mantraguy
2008-12-03, 08:28
Thanks Peku006,
Here's the content of OTViewIt.txt:
OTViewIt logfile created on: 12/2/2008 10:25:09 PM - Run
OTViewIt by OldTimer - Version 1.0.20.0 Folder = C:\Documents and Settings\Mark\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1023.47 Mb Total Physical Memory | 621.53 Mb Available Physical Memory | 60.73% Memory free
2.41 Gb Paging File | 2.16 Gb Available in Paging File | 89.78% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 186.30 Gb Total Space | 140.84 Gb Free Space | 75.60% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 298.08 Gb Total Space | 150.42 Gb Free Space | 50.46% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DESKTOP
Current User Name: Mark
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days
========== Processes ==========
[2008/09/30 06:16:57 | 00,098,304 | ---- | M] (Sophos Plc) -- C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
[2008/11/07 14:28:16 | 00,132,424 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
[2008/08/29 10:18:44 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe
[2008/10/29 20:06:12 | 00,168,432 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
[2008/10/23 07:56:52 | 00,069,632 | ---- | M] (Sophos Plc) -- C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
[2008/11/19 20:51:24 | 00,133,104 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\GoogleUpdate.exe
[2008/10/23 07:55:27 | 00,266,240 | ---- | M] (Sophos Plc) -- C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
[2008/09/30 06:18:47 | 00,172,032 | ---- | M] (Sophos Plc) -- C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
[2008/10/23 07:55:52 | 00,794,624 | ---- | M] (Sophos Plc) -- C:\Program Files\Sophos\Remote Management System\RouterNT.exe
[2001/10/26 21:32:54 | 00,270,336 | ---- | M] (ATI Technologies, Inc.) -- C:\WINDOWS\system32\atiptaxx.exe
[2001/08/20 20:30:00 | 00,466,944 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\ViewPort.exe
[2002/10/15 17:00:20 | 01,818,624 | ---- | M] (C-Media Electronic Inc. (www.cmedia.com.tw)) -- C:\WINDOWS\mixer.exe
[1998/07/16 00:00:00 | 00,042,496 | ---- | M] () -- C:\Program Files\SCANJET\PrecisionScanPro\HPLamp.exe
[2008/06/10 03:27:04 | 00,144,784 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
[2001/11/08 16:19:16 | 00,053,248 | ---- | M] (Morgan Multimedia) -- C:\WINDOWS\system32\MMTray.exe
[2008/11/20 13:20:54 | 00,290,088 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunesHelper.exe
[2006/11/13 12:39:52 | 01,289,000 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft ActiveSync\wcescomm.exe
[2008/08/11 16:46:50 | 21,741,864 | R--- | M] (Skype Technologies S.A.) -- C:\Program Files\Skype\Phone\Skype.exe
[2007/08/10 01:09:30 | 00,245,760 | ---- | M] (Sophos Plc) -- C:\Program Files\Sophos\AutoUpdate\ALMon.exe
[2006/11/13 12:39:34 | 00,199,464 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft ActiveSync\rapimgr.exe
[2008/11/20 13:20:44 | 00,536,872 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe
[2008/07/18 21:10:42 | 00,053,448 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wuauclt.exe
[2008/08/11 16:46:50 | 00,076,744 | R--- | M] (Skype Technologies) -- C:\Program Files\Skype\Plugin Manager\skypePM.exe
[2008/12/02 22:24:12 | 00,422,400 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mark\Desktop\OTViewIt.exe
========== (O23) Win32 Services ==========
[2008/11/07 14:28:16 | 00,132,424 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running])
[2008/08/29 10:18:44 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service [Auto | Running])
[2008/09/05 07:57:44 | 00,029,744 | ---- | M] (Google) -- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe -- (GoogleDesktopManager-061008-081103 [On_Demand | Stopped])
[2008/11/19 20:51:24 | 00,133,104 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\GoogleUpdate.exe -- (gupdate1c94acba94c51dc [Auto | Stopped])
[2008/10/29 20:06:12 | 00,168,432 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [Auto | Running])
[2008/11/20 13:20:44 | 00,536,872 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Running])
[2003/07/28 11:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
[2008/10/23 07:56:52 | 00,069,632 | ---- | M] (Sophos Plc) -- C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe -- (SAVAdminService [Unknown | Running])
[2008/09/30 06:16:57 | 00,098,304 | ---- | M] (Sophos Plc) -- C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe -- (SAVService [Unknown | Running])
[2008/10/23 07:55:27 | 00,266,240 | ---- | M] (Sophos Plc) -- C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe -- (Sophos Agent [Auto | Running])
[2008/09/30 06:18:47 | 00,172,032 | ---- | M] (Sophos Plc) -- C:\Program Files\Sophos\AutoUpdate\ALsvc.exe -- (Sophos AutoUpdate Service [Auto | Running])
[2008/10/23 07:55:52 | 00,794,624 | ---- | M] (Sophos Plc) -- C:\Program Files\Sophos\Remote Management System\RouterNT.exe -- (Sophos Message Router [Auto | Running])
========== Driver Services ==========
[1997/12/22 17:02:46 | 00,023,936 | ---- | M] (Adaptec) -- C:\WINDOWS\System32\drivers\aspi32.sys -- (Aspi32 [Auto | Running])
