9393-BB14-4566-99BF-D6ED63AEFCD7}" = Natural Color
"{F5223680-993A-11D4-86F6-0001031E5712}" = InterVideo Installer
"{F5577101-33CC-4711-8235-3A95BCD49DB0}" = EA Link
"{F6970FBD-809A-4C51-BAB3-D94A04C6C8E7}" = Garmin Communicator Plugin
"{FA3A247D-437A-455E-A88F-7EB6E5F9E799}" = Catalyst Control Center - Branding
"{FF477885-5EA8-40D0-ADF3-D4C1B86FAEA4}" = EPSON Print CD
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"0852D05415AB9A4F1EF451E342267F76C776ED2F" = Windows Driver Package - Nokia Modem (11/03/2006 6.82.0.1)
"0C5EDC3653FED5B121F464339EAC12534D253B25" = Windows Driver Package - Nokia Modem (02/15/2007 3.1)
"3ComNicUnInstall" = 3Com NIC Diagnostics
"82A44D22-9452-49FB-00FB-CEC7DCAF7E23" = EA SPORTS online 2007
"ActiveTouchMeetingClient" = WebEx
"Ad-Aware SE Personal" = Ad-Aware SE Personal
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"AdobeESD" = Adobe Download Manager 1.2 (Remove Only)
"Airliners Env" = Airliners Env 5.1
"All ATI Software" = ATI - Software Uninstall Utility
"ASUS Probe V2.20.07" = ASUS Probe V2.20.07
"AsusUpdate" = AsusUpdate
"ATI Display Driver" = ATI Display Driver
"avast!" = avast! Antivirus
"AVGAntiSpyware75" = AVG Anti-Spyware 7.5
"avi mpg asf wmv to DivX XviD/ to all format avi_is1" = avi2divx
"BitTorrent" = BitTorrent 3.4.2
"CCleaner" = CCleaner (remove only)
"CH Gameport Devices" = CH Gameport Devices
"CodeBaby Player (Remove Only)[removed]" = CodeBaby Player (Remove Only) [removed]
"DivXCodec" = DivX 4.12 Codec
"Driver Cleaner" = Driver Cleaner 3
"EAX Unified" = EAX Unified
"EPSON Printer and Utilities" = EPSON Printer Software
"EPSON Scanner" = EPSON Scan
"EVEREST Home Edition_is1" = EVEREST Home Edition v1.51
"F064B256B4A20996EA9E333B5E0F14B61AB3333D" = Windows Driver Package - Nokia (WUDFRd) WPD (03/19/2007 6.83.31.1)
"Flight Simulator 9.0" = Microsoft Flight Simulator 2004 A Century of Flight
"FS_Real_Time" = FS Real Time v1.65
"getPlus®_ocx" = getPlus®_ocx
"Handmark® MobileDB™ for Palm OS" = Handmark® MobileDB™ for Palm OS
"HijackThis" = HijackThis 1.99.1
"Hoyle Casino 5" = Hoyle Casino 5
"HP Image Zone Express" = HP Image Zone Express
"I am an Air Traffic Controller3" = I am an Air Traffic Controller3
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InCD!UninstallKey" = InCD (Ahead Software)
"InstallShield_{3D047C15-C859-45F7-81CE-F2681778069B}" = iPod for Windows 2006-01-10
"InstallShield_{654F0312-CB3D-4FE2-962C-6BB9752E9146}" = iPod for Windows 2005-06-26
"InstallShield_{D9F4A9F8-92C5-4289-9D04-F0F8F02D580A}" = iPod for Windows 2005-10-12
"InstallShield_{F5577101-33CC-4711-8235-3A95BCD49DB0}" = EA Link
"InstallWatch Pro 2.5" = InstallWatch Pro 2.5
"Kaspersky Online Scanner" = Kaspersky Online Scanner
"LDB ClockXP 2.00 Beta 3" = LDB ClockXP 2.00 Beta 3
"Level-D Simulations 767-300" = Level-D Simulations 767-300
"Macromedia Shockwave Player" = Macromedia Shockwave Player
"Mafia Game" = Mafia Game
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSCSR" = Microsoft Speech Recognition Engine 4.0 (English)
"MSDict" = Microsoft Dictation
"MSN Music Assistant" = MSN Music Assistant
"MSSpchSDK" = Microsoft Speech SDK 4.0
"MSTTS" = Microsoft Text-to-Speech Engine 4.0 (English)
"MSVoice" = Microsoft Voice
"MUSICMATCH Jukebox" = MUSICMATCH Jukebox
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Nokia PC Suite" = Nokia PC Suite
"OceanFX 2" = OceanFX 2
"PCFriendly" = PCFriendly
"powerOne Personal v3.1.4 for Handhelds" = powerOne Personal v3.1.4 for Handhelds
"Radar Contact v4.3_is1" = Radar Contact Version 4.3
"Roger Wilco" = Roger Wilco
"Shockwave" = Shockwave
"Silent Package Run-Time Sample" = EPSON RX595 User's Guide
"SiSoftware Sandra Standard 2004.SP2b (Win32 x86)_is1" = SiSoftware Sandra Standard 2004.SP2b (Win32 x86)
"SpchAll" = Microsoft Speech SDK 4.0 Suite
"SpeedFan" = SpeedFan (remove only)
"SpeedUp for MS FlightSimulator 9" = SpeedUp for MS FlightSimulator 9
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.4
"SpywareBlaster_is1" = SpywareBlaster 4.1
"SpywareGuard_is1" = SpywareGuard v2.2
"ST5UNST #1" = Microsoft Speech SDK 4.0 ActiveX Components
"ST6UNST #1" = ATCsimulator2 (Build 2.8.9)
"ST6UNST #2" = Active AirSource v3.27
"ST6UNST #3" = ATCsimulator2 (Build 2.8.9) (C:\Program Files\ATCsimulator2\)
"ST6UNST #4" = ATCsimulator2 (Build 2.8.9) (C:\Program Files\ATCsimulator2\) #3
"ST6UNST #5" = ATCsimulator2 (Build 2.8.9) (C:\Program Files\ATCsimulator2\) #4
"ST6UNST #6" = ATCsimulator2 (Build 2.8.9) (C:\Program Files\ATCsimulator2\) #5
"ST6UNST #7" = ATCsimulator2 (Build 2.8.9) (C:\Program Files\ATCsimulator2\) #6
"ST6UNST #8" = ATCsimulator2 (Build 2.8.9) (C:\Program Files\ATCsimulator2\) #7
"SUPER ©" = SUPER © Version 2007.bld.22 (Mar 14, 2007)
"Super Audio Converter_is1" = Super Audio Converter 5.0
"SyncBack_is1" = SyncBack
"Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2
"Tranquillity 1.0_is1" = Tranquillity 1.0
"tv_enua" = Lernout & Hauspie TruVoice American English TTS Engine
"Ultimate Terrain - Canada & Alaska" = Ultimate Terrain - Canada & Alaska
"UltimateTraffic10" = Ultimate Traffic
"UltimateTraffic110" = Ultimate Traffic - Upgrade
"UltimateTraffic13_Update" = Ultimate Traffic - Update
"Voice Editor" = Voice Editor
"VPN v1.4us" = VPN v1.4us
"WIC" = Windows Imaging Component
"Winamp" = Winamp (remove only)
"Window Washer" = Window Washer
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinMX" = WinMX
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XviD_is1" = XviD MPEG-4 Video Codec
"Yahoo! Messenger" = Yahoo! Messenger
"ZoneAlarm" = ZoneAlarm
"ZoneAlarmSB Uninstall" = ZoneAlarm Spy Blocker

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]
Error - 1/1/2009 10:29:28 PM | Computer Name = ENZO | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
E:\Melissa & Enzo\M&E_1497.jpg failed, 0000A420.

Error - 1/1/2009 10:30:38 PM | Computer Name = ENZO | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
E:\Melissa & Enzo\M&E_1498.jpg failed, 0000A420.