[2001/10/26 21:47:14 | 00,349,184 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag [On_Demand | Running])
[2001/10/26 19:47:30 | 00,065,024 | ---- | M] () -- C:\WINDOWS\system32\drivers\atinrvxx.sys -- (atinrvxx [On_Demand | Stopped])
[2001/10/26 19:46:22 | 00,035,952 | ---- | M] () -- C:\WINDOWS\system32\drivers\atintuxx.sys -- (ATITUNEP [Auto | Stopped])
[2001/10/26 19:49:22 | 00,032,848 | ---- | M] () -- C:\WINDOWS\system32\drivers\atinraxx.sys -- (ativraxx [On_Demand | Stopped])
[2001/10/26 19:50:02 | 00,032,752 | ---- | M] () -- C:\WINDOWS\system32\drivers\atinxsxx.sys -- (ATIXSAudio [Auto | Stopped])
[2001/10/01 14:29:22 | 00,006,144 | ---- | M] (Ravisent Technologies, Inc.) -- C:\WINDOWS\system32\drivers\cinemsup.sys -- (CINEMSUP [Auto | Running])
[2002/11/18 14:51:40 | 00,377,358 | ---- | M] (C-Media Inc) -- C:\WINDOWS\system32\drivers\cmaudio.sys -- (cmpci [On_Demand | Running])
[2001/08/17 04:19:20 | 00,003,712 | ---- | M] (Creative Technology Ltd.) -- C:\WINDOWS\system32\drivers\ctljystk.sys -- (ctljystk [On_Demand | Stopped])
[2001/08/17 04:19:26 | 00,283,904 | ---- | M] (Creative Technology Ltd.) -- C:\WINDOWS\system32\drivers\emu10k1m.sys -- (emu10k [On_Demand | Stopped])
[2001/08/17 04:19:28 | 00,006,912 | ---- | M] (Creative Technology Ltd.) -- C:\WINDOWS\system32\drivers\ctlfacem.sys -- (emu10k1 [On_Demand | Stopped])
[2004/08/03 15:08:22 | 00,010,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum [On_Demand | Running])
[2008/04/17 12:12:54 | 00,015,464 | ---- | M] (GEAR Software Inc.) -- C:\WINDOWS\system32\drivers\GEARAspiWDM.sys -- (GEARAspiWDM [On_Demand | Running])
[2007/03/08 16:18:00 | 00,008,320 | ---- | M] (GARMIN Corp.) -- C:\WINDOWS\system32\drivers\grmnusb.sys -- (grmnusb [On_Demand | Stopped])
[2001/10/26 19:49:30 | 00,011,280 | ---- | M] () -- C:\WINDOWS\system32\drivers\atinmdxx.sys -- (MVDCODEC [Auto | Stopped])
[2008/11/12 20:58:37 | 00,027,904 | ---- | M] (Windows (R) Codename Longhorn DDK provider) -- C:\WINDOWS\system32\drivers\ndisprot.sys -- (Ndisprot [On_Demand | Stopped])
[2001/10/26 19:49:38 | 00,011,760 | ---- | M] () -- C:\WINDOWS\system32\drivers\atinpdxx.sys -- (PCDCODEC [Auto | Stopped])
[2001/08/23 04:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink [On_Demand | Running])
[2004/08/03 14:31:34 | 00,020,992 | ---- | M] (Realtek Semiconductor Corporation) -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139 [On_Demand | Running])
[2008/09/30 06:17:40 | 00,104,704 | ---- | M] (Sophos Plc) -- C:\WINDOWS\system32\drivers\savonaccesscontrol.sys -- (SAVOnAccessControl [System | Running])
[2008/09/30 06:17:36 | 00,035,584 | ---- | M] (Sophos Plc) -- C:\WINDOWS\system32\drivers\savonaccessfilter.sys -- (SAVOnAccessFilter [System | Running])
[2004/07/17 07:36:38 | 00,027,440 | ---- | M] () -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv [On_Demand | Stopped])
[2001/08/17 04:19:34 | 00,036,480 | ---- | M] (Creative Technology Ltd.) -- C:\WINDOWS\system32\drivers\sfmanm.sys -- (sfman [On_Demand | Stopped])
[2001/08/17 04:50:56 | 00,050,432 | ---- | M] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\system32\drivers\SiSV.sys -- (SiSV [On_Demand | Running])
[2008/09/30 06:17:45 | 00,014,976 | ---- | M] (Sophos Plc) -- C:\WINDOWS\system32\drivers\SophosBootDriver.sys -- (SophosBootDriver [Disabled | Stopped])
[2008/10/01 12:01:28 | 00,032,000 | ---- | M] (Apple, Inc.) -- C:\WINDOWS\system32\drivers\usbaapl.sys -- (USBAAPL [On_Demand | Stopped])
[2006/11/06 17:04:56 | 00,028,672 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\wceusbsh.sys -- (wceusbsh [On_Demand | Stopped])
========== (R ) Internet Explorer ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]
"Start Page"=http://www.google.com
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search]
"SearchAssistant"=http://www.google.com/ie
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main]
"Search Page"=http://www.google.com
"Start Page"=http://www.google.com/
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURL]
""=http://www.google.com/keyword/%s
"provider"=gogl
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation)
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
"ProxyOverride" = *.local
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main]
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main]
[HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main]
[HKEY_USERS\S-1-5-21-220523388-484061587-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main]
"Search Page"=http://www.google.com
"Start Page"=http://www.google.com/
[HKEY_USERS\S-1-5-21-220523388-484061587-725345543-1003\Software\Microsoft\Internet Explorer\SearchURL]
""=http://www.google.com/keyword/%s
"provider"=gogl
[HKEY_USERS\S-1-5-21-220523388-484061587-725345543-1003\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-220523388-484061587-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
"ProxyOverride" = *.local
========== (O1) Hosts File ==========
HOSTS File = (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
First 25 entries...