Error - 1/1/2009 10:31:52 PM | Computer Name = ENZO | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
E:\Melissa & Enzo\M&E_1499.jpg failed, 0000A420.

Error - 1/1/2009 10:33:02 PM | Computer Name = ENZO | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
E:\Melissa & Enzo\M&E_1500.jpg failed, 0000001E.

Error - 1/1/2009 10:33:27 PM | Computer Name = ENZO | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
E:\Melissa & Enzo\M&E_1501.jpg failed, 0000A420.

Error - 1/2/2009 2:59:56 AM | Computer Name = ENZO | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
E:\Melissa & Enzo\M&E_1489.jpg failed, 0000A420.

Error - 1/2/2009 3:20:28 AM | Computer Name = ENZO | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
E:\Melissa & Enzo\M&E_1488.jpg failed, 0000001E.

Error - 1/2/2009 3:20:53 AM | Computer Name = ENZO | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
E:\Melissa & Enzo\M&E_1490.jpg failed, 0000001E.

Error - 1/2/2009 3:21:48 AM | Computer Name = ENZO | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
E:\Melissa & Enzo\M&E_1492.jpg failed, 0000001E.

Error - 1/2/2009 3:23:19 AM | Computer Name = ENZO | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
E:\Melissa & Enzo\M&E_1493.jpg failed, 0000A420.

[ Application Events ]
Error - 2/8/2009 7:04:44 PM | Computer Name = ENZO | Source = Application Hang | ID = 1002
Description = Hanging application atc3menu.exe, version 1.0.1.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2/8/2009 7:07:17 PM | Computer Name = ENZO | Source = Application Hang | ID = 1002
Description = Hanging application crawler.exe, version 1.0.0.3, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2/8/2009 7:07:33 PM | Computer Name = ENZO | Source = Application Hang | ID = 1002
Description = Hanging application crawler.exe, version 1.0.0.3, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2/8/2009 7:07:57 PM | Computer Name = ENZO | Source = Application Hang | ID = 1002
Description = Hanging application crawler.exe, version 1.0.0.3, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2/8/2009 7:08:06 PM | Computer Name = ENZO | Source = Application Hang | ID = 1002
Description = Hanging application crawler.exe, version 1.0.0.3, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2/8/2009 7:08:47 PM | Computer Name = ENZO | Source = Application Hang | ID = 1002
Description = Hanging application crawler.exe, version 1.0.0.3, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2/8/2009 7:08:53 PM | Computer Name = ENZO | Source = Application Hang | ID = 1002
Description = Hanging application crawler.exe, version 1.0.0.3, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2/8/2009 7:09:11 PM | Computer Name = ENZO | Source = Application Hang | ID = 1002
Description = Hanging application crawler.exe, version 1.0.0.3, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2/8/2009 7:09:13 PM | Computer Name = ENZO | Source = Application Hang | ID = 1002
Description = Hanging application crawler.exe, version 1.0.0.3, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2/8/2009 7:09:14 PM | Computer Name = ENZO | Source = Application Hang | ID = 1002
Description = Hanging application crawler.exe, version 1.0.0.3, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 1/2/2009 3:25:50 AM | Computer Name = ENZO | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort1, did not respond within the timeout
period.

Error - 1/2/2009 3:26:00 AM | Computer Name = ENZO | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort1, did not respond within the timeout
period.

Error - 1/2/2009 3:26:10 AM | Computer Name = ENZO | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 1/2/2009 3:26:19 AM | Computer Name = ENZO | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort1, did not respond within the timeout
period.

Error - 1/2/2009 3:26:29 AM | Computer Name = ENZO | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort1, did not respond within the timeout
period.

Error - 1/2/2009 3:26:39 AM | Computer Name = ENZO | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort1, did not respond within the timeout
period.

Error - 1/2/2009 3:26:49 AM | Computer Name = ENZO | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort1, did not respond within the timeout
period.

Error - 1/2/2009 3:26:59 AM | Computer Name = ENZO | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 1/2/2009 4:38:56 PM | Computer Name = ENZO | Source = LDMS | ID = 16780239
Description = The Logical Disk Manager Service failed while registering for device
handle notifications on device \\?\storage#removablemedia#8&116b2690&0&rm#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}.
Win32 Error: 2.

Error - 1/12/2009 3:51:49 PM | Computer Name = ENZO | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort1, did not respond within the timeout
period.


< End of report >

hello

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.



OTListIt logfile created on: 2/9/2009 2:01:47 PM - Run
OTListIt2 by OldTimer - Version 2.0.0.10 Folder = C:\Documents and Settings\Vincenzo\Desktop\TOOLS\Myweb search removal
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 3.85 Gb Available in Paging File | 96.19% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 32.44 Gb Free Space | 43.53% Space Free | Partition Type: NTFS
Drive D: | 629.86 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 465.65 Gb Total Space | 449.04 Gb Free Space | 96.43% Space Free | Partition Type: FAT32
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ENZO
Current User Name: Vincenzo
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\CTSVCCDA.EXE (Creative Technology Ltd)
PRC - C:\Program Files\Common Files\Motive\McciCMService.exe (Motive Communications, Inc.)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
PRC - C:\WINDOWS\system32\MsPMSPSv.exe (Microsoft Corporation)
PRC - C:\Program Files\Webroot\Washer\WasherSvc.exe (Webroot Software, Inc.)
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Advanced Micro Devices Inc.)
PRC - C:\Program Files\Logitech\MouseWare\system\EM_EXEC.EXE (Logitech Inc.)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
PRC - C:\Program Files\Palm\Hotsync.exe (PalmSource, Inc)
PRC - C:\Program Files\SpywareGuard\sgmain.exe ()
PRC - C:\Program Files\SpywareGuard\sgbhp.exe ()
PRC - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Webroot\Washer\wwDisp.exe (Webroot Software, Inc.)
PRC - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
PRC - C:\Program Files\Windows NT\Accessories\wordpad.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Vincenzo\Desktop\TOOLS\Myweb search removal\OTListIt22.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (ACDaemon [Disabled | Stopped]) – C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (aswUpdSv [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (Ati HotKey Poller [Auto | Running]) – C:\WINDOWS\system32\ati2evxx.exe (ATI Technologies Inc.)
SRV - (ATI Smart [Auto | Stopped]) – C:\WINDOWS\system32\ati2sgag.exe ()
SRV - (avast! Antivirus [Auto | Running]) – C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner [On_Demand | Running]) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner [On_Demand | Running]) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (AVG Anti-Spyware Guard [On_Demand | Stopped]) – C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe (GRISOFT s.r.o.)
SRV - (Bonjour Service [Disabled | Stopped]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (CLTNetCnService [Disabled | Stopped]) – File not found
SRV - (Creative Service for CDROM Access [Auto | Running]) – C:\WINDOWS\system32\CTSVCCDA.EXE (Creative Technology Ltd)
SRV - (DeepsightExtractor [Disabled | Stopped]) – File not found
SRV - (ExtractorServiceNPF03 [Disabled | Stopped]) – File not found
SRV - (ExtractorServiceNPF04 [Disabled | Stopped]) – File not found
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (iPod Service [On_Demand | Stopped]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (McciCMService [Auto | Running]) – C:\Program Files\Common Files\Motive\McciCMService.exe (Motive Communications, Inc.)
SRV - (ServiceLayer [On_Demand | Stopped]) – C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (Nokia.)
SRV - (SoundMAX Agent Service (default) [Auto | Running]) – C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
SRV - (Symantec Core LC [Disabled | Stopped]) – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (Symantec Corporation)
SRV - (usnjsvc [On_Demand | Stopped]) – C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (vsmon [Auto | Stopped]) – C:\WINDOWS\system32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (WMDM PMSP Service [Auto | Running]) – C:\WINDOWS\system32\MsPMSPSv.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (WudfSvc [On_Demand | Stopped]) – C:\WINDOWS\system32\WudfSvc.dll (Microsoft Corporation)
SRV - (wwEngineSvc [Auto | Running]) – C:\Program Files\Webroot\Washer\WasherSvc.exe (Webroot Software, Inc.)
SRV - (x10nets [On_Demand | Stopped]) – File not found

========== Driver Services (SafeList) ==========

DRV - (Aavmker4 [System | Running]) – C:\WINDOWS\system32\drivers\aavmker4.sys (ALWIL Software)
DRV - (aeaudio [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\aeaudio.sys (Andrea Electronics Corporation)
DRV - (Afc [On_Demand | Running]) – C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (aslm75 [Auto | Running]) – C:\WINDOWS\system32\drivers\ASLM75.SYS ()
DRV - (aswFsBlk [Auto | Running]) – C:\WINDOWS\system32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (aswMon2 [Auto | Running]) – C:\WINDOWS\system32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswRdr [On_Demand | Running]) – C:\WINDOWS\system32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswSP [System | Running]) – C:\WINDOWS\system32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswTdi [System | Running]) – C:\WINDOWS\system32\drivers\aswTdi.sys (ALWIL Software)
DRV - (atapi [Boot | Running]) – C:\WINDOWS\system32\drivers\atapi.sys ()
DRV - (ati2mtag [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (atinrvxx [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\atinrvxx.sys (ATI Technologies Inc.)
DRV - (ATITool [System | Running]) – C:\Program Files\ATITool\atitool.sys ()
DRV - (AVG Anti-Spyware Driver [System | Running]) – C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ()
DRV - (AvgAsCln [System | Running]) – C:\WINDOWS\system32\drivers\AvgAsCln.sys (GRISOFT, s.r.o.)
DRV - (BsStor [Boot | Running]) – C:\WINDOWS\system32\drivers\bsstor.sys (B.H.A Co.,Ltd.)
DRV - (BsUDF [Disabled | Stopped]) – C:\WINDOWS\system32\drivers\bsudf.sys (ahead software)
DRV - (chanalog [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\chanalog.sys (CH Products)
DRV - (ctac32k [On_Demand | Running]) – C:\WINDOWS\system32\drivers\CTAC32K.SYS (Creative Technology Ltd)
DRV - (ctaud2k [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctljystk [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ctljystk.sys (Creative Technology Ltd.)
DRV - (ctprxy2k [On_Demand | Running]) – C:\WINDOWS\system32\drivers\CTPRXY2K.SYS (Creative Technology Ltd)
DRV - (ctsfm2k [On_Demand | Running]) – C:\WINDOWS\system32\drivers\CTSFM2K.SYS (Creative Technology Ltd)
DRV - (d346bus [Boot | Running]) – C:\WINDOWS\system32\drivers\d346bus.sys ( )
DRV - (d346prt [Boot | Running]) – C:\WINDOWS\system32\drivers\d346prt.sys ( )
DRV - (EL2000 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\EL2K_XP.sys (3Com Corporation)
DRV - (emupia [On_Demand | Running]) – C:\WINDOWS\system32\drivers\EMUPIA2K.SYS (Creative Technology Ltd)
DRV - (ENETHUSB [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\enethusb.sys (Efficient Networks, Inc.)
DRV - (gameenum [On_Demand | Running]) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (giveio [Boot | Running]) – C:\WINDOWS\system32\giveio.sys ()
DRV - (gmer [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\gmer.sys (GMER)
DRV - (ha10kx2k [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (hap16v2k [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\HAP16V2K.SYS (Creative Technology Ltd)
DRV - (hidgame [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\hidgame.sys (Microsoft Corporation)
DRV - (kbdhid [System | Stopped]) – C:\WINDOWS\system32\drivers\kbdhid.sys (Microsoft Corporation)
DRV - (L8042pr2 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\L8042pr2.Sys (Logitech, Inc.)
DRV - (LHidFlt2 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\LHIDFLT2.SYS (Logitech, Inc.)
DRV - (LHidUsb [On_Demand | Running]) – C:\WINDOWS\system32\drivers\LHIDUSB.SYS (Logitech, Inc.)
DRV - (LMouFlt2 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\LMouFlt2.Sys (Logitech, Inc.)
DRV - (MidiSyn [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\MidiSyn.sys (Analog Devices Inc)
DRV - (MREMP50 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MRENDIS5 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MRENDIS5.sys (Motive, Inc.)
DRV - (MRESP50 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MVDCODEC [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\atinmdxx.sys (ATI Technologies Inc.)
DRV - (MxlW2k [On_Demand | Running]) – C:\WINDOWS\system32\drivers\MxlW2k.sys (MusicMatch, Inc.)
DRV - (ossrv [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (PalmUSBD [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\PalmUSBD.sys (PalmSource, Inc.)
DRV - (pfc [On_Demand | Running]) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (PfModNT [Auto | Running]) – C:\WINDOWS\system32\drivers\PFMODNT.SYS (Creative Technology Ltd.)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\system32\drivers\pxhelp20.sys (Sonic Solutions)
DRV - (Secdrv [Auto | Running]) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sfdrv01 [Boot | Running]) – C:\WINDOWS\system32\drivers\sfdrv01.sys (Protection Technology)
DRV - (sfhlp02 [Boot | Running]) – C:\WINDOWS\system32\drivers\sfhlp02.sys (Protection Technology)
DRV - (smwdm [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\smwdm.sys (Analog Devices, Inc.)
DRV - (speedfan [Boot | Running]) – C:\WINDOWS\system32\speedfan.sys (Windows ® 2000 DDK provider)
DRV - (srescan [Boot | Running]) – C:\WINDOWS\system32\ZoneLabs\srescan.sys (Check Point Software Technologies LTD)
DRV - (symlcbrd [Auto | Running]) – C:\WINDOWS\system32\drivers\symlcbrd.sys (Symantec Corporation)
DRV - (TCAITDI [Auto | Running]) – C:\WINDOWS\system32\drivers\TCAITDI.SYS (3Com Corporation)
DRV - (TVICHW32 [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\TVICHW32.SYS (EnTech Taiwan)
DRV - (vsdatant [System | Running]) – C:\WINDOWS\system32\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (WBHWDOCT [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\WBHWDOCT.sys (Winbond Electronics Corp.)
DRV - (WmBEnum [On_Demand | Running]) – C:\WINDOWS\system32\drivers\WmBEnum.sys (Logitech Inc.)
DRV - (WmFilter [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\WmFilter.sys (Logitech Inc.)
DRV - (WmVirHid [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\WmVirHid.sys (Logitech Inc.)
DRV - (WmXlCore [On_Demand | Running]) – C:\WINDOWS\system32\drivers\WmXlCore.sys (Logitech Inc.)
DRV - (WS2IFSL [System | Running]) – C:\WINDOWS\system32\drivers\ws2ifsl.sys (Microsoft Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.sympatico.msn.ca
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - URLSearchHook: {50B48177-18A1-B9B0-E399-90C5E06199DA} - Reg Error: Key error. File not found

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.MSN.ca
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