127.0.0.1 localhost
========== (O2) BHO's ==========
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (HKLM) -- C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
{39EA7695-B3F2-4C44-A4BC-297ADA8FD235} (HKLM) -- C:\Program Files\Sophos\Sophos Anti-Virus\SophosBHO.dll (Sophos Plc)
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (HKLM) -- C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
{AE7CD045-E861-484f-8273-0445EE161910} (HKLM) -- C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (HKLM) -- C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll (Google Inc.)
{E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} (HKLM) -- C:\Program Files\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll (Google Inc.)
========== (O3) Toolbars ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{47833539-D0C5-4125-9FA8-0819E2EAAC93}" (HKLM) -- C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{47833539-D0C5-4125-9FA8-0819E2EAAC93}" (HKLM) -- C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
[HKEY_USERS\S-1-5-21-220523388-484061587-725345543-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{47833539-D0C5-4125-9FA8-0819E2EAAC93}" (HKLM) -- C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll ()
========== (O4) Run Keys ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AtiPTA"=atiptaxx.exe (ATI Technologies, Inc.)
"C-Media Mixer"=Mixer.exe /startup (C-Media Electronic Inc. (www.cmedia.com.tw))
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup (Google)
"HP Lamp"=C:\PROGRAM FILES\SCANJET\PrecisionScanPro\HPLamp.exe ()
"HydarVisionDesktopManager"= File not found
"HydraVisionViewport"=viewport.exe (ATI Technologies Inc.)
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
"MMTray"=MMTray.exe (Morgan Multimedia)
"NeroCheck"=C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" (Sun Microsystems, Inc.)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATI Launchpad"= File not found
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\Wcescomm.exe" (Microsoft Corporation)
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized (Skype Technologies S.A.)
[HKEY_USERS\S-1-5-21-220523388-484061587-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATI Launchpad"= File not found
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\Wcescomm.exe" (Microsoft Corporation)
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized (Skype Technologies S.A.)
========== (O4) Startup Folders ==========
[2007/08/10 01:09:30 | 00,245,760 | ---- | M] (Sophos Plc) -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
========== (O6 & O7) Current Version Policies ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
[HKEY_USERS\S-1-5-21-220523388-484061587-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
========== (O8) IE Context Menu Extensions ==========
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE [2007/05/31 12:41:06 | 10,352,472 | ---- | M] (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-220523388-484061587-725345543-1003\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE [2007/05/31 12:41:06 | 10,352,472 | ---- | M] (Microsoft Corporation)
========== (O9) IE Extensions ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}: Menu: Sun Java Console -- %ProgramFiles%\Java\jre1.6.0_07\bin\npjpi160_07.dll [2008/06/10 03:27:02 | 00,132,496 | ---- | M] (Sun Microsystems, Inc.)
{09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5}: Menu: &Gears Settings -- %ProgramFiles%\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll [2008/11/29 16:27:46 | 01,667,072 | ---- | M] (Google Inc.)
{2EAF5BB1-070F-11D3-9307-00C04FAE2D4F}: Button: Create Mobile Favorite -- %ProgramFiles%\Microsoft ActiveSync\INetRepl.dll [2006/11/13 12:39:34 | 00,158,504 | ---- | M] (Microsoft Corporation)
{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F}: Menu: Create Mobile Favorite... -- %ProgramFiles%\Microsoft ActiveSync\INetRepl.dll [2006/11/13 12:39:34 | 00,158,504 | ---- | M] (Microsoft Corporation)
{44226DFF-747E-4edc-B30C-78752E50CD0C}: Button: ATI TV -- %ProgramFiles%\ATI Multimedia\TV\EXPLBAR.DLL [2001/08/24 07:27:34 | 00,131,072 | ---- | M] (ATI Technologies Inc.)
{92780B25-18CC-41C8-B9BE-3C9C571A8263}: Button: Research -- %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [2007/04/19 13:10:18 | 00,063,840 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Button: Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2004/08/04 00:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Menu: Windows Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2004/08/04 00:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_07\bin\npjpi160_07.dll [Sun Java Console] -> [2008/06/10 03:27:02 | 00,132,496 | ---- | M] (Sun Microsystems, Inc.)
CmdMapping\\{09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} [HKLM] -> %ProgramFiles%\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll [&Gears Settings] -> [2008/11/29 16:27:46 | 01,667,072 | ---- | M] (Google Inc.)
CmdMapping\\{2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} [HKLM] -> %ProgramFiles%\Microsoft ActiveSync\INetRepl.dll [Create Mobile Favorite] -> [2006/11/13 12:39:34 | 00,158,504 | ---- | M] (Microsoft Corporation)
CmdMapping\\{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} [HKLM] -> %ProgramFiles%\Microsoft ActiveSync\INetRepl.dll [Create Mobile Favorite...] -> [2006/11/13 12:39:34 | 00,158,504 | ---- | M] (Microsoft Corporation)
CmdMapping\\{44226DFF-747E-4edc-B30C-78752E50CD0C} [HKLM] -> %ProgramFiles%\ATI Multimedia\TV\EXPLBAR.DLL [&ATI TV] -> [2001/08/24 07:27:34 | 00,131,072 | ---- | M] (ATI Technologies Inc.)