O1 HOSTS File: (291440 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 127.0.0.1 www.163ns.com
O1 - Hosts: 10060 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - Reg Error: Key error. File not found
O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\epson\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [Logitech Utility] Logi_MwX.Exe (Logitech Inc.)
O4 - HKLM..\Run: [LtcyCfgApply] "C:\Documents and Settings\Vincenzo\Desktop\latency tool pci\LtcyCfg.exe" /a ()
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TCASUTIEXE] TCAUDIAG.exe -on File not found
O4 - HKLM..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [EPSON Stylus Photo RX595 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICLA.EXE /FU "C:\WINDOWS\TEMP\E_S1DD.tmp" /EF "HKCU" (SEIKO EPSON CORPORATION)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9f.exe File not found
O4 - HKCU..\RunOnce: [Index Washer] C:\Program Files\Webroot\Washer\WashIdx.exe "Vincenzo" (Webroot Software, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HOTSYNCSHORTCUTNAME.lnk = C:\Program Files\Palm\Hotsync.exe (PalmSource, Inc)
O4 - Startup: C:\Documents and Settings\Vincenzo\Start Menu\Programs\Startup\SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll (InterTrust Technologies Corporation, Inc.)
O15 - HKLM\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: bmo.com ([www1] https in Trusted sites)
O15 - HKCU\..Trusted Domains: 58 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab (Checkers Class)
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab (SupportSoft SmartIssue)
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab (SupportSoft Script Runner Class)
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab (StagingUI Object)
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} http://support.f-secure.com/ols/fscax.cab (F-Secure Online Scanner 3.1)
O16 - DPF: {0DB074F0-617E-4EE9-912C-2965CF2AA5A4} http://download.microsoft.com/download/7/0…tualEarth3D.cab (SentinelVE3D Class)
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} http://downloadcenter.samsung.com/content/…trolLite_EN.cab (DjVuCtl Class)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab (CKAVWebScan Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} http://www.symantec.com/techsupp/asa/LSSupCtl.cab (LSSupCtl Class)
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} http://us.chat1.yimg.com/us.yimg.com/i/cha…v45/yacscom.cab (Yahoo! Audio Conferencing)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab (Symantec AntiVirus scanner)
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} http://download.yahoo.com/dl/installs/yinst0401.cab (YInstStarter Class)
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab (MSN Games – Buddy Invite)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://by121fd.bay121.hotmail.msn.com/resources/MsnPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} http://files.ea.com/downloads/rtpatch/v2/EARTPX.cab (EARTPatchX Class)
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab (ZonePAChat Object)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/microsoftu…b?1183322733905 (WUWebControl Class)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1183322725405 (MUWebControl Class)
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} http://chat.yahoo.com/cab/yacsui.cab (Yahoo! Audio UI1)
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} http://download.zonelabs.com/bin/promotion…canner37680.cab (ICSScanner Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab (MessengerStatsClient Class)
O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} http://zone.msn.com/bingame/zpagames/zpa_txhe.cab60231.cab (MSN Games – Texas Holdem Poker)
O16 - DPF: {AFAB176A-0D25-436A-8555-286F6D7AA388} http://www.actualresearch.com/files/rfscanax.cab (CRegFreezeScanModule Object)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab (ActiveDataInfo Class)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://www.adobe.com/products/acrobat/nos/gp.cab (get_atlcom Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} http://zone.msn.com/binframework/v10/StProxy.cab55579.cab (MSN Games – Game Communicator)
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} http://driveragent.com/files/driveragent.cab (Driver Agent ActiveX Control)
O16 - DPF: Microsoft XML Parser for Java file:///C:/WINDOWS/Java/classes/xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {57B86673-276A-48B2-BAE7-C6DBB3020EB8} - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll (GRISOFT s.r.o.)
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O29 - HKLM SecurityProviders - ( xlibgfl254.dll) - File not found
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - D:\AUTORUN.INF () - [ CDFS ]
O32 - Autorun File - G:\autorun.inf () - [ FAT32 ]
O32 - Autorun File - G:\autorun [2002/01/05 14:30:58 00,000,000 | —D | M] - [ FAT32 ]
O33 - MountPoints2\{c348e5dc-f33b-11dd-a240-000c6e7bf812}\Shell\AutoRun\command - "" = G:\wd_windows_tools\WDSetup.exe – [2008/06/19 12:46:02 | 01,760,476 | —- | M] (Western Digital Corporation )

========== Files/Folders - Created Within 30 Days ==========

[2009/02/09 12:56:55 | 00,001,215 | —- | C] () – C:\Documents and Settings\Vincenzo\Desktop\767-300 Configuration Manager.lnk
[2009/02/09 12:52:17 | 00,002,048 | —- | C] () – C:\WINDOWS\lvld67.lic
[2009/02/09 12:29:16 | 00,000,000 | —D | C] – C:\Rooter$
[2009/02/08 18:30:27 | 00,004,096 | —- | C] () – C:\WINDOWS\System32\crash
[2009/02/08 01:57:10 | 00,000,000 | —D | C] – C:\Documents and Settings\Vincenzo\Desktop\Level D 767 (FS9)
[2009/02/05 00:10:55 | 00,000,000 | —D | C] – C:\Program Files\Western Digital Technologies
[2009/02/01 14:11:04 | 00,030,208 | —- | C] () – C:\Documents and Settings\Vincenzo\My Documents\HEARTS.doc
[2009/01/31 13:49:20 | 00,065,536 | —- | C] () – C:\Documents and Settings\Vincenzo\My Documents\Enleo.doc
[2009/01/31 13:48:30 | 00,067,072 | —- | C] () – C:\Documents and Settings\Vincenzo\My Documents\Melea.doc
[2009/01/31 03:05:10 | 00,000,000 | —D | C] – C:\Documents and Settings\Vincenzo\Desktop\sounds
[2009/01/31 01:48:04 | 00,000,000 | —D | C] – C:\Documents and Settings\Vincenzo\Desktop\Load fs9 2
[2009/01/31 01:43:50 | 00,000,000 | —D | C] – C:\Documents and Settings\Vincenzo\Desktop\Load fs9
[2009/01/25 23:39:17 | 00,032,256 | —- | C] () – C:\Documents and Settings\Vincenzo\My Documents\VIDEO EDITING 2.doc
[2009/01/21 23:03:55 | 00,027,136 | —- | C] () – C:\Documents and Settings\Vincenzo\My Documents\You Found Me.doc
[2009/01/16 13:10:10 | 00,000,935 | —- | C] () – C:\Documents and Settings\Vincenzo\Desktop\rick email.rtf

========== Files - Modified Within 30 Days ==========

[5 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[2009/02/09 12:56:55 | 00,001,215 | —- | M] () – C:\Documents and Settings\Vincenzo\Desktop\767-300 Configuration Manager.lnk
[2009/02/09 12:52:17 | 00,002,048 | —- | M] () – C:\WINDOWS\lvld67.lic
[2009/02/09 12:42:32 | 00,482,444 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/02/09 12:42:32 | 00,413,244 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/02/09 12:42:32 | 00,061,356 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/02/09 12:39:28 | 00,348,376 | -H– | M] () – C:\WINDOWS\System32\vsconfig.xml
[2009/02/09 12:39:22 | 00,013,002 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/02/09 12:38:11 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/02/09 12:38:03 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/02/09 12:38:02 | 00,003,568 | —- | M] () – C:\WINDOWS\System32\ativvaxx.cap
[2009/02/09 12:36:47 | 00,024,144 | —- | M] () – C:\WINDOWS\System32\BMXCtrlState-{00000002-00000000-0000000D-00001102-00000002-80671102}.rfx
[2009/02/09 12:36:47 | 00,024,144 | —- | M] () – C:\WINDOWS\System32\BMXBkpCtrlState-{00000002-00000000-0000000D-00001102-00000002-80671102}.rfx
[2009/02/09 12:36:47 | 00,016,348 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000002-00000000-0000000D-00001102-00000002-80671102}.rfx
[2009/02/09 12:36:47 | 00,016,348 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000002-00000000-0000000D-00001102-00000002-80671102}.rfx
[2009/02/09 12:36:47 | 00,002,056 | —- | M] () – C:\WINDOWS\System32\settingsbkup.sfm
[2009/02/09 12:36:47 | 00,002,056 | —- | M] () – C:\WINDOWS\System32\settings.sfm
[2009/02/09 12:36:47 | 00,000,288 | —- | M] () – C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-0000000D-00001102-00000002-80671102}.dat
[2009/02/09 12:36:47 | 00,000,288 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000002-00000000-0000000D-00001102-00000002-80671102}.dat
[2009/02/09 10:59:12 | 00,002,626 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2009/02/08 18:30:27 | 00,004,096 | —- | M] () – C:\WINDOWS\System32\crash
[2009/02/07 15:59:01 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/02/07 15:37:41 | 00,291,440 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/02/05 16:11:35 | 01,256,296 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\aswBoot.exe
[2009/02/05 16:08:19 | 00,093,296 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon.sys
[2009/02/05 16:08:10 | 00,094,032 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswmon2.sys
[2009/02/05 16:07:23 | 00,114,768 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2009/02/05 16:07:12 | 00,020,560 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2009/02/05 16:06:20 | 00,051,376 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswTdi.sys
[2009/02/05 16:06:10 | 00,023,152 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2009/02/05 16:05:11 | 00,026,944 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\drivers\aavmker4.sys
[2009/02/05 16:04:45 | 00,097,480 | —- | M] (ALWIL Software) – C:\WINDOWS\System32\AVASTSS.scr
[2009/02/04 23:51:28 | 00,000,892 | —- | M] () – C:\WINDOWS\win.ini
[2009/02/04 23:51:28 | 00,000,254 | —- | M] () – C:\WINDOWS\system.ini
[2009/02/04 23:51:28 | 00,000,211 | RHS- | M] () – C:\boot.ini
[2009/02/01 14:11:05 | 00,030,208 | —- | M] () – C:\Documents and Settings\Vincenzo\My Documents\HEARTS.doc
[2009/01/31 13:49:20 | 00,065,536 | —- | M] () – C:\Documents and Settings\Vincenzo\My Documents\Enleo.doc
[2009/01/31 13:48:30 | 00,067,072 | —- | M] () – C:\Documents and Settings\Vincenzo\My Documents\Melea.doc
[2009/01/31 12:05:16 | 00,019,640 | —- | M] () – C:\Documents and Settings\Vincenzo\Application Data\GDIPFONTCACHEV1.DAT
[2009/01/31 10:54:56 | 00,019,640 | —- | M] () – C:\Documents and Settings\Vincenzo\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/01/31 10:53:49 | 00,119,744 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/01/31 01:49:10 | 00,000,056 | —- | M] () – C:\WINDOWS\fs9configurator.ini
[2009/01/30 00:14:06 | 00,004,212 | -H– | M] () – C:\WINDOWS\System32\zllictbl.dat
[2009/01/25 23:39:18 | 00,032,256 | —- | M] () – C:\Documents and Settings\Vincenzo\My Documents\VIDEO EDITING 2.doc
[2009/01/21 23:03:55 | 00,027,136 | —- | M] () – C:\Documents and Settings\Vincenzo\My Documents\You Found Me.doc
[2009/01/16 13:10:11 | 00,000,935 | —- | M] () – C:\Documents and Settings\Vincenzo\Desktop\rick email.rtf

========== LOP Check ==========

[2008/11/11 22:53:55 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2008/11/09 18:15:54 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2007/09/16 14:55:28 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2007/03/07 12:16:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2008/12/29 01:49:09 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ArcSoft
[2008/09/21 21:14:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ATI
[2003/11/12 02:30:19 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Creative
[2004/04/13 23:24:50 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2008/02/08 00:16:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EPSON
[2008/07/09 13:55:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Geek Squad
[2007/09/04 01:33:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2006/07/24 11:52:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HotSync
[2007/04/26 22:39:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Installations
[2007/09/20 00:29:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iolo
[2007/06/26 11:57:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
[2007/09/20 00:21:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MailFrontier
[2005/03/06 11:54:09 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee
[2005/03/06 11:53:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com
[2009/01/31 00:34:57 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2008/08/01 11:45:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Motive
[2007/08/06 13:50:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MotiveSysIDs
[2007/04/26 22:50:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Suite
[2003/12/21 23:08:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2009/02/09 13:03:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2007/06/18 13:55:11 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2009/02/07 22:48:58 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2007/09/06 13:12:19 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Webroot
[2006/02/08 13:31:01 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/12/06 13:58:27 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Vincenzo\Application Data
[2008/12/10 23:16:18 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Adobe
[2004/11/02 12:35:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Adorons
[2005/01/21 00:08:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\AISchedule
[2006/05/20 13:57:01 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Apple Computer
[2008/12/29 14:51:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\ArcSoft
[2008/08/28 01:15:14 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Atari
[2005/06/23 23:39:51 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\ATI
[2008/10/26 13:04:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Auslogics
[2003/11/12 02:49:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Creative
[2008/02/10 20:28:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\EPSON
[2005/02/18 13:20:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\FSAutoStart
[2008/12/06 13:58:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\GARMIN
[2006/12/30 17:24:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Help
[2006/07/24 11:49:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\HotSync
[2007/08/12 01:30:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Identities
[2008/07/29 22:22:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Image Zone Express
[2008/02/08 00:11:55 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\InstallShield
[2003/11/12 14:14:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\InterTrust
[2004/04/13 22:49:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\InterVideo
[2007/09/20 00:29:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\iolo
[2005/05/28 14:32:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Lavasoft
[2004/07/15 01:19:08 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Leadertech
[2008/02/10 21:34:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\LimeWire
[2004/11/07 16:53:45 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Macromedia
[2009/01/31 00:34:55 | 00,000,000 | –SD | M] – C:\Documents and Settings\Vincenzo\Application Data\Microsoft
[2008/08/01 11:48:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Motive
[2007/08/08 22:10:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Mozilla
[2007/04/27 00:13:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Nokia
[2008/02/11 14:49:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Nokia Multimedia Player
[2007/04/26 22:50:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\PC Suite
[2003/12/06 03:06:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Sun
[2005/02/17 02:12:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Symantec
[2006/08/31 23:58:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\teamspeak2
[2007/08/08 22:10:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Thunderbird
[2008/03/05 19:13:41 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\webex
[2008/07/09 13:58:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Webroot
[2005/06/24 01:13:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\X10 Commander
[2004/08/24 23:19:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Vincenzo\Application Data\Yahoo! Messenger
[2009/02/07 15:59:01 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2001/08/23 07:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/02/09 12:38:11 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34

< End of report >
OTListIt Extras logfile created on: 2/9/2009 2:01:47 PM - Run
OTListIt2 by OldTimer - Version 2.0.0.10 Folder = C:\Documents and Settings\Vincenzo\Desktop\TOOLS\Myweb search removal
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 3.85 Gb Available in Paging File | 96.19% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 32.44 Gb Free Space | 43.53% Space Free | Partition Type: NTFS
Drive D: | 629.86 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ENZO
Current User Name: Vincenzo
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.chm [@ = chm.file] – C:\WINDOWS\hh.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\WINDOWS\system32\winhlp32.exe (Microsoft Corporation)
.hta [@ = htafile] – C:\WINDOWS\system32\mshta.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.inf [@ = inffile] – C:\WINDOWS\system32\notepad.exe (Microsoft Corporation)
.ini [@ = inifile] – C:\WINDOWS\system32\notepad.exe (Microsoft Corporation)
.js [@ = JSFile] – C:\WINDOWS\system32\wscript.exe (Microsoft Corporation)
.jse [@ = JSEFile] – C:\WINDOWS\system32\wscript.exe (Microsoft Corporation)
.reg [@ = regfile] – C:\WINDOWS\regedit.exe (Microsoft Corporation)
.txt [@ = txtfile] – C:\WINDOWS\system32\notepad.exe (Microsoft Corporation)
.vbe [@ = VBEFile] – C:\WINDOWS\system32\wscript.exe (Microsoft Corporation)
.vbs [@ = VBSFile] – C:\WINDOWS\system32\wscript.exe (Microsoft Corporation)
.wsf [@ = WSFFile] – C:\WINDOWS\system32\wscript.exe (Microsoft Corporation)
.wsh [@ = WSHFile] – C:\WINDOWS\system32\wscript.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring" = 1