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2007/04/19 13:10:18 | 00,063,840 | ---- | M] (Microsoft Corporation)
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/08/04 00:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation)
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/08/04 00:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation)
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/08/04 00:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-220523388-484061587-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_07\bin\npjpi160_07.dll [Sun Java Console] -> [2008/06/10 03:27:02 | 00,132,496 | ---- | M] (Sun Microsystems, Inc.)
CmdMapping\\{09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} [HKLM] -> %ProgramFiles%\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll [&Gears Settings] -> [2008/11/29 16:27:46 | 01,667,072 | ---- | M] (Google Inc.)
CmdMapping\\{2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} [HKLM] -> %ProgramFiles%\Microsoft ActiveSync\INetRepl.dll [Create Mobile Favorite] -> [2006/11/13 12:39:34 | 00,158,504 | ---- | M] (Microsoft Corporation)
CmdMapping\\{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} [HKLM] -> %ProgramFiles%\Microsoft ActiveSync\INetRepl.dll [Create Mobile Favorite...] -> [2006/11/13 12:39:34 | 00,158,504 | ---- | M] (Microsoft Corporation)
CmdMapping\\{44226DFF-747E-4edc-B30C-78752E50CD0C} [HKLM] -> %ProgramFiles%\ATI Multimedia\TV\EXPLBAR.DLL [&ATI TV] -> [2001/08/24 07:27:34 | 00,131,072 | ---- | M] (ATI Technologies Inc.)
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2007/04/19 13:10:18 | 00,063,840 | ---- | M] (Microsoft Corporation)
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/08/04 00:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation)
========== (O12) Internet Explorer Plugins ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\]
PluginsPage: "" = http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s
PluginsPageFriendlyName: "" = Microsoft ActiveX Gallery
========== (O13) Default Prefixes ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
""=http://
========== (O15) Trusted Sites ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
1 domain(s) and sub-domain(s) not assigned to a zone.
========== (O16) DPF ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\]
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}: http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1218690370859 -- MUWebControl Class
{8AD9C840-044E-11D1-B3E9-00805F499D93}: http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab -- Java Plug-in 1.6.0_07
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}: http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab -- Reg Error: Key does not exist or could not be opened.
{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab -- Java Plug-in 1.6.0_07
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab -- Java Plug-in 1.6.0_07
========== (O17) DNS Name Servers ==========
{1CA20587-94F4-4CEC-8B7E-139A304A5F4A} (Servers: | Description: 1394 Net Adapter)
{88E7FFF5-0FD8-495F-A205-DADC3BF25373} (Servers: | Description: )
{B817D263-0F44-4431-970E-BC0234B1C485} (Servers: | Description: Realtek RTL8139 Family PCI Fast Ethernet NIC)
========== (O20) AppInit_DLLs ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_Dlls"=C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL,C:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL
>[2008/09/05 07:57:52 | 00,113,664 | ---- | M] (Google) -- C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll
>[2008/09/20 11:37:37 | 00,173,056 | ---- | M] (Sophos Plc) -- C:\Program Files\Sophos\Sophos Anti-Virus\sophos_detoured.dll
========== (O20) Winlogon Notify Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\]
AtiExtEvent: "DllName" = Ati2evxx.dll -- C:\WINDOWS\system32\ati2evxx.dll (ATI Technologies Inc.)
========== Safeboot Options ==========
"AlternateShell"=cmd.exe
========== CDRom AutoRun Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1
========== Autorun Files on Drives ==========
AUTOEXEC.BAT []
[2008/08/13 20:57:15 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT -- [ NTFS ]
========== Files/Folders - Created Within 30 Days ==========
[3 C:\WINDOWS\*.tmp files]
[2008/12/02 22:24:01 | 00,422,400 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Mark\Desktop\OTViewIt.exe
[2008/11/26 21:07:46 | 00,002,137 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2008/11/26 21:07:15 | 00,000,000 | ---D | C] -- C:\Program Files\iPod
[2008/11/26 21:07:11 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2008/11/26 21:05:20 | 00,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2008/11/26 21:03:18 | 00,000,000 | ---D | C] -- C:\Program Files\WinFF
[2008/11/26 20:58:56 | 03,549,587 | ---- | C] (WinFF.org ) -- C:\Documents and Settings\Mark\Desktop\WinFF-0.43-setup.exe
[2008/11/26 16:12:10 | 00,000,142 | ---- | C] () -- C:\Documents and Settings\Mark\Desktop\fix.reg
[2008/11/26 16:11:05 | 71,371,754 | ---- | C] () -- C:\backup.reg
[2008/11/26 08:02:46 | 00,000,000 | ---D | C] -- C:\_OTScanIt
[2008/11/25 21:12:11 | 00,576,581 | ---- | C] () -- C:\Documents and Settings\Mark\Desktop\OTScanIt.exe
[2008/11/24 19:38:15 | 00,305,705 | ---- | C] () -- C:\Documents and Settings\Mark\Desktop\RSIT.exe
[2008/11/21 18:23:32 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2008/11/21 18:23:32 | 00,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2008/11/21 18:23:29 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2008/11/21 18:23:28 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2008/11/21 18:22:40 | 02,372,472 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Mark\Desktop\mbam-setup.exe
[2008/11/21 13:11:20 | 00,000,000 | ---D | C] -- F:\AAAStick
[2008/11/19 20:14:07 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2008/11/19 20:13:36 | 00,812,344 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\Mark\Desktop\HJTInstall.exe
[2008/11/19 16:40:16 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Mark\Application Data\Malwarebytes
[2008/11/19 16:40:09 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2008/11/18 23:26:29 | 03,330,176 | ---- | C] () -- C:\Documents and Settings\Mark\Desktop\ACDC_Highway_To_Hell.mp3
[2008/11/18 23:24:31 | 04,679,145 | ---- | C] () -- C:\Documents and Settings\Mark\Desktop\Thunderstruck.mp3
[2008/11/17 14:24:22 | 00,000,077 | ---- | C] () -- C:\WINDOWS\huffyuv.ini
[2008/11/17 11:52:55 | 00,000,000 | ---D | C] -- C:\Program Files\Exterminate It!