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1 (Microsoft Corporation)
C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger (Microsoft Corporation)
C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire File not found
C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour (Apple Inc.)
C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes (Apple Inc.)
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1 (Microsoft Corporation)
C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) (Microsoft Corporation)
C:\Program Files\Yahoo!\Messenger\YPager.exe:*:Enabled:Yahoo! Messenger (Yahoo! Inc.)
C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server (Yahoo! Inc.)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0030188A-533E-42EE-9837-E044F10E4369}" = Palm
"{007B37D9-0C45-4202-834B-DD5FAAE99D63}" = ArcSoft Print Creations - Slimline Card
"{01A1A019-E1D8-482A-BE17-5E118D17C0A0}" = ArcSoft Print Creations - Brochures & Flyers
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{066D65EA-ED53-44E4-A96A-F81B6E409D2E}" = PC Connectivity Solution
"{08C5815C-2C6E-44f8-8748-0E61BC9AFB68}" = Symantec KB-DocID:2003093015493306
"{08CA9554-B5FE-4313-938F-D4A417B81175}" = QuickTime
"{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}" = WD Diagnostics
"{11396328-AAFB-C592-B715-8D461CE7B495}" = Catalyst Control Center Graphics Previews Common
"{121634B0-2F4A-11D3-ADA3-00C04F52DD53}" = Windows Installer Clean Up
"{1A1F46B3-9B31-A93C-F5F9-2A3DBFC71BCC}" = Skins
"{1CA2E5E4-F4FE-44B4-95E9-77523FB95838}" = EPSON Stylus Photo RX595 Series Scanner Driver Update
"{1EC65D1D-3911-4F7D-8B6A-63C69EDBFC6E}" = EditVoicepack
"{2758F387-D016-4725-9D03-AB039364DF3D}" = PMDG_747-400_Sound_Update
"{286CB62B-0D03-4BF7-BEAC-AECA224C4FB7}" = ArcSoft Print Creations
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{366FFC89-C800-4366-B903-B9C4314109A5}" = Garmin WebUpdater
"{3CCB26F5-E2A7-4C91-8340-9149D7B7C2BE}" = Virtual Earth 3D (Beta)
"{3CE47E6B-AE27-4E40-AC54-329EED96B933}" = ArcSoft Print Creations - Funhouse II
"{3D047C15-C859-45F7-81CE-F2681778069B}" = iPod for Windows 2006-01-10
"{3DE0053C-FD9A-483E-B7C9-B06E4392206E}" = iTunes
"{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}" = Bonjour
"{49C88E44-1B38-4FC6-824E-2BDA3063B0E3}" = Apple Mobile Device Support
"{5023B3E9-6B73-471E-8BD9-DA4442AE357C}" = ArcSoft Print Creations - Quick Photo Book
"{56589DFE-0C29-4DFE-8E42-887B771ECD23}" = ArcSoft Print Creations - Photo Book
"{56CA5D3B-3002-4E7B-90FE-071D8FDF3814}" =
"{571700F0-DB9D-4B3A-B03D-35A14BB5939F}" = Windows Live Messenger
"{57A48477-92F0-4C1F-ADF9-4806C4EC3CF2}" = Nokia PC Suite
"{5809E7CF-4DCF-11D4-9875-00105ACE7734}" = Logitech MouseWare 9.76
"{5D1C82E7-7EC0-4404-A8AD-36C3B444BC34}" = ArcSoft Print Creations - Poster Creator
"{654F0312-CB3D-4FE2-962C-6BB9752E9146}" = iPod for Windows 2005-06-26
"{666E0B91-3FD3-43B7-B6A2-EB9012758982}" = FSAutoStart
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6A6E453A-24DE-3F26-E6AD-7C22A6440B93}" = CCC Help English
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{77DC8E20-5D4B-9563-3F36-BC481384AE9E}" = ccc-core-preinstall
"{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}" = EPSON Web-To-Page
"{7F34A21F-2DEB-4598-BB19-611D6BD24271}" = Managed DirectX (0900)
"{7FFD52E3-239B-4096-B1F5-6B1B5F2A72F8}" = FSBrowser
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E1DCD15-C9F1-49CE-807B-198C8241EB6B}" = ALi USB2.0 Driver
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{907B4640-266B-4A21-92FB-CD1A86CD0F63}" = RollerCoaster Tycoon 3 Platinum
"{9115E7DB-3B29-445A-802D-11E0AA945B7F}" = Sound Blaster Live!
"{9591C049-5CAE-4E89-A8D9-191F1899628B}" = ArcSoft Print Creations - Funhouse
"{95F875CC-1B85-43E6-B3E0-13EA04F3D995}" = ArcSoft Print Creations - Photo Prints
"{972B1D9B-0EAD-49E8-B7D6-3B83FD5665B1}" = Nokia Connectivity Cable Driver
"{97679567-0095-464E-B5F2-E218A1CF3421}" = PMDG747_400 Queen of the Skies
"{98E8A2EF-4EAE-43B8-A172-74842B764777}" = InterVideo WinDVD 4
"{9933F0EE-DFCD-4829-B979-3C56C367CB1A}" = InterVideo WinDVD Creator
"{A040AC77-C1AA-4CC9-8931-9F648AF178F6}" = VC 9.0 Runtime
"{A403D88E-ED7D-48E3-91FD-B8C8A720EDA1}" = Microsoft Speech SDK 5.1
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A4D7B764-4140-11D4-88EB-0050DA3579C0}" = Nero - Burning Rom
"{A6D7A411-7A86-F032-F2DF-470E28B2D835}" = ccc-utility
"{A96D3ED0-E7B3-41F6-8BB5-F3C63D80901D}" = SplashPhoto
"{AC696733-F8C5-4EAD-B165-AC8AB8C2A755}" = TTS_Technology
"{AC76BA86-7AD7-1033-7B44-A81300000003}" = Adobe Reader 8.1.3
"{B0D83FCD-9D42-43ED-8315-250326AADA02}" = ArcSoft Print Creations - Scrapbook
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{B9242864-2841-4ADE-86E0-8F90F91B04DD}" = Logitech Gaming Software
"{B98DA566-F72B-5A7B-1992-DBB0243C5C23}" = Catalyst Control Center Graphics Full New
"{BD12C3FF-F520-4A9D-9B36-A7756466F1AA}" = ArcSoft MediaImpression
"{C176A8E4-FDAE-BFFB-AA04-CE75372C72B0}" = Catalyst Control Center Graphics Light
"{C51738A2-0FD3-49A0-8634-77D84842580D}" = My Active AirSource
"{CA9ED5E4-1548-485B-A293-417840060158}" = ArcSoft Print Creations - Photo Calendar
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{D03E7B00-CA85-4684-9321-1888873C34BD}" = ArcSoft PhotoImpression 6
"{D32D4182-DE6C-457E-838C-8D7B9CE332BA}" = InterVideo WinRip
"{D4E22434-1BCE-4C91-A1E4-FC352DFD4B3B}" = aerosoft's - Mega Airport Frankfurt - FS2004
"{D72B7816-2616-4695-84BD-EB5D6DE75A83}" = ASRC
"{D8E00A2F-9CAE-47B1-BA09-C4A126D7DBA4}" = SquawkBox
"{D9F4A9F8-92C5-4289-9D04-F0F8F02D580A}" = iPod for Windows 2005-10-12
"{DB909A1C-B447-428F-8103-E8975BCB99F0}" = ArcSoft RAW Thumbnail Viewer
"{DDA85049-52FF-4CD0-B30D-9722508C6A01}" = AISchedule
"{DE2A8612-B454-62A6-BE86-2E9F2F830390}" = ccc-core-static
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = AusLogics Disk Defrag
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E3D521EB-AD0D-4184-9FF0-8321D88DCF0E}" = ActiveSky Version 6 and ActiveSky Graphics
"{E6B4117F-AC59-4B13-9274-EB136E8897EE}" = ArcSoft Print Creations - Album Page
"{EA01B804-60DA-41ED-80D3-4C7EBB62774A}" = ArcSoft Video Downloader
"{EA67A493-7B35-D0C1-ACC5-2F0A239D0FFB}" = Catalyst Control Center Graphics Full Existing
"{ED654F5D-5DC9-46EA-9D10-621231527F98}" = FS9 Configurator
"{ED8FF847-6705-4D71-B4E6-876A3FA2344A}" = DeepSight Extractor
"{F04F9557-81A9-4293-BC49-2C216FA325A7}" = ArcSoft Print Creations - Greeting Card
"{F0681859-D086-4384-B204-386FA7D80A5B}" = SplashShopper
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F36A2ADA-7106-8F06-9838-99299A8DC6AC}" = Catalyst Control Center Core Implementation
"{F51D9393-BB14-4566-99BF-D6ED63AEFCD7}" = Natural Color
"{F5223680-993A-11D4-86F6-0001031E5712}" = InterVideo Installer
"{F5577101-33CC-4711-8235-3A95BCD49DB0}" = EA Link
"{F6970FBD-809A-4C51-BAB3-D94A04C6C8E7}" = Garmin Communicator Plugin
"{FA3A247D-437A-455E-A88F-7EB6E5F9E799}" = Catalyst Control Center - Branding
"{FF477885-5EA8-40D0-ADF3-D4C1B86FAEA4}" = EPSON Print CD
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"0852D05415AB9A4F1EF451E342267F76C776ED2F" = Windows Driver Package - Nokia Modem (11/03/2006 6.82.0.1)
"0C5EDC3653FED5B121F464339EAC12534D253B25" = Windows Driver Package - Nokia Modem (02/15/2007 3.1)
"3ComNicUnInstall" = 3Com NIC Diagnostics
"82A44D22-9452-49FB-00FB-CEC7DCAF7E23" = EA SPORTS online 2007
"ActiveTouchMeetingClient" = WebEx
"Ad-Aware SE Personal" = Ad-Aware SE Personal
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11
"AdobeESD" = Adobe Download Manager 1.2 (Remove Only)
"Airliners Env" = Airliners Env 5.1
"All ATI Software" = ATI - Software Uninstall Utility
"ASUS Probe V2.20.07" = ASUS Probe V2.20.07
"AsusUpdate" = AsusUpdate
"ATI Display Driver" = ATI Display Driver
"avast!" = avast! Antivirus
"AVGAntiSpyware75" = AVG Anti-Spyware 7.5
"avi mpg asf wmv to DivX XviD/ to all format avi_is1" = avi2divx
"BitTorrent" = BitTorrent 3.4.2
"CCleaner" = CCleaner (remove only)
"CH Gameport Devices" = CH Gameport Devices
"CodeBaby Player (Remove Only)[removed]" = CodeBaby Player (Remove Only) [removed]
"DivXCodec" = DivX 4.12 Codec
"Driver Cleaner" = Driver Cleaner 3
"EAX Unified" = EAX Unified
"EPSON Printer and Utilities" = EPSON Printer Software
"EPSON Scanner" = EPSON Scan
"EVEREST Home Edition_is1" = EVEREST Home Edition v1.51
"F064B256B4A20996EA9E333B5E0F14B61AB3333D" = Windows Driver Package - Nokia (WUDFRd) WPD (03/19/2007 6.83.31.1)
"Flight Simulator 9.0" = Microsoft Flight Simulator 2004 A Century of Flight
"FS_Real_Time" = FS Real Time v1.65
"getPlus®_ocx" = getPlus®_ocx
"Handmark® MobileDB™ for Palm OS" = Handmark® MobileDB™ for Palm OS
"HijackThis" = HijackThis 1.99.1
"Hoyle Casino 5" = Hoyle Casino 5
"HP Image Zone Express" = HP Image Zone Express
"I am an Air Traffic Controller3" = I am an Air Traffic Controller3
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InCD!UninstallKey" = InCD (Ahead Software)
"InstallShield_{3D047C15-C859-45F7-81CE-F2681778069B}" = iPod for Windows 2006-01-10
"InstallShield_{654F0312-CB3D-4FE2-962C-6BB9752E9146}" = iPod for Windows 2005-06-26
"InstallShield_{D9F4A9F8-92C5-4289-9D04-F0F8F02D580A}" = iPod for Windows 2005-10-12
"InstallShield_{F5577101-33CC-4711-8235-3A95BCD49DB0}" = EA Link
"InstallWatch Pro 2.5" = InstallWatch Pro 2.5
"Kaspersky Online Scanner" = Kaspersky Online Scanner
"LDB ClockXP 2.00 Beta 3" = LDB ClockXP 2.00 Beta 3
"Level-D Simulations 767-300" = Level-D Simulations 767-300
"Macromedia Shockwave Player" = Macromedia Shockwave Player
"Mafia Game" = Mafia Game
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSCSR" = Microsoft Speech Recognition Engine 4.0 (English)
"MSDict" = Microsoft Dictation
"MSN Music Assistant" = MSN Music Assistant
"MSSpchSDK" = Microsoft Speech SDK 4.0
"MSTTS" = Microsoft Text-to-Speech Engine 4.0 (English)
"MSVoice" = Microsoft Voice
"MUSICMATCH Jukebox" = MUSICMATCH Jukebox
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Nokia PC Suite" = Nokia PC Suite
"OceanFX 2" = OceanFX 2
"PCFriendly" = PCFriendly
"powerOne Personal v3.1.4 for Handhelds" = powerOne Personal v3.1.4 for Handhelds
"Radar Contact v4.3_is1" = Radar Contact Version 4.3
"Roger Wilco" = Roger Wilco
"Shockwave" = Shockwave
"Silent Package Run-Time Sample" = EPSON RX595 User's Guide
"SiSoftware Sandra Standard 2004.SP2b (Win32 x86)_is1" = SiSoftware Sandra Standard 2004.SP2b (Win32 x86)
"SpchAll" = Microsoft Speech SDK 4.0 Suite
"SpeedFan" = SpeedFan (remove only)
"SpeedUp for MS FlightSimulator 9" = SpeedUp for MS FlightSimulator 9
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.4
"SpywareBlaster_is1" = SpywareBlaster 4.1
"SpywareGuard_is1" = SpywareGuard v2.2
"ST5UNST #1" = Microsoft Speech SDK 4.0 ActiveX Components
"ST6UNST #1" = ATCsimulator2 (Build 2.8.9)
"ST6UNST #2" = Active AirSource v3.27
"ST6UNST #3" = ATCsimulator2 (Build 2.8.9) (C:\Program Files\ATCsimulator2\)
"ST6UNST #4" = ATCsimulator2 (Build 2.8.9) (C:\Program Files\ATCsimulator2\) #3
"ST6UNST #5" = ATCsimulator2 (Build 2.8.9) (C:\Program Files\ATCsimulator2\) #4
"ST6UNST #6" = ATCsimulator2 (Build 2.8.9) (C:\Program Files\ATCsimulator2\) #5
"ST6UNST #7" = ATCsimulator2 (Build 2.8.9) (C:\Program Files\ATCsimulator2\) #6
"ST6UNST #8" = ATCsimulator2 (Build 2.8.9) (C:\Program Files\ATCsimulator2\) #7
"SUPER ©" = SUPER © Version 2007.bld.22 (Mar 14, 2007)
"Super Audio Converter_is1" = Super Audio Converter 5.0
"SyncBack_is1" = SyncBack
"Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2
"Tranquillity 1.0_is1" = Tranquillity 1.0
"tv_enua" = Lernout & Hauspie TruVoice American English TTS Engine
"Ultimate Terrain - Canada & Alaska" = Ultimate Terrain - Canada & Alaska
"UltimateTraffic10" = Ultimate Traffic
"UltimateTraffic110" = Ultimate Traffic - Upgrade
"UltimateTraffic13_Update" = Ultimate Traffic - Update
"Voice Editor" = Voice Editor
"VPN v1.4us" = VPN v1.4us
"WIC" = Windows Imaging Component
"Winamp" = Winamp (remove only)
"Window Washer" = Window Washer
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinMX" = WinMX
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XviD_is1" = XviD MPEG-4 Video Codec
"Yahoo! Messenger" = Yahoo! Messenger
"ZoneAlarm" = ZoneAlarm
"ZoneAlarmSB Uninstall" = ZoneAlarm Spy Blocker