[2008/11/17 11:34:05 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Mark\Desktop\backups
[2008/11/14 10:42:50 | 00,001,602 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2008/11/14 09:33:08 | 00,000,000 | ---D | C] -- C:\WINDOWS\CSC
[2008/11/13 22:28:41 | 00,000,724 | ---- | C] () -- C:\Documents and Settings\Mark\Desktop\OnTheRocks.dvp.lnk
[2008/11/13 21:20:07 | 00,000,639 | ---- | C] () -- C:\WINDOWS\M3JPEG.INI
[2008/11/13 21:19:49 | 00,224,256 | ---- | C] (Morgan Multimedia) -- C:\WINDOWS\System32\MMIJG32.dll
[2008/11/13 21:19:49 | 00,062,976 | ---- | C] (Morgan Multimedia) -- C:\WINDOWS\System32\M3JPEGdec.ax
[2008/11/13 21:19:49 | 00,053,248 | ---- | C] (Morgan Multimedia) -- C:\WINDOWS\System32\MMTray.exe
[2008/11/13 21:19:49 | 00,051,200 | ---- | C] (Morgan Multimedia) -- C:\WINDOWS\System32\M3JPEGenc.ax
[2008/11/13 21:19:46 | 00,000,000 | ---D | C] -- C:\Program Files\Morgan
[2008/11/13 21:01:53 | 00,000,000 | ---D | C] -- C:\Program Files\Ulead Systems
[2008/11/12 22:12:53 | 00,054,156 | -H-- | C] () -- C:\WINDOWS\QTFont.qfn
[2008/11/12 22:12:53 | 00,001,409 | ---- | C] () -- C:\WINDOWS\QTFont.for
[2008/11/12 20:58:37 | 00,027,904 | ---- | C] (Windows (R) Codename Longhorn DDK provider) -- C:\WINDOWS\System32\drivers\ndisprot.sys
[2008/11/12 18:23:18 | 00,000,000 | ---D | C] -- C:\WINDOWS\Downloaded Installations
[2008/11/12 18:01:34 | 00,009,599 | ---- | C] () -- C:\WINDOWS\System32\QuickTime.qtp
[2008/11/12 18:01:26 | 00,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2008/11/12 17:49:22 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\QuickTime
[2008/11/12 14:19:19 | 00,453,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mrxsmb.sys
[2008/11/12 08:40:31 | 00,019,968 | ---- | C] () -- F:\SmallEnvelope.doc
[2008/11/08 20:11:28 | 00,000,000 | R--D | C] -- F:\My Pictures
[2008/11/07 22:15:42 | 00,000,000 | ---D | C] -- C:\Program Files\Avery
[2008/11/07 22:01:30 | 24,585,544 | ---- | C] (Avery ) -- C:\Documents and Settings\Mark\Desktop\Avery Wizard 3.1.5.exe
[2008/11/07 14:56:30 | 00,000,000 | ---D | C] -- F:\Web
[2008/11/05 18:34:44 | 00,000,000 | ---D | C] -- F:\RC Planes
========== Files - Modified Within 30 Days ==========
[1 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2008/12/02 22:24:12 | 00,422,400 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Mark\Desktop\OTViewIt.exe
[2008/12/02 20:24:52 | 00,072,192 | ---- | M] () -- C:\Documents and Settings\Mark\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/12/02 20:24:43 | 00,000,639 | ---- | M] () -- C:\WINDOWS\M3JPEG.INI
[2008/12/02 20:07:00 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2008/12/02 20:06:51 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2008/12/02 20:06:48 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2008/12/01 22:39:11 | 00,013,030 | ---- | M] () -- C:\PDOXUSRS.NET
[2008/12/01 13:26:42 | 00,002,623 | ---- | M] () -- C:\WINDOWS\ODBC.INI
[2008/12/01 11:07:57 | 00,002,137 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2008/11/29 17:36:01 | 00,000,040 | ---- | M] () -- C:\WINDOWS\nero.INI
[2008/11/29 13:11:02 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2008/11/27 09:35:26 | 00,000,712 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoUpdate Monitor.lnk
[2008/11/26 23:04:22 | 00,001,258 | ---- | M] () -- C:\WINDOWS\ULead32.ini
[2008/11/26 21:12:57 | 00,000,023 | ---- | M] () -- C:\WINDOWS\msdevctl.ini
[2008/11/26 21:00:15 | 03,549,587 | ---- | M] (WinFF.org ) -- C:\Documents and Settings\Mark\Desktop\WinFF-0.43-setup.exe
[2008/11/26 16:12:10 | 00,000,142 | ---- | M] () -- C:\Documents and Settings\Mark\Desktop\fix.reg
[2008/11/26 16:11:17 | 71,371,754 | ---- | M] () -- C:\backup.reg
[2008/11/25 21:59:59 | 00,576,581 | ---- | M] () -- C:\Documents and Settings\Mark\Desktop\OTScanIt.exe
[2008/11/24 19:38:19 | 00,305,705 | ---- | M] () -- C:\Documents and Settings\Mark\Desktop\RSIT.exe
[2008/11/21 18:23:32 | 00,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2008/11/21 18:23:01 | 02,372,472 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Mark\Desktop\mbam-setup.exe
[2008/11/21 10:22:00 | 00,000,101 | ---- | M] () -- C:\WINDOWS\CMMIXER.INI
[2008/11/21 10:21:21 | 00,000,092 | ---- | M] () -- C:\WINDOWS\mixerdef.ini
[2008/11/20 10:04:39 | 00,001,636 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2008/11/19 20:13:45 | 00,812,344 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\Mark\Desktop\HJTInstall.exe
[2008/11/18 23:28:29 | 03,330,176 | ---- | M] () -- C:\Documents and Settings\Mark\Desktop\ACDC_Highway_To_Hell.mp3
[2008/11/18 23:28:27 | 04,679,145 | ---- | M] () -- C:\Documents and Settings\Mark\Desktop\Thunderstruck.mp3
[2008/11/17 14:24:22 | 00,000,077 | ---- | M] () -- C:\WINDOWS\huffyuv.ini
[2008/11/16 15:07:05 | 00,000,038 | ---- | M] () -- C:\WINDOWS\AviSplitter.INI
[2008/11/14 10:42:50 | 00,001,602 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2008/11/13 23:54:39 | 00,051,248 | ---- | M] () -- C:\Documents and Settings\Mark\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2008/11/13 22:28:40 | 00,000,724 | ---- | M] () -- C:\Documents and Settings\Mark\Desktop\OnTheRocks.dvp.lnk
[2008/11/13 19:22:36 | 00,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
[2008/11/13 15:31:48 | 00,000,666 | ---- | M] () -- C:\Documents and Settings\Mark\Desktop\Shortcut to TMPGEnc.exe.lnk
[2008/11/13 03:01:11 | 00,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2008/11/12 22:12:53 | 00,001,409 | ---- | M] () -- C:\WINDOWS\QTFont.for
[2008/11/12 20:58:37 | 00,027,904 | ---- | M] (Windows (R) Codename Longhorn DDK provider) -- C:\WINDOWS\System32\drivers\ndisprot.sys
[2008/11/12 18:07:49 | 00,009,599 | ---- | M] () -- C:\WINDOWS\System32\QuickTime.qtp
[2008/11/12 08:40:31 | 00,019,968 | ---- | M] () -- F:\SmallEnvelope.doc
[2008/11/08 07:34:10 | 00,211,288 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2008/11/07 22:03:18 | 24,585,544 | ---- | M] (Avery ) -- C:\Documents and Settings\Mark\Desktop\Avery Wizard 3.1.5.exe
[2008/11/03 13:23:18 | 00,360,124 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2008/11/03 13:23:18 | 00,314,508 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2008/11/03 13:23:18 | 00,040,836 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
< End of report >
And the content of Extras.txt:
OTViewIt Extras logfile created on: 12/2/2008 10:25:09 PM - Run
OTViewIt by OldTimer - Version 1.0.20.0 Folder = C:\Documents and Settings\Mark\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1023.47 Mb Total Physical Memory | 621.53 Mb Available Physical Memory | 60.73% Memory free
2.41 Gb Paging File | 2.16 Gb Available in Paging File | 89.78% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 186.30 Gb Total Space | 140.84 Gb Free Space | 75.60% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 298.08 Gb Total Space | 150.42 Gb Free Space | 50.46% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DESKTOP
Current User Name: Mark
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled"=1
"AntiVirusDisableNotify"=0
"FirewallDisableNotify"=0
"UpdatesDisableNotify"=0
"AntiVirusOverride"=1
"FirewallOverride"=0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
"DisableMonitoring"=1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[2004/08/03 20:56:58 | 00,140,800 | ---- | M] (Microsoft Corporation) -- %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
[2006/11/13 12:39:34 | 00,199,464 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
[2006/11/13 12:39:52 | 01,289,000 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
[2006/11/13 12:39:54 | 04,270,888 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[2004/08/03 20:56:58 | 00,140,800 | ---- | M] (Microsoft Corporation) -- %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
[2006/11/13 12:39:34 | 00,199,464 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
[2006/11/13 12:39:52 | 01,289,000 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
[2006/11/13 12:39:54 | 04,270,888 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
[2004/08/03 20:56:50 | 00,083,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test
[2004/08/03 20:56:56 | 00,033,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\rundll32.exe:*:Enabled:Run a DLL as an App
[2008/10/16 13:38:28 | 00,634,672 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
[2008/08/29 10:18:44 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour
[2008/11/20 13:20:48 | 14,294,824 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes
[2008/08/11 16:46:50 | 21,741,864 | R--- | M] (Skype Technologies S.A.) -- C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype
========== (O10) Winsock2 Catalogs ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\]
NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] -- C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
========== (O18) Protocol Handlers ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
ipp: [HKLM - No CLSID value]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2005/09/20 11:33:58 | 00,843,984 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL ipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
msdaipp: [HKLM - No CLSID value]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2005/09/20 11:33:58 | 00,843,984 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2005/09/20 11:33:58 | 00,843,984 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\oledb:{E1D2BF40-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAIPP.BINDER]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2007/03/14 12:10:22 | 07,255,384 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (mso-offdap:{3D9F03FA-7A94-11D3-BE81-0050048385D1} (HKLM) [Data Page Pluggable Protocol mso-offdap Handler])
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2007/05/10 12:45:34 | 08,069,464 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (mso-offdap11:{32505114-5902-49B2-880A-1F7738E5A384} (HKLM) [Data Page Plugable Protocal mso-offdap11 Handler])
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2008/08/11 16:46:50 | 01,942,864 | R--- | M] (Skype Technologies) C:\Program Files\Common Files\Skype\Skype4COM.dll (skype4com:{FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} (HKLM) [IEProtocolHandler Class])
========== (O18) Protocol Filters ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\] - Protocol Filters
[2007/04/19 12:57:40 | 00,046,432 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL text/xml:{807553E5-5146-11D5-A672-00B0D022E945} (HKLM) [Reg Error: Value does not exist or could not be read.]
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{001AB29C-5468-4972-8D24-2EBDB2B12133}"=Camera Window DVC
"{001EB665-D9EC-415E-9E13-AD2125B2B992}"=RAW Image Task 2.1
"{034759DA-E21A-4795-BFB3-C66D17FAD183}"=Sophos Anti-Virus
"{15C418EB-7675-42be-B2B3-281952DA014D}"=Sophos AutoUpdate
"{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}"=Google Earth
"{218BBBE3-FE63-4BB2-81A8-7435575A84FA}"=PhotoStitch
"{2A9C3F41-DACA-37AB-84FB-2E6193C42151}"=Google Gears
"{318AB667-3230-41B5-A617-CB3BF748D371}"=iTunes
"{3248F0A8-6813-11D6-A77B-00B0D0160070}"=Java(TM) 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}"=WebFldrs XP
"{38B9A4E1-4482-44D9-AC14-64F70938CCB5}"=Garmin MapSource
"{3EA9D975-BFDC-4E8E-B88B-0446FBC8CA66}"=HydraVision
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}"=Skype™ 3.8
"{5E3CFCA6-C95A-47CB-A822-7FA80D423AF2}"=MapSource
"{6693BD7C-CB4E-43AC-A0D6-10D1A1B88DCF}"=Canon PhotoRecord
"{68D27126-BF6A-457D-8DD0-5F35E8D41310}"=MovieEdit Task
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}"=Apple Software Update
"{6B8BDABA-6737-4998-AEE4-E218EDE5FC7A}"=Camera Window DS
"{7288831E-1418-40E5-A70A-A55D0AA6657B}"=Simply Accounting by Sage 2006
"{7299052b-02a4-4627-81f2-1818da5d550d}"=Microsoft Visual C++ 2005 Redistributable
"{76275358-C154-11D5-8D5A-00105A22D3D2}"=ATI Multimedia Center
"{89EB3ED7-225A-412E-B048-623D502C000F}"=Camera Window MC
"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}"=Bonjour
"{90110409-6000-11D3-8CFE-0150048383C9}"=Microsoft Office Professional Edition 2003
"{99052DB7-9592-4522-A558-5417BBAD48EE}"=Microsoft ActiveSync
"{99D34763-7E45-4FE5-8424-28DBC3A5F0BF}"=GUIDE PLUS+(TM) for Windows® System - ATI
"{A1D0D14A-B776-4907-BC00-5149F2298086}"=Camera Support Core Library
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}"=Google Update
"{AC76BA86-1033-0000-BA7E-000000000001}"=Adobe Acrobat 6.0 Standard
"{B4E96960-5F6B-48B9-A5BD-6A5A9BB4F027}"=Avery Wizard 3.1
"{C1D76D7A-F3BB-47EA-A746-5B1E2FFC1DF2}"=Canon ZoomBrowser EX
"{C8C8387B-A98B-44E8-807A-1A9B7F51FFDA}"=Blaze Media Pro
"{EC4455AB-F155-4CC1-A4C5-88F3777F9886}"=Apple Mobile Device Support
"{F958CA02-BB40-4007-894B-258729456EE4}"=QuickTime
"{FF11005D-CBC8-45D5-A288-25C7BB304121}"=Sophos Remote Management System
"Adobe Flash Player ActiveX"=Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin"=Adobe Flash Player Plugin
"Adobe Shockwave Player"=Adobe Shockwave Player
"ATI Display Driver"=ATI Display Driver
"AVI Codec Pack"=AVI Codec Pack
"Blaze Media Pro"=Blaze Media Pro
"Free WMA MP3 Converter"=Free WMA MP3 Converter
"Free WMA to MP3 Converter_is1"=Free WMA to MP3 Converter 1.16
"Google Desktop"=Google Desktop
"Google Updater"=Google Updater
"HijackThis"=HijackThis 2.0.2
"HP Scanning Software"=HP PrecisionScan Pro and Utilities
"HUFFYUV"=Huffyuv AVI lossless video codec (Remove Only)
"InstallShield_{001AB29C-5468-4972-8D24-2EBDB2B12133}"=Canon Camera Window DC_DV 5 for ZoomBrowser EX
"InstallShield_{001EB665-D9EC-415E-9E13-AD2125B2B992}"=Canon RAW Image Task for ZoomBrowser EX
"InstallShield_{218BBBE3-FE63-4BB2-81A8-7435575A84FA}"=Canon Utilities PhotoStitch 3.1
"InstallShield_{68D27126-BF6A-457D-8DD0-5F35E8D41310}"=Canon MovieEdit Task for ZoomBrowser EX
"InstallShield_{6B8BDABA-6737-4998-AEE4-E218EDE5FC7A}"=Canon Camera Window DS for ZoomBrowser EX
"InstallShield_{89EB3ED7-225A-412E-B048-623D502C000F}"=Canon Camera Window MC 5 for ZoomBrowser EX
"InstallShield_{A1D0D14A-B776-4907-BC00-5149F2298086}"=Canon Camera Support Core Library
"LiveUpdate1.7"=LiveUpdate 1.7 (Symantec Corporation)
"m3jpegV3"=Morgan M-JPEG codec V3
"Malwarebytes' Anti-Malware_is1"=Malwarebytes' Anti-Malware
"Mozilla Firefox (3.0.4)"=Mozilla Firefox (3.0.4)
"Nero - Burning Rom!UninstallKey"=Ahead Nero Burning ROM
"NZ Open Autorouting GPS Project"=NZ Open Autorouting GPS Project 1 Mar 2008
"OziExplorer 3.95_is1"=OziExplorer 3.95
"PCI Audio Driver"=PCI Audio Driver
"WinFF_is1"=WinFF 0.43
"WinISO_is1"=WinISO 5.3
"WinZip"=WinZip
"WS_FTP Pro"=Ipswitch WS_FTP Pro
"WXTide32"=WXTide32
"XP Codec Pack"=XP Codec Pack
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"BitTorrent"=BitTorrent
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-220523388-484061587-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"BitTorrent"=BitTorrent
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 12/3/2008 12:40:43 AM | Computer Name = DESKTOP | Source = Sophos Message Router | ID = 8005
Description = DNS lookup failure trying to resolve the following addresses: wins2.%3
Error - 12/3/2008 12:51:32 AM | Computer Name = DESKTOP | Source = Sophos Message Router | ID = 8005
Description = DNS lookup failure trying to resolve the following addresses: wins2.%3
Error - 12/3/2008 1:02:21 AM | Computer Name = DESKTOP | Source = Sophos Message Router | ID = 8005
Description = DNS lookup failure trying to resolve the following addresses: wins2.%3
Error - 12/3/2008 1:13:10 AM | Computer Name = DESKTOP | Source = Sophos Message Router | ID = 8005
Description = DNS lookup failure trying to resolve the following addresses: wins2.%3
Error - 12/3/2008 1:23:58 AM | Computer Name = DESKTOP | Source = Sophos Message Router | ID = 8005
Description = DNS lookup failure trying to resolve the following addresses: wins2.%3
Error - 12/3/2008 1:34:48 AM | Computer Name = DESKTOP | Source = Sophos Message Router | ID = 8005
Description = DNS lookup failure trying to resolve the following addresses: wins2.%3
Error - 12/3/2008 1:45:37 AM | Computer Name = DESKTOP | Source = Sophos Message Router | ID = 8005
Description = DNS lookup failure trying to resolve the following addresses: wins2.%3
Error - 12/3/2008 1:56:27 AM | Computer Name = DESKTOP | Source = Sophos Message Router | ID = 8005
Description = DNS lookup failure trying to resolve the following addresses: wins2.%3
Error - 12/3/2008 2:07:15 AM | Computer Name = DESKTOP | Source = Sophos Message Router | ID = 8005
Description = DNS lookup failure trying to resolve the following addresses: wins2.%3
Error - 12/3/2008 2:18:07 AM | Computer Name = DESKTOP | Source = Sophos Message Router | ID = 8005
Description = DNS lookup failure trying to resolve the following addresses: wins2.%3
[ System Events ]
Error - 12/1/2008 1:29:34 PM | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7000
Description = The ATI WDM TV Audio Crossbar service failed to start due to the following
error: %%1058
Error - 12/1/2008 1:29:34 PM | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7000
Description = The ATI WDM Specialized MVD Codec service failed to start due to the
following error: %%1058
Error - 12/1/2008 1:29:34 PM | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7000
Description = The NAVAPEL service failed to start due to the following error: %%3
Error - 12/1/2008 1:29:34 PM | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7000
Description = The ATI WDM Specialized PCD Codec service failed to start due to the
following error: %%1058
Error - 12/2/2008 1:01:10 AM | Computer Name = DESKTOP | Source = Windows Update Agent | ID = 16
Description = Unable to Connect: Windows is unable to connect to the automatic updates
service and therefore cannot download and install updates according to the set
schedule. Windows will continue to try to establish a connection.
Error - 12/3/2008 12:07:19 AM | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7000
Description = The ATI WDM TV Tuner service failed to start due to the following
error: %%1058
Error - 12/3/2008 12:07:19 AM | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7000
Description = The ATI WDM TV Audio Crossbar service failed to start due to the following
error: %%1058
Error - 12/3/2008 12:07:19 AM | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7000
Description = The ATI WDM Specialized MVD Codec service failed to start due to the
following error: %%1058
Error - 12/3/2008 12:07:19 AM | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7000
Description = The NAVAPEL service failed to start due to the following error: %%3
Error - 12/3/2008 12:07:19 AM | Computer Name = DESKTOP | Source = Service Control Manager | ID = 7000
Description = The ATI WDM Specialized PCD Codec service failed to start due to the
following error: %%1058
< End of report >
Thanks!