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]
Error - 1/1/2009 10:29:28 PM | Computer Name = ENZO | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
E:\Melissa & Enzo\M&E_1497.jpg failed, 0000A420.

Error - 1/1/2009 10:30:38 PM | Computer Name = ENZO | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
E:\Melissa & Enzo\M&E_1498.jpg failed, 0000A420.

Error - 1/1/2009 10:31:52 PM | Computer Name = ENZO | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
E:\Melissa & Enzo\M&E_1499.jpg failed, 0000A420.

Error - 1/1/2009 10:33:02 PM | Computer Name = ENZO | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
E:\Melissa & Enzo\M&E_1500.jpg failed, 0000001E.

Error - 1/1/2009 10:33:27 PM | Computer Name = ENZO | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
E:\Melissa & Enzo\M&E_1501.jpg failed, 0000A420.

Error - 1/2/2009 2:59:56 AM | Computer Name = ENZO | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
E:\Melissa & Enzo\M&E_1489.jpg failed, 0000A420.

Error - 1/2/2009 3:20:28 AM | Computer Name = ENZO | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
E:\Melissa & Enzo\M&E_1488.jpg failed, 0000001E.

Error - 1/2/2009 3:20:53 AM | Computer Name = ENZO | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
E:\Melissa & Enzo\M&E_1490.jpg failed, 0000001E.

Error - 1/2/2009 3:21:48 AM | Computer Name = ENZO | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
E:\Melissa & Enzo\M&E_1492.jpg failed, 0000001E.

Error - 1/2/2009 3:23:19 AM | Computer Name = ENZO | Source = avast! | ID = 33554522
Description = AAVM - scanning error: x_AavmCheckFileDirectEx: avfilesScanReal of
E:\Melissa & Enzo\M&E_1493.jpg failed, 0000A420.

[ Application Events ]
Error - 2/8/2009 7:04:44 PM | Computer Name = ENZO | Source = Application Hang | ID = 1002
Description = Hanging application atc3menu.exe, version 1.0.1.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2/8/2009 7:07:17 PM | Computer Name = ENZO | Source = Application Hang | ID = 1002
Description = Hanging application crawler.exe, version 1.0.0.3, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2/8/2009 7:07:33 PM | Computer Name = ENZO | Source = Application Hang | ID = 1002
Description = Hanging application crawler.exe, version 1.0.0.3, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2/8/2009 7:07:57 PM | Computer Name = ENZO | Source = Application Hang | ID = 1002
Description = Hanging application crawler.exe, version 1.0.0.3, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2/8/2009 7:08:06 PM | Computer Name = ENZO | Source = Application Hang | ID = 1002
Description = Hanging application crawler.exe, version 1.0.0.3, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2/8/2009 7:08:47 PM | Computer Name = ENZO | Source = Application Hang | ID = 1002
Description = Hanging application crawler.exe, version 1.0.0.3, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2/8/2009 7:08:53 PM | Computer Name = ENZO | Source = Application Hang | ID = 1002
Description = Hanging application crawler.exe, version 1.0.0.3, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2/8/2009 7:09:11 PM | Computer Name = ENZO | Source = Application Hang | ID = 1002
Description = Hanging application crawler.exe, version 1.0.0.3, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2/8/2009 7:09:13 PM | Computer Name = ENZO | Source = Application Hang | ID = 1002
Description = Hanging application crawler.exe, version 1.0.0.3, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2/8/2009 7:09:14 PM | Computer Name = ENZO | Source = Application Hang | ID = 1002
Description = Hanging application crawler.exe, version 1.0.0.3, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 1/2/2009 3:25:50 AM | Computer Name = ENZO | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort1, did not respond within the timeout
period.

Error - 1/2/2009 3:26:00 AM | Computer Name = ENZO | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort1, did not respond within the timeout
period.

Error - 1/2/2009 3:26:10 AM | Computer Name = ENZO | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 1/2/2009 3:26:19 AM | Computer Name = ENZO | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort1, did not respond within the timeout
period.

Error - 1/2/2009 3:26:29 AM | Computer Name = ENZO | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort1, did not respond within the timeout
period.

Error - 1/2/2009 3:26:39 AM | Computer Name = ENZO | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort1, did not respond within the timeout
period.

Error - 1/2/2009 3:26:49 AM | Computer Name = ENZO | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort1, did not respond within the timeout
period.

Error - 1/2/2009 3:26:59 AM | Computer Name = ENZO | Source = Cdrom | ID = 262151
Description = The device, \Device\CdRom0, has a bad block.

Error - 1/2/2009 4:38:56 PM | Computer Name = ENZO | Source = LDMS | ID = 16780239
Description = The Logical Disk Manager Service failed while registering for device
handle notifications on device \\?\storage#removablemedia#8&116b2690&0&rm#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}.
Win32 Error: 2.

Error - 1/12/2009 3:51:49 PM | Computer Name = ENZO | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort1, did not respond within the timeout
period.


< End of report >
hello

Run OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTLI
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
    PRC - C:\Program Files\SpywareGuard\sgmain.exe ()
    PRC - C:\Program Files\SpywareGuard\sgbhp.exe ()
    IE - URLSearchHook: {50B48177-18A1-B9B0-E399-90C5E06199DA} - Reg Error: Key error. File not found
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - Reg Error: Key error. File not found
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA} - Reg Error: Key error. File not found
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - Reg Error: Key error. File not found
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA} - Reg Error: Key error. File not found
    O33 - MountPoints2\{c348e5dc-f33b-11dd-a240-000c6e7bf812}\Shell\AutoRun\command - "" = G:\wd_windows_tools\WDSetup.exe – [2008/06/19 12:46:02 | 01,760,476 | —- | M] (Western Digital Corporation )
    
    :Services
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL2 log ( don't check the boxes beside LOP Check or Purity this time )



Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.




Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.






Go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.

hello

Run OTList2.exe

  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTLI
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
    PRC - C:\Program Files\SpywareGuard\sgmain.exe ()
    PRC - C:\Program Files\SpywareGuard\sgbhp.exe ()
    IE - URLSearchHook: {50B48177-18A1-B9B0-E399-90C5E06199DA} - Reg Error: Key error. File not found
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - Reg Error: Key error. File not found
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
    O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA} - Reg Error: Key error. File not found
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - Reg Error: Key error. File not found
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA} - Reg Error: Key error. File not found
    O33 - MountPoints2\{c348e5dc-f33b-11dd-a240-000c6e7bf812}\Shell\AutoRun\command - "" = G:\wd_windows_tools\WDSetup.exe – [2008/06/19 12:46:02 | 01,760,476 | —- | M] (Western Digital Corporation )
    
    :Services
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL2 log ( don't check the boxes beside LOP Check or Purity this time )



Please download ATF Cleaner by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.




Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.






Go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.


The otlist2 file froze my pc on 2 occasions, at the bottom it said file not found upon freezing a hard boot was necessary.

Here are the results of malware.

Malwarebytes' Anti-Malware 1.33
Database version: 1742
Windows 5.1.2600 Service Pack 3

2/9/2009 3:22:57 PM
mbam-log-2009-02-09 (15-22-57).txt

Scan type: Quick Scan
Objects scanned: 59297
Time elapsed: 5 minute(s), 12 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\inf\ultra.PNF (Malware.Trace) -> Quarantined and deleted successfully.

ok lets see what Kaspersky shows


Ok I'll report later this evening though.

Thanks!


Ok After a very long scan, the end result was no infected files i also had nothing in the report.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI