PDA

View Full Version : Internet Redirect - iexplorer - shutting down select programs - help?



proskoma
2009-04-18, 21:10
Running Windows XP Ver 2002 SP 3

Last week I neglected to update AVG before the previous free version expired. Got an error message (didn't write down) that the installer had problems - installed new version anyway - full scan - but have four symptioms:
1. Web page redirects - especially from google, but not exclusivly
2. CyberSitter will not stay running. If I type cyb2k.exe in start/run the icon shows up in the tray and I see the process appear in task manager but the process ends almost right away and the icon dissapears when the curser rolls over it.
3. Certain windows dialog boxes will not populate... ie system resore opens to a white screen. Before I started trying to clean it would give an internet looking error - script error occured when trying to run scripts on this screen. With no details in the underlying fields. Usually had to fource quit.
4. I seem to have the iexplorer.exe trojan as this process shows up at least once and often multiple times in the taks manager when no browser windows are open... my current default browser is Opera, but when windows boots, I usually get a message about internet explorer being the default browser even though it hasn't been run.

I have run the following to try and fix:
Malwarebytes Anti-Malware
Prevx 3.0
1-2-3-Spyware
Spybot S&D
Norman Malware Cleaner
Stinger 1001

Here's my HijackThis Log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:10:04 PM, on 4/18/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\CBP\DCSchdler.exe
C:\Program Files\Prevx\prevx.exe
C:\Program Files\Promise\FastTrak\FtrakSvc.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\NovaStor\NovaStor NovaBACKUP\NsService.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\Fsloader.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Prevx\prevx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\PRISMSVR.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ezSP_Px.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.exe
C:\Program Files\TrayDay\TrayDay.exe
C:\Program Files\iPod\bin\iPodService.exe
F:\Program Files\Opera\Opera.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Yahoo!
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - E:\Program Files\GetRight\xx2gr.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\system32\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [C2K] C:\WINDOWS\CYB2K.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe
O4 - Startup: TrayDay.lnk = C:\Program Files\TrayDay\TrayDay.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Logitech Desktop Messenger.lnk = E:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: 2Wire Wireless Client.lnk = C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.exe
O8 - Extra context menu item: Download with GetRight - E:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Browser - E:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - http://www.net2phone.com/ (file missing)
O9 - Extra 'Tools' menuitem: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - http://www.net2phone.com/ (file missing)
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - E:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - E:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Share in Hello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll
O9 - Extra 'Tools' menuitem: Share in H&ello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {16BF42FD-CA0A-4f48-819D-B0343254DD67} - file://C:\Program Files\UpromiseRemindU\System\Temp\upromise_script0.htm (file missing) (HKCU)
O16 - DPF: Yahoo! Checkers - http://download.games.yahoo.com/games/clients/y/kt0_x.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://gulllake.gospelcom.net/unsecure/other_media/views/ipixx.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {40272BF7-4FF5-4D6F-9BAD-3C1D3CB32982} (Live365PlayerVIP Class) - http://www.live365.com/players/p365vip.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www2.snapfish.com/SnapfishActivia.cab
O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} (Microsoft.WinRep) - https://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab
O16 - DPF: {5197842F-0557-48AE-9552-7594F7C98F04} (PWReset Control) - http://www.cybersitter.com/recovery/ocx/PasswordReset.ocx
O16 - DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} (Install Class) - http://updates.lifescapeinc.com/installers/pinstall/pinstall.cab
O16 - DPF: {712362BF-E411-4F43-99D2-EB15F80AF1DB} (MsneDiag Class) - http://entimg.msn.com/client/msnediag3518.cab
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - http://picture.vzw.com/activex/VerizonWirelessUploadControl.cab
O16 - DPF: {9DBAFCCF-592F-FFFF-FFFF-00608CEC297C} -
O16 - DPF: {A662DA7E-CCB7-4743-B71A-D817F6D575DF} (Autodesk DWF Viewer Control) - http://www.autodesk.com/global/dwfviewer/installer/DwfViewerSetup.cab
O16 - DPF: {A7E092C3-692A-11D0-A7E5-08002B322F3B} (WebResponseAttachments Control) - https://webresponse.one.microsoft.com/oas/ActiveX/FileXfer.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} (MsnMusicAx Class) - http://entimg.msn.com/client/msnmusax3518.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Backup Scheduler - Unknown owner - C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\CBP\DCSchdlerSRVC.exe
O23 - Service: CSIScanner - Prevx - C:\Program Files\Prevx\prevx.exe
O23 - Service: Promise FastTrak Log Service (FastTrakSvc) - Promise Technology Inc. - C:\Program Files\Promise\FastTrak\FtrakSvc.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NovaStor NovaBACKUP Backup/Copy Engine (NsService) - NovaStor - C:\Program Files\NovaStor\NovaStor NovaBACKUP\NsService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe
O23 - Service: Real time Backup Loader - Unknown owner - C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\Fsloader.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\supportsoft\bin\ssrc.exe
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe

--
End of file - 12005 bytes

Blade81
2009-04-19, 12:52
Hi proskoma,



I have run the following to try and fix:
Malwarebytes Anti-Malware
Do you have that log still around? Please look for C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt file. If found, post back its contents.


Download DDS and save it to your desktop from here (http://www.techsupportforum.com/sectools/sUBs/dds) or here (http://download.bleepingcomputer.com/sUBs/dds.scr) or here (http://www.forospyware.com/sUBs/dds).
Disable any script blocker, and then double click dds.scr to run the tool.
When done, DDS will open two (2) logs:
DDS.txt
Attach.txt

Save both reports to your desktop. Post them back to your topic.

proskoma
2009-04-20, 00:51
Computer is worse today - can't get to internet at all (posting from a borrowed lap-top), iExplorer shows up at least 10 times in process and force quit doesn't work. Had to shut down at one point and the computer had two processes I've never heard of before it asked me about shutting down "Auto Suggest Drop Down" and "SysFader".

The DDS.SCR is not automatically opening any log files - any chance they're saved on my HD somewhere?

2 Malware log files follow:

Malwarebytes' Anti-Malware 1.36
Database version: 1945
Windows 5.1.2600 Service Pack 3

4/17/2009 9:17:30 PM
mbam-log-2009-04-17 (21-17-30).txt

Scan type: Full Scan (C:\|D:\|E:\|F:\|G:\|)
Objects scanned: 76969
Time elapsed: 12 minute(s), 5 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 23
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\c:/windows/downloaded program files/minibugtransporter.dll (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{3c2d2a1e-031f-4397-9614-87c932a848e0} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{04a38f6b-006f-4247-ba4c-02a139d5531c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{2b96d5cc-c5b5-49a5-a69d-cc0a30f9028c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{2b96d5cc-c5b5-49a5-a69d-cc0a30f9028c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx.1 (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\c:/windows/downloaded program files/popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{c9c5deaf-0a1f-4660-8279-9edfad6fefe1} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e4e3e0f8-cd30-4380-8ce9-b96904bdefca} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{fe8a736f-4124-4d9c-b4b1-3b12381efabe} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{87255c51-cd7d-4506-b9ad-97606daf53f3} (Adware.Coupons) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{00021494-0000-0000-c000-000000000046} (Adware.ISTBar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{87255c51-cd7d-4506-b9ad-97606daf53f3} (Adware.Coupons) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9522b3fb-7a2b-4646-8af6-36e7f593073c} (Adware.Coupons) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3aa42713-5c1e-48e2-b432-d8bf420dd31d} (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{9522b3fb-7a2b-4646-8af6-36e7f593073c} (Adware.Coupons) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8fcdf9d9-a28b-480f-8c3d-581f119a8ab8} (Adware.180Solutions) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\Downloaded Program Files\MiniBugTransporter.dll (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\Downloaded Program Files\popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\Downloaded Program Files\MiniBugTransporter.dll (Adware.Minibug) -> Quarantined and deleted successfully.
C:\WINDOWS\Downloaded Program Files\popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully.

_____________________________________________________________

Malwarebytes' Anti-Malware 1.36
Database version: 1945
Windows 5.1.2600 Service Pack 3

4/17/2009 10:25:48 PM
mbam-log-2009-04-17 (22-25-48).txt

Scan type: Quick Scan
Objects scanned: 88929
Time elapsed: 3 minute(s), 50 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\egauth.egegauth.1 (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\egcomservice.egcomsvc.1 (Adware.EGDAccess) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\egcomservice2.egcomsvc2.1 (Adware.EGDAccess) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\setup.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\casino1.ini (Malware.Trace) -> Quarantined and deleted successfully.

proskoma
2009-04-20, 12:56
Ran DDS.SCR on lap-top to understand functionality. Will not run on infected computer... sometimes briefly see command box open but never starts and runs scan.

Blade81
2009-04-20, 16:22
Hi

Please rename dds.scr file -> something.scr and try running again.

proskoma
2009-04-21, 01:08
This had no effect. Same symptoms. Could see command window open briefly - then program quit without running the scan.

Blade81
2009-04-21, 17:44
Hi

Time for another program.

Download random's system information tool (RSIT) by random/random from here (http://images.malwareremoval.com/random/RSIT.exe) and save it to your desktop.
Double click on RSIT.exe to run RSIT.
Click Continue at the disclaimer screen.
Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized, if not you'll find it in c:\rsit folder)

proskoma
2009-04-22, 03:25
Logfile of random's system information tool 1.06 (written by random/random)
Run by David Wilson at 2009-04-21 21:21:34
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 31 GB (27%) free of 112 GB
Total RAM: 1535 MB (72% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:21:38 PM, on 4/21/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\CBP\DCSchdler.exe
C:\Program Files\Promise\FastTrak\FtrakSvc.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\NovaStor\NovaStor NovaBACKUP\NsService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\Fsloader.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\PRISMSVR.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\ezSP_Px.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.exe
C:\Program Files\TrayDay\TrayDay.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\David Wilson\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\David Wilson.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Yahoo!
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - E:\Program Files\GetRight\xx2gr.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\system32\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [C2K] C:\WINDOWS\CYB2K.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe
O4 - Startup: TrayDay.lnk = C:\Program Files\TrayDay\TrayDay.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Logitech Desktop Messenger.lnk = E:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: 2Wire Wireless Client.lnk = C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.exe
O8 - Extra context menu item: Download with GetRight - E:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Browser - E:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - http://www.net2phone.com/ (file missing)
O9 - Extra 'Tools' menuitem: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - http://www.net2phone.com/ (file missing)
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - E:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - E:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Share in Hello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll
O9 - Extra 'Tools' menuitem: Share in H&ello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {16BF42FD-CA0A-4f48-819D-B0343254DD67} - file://C:\Program Files\UpromiseRemindU\System\Temp\upromise_script0.htm (file missing) (HKCU)
O16 - DPF: Yahoo! Checkers - http://download.games.yahoo.com/games/clients/y/kt0_x.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://gulllake.gospelcom.net/unsecure/other_media/views/ipixx.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {40272BF7-4FF5-4D6F-9BAD-3C1D3CB32982} (Live365PlayerVIP Class) - http://www.live365.com/players/p365vip.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www2.snapfish.com/SnapfishActivia.cab
O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} (Microsoft.WinRep) - https://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab
O16 - DPF: {5197842F-0557-48AE-9552-7594F7C98F04} (PWReset Control) - http://www.cybersitter.com/recovery/ocx/PasswordReset.ocx
O16 - DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} (Install Class) - http://updates.lifescapeinc.com/installers/pinstall/pinstall.cab
O16 - DPF: {712362BF-E411-4F43-99D2-EB15F80AF1DB} (MsneDiag Class) - http://entimg.msn.com/client/msnediag3518.cab
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - http://picture.vzw.com/activex/VerizonWirelessUploadControl.cab
O16 - DPF: {9DBAFCCF-592F-FFFF-FFFF-00608CEC297C} -
O16 - DPF: {A662DA7E-CCB7-4743-B71A-D817F6D575DF} (Autodesk DWF Viewer Control) - http://www.autodesk.com/global/dwfviewer/installer/DwfViewerSetup.cab
O16 - DPF: {A7E092C3-692A-11D0-A7E5-08002B322F3B} (WebResponseAttachments Control) - https://webresponse.one.microsoft.com/oas/ActiveX/FileXfer.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} (MsnMusicAx Class) - http://entimg.msn.com/client/msnmusax3518.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Backup Scheduler - Unknown owner - C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\CBP\DCSchdlerSRVC.exe
O23 - Service: Promise FastTrak Log Service (FastTrakSvc) - Promise Technology Inc. - C:\Program Files\Promise\FastTrak\FtrakSvc.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NovaStor NovaBACKUP Backup/Copy Engine (NsService) - NovaStor - C:\Program Files\NovaStor\NovaStor NovaBACKUP\NsService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe
O23 - Service: Real time Backup Loader - Unknown owner - C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\Fsloader.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\supportsoft\bin\ssrc.exe
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe

--
End of file - 11330 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\Uninstall Expiration Reminder.job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-12-18 59032]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31FF080D-12A3-439A-A2EF-4BA95A3148E8}]
bho2gr Class - E:\Program Files\GetRight\xx2gr.dll [2006-12-08 243016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
"PRISMSVR.EXE"=C:\WINDOWS\system32\PRISMSVR.EXE [2004-04-13 290905]
"C2K"=C:\WINDOWS\CYB2K.EXE [2007-07-24 3163648]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2007-02-14 7700480]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2007-02-14 86016]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2008-11-20 290088]
"nwiz"=nwiz.exe /install []
"ezShieldProtector for Px"=C:\WINDOWS\system32\ezSP_Px.exe [2002-08-20 40960]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"WPCycle.exe"= []
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
"LDM"=\Program\BackWeb-8876480.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe [2007-03-09 63712]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ADUserMon]
C:\Program Files\Iomega\AutoDisk\ADUserMon.exe [2002-01-24 106496]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AtiPTA]
C:\WINDOWS\system32\atiptaxx.exe [2001-09-27 245760]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Deskup]
E:\Program Files\Iomega\DriveIcons\deskup.exe [2001-10-01 28672]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dskmgr32]
C:\WINDOWS\System32\dskmgr32.exe [2003-04-21 671744]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EM_EXEC]
E:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE [2001-09-19 35328]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ezShieldProtector for Px]
C:\WINDOWS\System32\ezSP_Px.exe [2002-08-20 40960]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GhostStartTrayApp]
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe [2003-12-17 94208]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe [2001-11-15 196608]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Iomega Drive Icons]
E:\Program Files\Iomega\DriveIcons\ImgIcon.exe [2001-11-20 57344]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Iomega Startup Options]
E:\Program Files\Iomega\Common\ImgStart.exe [2001-01-17 45056]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe [2008-11-20 290088]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
\Program\BackWeb-8876480.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
D:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PicasaNet]
C:\Program Files\Hello\Hello.exe [2005-01-11 2572288]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickFinder Scheduler]
E:\Program Files\Corel\WordPerfect Office 2002\Programs\QFSCHD100.EXE [2001-04-02 77887]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
E:\Program Files\QuickTime\QTTask.exe [2008-11-04 413696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe [2004-05-07 1552384]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sunkist2k]
C:\Program Files\Multimedia Card Reader\shwicon2k.exe [2005-10-07 139264]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^CorelCENTRAL 10.lnk]
C:\WINDOWS\Installer\{A0B295C3-FD3C-11D4-A811-0090279106C3}\I_26dadCC.exe [2002-10-20 5222]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^FastCheck Monitoring Utility.lnk]
C:\Program Files\Promise\FastTrak\RAIDeUtility.exe [2001-11-22 540672]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Sonic CinePlayer Quick Launch.lnk]
C:\PROGRA~1\COMMON~1\SONICS~1\cinetray.exe [2002-09-18 98304]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^David Wilson^Start Menu^Programs^Startup^Dialog Box Assistant.lnk]
E:\Program Files\OSDEx\OSDEx.exe [2002-04-26 35328]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^David Wilson^Start Menu^Programs^Startup^Webshots.lnk]
[]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Logitech Desktop Messenger.lnk - E:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
2Wire Wireless Client.lnk - C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.exe

C:\Documents and Settings\David Wilson\Start Menu\Programs\Startup
TrayDay.lnk - C:\Program Files\TrayDay\TrayDay.exe
ERUNT AutoBackup.lnk - C:\Program Files\ERUNT\AUTOBACK.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2007-03-15 236928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-13 239616]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"=E:\PROGRAM FILES\EUDORA\EUSHLEXT.DLL [2005-11-14 86016]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=149
"NoFavoritesMenu"=1
"NoLogOff"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\WINDOWS\Cyb2k.exe"="C:\WINDOWS\Cyb2k.exe:*:Enabled:CYBERsitter Control Panel"
"E:\Program Files\GetRight\getright.exe"="E:\Program Files\GetRight\getright.exe:*:Enabled:GetRightŪ www.getright.com"
"E:\Age of Empires II\Age2_X1\AGE2_X1.ICD"="E:\Age of Empires II\Age2_X1\AGE2_X1.ICD:*:Enabled:Age of Empires II Expansion"
"E:\Program Files\Macromedia\Dreamweaver 4\Dreamweaver.exe"="E:\Program Files\Macromedia\Dreamweaver 4\Dreamweaver.exe:*:Enabled:Dreamweaver"
"C:\Program Files\Common Files\Doppler 10 Pinpoint Alert\TrueWeather.exe"="C:\Program Files\Common Files\Doppler 10 Pinpoint Alert\TrueWeather.exe:*:Enabled:TrueWeather"
"C:\Program Files\SnapStream Media\Beyond TV 3\PVSLibraryAppService.exe"="C:\Program Files\SnapStream Media\Beyond TV 3\PVSLibraryAppService.exe:*:Enabled:Beyond TV Library Service"
"C:\Program Files\SnapStream Media\Beyond TV 3\BTVWebServer.exe"="C:\Program Files\SnapStream Media\Beyond TV 3\BTVWebServer.exe:*:Enabled:Beyond TV Web Server"
"C:\Program Files\SnapStream Media\Beyond TV 3\BTVRecordingEngine.exe"="C:\Program Files\SnapStream Media\Beyond TV 3\BTVRecordingEngine.exe:*:Enabled:Beyond TV Recording Engine"
"C:\Program Files\SnapStream Media\Beyond TV 3\BTVGuideDataLoader.exe"="C:\Program Files\SnapStream Media\Beyond TV 3\BTVGuideDataLoader.exe:*:Enabled:Beyond TV Guide Data Loader"
"C:\Program Files\SnapStream Media\Beyond TV 3\PVSConfigService.exe"="C:\Program Files\SnapStream Media\Beyond TV 3\PVSConfigService.exe:*:Enabled:Beyond TV Settings Service"
"C:\Program Files\SnapStream Media\Beyond TV 3\BTVD3DShell.exe"="C:\Program Files\SnapStream Media\Beyond TV 3\BTVD3DShell.exe:*:Enabled:Beyond TV ViewScape"
"C:\WINDOWS\System32\mmc.exe"="C:\WINDOWS\System32\mmc.exe:*:Enabled:Microsoft Management Console"
"E:\Program Files\ICQ\Icq.exe"="E:\Program Files\ICQ\Icq.exe:*:Enabled:ICQ"
"C:\Program Files\SnapStream Media\Beyond TV 3\BTVRegistrationService.exe"="C:\Program Files\SnapStream Media\Beyond TV 3\BTVRegistrationService.exe:*:Enabled:Beyond TV Registration Service"
"C:\Program Files\SnapStream Media\Beyond TV 3\BTVWebServiceProxy.exe"="C:\Program Files\SnapStream Media\Beyond TV 3\BTVWebServiceProxy.exe:*:Enabled:Beyond TV Web Service Proxy"
"C:\Program Files\SnapStream Media\Beyond TV 3\BTVLibraryService.exe"="C:\Program Files\SnapStream Media\Beyond TV 3\BTVLibraryService.exe:*:Enabled:Beyond TV Library Service"
"C:\Program Files\SnapStream Media\Beyond TV 3\BTVNetworkService.exe"="C:\Program Files\SnapStream Media\Beyond TV 3\BTVNetworkService.exe:*:Enabled:Beyond TV Network Service"
"C:\Program Files\Grisoft\AVG Free\avgw.exe"="C:\Program Files\Grisoft\AVG Free\avgw.exe:*:Enabled:AVG Free Edition for Windows"
"C:\Program Files\Grisoft\AVG Free\avgvv.exe"="C:\Program Files\Grisoft\AVG Free\avgvv.exe:*:Enabled:AVG Free Virus Vault"
"C:\Program Files\SnapStream Media\Beyond TV 3\BTVSettingsService.exe"="C:\Program Files\SnapStream Media\Beyond TV 3\BTVSettingsService.exe:*:Enabled:Beyond TV Settings Service"
"C:\Program Files\SnapStream Media\Beyond TV 3\BTVTaskManagerService.exe"="C:\Program Files\SnapStream Media\Beyond TV 3\BTVTaskManagerService.exe:*:Enabled:Beyond TV Task Manager Service"
"E:\Program Files\Sierra\Empire Earth\Empire Earth.exe"="E:\Program Files\Sierra\Empire Earth\Empire Earth.exe:*:Enabled:Empire Earth"
"C:\Program Files\RealVNC\VNC4\vncviewer.exe"="C:\Program Files\RealVNC\VNC4\vncviewer.exe:*:Enabled:VNC Viewer Free Edition for Win32"
"F:\Program Files\Opera\Opera.exe"="F:\Program Files\Opera\Opera.exe:*:Enabled:Opera Internet Browser"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\EA Games\Command and Conquer Generals\patchget.dat"="C:\Program Files\EA Games\Command and Conquer Generals\patchget.dat:*:Disabled:patchgrabber"
"E:\Program Files\Real\RealOne Player\realplay.exe"="E:\Program Files\Real\RealOne Player\realplay.exe:*:Disabled:RealOne Player"
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\Program Files\Yahoo!\Messenger\YServer.exe"="C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Disabled:Yahoo! FT Server"
"C:\Program Files\Yahoo!\Messenger\YPager.exe"="C:\Program Files\Yahoo!\Messenger\YPager.exe:*:Disabled:Yahoo! Messenger"
"C:\Program Files\SnapStream Media\Beyond TV 3\SetupWizard.exe"="C:\Program Files\SnapStream Media\Beyond TV 3\SetupWizard.exe:*:Enabled:Beyond TV Setup Wizard"
"C:\Program Files\SnapStream Media\Beyond TV\BTVRegistrationService.exe"="C:\Program Files\SnapStream Media\Beyond TV\BTVRegistrationService.exe:*:Enabled:Beyond TV Registration Service"
"C:\Program Files\SnapStream Media\Beyond TV\BTVLibraryService.exe"="C:\Program Files\SnapStream Media\Beyond TV\BTVLibraryService.exe:*:Enabled:Beyond TV Library Service"
"C:\Program Files\SnapStream Media\Beyond TV\BTVNetworkService.exe"="C:\Program Files\SnapStream Media\Beyond TV\BTVNetworkService.exe:*:Enabled:Beyond TV Network Service"
"C:\Program Files\SnapStream Media\Beyond TV\BTVRecordingEngine.exe"="C:\Program Files\SnapStream Media\Beyond TV\BTVRecordingEngine.exe:*:Enabled:Beyond TV Recording Engine"
"C:\Program Files\SnapStream Media\Beyond TV\BTVGuideDataLoader.exe"="C:\Program Files\SnapStream Media\Beyond TV\BTVGuideDataLoader.exe:*:Enabled:Beyond TV Guide Data Loader"
"C:\Program Files\SnapStream Media\Beyond TV\BTVSettingsService.exe"="C:\Program Files\SnapStream Media\Beyond TV\BTVSettingsService.exe:*:Enabled:Beyond TV Settings Service"
"C:\Program Files\SnapStream Media\Beyond TV\BTVTaskManagerService.exe"="C:\Program Files\SnapStream Media\Beyond TV\BTVTaskManagerService.exe:*:Enabled:Beyond TV Task Manager Service"
"C:\Program Files\SnapStream Media\Beyond TV\BTVD3DShell.exe"="C:\Program Files\SnapStream Media\Beyond TV\BTVD3DShell.exe:*:Enabled:Beyond TV ViewScape"
"C:\Program Files\SnapStream Media\Beyond TV\SetupWizard.exe"="C:\Program Files\SnapStream Media\Beyond TV\SetupWizard.exe:*:Enabled:Beyond TV Setup Wizard"
"C:\Program Files\SnapStream Media\Beyond TV\BTVWebServiceProxy.exe"="C:\Program Files\SnapStream Media\Beyond TV\BTVWebServiceProxy.exe:*:Enabled:Beyond TV Web Service Proxy"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Internet Explorer\iexplore.exe"="C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\Smart PC Solutions\1-2-3 Spyware Free\SpywareFree.exe"="C:\Program Files\Smart PC Solutions\1-2-3 Spyware Free\SpywareFree.exe:*:Enabled:Protecting from spyware and adware can be easy and effective!"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
shell\AutoRun\command - H:\LaunchU3.exe -a


======File associations======

.js - open - "E:\Program Files\Macromedia\Dreamweaver 4\Dreamweaver.exe" "%1"

======List of files/folders created in the last 1 months======

2009-04-20 19:43:08 ----D---- C:\rsit
2009-04-18 17:51:58 ----A---- C:\WINDOWS\RegNet98.txt
2009-04-18 17:51:58 ----A---- C:\WINDOWS\RegNet.txt
2009-04-18 14:49:36 ----D---- C:\WINDOWS\ERDNT
2009-04-18 14:49:00 ----D---- C:\Program Files\ERUNT
2009-04-18 14:29:18 ----SHD---- C:\Config.Msi
2009-04-18 10:09:25 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
2009-04-18 00:21:35 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-04-18 00:21:35 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-04-17 21:04:13 ----D---- C:\Documents and Settings\David Wilson\Application Data\Malwarebytes
2009-04-17 21:04:06 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-04-17 21:04:06 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-04-17 19:53:43 ----A---- C:\WINDOWS\wininit.ini
2009-04-17 08:22:21 ----D---- C:\!KillBox
2009-04-16 21:00:04 ----D---- C:\Documents and Settings\All Users\Application Data\{A21E413E-98CC-4ABB-9843-E6AA4F456F61}
2009-04-14 09:48:02 ----A---- C:\WINDOWS\IE4 Error Log.txt
2009-04-14 09:44:35 ----D---- C:\fixwareout
2009-04-14 09:40:48 ----D---- C:\Program Files\Trend Micro
2009-04-13 21:09:24 ----D---- C:\Program Files\AVG
2009-04-13 21:09:24 ----D---- C:\Documents and Settings\All Users\Application Data\avg8

======List of files/folders modified in the last 1 months======

2009-04-20 20:29:30 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-04-20 20:27:30 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-04-20 19:42:18 ----A---- C:\WINDOWS\ntbtlog.txt
2009-04-18 14:30:14 ----A---- C:\WINDOWS\cylsplog.txt
2009-04-14 07:11:02 ----A---- C:\WINDOWS\win.ini
2009-04-13 22:12:42 ----A---- C:\WINDOWS\RAIDeUtility.ini
2009-04-13 21:57:24 ----A---- C:\WINDOWS\OEWABLog.txt
2009-04-02 08:25:08 ----A---- C:\WINDOWS\system32\wzfil.dll
2009-04-02 08:25:08 ----A---- C:\WINDOWS\system32\wrestfil.dll
2009-04-02 08:25:08 ----A---- C:\WINDOWS\system32\viofil.dll
2009-04-02 08:25:08 ----A---- C:\WINDOWS\system32\vgamfil.dll
2009-04-02 08:25:08 ----A---- C:\WINDOWS\system32\urifil.dll
2009-04-02 08:25:08 ----A---- C:\WINDOWS\system32\tapfil.dll
2009-04-02 08:25:08 ----A---- C:\WINDOWS\system32\tafil.dll
2009-04-02 08:25:08 ----A---- C:\WINDOWS\system32\swfil.dll
2009-04-02 08:25:08 ----A---- C:\WINDOWS\system32\srchout.dll
2009-04-02 08:25:08 ----A---- C:\WINDOWS\system32\srchin.dll
2009-04-02 08:25:08 ----A---- C:\WINDOWS\system32\srchfrgn.dll
2009-04-02 08:25:08 ----A---- C:\WINDOWS\system32\sporfil.dll
2009-04-02 08:25:08 ----A---- C:\WINDOWS\system32\spmfil.dll
2009-04-02 08:25:08 ----A---- C:\WINDOWS\system32\snetfil.dll
2009-04-02 08:25:08 ----A---- C:\WINDOWS\system32\snetbonly.dll
2009-04-02 08:25:08 ----A---- C:\WINDOWS\system32\pxyfil.dll
2009-04-02 08:25:08 ----A---- C:\WINDOWS\system32\psyfil.dll
2009-04-02 08:25:08 ----A---- C:\WINDOWS\system32\popfil.dll
2009-04-02 08:25:08 ----A---- C:\WINDOWS\system32\pkmon.dll
2009-04-02 08:25:08 ----A---- C:\WINDOWS\system32\picsfil.dll
2009-04-02 08:25:08 ----A---- C:\WINDOWS\system32\perfil.dll
2009-04-02 08:25:08 ----A---- C:\WINDOWS\system32\nvgamfil.dll
2009-04-02 08:25:08 ----A---- C:\WINDOWS\system32\nfil.dll
2009-04-02 08:25:08 ----A---- C:\WINDOWS\system32\mp3fil.dll
2009-04-02 08:25:08 ----A---- C:\WINDOWS\system32\movfil.dll
2009-04-02 08:25:08 ----A---- C:\WINDOWS\system32\macfil.dll
2009-04-02 08:25:08 ----A---- C:\WINDOWS\system32\lgwfil.dll
2009-04-02 08:25:08 ----A---- C:\WINDOWS\system32\lastupdate.dll
2009-04-02 08:25:08 ----A---- C:\WINDOWS\system32\jbfil.dll
2009-04-02 08:25:08 ----A---- C:\WINDOWS\system32\imgfil.dll
2009-04-02 08:25:08 ----A---- C:\WINDOWS\system32\igefil.dll
2009-04-02 08:25:08 ----A---- C:\WINDOWS\system32\iawfil.dll
2009-04-02 08:25:08 ----A---- C:\WINDOWS\system32\hatfil.dll
2009-04-02 08:25:08 ----A---- C:\WINDOWS\system32\gnfil.dll
2009-04-02 08:25:08 ----A---- C:\WINDOWS\system32\gdwfil.dll
2009-04-02 08:25:08 ----A---- C:\WINDOWS\system32\gblfil.dll
2009-04-02 08:25:08 ----A---- C:\WINDOWS\system32\fshrfil.dll
2009-04-02 08:25:08 ----A---- C:\WINDOWS\system32\fmfil.dll
2009-04-02 08:25:06 ----A---- C:\WINDOWS\system32\finfil.dll
2009-04-02 08:25:06 ----A---- C:\WINDOWS\system32\entfil.dll
2009-04-02 08:25:06 ----A---- C:\WINDOWS\system32\cultfil.dll
2009-04-02 08:25:06 ----A---- C:\WINDOWS\system32\csnews.dll
2009-04-02 08:25:06 ----A---- C:\WINDOWS\system32\chtfil.dll
2009-04-02 08:25:06 ----A---- C:\WINDOWS\system32\bsnlst.dll
2009-04-02 08:25:06 ----A---- C:\WINDOWS\system32\bnrfil.dll
2009-04-02 08:25:06 ----A---- C:\WINDOWS\system32\Auctfil.dll
2009-04-02 08:25:06 ----A---- C:\WINDOWS\system32\adwfil.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Aspi32;Aspi32; C:\WINDOWS\system32\drivers\Aspi32.sys [2007-02-06 16512]
R1 cdudf_xp;cdudf_xp; C:\WINDOWS\system32\drivers\cdudf_xp.sys [2004-04-13 285824]
R1 Cinemsup;Cinemsup; C:\WINDOWS\system32\drivers\Cinemsup.sys [2002-07-19 6656]
R1 DCDisk;DCDisk; C:\WINDOWS\system32\drivers\DCDisk.sys [2008-06-17 155648]
R1 DVDVRRdr_xp;DVDVRRdr_xp; C:\WINDOWS\system32\drivers\DVDVRRdr_xp.sys [2004-04-15 140416]
R1 GhPciScan;GhostPciScanner; \??\C:\Program Files\Symantec\Norton Ghost 2003\ghpciscan.sys []
R1 PQNTDrv;PQNTDrv; C:\WINDOWS\system32\drivers\PQNTDrv.sys [2003-04-16 4228]
R1 pwd_2k;pwd_2k; C:\WINDOWS\system32\drivers\pwd_2k.sys [2004-04-13 117248]
R1 UDFReadr;UDFReadr; C:\WINDOWS\system32\drivers\UDFReadr.sys [2004-04-15 198528]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2001-08-23 12032]
R2 MDC8021X;AEGIS Protocol (IEEE 802.1x) v2.3.1.9; C:\WINDOWS\system32\DRIVERS\mdc8021x.sys [2004-04-13 15781]
R3 4mmdat;4mmdat; C:\WINDOWS\System32\DRIVERS\4mmdat.sys [2008-04-13 12288]
R3 AN983;ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter; C:\WINDOWS\System32\DRIVERS\AN983.sys [2002-08-29 36224]
R3 dvd_2K;dvd_2K; C:\WINDOWS\system32\drivers\dvd_2K.sys [2004-04-13 23680]
R3 es1371;Creative AudioPCI (ES1371,ES1373) (WDM); C:\WINDOWS\system32\drivers\es1371mp.sys [2002-06-03 40832]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys [2008-04-17 15464]
R3 hcwPP2;Hauppauge WinTV PVR PCI II ([23|25|26]xxx); C:\WINDOWS\system32\DRIVERS\hcwPP2.sys [2007-02-06 185728]
R3 LHidFlt2;Logitech HID/USB Mouse Filter Driver; C:\WINDOWS\System32\DRIVERS\LHidFlt2.sys [2001-09-19 22064]
R3 LHidUsb;Logitech USB Receiver device driver; C:\WINDOWS\system32\drivers\LHidUsb.Sys [2001-09-19 37822]
R3 LKbdFlt2;Logitech Keyboard Class Filter Driver; C:\WINDOWS\System32\DRIVERS\LKbdFlt2.sys [2001-09-19 5840]
R3 LMouFlt2;Logitech Mouse Class Filter Driver; C:\WINDOWS\System32\DRIVERS\LMouFlt2.sys [2001-09-19 67440]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-08-23 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2007-02-14 3983872]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbohci.sys [2008-04-13 17152]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\System32\DRIVERS\usbprint.sys [2008-04-13 25856]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 wlanCIG;2Wire 802.11g Driver; C:\WINDOWS\system32\DRIVERS\wlanCIG.sys [2004-05-16 390752]
S1 Cdr4_xp;Cdr4_xp; C:\WINDOWS\system32\drivers\Cdr4_xp.sys [2006-05-04 2432]
S1 Cdralw2k;Cdralw2k; C:\WINDOWS\system32\drivers\Cdralw2k.sys [2006-05-04 2560]
S1 DVDRC;DVDRC; C:\WINDOWS\System32\drivers\DVDRC.sys []
S1 efbDisk;efbDisk; C:\WINDOWS\system32\drivers\efbDisk.sys []
S2 MVDCODEC;ATI WDM Specialized MVD Codec; C:\WINDOWS\System32\DRIVERS\atinmdxx.sys [2004-08-04 13824]
S3 AMDPCI;AMDPCI; \??\C:\DOCUME~1\DAVIDW~1\LOCALS~1\Temp\AMDPCI.sys []
S3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\System32\DRIVERS\arp1394.sys [2008-04-13 60800]
S3 ati2mpaa;ati2mpaa; C:\WINDOWS\System32\DRIVERS\ati2mpaa.sys [2001-08-17 281856]
S3 ati2mtaa;ati2mtaa; C:\WINDOWS\System32\DRIVERS\ati2mtaa.sys [2001-09-26 285088]
S3 atinrvxx;ATI WDM Rage Theater Video; C:\WINDOWS\System32\DRIVERS\atinrvxx.sys [2004-08-04 104960]
S3 ATIVRVXX;ATI Rage Theatre Video (ATIRTCAP); C:\WINDOWS\System32\DRIVERS\atirtcap.sys [2001-08-17 49920]
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 DDCCI;DDC/CI monitor; C:\WINDOWS\System32\DRIVERS\Moni2c.sys [2003-03-30 6494]
S3 hcwPVRP2;Hauppauge WinTV PVR PCI II (Encoder); C:\WINDOWS\system32\DRIVERS\hcwPVRP2.sys [2004-09-22 814464]
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\drivers\HidUsb.sys [2008-04-13 10368]
S3 l8042pr2;Logitech PS/2 Mouse Filter Driver; C:\WINDOWS\System32\DRIVERS\L8042Pr2.sys [2001-09-19 50432]
S3 mmc_2K;mmc_2K; C:\WINDOWS\system32\drivers\mmc_2K.sys [2004-04-13 23680]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\System32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\System32\DRIVERS\nic1394.sys [2008-04-13 61824]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\System32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\System32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 SunkFilt;Alcor Micro Corp Reader; \??\C:\WINDOWS\System32\Drivers\sunkfilt.sys []
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\System32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S3 zremote;zremote; C:\WINDOWS\system32\drivers\zremote.sys [2004-03-01 10368]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 _IOMEGA_ACTIVE_DISK_SERVICE_;Iomega Active Disk; C:\Program Files\Iomega\AutoDisk\ADService.exe [2002-01-24 126976]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-11-07 132424]
R2 FastTrakSvc;Promise FastTrak Log Service; C:\Program Files\Promise\FastTrak\FtrakSvc.exe [2000-11-15 237568]
R2 GhostStartService;GhostStartService; C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe [2003-12-17 200704]
R2 Iomega App Services;Iomega App Services; C:\PROGRA~1\Iomega\System32\AppServices.exe [2002-01-14 73728]
R2 Iprip;RIP Listener; C:\WINDOWS\System32\svchost.exe [2008-04-13 14336]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2005-02-22 38912]
R2 NsService;NovaStor NovaBACKUP Backup/Copy Engine; C:\Program Files\NovaStor\NovaStor NovaBACKUP\NsService.exe [2008-06-17 207936]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2007-02-14 159811]
R2 Real time Backup Loader;Real time Backup Loader; C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\Fsloader.exe [2008-06-17 93248]
R2 SimpTcp;Simple TCP/IP Services; C:\WINDOWS\System32\tcpsvcs.exe [2001-08-23 19456]
R2 SNMP;SNMP Service; C:\WINDOWS\System32\snmp.exe [2008-04-13 33280]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2008-11-20 536872]
S2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\System32\Ati2evxx.exe [2000-11-30 57344]
S2 Backup Scheduler;Backup Scheduler; C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\CBP\DCSchdlerSRVC.exe [2008-06-17 98304]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2006-10-20 36864]
S3 getPlus(R) Helper;getPlus(R) Helper; C:\Program Files\NOS\bin\getPlus_HelperSvc.exe [2008-08-29 33752]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2006-10-30 741376]
S3 LPDSVC;TCP/IP Print Server; C:\WINDOWS\System32\tcpsvcs.exe [2001-08-23 19456]
S3 PACSPTISVR;PACSPTISVR; C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe [2004-01-30 65625]
S3 SNMPTRAP;SNMP Trap Service; C:\WINDOWS\System32\snmptrap.exe [2008-04-13 8704]
S3 SPTISRV;Sony SPTI Service; C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe [2004-01-30 65622]
S3 SupportSoft RemoteAssist;SupportSoft RemoteAssist; C:\Program Files\Common Files\supportsoft\bin\ssrc.exe [2008-07-15 394608]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
S4 Iomega Activity Disk2;Iomega Activity Disk2; []
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2006-10-30 122880]

-----------------EOF-----------------

proskoma
2009-04-22, 03:26
info.txt logfile of random's system information tool 1.06 2009-04-20 19:43:15

======Uninstall list======

-->"C:\Program Files\Outlook Express\setup50.exe" /APP:WAB /CALLER:IE50 /UNINSTALL /PROMPT
-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Gigabyte\Gigabyte Management Tools\Uninst.isu"
-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\GIGABYTE\Promise ATA 133 Driver\Uninst.isu"
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
123 Free Solitaire-->E:\PROGRA~1\123FRE~1\UNWISE.EXE E:\PROGRA~1\123FRE~1\INSTALL.LOG
1Click DVD to Divx Avi 2.12-->"E:\Program Files\1Click DVD to Divx Avi\unins000.exe"
2Wire Wireless Client-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A3BC5D37-30F9-4CF7-BD5C-0DFF063E4B6D}\Setup.exe" -l0x9 -L0x9
AccuChef-->E:\PROGRA~1\ACCUCH~1\UNWISE.EXE E:\PROGRA~1\ACCUCH~1\INSTALL.LOG
Active Disk-->C:\WINDOWS\unvise32.exe C:\Program Files\Iomega\AutoDisk\uninstal.log
Actual Checkers 2000 R-->"E:\Program Files\Atlant Software\Actual Checkers 2000 R\unins000.exe"
Adaptec EZ-SCSI Standard Edition 5.0-->C:\WINDOWS\uninst.exe -f"C:\Program Files\SCSI_SE\DeIsL1.isu"
Adobe After Effects 5.5-->MsiExec.exe /I{31851B85-C98E-44DE-8750-9843BCD63963}
Adobe Atmosphere Player for Acrobat and Adobe Reader-->C:\WINDOWS\atmoUn.exe
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe GoLive 6.0-->"C:\Program Files\InstallShield Installation Information\{97E38F11-0FBE-4BC2-9EE1-5B1421C76F27}\setup.exe"
Adobe Illustrator 10.0.3-->"C:\Program Files\InstallShield Installation Information\{412033BC-44CF-48D9-B813-4B835101F4D3}\setup.exe"
Adobe PageMaker 6.5-->C:\WINDOWS\uninst.exe -f"E:\Program Files\PM65\DeIsL2.isu"
Adobe Photoshop 6.0-->C:\WINDOWS\ISUNINST.EXE -f"E:\Program Files\Adobe\Photoshop 6.0\Uninst.isu" -c"E:\Program Files\Adobe\Photoshop 6.0\Uninst.dll"
Adobe Photoshop 7.0-->C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Adobe\Photoshop 7.0\Uninst.isu" -c"C:\Program Files\Adobe\Photoshop 7.0\Uninst.dll"
Adobe Reader 7.0.5 Language Support-->MsiExec.exe /I{AC76BA86-7AD7-5464-3428-7050000000A7}
Adobe Reader 7.1.0-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A71000000002}
Adobe SVG Viewer 3.0-->C:\Program Files\Common Files\Adobe\SVG Viewer 3.0\Uninstall\Winstall.exe -u -fC:\Program Files\Common Files\Adobe\SVG Viewer 3.0\Uninstall\Install.log
Adobe Type Manager Deluxe 4.1-->C:\WINDOWS\uninst.exe -ff:\psfonts\DeIsL1.isu -c"f:\psfonts\UNINST.DLL"
AdobeŪ PhotoshopŪ Album Starter Edition 3.2-->MsiExec.exe /I{A654A805-41D9-40C7-AA46-4AF04F044D61}
AniRez-->C:\WINDOWS\unvise32.exe E:\Program Files\uninstal.log
Apple Mobile Device Support-->MsiExec.exe /I{EC4455AB-F155-4CC1-A4C5-88F3777F9886}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
ATI Display Driver-->rundll32 C:\WINDOWS\System32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
ATI Multimedia Center-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\ATI Multimedia\Uninst.isu" -c"C:\Program Files\ATI Multimedia\ISuninst.dll
Autodesk DWF Viewer-->C:\PROGRA~1\Autodesk\AUTODE~1\Setup.exe /remove
AWSPS 4.02-->C:\WINDOWS\uninst.exe -f"D:\Atelier Web\AWSPS 4.02\DeIsL1.isu" -c"D:\Atelier Web\AWSPS 4.02\_ISREG32.DLL"
Beyond TV DVD Burning Foundation-->MsiExec.exe /I{3EDFFD11-B9AB-4296-9757-B5AF1F2B8E5C}
Beyond TV DVD Burning Foundation-->MsiExec.exe /I{E86496D9-5009-4FFF-AABD-6E62CDFAC7B7}
Calculator Powertoy for Windows XP-->MsiExec.exe /I{B37C842A-B624-46B8-A727-654E72F1C91A}
Chessmaster 8000-->C:\WINDOWS\IsUninst.exe -f"d:\Chessmaster 8000\CM8kUninst.isu"
Command & Conquer Generals-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{06F80017-8F98-4C94-B868-52358569FC32}
Command & Conquer Red Alert 2-->E:\Westwood\RedAlert\Uninstll.EXE
Command & Conquer Tiberian Sun-->C:\Westwood\SUN\Uninstll.EXE
Command && Conquer Red Alert 2 - Yuri's Revenge-->E:\Westwood\RedAlert\Uninstll.EXE
Command and ConquerTM Generals Zero Hour-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{F3E9C243-122E-4D6B-ACC1-E1FEC02F6CA1}
Cover Art Downloader v1.2-->"C:\Program Files\Cover Art Downloader\unins000.exe"
Critical Update for Windows Media Player 11 (KB959772)-->"C:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
CuteFTP 5.0 XP-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{18DF995F-2ACC-47E4-A33B-A703F4D39E92}\IS6.exe" -l0x9 /l0009 UNINSTALL
dBpowerAMP Music Converter-->"C:\WINDOWS\system32\SpoonUninstall.exe" <uninstall>C:\WINDOWS\system32\SpoonUninstall-dBpowerAMP Music Converter.dat
DesignPro 5.0 Limited Edition-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{97AE00A8-1336-410F-B467-1C6623127BD6}
Desktop Architect-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Freeware\Desktop Architect\Uninst.isu"
Dialog Box Assistant 1.01-->"E:\Program Files\OSDEx\unins000.exe"
DING!-->MsiExec.exe /X{84031A18-BA9A-4156-A74F-E05B52DDFCE2}
Director 8 Shockwave Studio-->E:\PROGRA~1\MACROM~1\DIRECT~1\UNWISE.EXE E:\PROGRA~1\MACROM~1\DIRECT~1\install.log
DirectVobSub (remove only)-->"C:\Program Files\DirectVobSub\uninstall.exe"
DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
Doppler 10 Pinpoint Alert-->C:\WINDOWS\wnUninstall.exe "Doppler 10 Pinpoint Alert"
DR-92 Manager-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\DR-92 Manager\Uninst.isu"
Elecard MPEG Player-->"C:\Program Files\Elecard\Elecard MPEG Player\Uninstall.exe" "C:\Program Files\Elecard\Elecard MPEG Player\install.log" -u
Empire Earth-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2447500B-22D7-47BD-9B13-1A927F43A267}\Setup.exe"
Enable S3 for USB Device-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Gigabyte\Enable S3 for USB Device\Uninst.isu"
ERUNT 1.1j-->"C:\Program Files\ERUNT\unins000.exe"
Eudora-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9CD51F8E-A936-46D2-93BA-140D3F08BDD6}\setup.exe" -l0x9
FastTrak RAID controller utility-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Promise\FastTrak\UninstNT.isu" -c"C:\Program Files\Promise\FastTrak\uninst.dll"
FontLook-->E:\PROGRA~1\FONTLOOK\UNWISE.EXE E:\PROGRA~1\FONTLOOK\INSTALL.LOG
getPlus(R) for Adobe-->"C:\Program Files\NOS\bin\getPlus_HelperSvc.exe" /UninstallGet1
GetRight-->E:\Program Files\GetRight\GETRIGHT.EXE /UNINSTALL
GoldLeo DVD Ripper 2.2-->"C:\Program Files\GoldLeo DVD Ripper\unins000.exe"
Hauppauge WinTV Scheduler-->C:\PROGRA~1\WINTV\SCHEDU~1\UNISCHED.EXE C:\PROGRA~1\WINTV\SCHEDU~1\INSTALL.LOG
Hauppauge WinTV2000-->C:\PROGRA~1\WINTV\UNTV32.EXE C:\PROGRA~1\WINTV\WINTV2K.LOG
Hauppauge WinTV-PVR 150 Drivers-->C:\PROGRA~1\WINTV\UNPVR48.EXE C:\PROGRA~1\WINTV\pvr26xxx.LOG
Hello (remove only)-->"C:\Program Files\Hello\Uninstall.exe"
HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
hp deskjet 840c series (Remove only)-->C:\Program Files\hp deskjet 840c series\hpfiui.exe -c -vdivid=HPF -vpnum=90 -vinstport=USB001 -vproduct=840c -huninstall
hp deskjet 840c series-->rundll32 hpzcon04.dll,VendorJettison hp deskjet 840c series
HTMLPad 2004 Pro v5.0-->"E:\Program Files\HTMLPad 2004 Pro\unins000.exe"
HyperCD-->C:\WINDOWS\IsUninst.exe -fC:\HyperCD\Uninst.isu
ICQ-->E:\PROGRA~1\ICQ\ICQUninstall.EXE
IKEA HomePlanner Kitchen-->MsiExec.exe /I{A36BE275-BD22-406C-8D2D-ED99F9E6C0B4}
InterVideo FilterSDK for Hauppauge-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2227E1FA-01F5-483C-AB0E-2A308E900B3D}\setup.exe" REMOVEALL
Iomega App Services-->C:\WINDOWS\unvise32.exe C:\Program Files\Iomega\System32\uninstal.log
IomegaWare-->C:\WINDOWS\unvise32.exe E:\Program Files\Iomega\uninstal.log
iSofter DVD Ripper Platinum 3.0.2007.228-->"C:\Program Files\iSofter\DVDPlatinum\unins000.exe"
iTunes-->MsiExec.exe /I{318AB667-3230-41B5-A617-CB3BF748D371}
J2SE Runtime Environment 5.0 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150020}
J2SE Runtime Environment 5.0 Update 4-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150040}
J2SE Runtime Environment 5.0 Update 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060}
Java 2 Runtime Environment Standard Edition v1.3.1-->C:\WINDOWS\IsUninst.exe -f"E:\Program Files\JavaSoft\JRE\1.3.1\Uninst.isu"
Java 2 Runtime Environment, SE v1.4.2_06-->MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142060}
Java(TM) 6 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
Java(TM) 6 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Java(TM) SE Runtime Environment 6 Update 1-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
JMail-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FC0C3855-5651-4313-AC56-9A3F17D2ADC9}\Setup.exe"
LiveUpdate 2.5 (Symantec Corporation)-->C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE /U
Logitech Desktop Messenger-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}\Setup.exe" UNINSTALL /L9
Logitech MouseWare 9.41 .1-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{5809E7CF-4DCF-11D4-9875-00105ACE7734}\setup.exe" -l0009 UNINSTALL
Macromedia Dreamweaver 4-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{ABDA9912-5D00-11D4-BAE7-9367CA097955}\Setup.exe" mmUninstall
Macromedia Extension Manager-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A5BA14E0-7384-11D4-BAE7-00409631A2C8}\setup.exe" mmUninstall
Macromedia Flash 5-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\ENGINE\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4C93C363-414E-11D4-9756-00C04F8EEB39}\SETUP.EXE" UNINSTALL
Macromedia FreeHand 9-->C:\WINDOWS\IsUninst.exe -f"D:\Macromedia\FreeHand 9\Uninst.isu"
Macromedia Generator 2-->C:\WINDOWS\IsUninst.exe -f"d:\macromedia\Generator2\Generator 2\Uninst.isu" -c"d:\macromedia\Generator2\Generator 2\bin\uninstall.dll"
Macromedia Shockwave Player-->C:\WINDOWS\SYSTEM32\MACROMED\SHOCKW~3\UNWISE.EXE C:\WINDOWS\SYSTEM32\MACROMED\SHOCKW~3\Install.log
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Media Cleaner Pro-->C:\WINDOWS\uninst.exe -f"C:\Program Files\Media Cleaner Pro 4.0.2\DeIsL1.isu" -c"C:\PROGRA~1\MEDIAC~1.2\uninst.dll
Media Library Management Wizard-->RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\mplibwiz.inf,DefaultUninstall
microKORG SoundEditor-->MsiExec.exe /X{EB091860-8C2B-4E49-A543-666373C39E6F}
Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
Microsoft .NET Framework 3.0-->C:\WINDOWS\Microsoft.NET\Framework\v3.0\Microsoft .NET Framework 3.0\setup.exe
Microsoft .NET Framework 3.0-->MsiExec.exe /X{15095BF3-A3D7-4DDF-B193-3A496881E003}
Microsoft Age of Empires II-->"E:\Age of Empires II\UNINSTAL.EXE" /runtemp /uninstall
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Data Access Components KB870669-->C:\WINDOWS\muninst.exe C:\WINDOWS\INF\KB870669.inf
Microsoft Interactive CD Sampler-->C:\UNWISE.EXE C:\Sampler7.LOG
Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft Money Plus-->"C:\Program Files\Microsoft Money Plus\MNYCoreFiles\Setup\uninst.exe" /s:120
Microsoft Money Shared Libraries-->MsiExec.exe /X{7F1B3341-A94E-4F5C-B587-CA0EB964221E}
Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office XP Professional with FrontPage-->MsiExec.exe /I{90280409-6000-11D3-8CFE-0050048383C9}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Windows Media Video 9 VCM-->RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmv9vcm.inf, Uninstall
Microsoft Windows XP Video Decoder Checkup Utility-->RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\DECCHECK.inf,Uninstall
Microsoft Word 97 Time Mgmt Wizard Pack (Remove only)-->RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\wdtmgmt.inf, Uninstall.NT
Movavi Video Converter 6-->MsiExec.exe /I{6A750221-B84D-419D-B11C-5F597FDBA826}
Movie Maker Background Music Files-->RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\mmmusic.inf,DefaultUninstall
Movie Maker Sound Effects-->RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\mmsounds.inf,DefaultUninstall
Movie Maker Title Images-->RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\mmtitle.inf,DefaultUninstall
Mozilla Firefox (2.0.0.8)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSN Entertainment Download Troubleshooter-->rundll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnediag.inf,Uninstall
MSN Music Assistant-->rundll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\msninst.inf,Uninstall
MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 6.0 Parser (KB933579)-->MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
Multimedia Card Reader-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{07B02BD4-E799-4945-B240-166CA9A9BE2D} /l1033
MusicmatchŪ Jukebox-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8EF1122E-E90C-4EE9-AB0C-7FDE2BA42C26}\setup.exe" -l0x9 -uninst
Musicnotes Player V1.23.1 and Viewer-->"C:\Program Files\Musicnotes\Player\unins000.exe"
MySQL Connector/ODBC 3.51-->C:\WINDOWS\SYSTEM32\UNWISE.EXE C:\WINDOWS\SYSTEM32\myodbc3_install.LOG
Myst IV - Revelation-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{96F702F3-7CA4-41B5-A70A-4F348DF99A9A}\setup.exe" -l0x9
nanoPEG-Editor 2.2 Hauppauge Edition-->"C:\Program Files\nanocosmos\MPEG-Tools for Hauppauge\Editor2\unins000.exe"
Napster-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BBBCAE4B-B416-4182-A6F2-438180894A81}\setup.exe" -l0x9 AddRemoveCPRun
NEC-Mitsubishi NaViSet-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{8287E5A6-A0D1-4074-B149-F6157EE0DEEB}
NetAccountability-->C:\WINDOWS\System32\nak.exe -u
Netflix Movie Viewer-->MsiExec.exe /X{BCE72AED-3332-4863-9567-C5DCB9052CA2}
Norton Ghost-->MsiExec.exe /I{BBAAACFA-B012-4367-ADDA-4DDCDFD48F96}
NovaBACKUP-->MsiExec.exe /I{372FB8CA-E690-4FB2-B2DB-649768691561}
NovaBACKUP-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0C3B9465-E882-11D3-BF71-00C04FA0D6AE}\setup.exe" -L0x9
NVIDIA Drivers-->C:\WINDOWS\system32\nvudisp.exe UninstallGUI
OpenMG Limited Patch 3.4-04-16-16-01-->C:\Program Files\Common Files\Sony Shared\OpenMG\HotFixes\HotFix3.4-04-16-16-01\HotFixSetup\setup.exe /u
OpenMG Secure Module 3.4.01-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{26C849AB-1865-412D-B87D-B18BC5CB6C60}\setup.exe" -l0x9 UNINSTALL
Opera 9.10-->MsiExec.exe /X{5D582D33-EB35-4D77-B7AF-403322D947E6}
Palm Desktop-->MsiExec.exe /X{E89D78B8-28F7-412F-8B26-C684739CBBDC}
Personal Color Viewer 2.0-->MsiExec.exe /I{B3E3EAEC-A20E-48EE-B161-A43B552D5465}
Plus! MP3 Audio Converter LE-->RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\audcle.inf,DefaultUninstall
PolderbitS Sound Recorder and Editor-->"C:\Program Files\PolderbitS\Recorder\Recorder.exe" /uninstall
QTam Bitmap to Icon 3.5-->"E:\Program Files\QTam\Bitmap to Icon 3.5\unins000.exe"
QuickTime-->MsiExec.exe /I{F958CA02-BB40-4007-894B-258729456EE4}
Ray Dream Studio v5.0-->C:\WINDOWS\uninst.exe -f"c:\program files\RayDream\DeIsL1.isu"
Real Alternative 1.52 Lite-->"C:\Program Files\Real Alternative\unins000.exe"
REALmagic Hollywood Plus-->C:\WINDOWS\IsUninst.exe -fC:\REALmagc\Uninst.isu -c"C:\REALmagc\rmset.dll
Red Alert Windows 95-->C:\WINDOWS\RAUNINST.EXE C:\WINDOWS\UNINST.EXE -fC:\WESTWOOD\REDALERT\DEISL1.ISU
Roxio Burn Engine-->MsiExec.exe /I{8DCE550C-CA43-4E82-92DF-FFC4A48F5BE1}
Roxio Easy Media Creator 7-->MsiExec.exe /I{89818D7D-C128-4DC2-8DC8-326DC904969C}
Safari-->MsiExec.exe /I{582D2A53-F426-4C5E-A2E6-43C1AB36B907}
SCRABBLE-->C:\PROGRA~1\HASBRO\SCRABB~1\UNWISE.EXE /U C:\PROGRA~1\HASBRO\SCRABB~1\INSTALL.LOG
Security Update for Windows Internet Explorer 7 (KB928090)-->"C:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB929969)-->"C:\WINDOWS\ie7updates\KB929969\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB931768)-->"C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB933566)-->"C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB937143)-->"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player 10 (KB911565)-->"C:\WINDOWS\$NtUninstallKB911565$\spuninst\spuninst.exe"
Security Update for Windows Media Player 10 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP10$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938464-v2)-->"C:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953155)-->"C:\WINDOWS\$NtUninstallKB953155$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
Shockwave-->C:\WINDOWS\SYSTEM32\MACROMED\SHOCKW~2\UNWISE.EXE C:\WINDOWS\SYSTEM32\MACROMED\SHOCKW~2\Install.log
Sid Meier's Alpha Centauri-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Firaxis Games\Sid Meier's Alpha Centauri\Uninst.isu"
SimCity 3000-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Maxis\SimCity 3000\Uninst.isu"
SnapStream Beyond TV 4.6.1-->"C:\Program Files\SnapStream Media\Beyond TV\uninstall-btv.exe"
SnapStream Firefly Mini 1.0.2-->"C:\Program Files\SnapStream Media\Firefly Mini\Uninstall.exe"
Solid Oak Software WhatsMyDNS 1.8.2.23-->C:\WINDOWS\UnDeploy.exe "C:\Program Files\Solid Oak Software\WhatsMyDNS\Deploy.log"
Sonic CinePlayer MPEG Combo Pack-->MsiExec.exe /I{17F44736-17BF-4ACE-910E-A743C5D55129}
Sound Blaster PCI128-->C:\WINDOWS\uninst.exe -f"C:\Program Files\Creative\CTSND\DeIsL1.isu"
Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
SuperDVD Player V4.0-->"C:\Program Files\MasterSoft\unins000.exe"
SureThing CD Labeler 4 SE-->C:\WINDOWS\mvuninst\App1\mvuninst.exe "SureThing CD Labeler 4 SE"
Ten Thumbs 4.3-->MsiExec.exe /I{312DFE8A-7B3A-41D4-AB00-52ACDB05ABE2}
Ten Thumbs Typing Tutor-->MsiExec.exe /X{28638102-02DB-43C5-9358-7596ED0FCBC2}
TPP Storage Class Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{179C8887-E768-4FF6-9008-1F665AD9F6FC}\Setup.exe" NotFirstIntall
TrayDay-->C:\PROGRA~1\TRAYDAY\Uninstall.exe C:\PROGRA~1\TRAYDAY\Install.log
TWC Customer Controls-->MsiExec.exe /I{F8722041-B63A-47FB-82A8-5F0977E1CF45}
Tweaki...for Power Users-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\ENGINE\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{71AE4702-5C47-43BB-BDD6-21C84D086B82}\setup.exe"
Tweakui Powertoy for Windows XP-->MsiExec.exe /I{C7793EE8-F666-4E6B-9827-76468679480E}
Update for Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Update for Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Update for Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
USB 2.0 Host Controller Driver-->C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\GIGABYTE\USB 2.0 Host Controller Driver\Uninst.isu" -c"C:\Program Files\GIGABYTE\USB 2.0 Host Controller Driver\uninst.dll"
Visual C++ 2008 x86 Runtime - (v9.0.30729)-->MsiExec.exe /X{F333A33D-125C-32A2-8DCE-5C5D14231E27}
Visual C++ 2008 x86 Runtime - v9.0.30729.01-->C:\WINDOWS\system32\msiexec.exe /x {F333A33D-125C-32A2-8DCE-5C5D14231E27} /qb+ REBOOTPROMPT=""
Visual Studio 2005 Redist Package-->MsiExec.exe /I{D8C2C5B1-1A88-4B87-9116-59D082B1CE30}
VNC Free Edition 4.1.1-->"C:\Program Files\RealVNC\VNC4\unins000.exe"
WavePad Uninstall-->C:\Program Files\NCH Swift Sound\WavePad\uninst.exe
Westwood Shared Internet Components-->C:\Westwood\Internet\UnstllAP.EXE
Windows Communication Foundation-->MsiExec.exe /X{491DD792-AD81-429C-9EB4-86DD3D22E333}
Windows Genuine Advantage v1.3.0254.0-->MsiExec.exe /I{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}
Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
Windows Media Bonus Pack for Windows XP-->RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmbonus.inf,DefaultUninstall
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows Media Player Playlist Import to Excel Wizard-->RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\mpxlswiz.inf,DefaultUninstall
Windows Media Player Skin Importer-->RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\wa2wmp.inf,DefaultUninstall
Windows Media Player Tray Control-->RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\mpxptray.inf,DefaultUninstall
Windows Presentation Foundation-->MsiExec.exe /X{BAF78226-3200-4DB4-BE33-4D922A799840}
Windows Workflow Foundation-->MsiExec.exe /I{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
WinZip-->"E:\PROGRA~1\WINZIP\winzip32.exe" /uninstall
WordPerfect Office 2002-->C:\WINDOWS\Corel\uninst32.exe
WordPerfect Office 2002-->MsiExec.exe /I{A0B295C3-FD3C-11D4-A811-0090279106C3}
Wtcc II-->C:\PROGRA~1\WTCC2\UNWISE.EXE C:\PROGRA~1\WTCC2\INSTALL.LOG
XviD MPEG-4 Video Codec-->"C:\Program Files\XviD\unins000.exe"

======System event log======

Computer Name: DAVEHOME
Event Code: 7000
Message: The ATI WDM Specialized MVD Codec service failed to start due to the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.


Record Number: 802605
Source Name: Service Control Manager
Time Written: 20090201155951.000000-300
Event Type: error
User:

Computer Name: DAVEHOME
Event Code: 7000
Message: The ATI WDM Specialized MVD Codec service failed to start due to the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.


Record Number: 802568
Source Name: Service Control Manager
Time Written: 20090131093847.000000-300
Event Type: error
User:

Computer Name: DAVEHOME
Event Code: 1001
Message: Your computer was not assigned an address from the network (by the DHCP
Server) for the Network Card with network address 0060B31CC114. The following error
occurred:
The operation was canceled by the user.
.
Your computer will continue to try and obtain an address on its own from
the network address (DHCP) server.

Record Number: 802562
Source Name: Dhcp
Time Written: 20090131093828.000000-300
Event Type: error
User:

Computer Name: DAVEHOME
Event Code: 7000
Message: The ATI WDM Specialized MVD Codec service failed to start due to the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.


Record Number: 802528
Source Name: Service Control Manager
Time Written: 20090127211231.000000-300
Event Type: error
User:

Computer Name: DAVEHOME
Event Code: 1001
Message: Your computer was not assigned an address from the network (by the DHCP
Server) for the Network Card with network address 0060B31CC114. The following error
occurred:
The operation was canceled by the user.
.
Your computer will continue to try and obtain an address on its own from
the network address (DHCP) server.

Record Number: 802510
Source Name: Dhcp
Time Written: 20090126211403.000000-300
Event Type: error
User:

=====Application event log=====

Computer Name: DAVEHOME
Event Code: 5
Message: Exception Error - UID List index out of bounds (1)
Record Number: 833781
Source Name: CYBERsitter
Time Written: 20090319173259.000000-240
Event Type: error
User: DAVEHOME\David Wilson

Computer Name: DAVEHOME
Event Code: 5
Message: Exception Error - UID List index out of bounds (1)
Record Number: 833780
Source Name: CYBERsitter
Time Written: 20090319173159.000000-240
Event Type: error
User: DAVEHOME\David Wilson

Computer Name: DAVEHOME
Event Code: 5
Message: Exception Error - UID List index out of bounds (1)
Record Number: 833779
Source Name: CYBERsitter
Time Written: 20090319173059.000000-240
Event Type: error
User: DAVEHOME\David Wilson

Computer Name: DAVEHOME
Event Code: 5
Message: Exception Error - UID List index out of bounds (1)
Record Number: 833778
Source Name: CYBERsitter
Time Written: 20090319172959.000000-240
Event Type: error
User: DAVEHOME\David Wilson

Computer Name: DAVEHOME
Event Code: 5
Message: Exception Error - UID List index out of bounds (1)
Record Number: 833777
Source Name: CYBERsitter
Time Written: 20090319172859.000000-240
Event Type: error
User: DAVEHOME\David Wilson

======Environment variables======

"BLASTER"=A220 I7 D1 H7 P330 T6
"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"NUMBER_OF_PROCESSORS"=1
"OS"=Windows_NT
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\system32\WBEM;C:\PROGRA~1\MICROS~5\Office;"C:\Program Files\Symantec\Norton Ghost 2003\";C:\Program Files\Common Files\Roxio Shared\DLLShared;C:\Program Files\Common Files\Ulead Systems\MPEG;E:\Program Files\QuickTime\QTSystem\
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 8 Stepping 0, AuthenticAMD
"PROCESSOR_LEVEL"=6
"PROCESSOR_REVISION"=0800
"PROMPT"=$p$g
"TEMP"=C:\WINDOWS\TEMP
"TMP"=C:\WINDOWS\TEMP
"winbootdir"=C:\WINDOWS
"windir"=C:\WINDOWS
"CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip
"SAFEBOOT_OPTION"=NETWORK

-----------------EOF-----------------

Blade81
2009-04-22, 15:14
Hi again,

Please visit this webpage for download links, and instructions for running ComboFix tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Please ensure you read this guide carefully and install the Recovery Console first.

The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

Once installed, you should see a blue screen prompt that says:

The Recovery Console was successfully installed.

Please continue as follows:


Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link (http://www.bleepingcomputer.com/forums/topic114351.html)
Remember to re-enable them afterwards.


Click Yes to allow ComboFix to continue scanning for malware.


When the tool is finished, it will produce a report for you.

Please include the following reports for further review, and so we may continue cleansing the system:

C:\ComboFix.txt
New HijackThis log.

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix. This tool is not a toy and not for everyday use.

proskoma
2009-04-23, 01:13
ComboFix 09-04-23.02 - David Wilson 04/22/2009 18:53.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1535.1107 [GMT -4:00]
Running from: c:\documents and settings\David Wilson\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\dds.pif
c:\windows\IE4 Error Log.txt
c:\windows\jestertb.dll
c:\windows\system32\bnrfil.dll
c:\windows\system32\bsnlst.dll
c:\windows\system32\igefil.dll
c:\windows\system32\lastupdate.dll
c:\windows\system32\macfil.dll
c:\windows\system32\nfil.dll
c:\windows\system32\picsfil.dll
c:\windows\system32\snetfil.dll
c:\windows\system32\srchfrgn.dll
c:\windows\system32\srchout.dll
c:\windows\vaseo.lex
c:\windows\winhelp.ini

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_IPRIP
-------\Service_Iprip


((((((((((((((((((((((((( Files Created from 2009-03-22 to 2009-04-22 )))))))))))))))))))))))))))))))
.

2009-04-22 01:22 . 2009-04-22 01:22 2709 ----a-w c:\windows\system32\co32andlo.dat
2009-04-20 23:43 . 2009-04-20 23:43 -------- d-----w C:\rsit
2009-04-20 22:47 . 2009-04-20 22:47 2709 ----a-w c:\windows\system32\gapiyshe.dat
2009-04-20 01:14 . 2009-04-20 01:14 2709 ----a-w c:\windows\system32\cocoerrfo.dat
2009-04-19 22:34 . 2009-04-19 22:29 360021 ----a-w C:\something.scr
2009-04-19 22:13 . 2009-04-19 22:13 2709 ----a-w c:\windows\system32\orptofo.dat
2009-04-18 14:09 . 2009-04-18 14:09 -------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2009-04-18 04:21 . 2009-04-18 04:21 -------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-04-18 01:04 . 2009-04-18 01:04 -------- d-----w c:\documents and settings\David Wilson\Application Data\Malwarebytes
2009-04-18 01:04 . 2009-04-06 19:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-04-18 01:04 . 2009-04-06 19:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-18 01:04 . 2009-04-18 01:04 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-17 23:53 . 2009-04-17 23:53 66 ----a-w c:\windows\wininit.ini
2009-04-17 12:22 . 2009-04-17 12:22 -------- d-----w C:\!KillBox
2009-04-17 01:53 . 2009-04-17 01:53 184304 ----a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-17 01:42 . 2009-04-17 01:42 -------- d-----w c:\documents and settings\Administrator\Local Settings\Application Data\Seven Zip
2009-04-17 01:28 . 2009-04-17 01:28 -------- d-----w c:\documents and settings\Administrator\Local Settings\Application Data\Apple Computer
2009-04-17 01:28 . 2009-04-17 01:28 -------- d-----w c:\documents and settings\Administrator\Application Data\Apple Computer
2009-04-17 01:19 . 2009-04-17 01:19 -------- d-----w c:\documents and settings\Guest\Local Settings\Application Data\Seven Zip
2009-04-17 01:18 . 2009-04-17 01:18 -------- d-----w c:\documents and settings\Guest\Application Data\Apple Computer
2009-04-17 01:18 . 2009-04-17 01:18 -------- d-----w c:\documents and settings\Guest\Local Settings\Application Data\Mozilla
2009-04-17 01:00 . 2009-04-17 01:00 -------- d-----w c:\documents and settings\All Users\Application Data\{A21E413E-98CC-4ABB-9843-E6AA4F456F61}
2009-04-17 00:59 . 2009-04-17 00:59 -------- d-----w c:\documents and settings\David Wilson\Local Settings\Application Data\Seven Zip
2009-04-14 18:33 . 2009-04-15 01:39 2709 ----a-w c:\windows\system32\dllto32to.dat
2009-04-14 13:44 . 2009-04-14 13:44 -------- d-----w C:\fixwareout
2009-04-14 01:57 . 2009-04-14 01:57 -------- d-----w c:\documents and settings\Guest\Local Settings\Application Data\NovaStor
2009-04-14 01:09 . 2009-04-14 01:09 -------- d-----w c:\documents and settings\All Users\Application Data\avg8

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-22 22:58 . 2008-10-11 18:01 1024 ---h--w C:\diskfile1
2009-04-22 22:58 . 2008-10-11 17:52 16896 ---h--w C:\logicinf.bin
2009-04-18 21:54 . 2003-10-25 14:41 40654 ----a-w C:\winzip.log
2009-04-18 18:49 . 2009-04-18 18:49 -------- d-----w c:\program files\ERUNT
2009-04-18 18:32 . 2009-04-18 18:11 722 ----a-w C:\aaw7boot.log
2009-04-18 04:21 . 2009-04-18 04:21 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-04-18 01:04 . 2009-04-18 01:04 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-04-14 13:40 . 2009-04-14 13:40 -------- d-----w c:\program files\Trend Micro
2009-04-14 01:09 . 2009-04-14 01:09 -------- d-----w c:\program files\AVG
2009-03-07 13:20 . 2009-03-07 13:20 -------- d-----w c:\program files\RayDream
2009-02-09 11:13 . 2008-10-14 21:51 1846784 ------w c:\windows\SYSTEM32\dllcache\win32k.sys
2009-02-09 11:13 . 2001-08-23 16:00 1846784 ------w c:\windows\SYSTEM32\win32k.sys
2008-12-16 23:23 . 2008-12-16 23:23 726008 ----a-w c:\documents and settings\David Wilson\gotomypc_438.exe
2008-11-06 16:33 . 2008-03-15 15:11 726008 ----a-w c:\documents and settings\David Wilson\gotomypc_437.exe
2008-10-11 15:27 . 2004-10-06 03:17 184304 ----a-w c:\documents and settings\David Wilson\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2008-03-11 03:02 . 2008-03-11 03:02 311752 ----a-w c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2005-01-15 03:17 . 2005-01-15 03:17 135 ----a-w c:\documents and settings\David Wilson\Local Settings\Application Data\fusioncache.dat
2001-11-06 04:23 . 2000-05-13 03:43 266 --sh--w c:\program files\desktop.ini
2001-11-06 04:23 . 2000-05-13 03:43 11079 ---h--w c:\program files\folder.htt
2001-01-19 16:04 . 2005-02-06 20:12 21841 ----a-w c:\program files\Common Files\tppupd2k.dll
2001-01-19 15:04 . 2002-02-24 01:38 21329 ------w c:\program files\Common Files\tppupd98.dll
2007-10-09 05:2005-04-28 02:53 33:30 . c:\program files\mozilla firefox\components\jar50.dll
2007-10-09 05:2005-04-28 02:53 33:30 . c:\program files\mozilla firefox\components\jsd3250.dll
2007-10-09 05:2007-10-20 14:31 33:32 . c:\program files\mozilla firefox\components\myspell.dll
2007-10-09 05:2007-10-20 14:31 33:32 . c:\program files\mozilla firefox\components\spellchk.dll
2007-10-09 05:2005-04-28 02:53 33:32 . c:\program files\mozilla firefox\components\xpinstal.dll
2008-10-04 19:44 . 2008-10-04 19:44 32768 --sha-w c:\windows\SYSTEM32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008100420081005\index.dat
2001-11-13 14:18 . 2001-11-13 14:18 8 --sh--w c:\windows\All Users\DRM\pdrm.dat
2008-05-19 02:07 . 2008-05-19 02:07 0 --sha-w c:\windows\All Users\DRM\Cache\Indiv02.tmp
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"PRISMSVR.EXE"="c:\windows\system32\PRISMSVR.EXE" [2004-04-13 290905]
"C2K"="c:\windows\CYB2K.EXE" [2007-07-24 3163648]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-02-14 7700480]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-02-14 86016]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"ezShieldProtector for Px"="c:\windows\system32\ezSP_Px.exe" [2002-08-20 40960]
"nwiz"="nwiz.exe" - c:\windows\SYSTEM32\nwiz.exe [2007-02-14 1622016]

c:\documents and settings\David Wilson\Start Menu\Programs\Startup\
TrayDay.lnk - c:\program files\TrayDay\TrayDay.exe [2003-12-6 204800]
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech Desktop Messenger.lnk - e:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2002-9-25 156160]
2Wire Wireless Client.lnk - c:\program files\2Wire 802.11g Wireless\PRISMCFG.exe [2007-8-18 335979]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoFavoritesMenu"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoFavoritesMenu"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= "e:\program files\EUDORA\EUSHLEXT.DLL" [2005-11-14 86016]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^CorelCENTRAL 10.lnk]
backup=c:\windows\pss\CorelCENTRAL 10.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^FastCheck Monitoring Utility.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\FastCheck Monitoring Utility.lnk
backup=c:\windows\pss\FastCheck Monitoring Utility.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Sonic CinePlayer Quick Launch.lnk]
backup=c:\windows\pss\Sonic CinePlayer Quick Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^David Wilson^Start Menu^Programs^Startup^Dialog Box Assistant.lnk]
path=c:\documents and settings\David Wilson\Start Menu\Programs\Startup\Dialog Box Assistant.lnk
backup=c:\windows\pss\Dialog Box Assistant.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^David Wilson^Start Menu^Programs^Startup^Webshots.lnk]
backup=c:\windows\pss\Webshots.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"EnsoniqMixer"=starter.exe
"AtiPTA"=Atiptaxx.exe
"AtiCwd32"=Aticwd32.exe
"AtiQiPcl"=AtiQiPcl.exe
"POINTER"=point32.exe
"LoadQM"=loadqm.exe
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
"QuickTime Task"=e:\program files\QuickTime\qttask.exe
"MMTray"=d:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\Cyb2k.exe"=
"e:\\Program Files\\GetRight\\getright.exe"=
"e:\\Age of Empires II\\Age2_X1\\AGE2_X1.ICD"=
"e:\\Program Files\\Macromedia\\Dreamweaver 4\\Dreamweaver.exe"=
"c:\\Program Files\\Common Files\\Doppler 10 Pinpoint Alert\\TrueWeather.exe"=
"c:\\WINDOWS\\System32\\mmc.exe"=
"e:\\Program Files\\ICQ\\Icq.exe"=
"e:\\Program Files\\Sierra\\Empire Earth\\Empire Earth.exe"=
"c:\\Program Files\\RealVNC\\VNC4\\vncviewer.exe"=
"f:\\Program Files\\Opera\\Opera.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\EA Games\\Command and Conquer Generals\\patchget.dat"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVRegistrationService.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVLibraryService.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVNetworkService.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVRecordingEngine.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVGuideDataLoader.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVSettingsService.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVTaskManagerService.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVD3DShell.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\SetupWizard.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVWebServiceProxy.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009

R1 efbDisk;efbDisk; [x]
R2 Backup Scheduler;Backup Scheduler;c:\program files\NovaStor\NovaStor NovaBACKUP\DR\CBP\DCSchdlerSRVC.exe [2008-06-17 98304]
R3 ati2mpaa;ati2mpaa;c:\windows\system32\DRIVERS\ati2mpaa.sys [2001-08-17 281856]
R3 ATIVRVXX;ATI Rage Theatre Video (ATIRTCAP);c:\windows\system32\DRIVERS\atirtcap.sys [2001-08-17 49920]
R3 DDCCI;DDC/CI monitor;c:\windows\system32\DRIVERS\Moni2c.sys [2003-03-30 6494]
R3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-08-29 33752]
R3 zremote;zremote;c:\windows\system32\drivers\zremote.sys [2004-03-01 10368]
S0 amdagp10;AMD IG AGP Bus Filter;c:\windows\System32\DRIVERS\amdagp10.sys [2000-06-27 22994]
S0 dcsnap;dcsnap; [x]
S0 fasttrak;fasttrak;c:\windows\system32\DRIVERS\fasttrak.sys [2002-05-23 70656]
S1 DCDisk;DCDisk; [x]
S1 GhPciScan;GhostPciScanner;c:\program files\Symantec\Norton Ghost 2003\ghpciscan.sys [2003-12-17 5632]
S2 NsService;NovaStor NovaBACKUP Backup/Copy Engine;c:\program files\NovaStor\NovaStor NovaBACKUP\NsService.exe [2008-06-17 207936]
S2 Real time Backup Loader;Real time Backup Loader;c:\program files\NovaStor\NovaStor NovaBACKUP\DR\Fsloader.exe [2008-06-17 93248]
S3 4mmdat;4mmdat;c:\windows\system32\DRIVERS\4mmdat.sys [2008-04-13 12288]


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\Shell\AutoRun\command - H:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e2de2786-6cdd-11db-97eb-00045a68bf2f}]
\Shell\AutoRun\command - H:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder

2009-04-22 c:\windows\Tasks\Uninstall Expiration Reminder.job
- c:\windows\System32\OOBE\oobebaln.exe [2003-01-09 00:12]

2009-04-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-07-25 16:34]
.
- - - - ORPHANS REMOVED - - - -

ShellIconOverlayIdentifiers-{7D688A77-C613-11D0-999B-00C04FD655E1} - (no file)
HKCU-Run-LDM - \Program\BackWeb-8876480.exe
HKCU-Run-WPCycle.exe - (no file)


.
------- Supplementary Scan -------
.
uStart Page = hxxp://my.yahoo.com/index.html
mStart Page = hxxp://my.yahoo.com/index.html
IE: Download with GetRight - e:\program files\GetRight\GRdownload.htm
IE: E&xport to Microsoft Excel - e:\progra~1\MICROS~1\Office10\EXCEL.EXE/3000
IE: Open with GetRight Browser - e:\program files\GetRight\GRbrowse.htm
LSP: c:\windows\system32\lspcs.dll
Trusted Zone: aol.com\free
DPF: DirectAnimation Java Classes - file://c:\windows\SYSTEM\dajava.cab
DPF: Internet Explorer Classes for Java - file://c:\windows\SYSTEM\iejava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {40272BF7-4FF5-4D6F-9BAD-3C1D3CB32982} - hxxp://www.live365.com/players/p365vip.cab
DPF: {5197842F-0557-48AE-9552-7594F7C98F04} - hxxp://www.cybersitter.com/recovery/ocx/PasswordReset.ocx
FF - ProfilePath -
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-22 18:59
Windows 5.1.2600 Service Pack 3 FAT NTAPI

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Iomega Activity Disk2]
"ImagePath"="\"\""
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\$$$\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\$$$\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E8066BAB-BCF1-46CA-D8AA-605D8DE00F6D}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{210BD7C7-47ED-BBE9-95D0F9FAA3BD0E97}\{C5D4C247-F1D1-D183-A63FC2DFAAC29AA3}\{B55B3474-A2E6-F6F7-4AD088E6434601A2}*]
"KGHQ1WVPMWYCTK5FHYUB2KQRGA1"=hex:01,00,01,00,00,00,00,00,61,e9,6d,81,db,39,d8,
7a,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{945169D7-C27E-315B-97A3E6913A1C7622}\{06C63AB7-5C18-FA8E-E5D32118C99A5B59}\{F7BD6AFF-A45B-6FB8-BB91AB79C0A3DA53}*]
"KGHQ1WVPMWYCTK5FHYUB2KQRGA1"=hex:01,00,01,00,00,00,00,00,61,e9,6d,81,db,39,d8,
7a,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A73A7B6D-D5C7-2D01-6A3ED58A203D5FEA}\{958FE6C0-B367-4AD6-C310294BFC5DB709}\{E2E9EAF6-387C-4947-07B2C800F4ACC9F3}*]
"KGHQ1WVPMWYCTK5FHYUB2KQRGA1"=hex:01,00,01,00,00,00,00,00,61,e9,6d,81,db,39,d8,
7a,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BF11F383-757D-CF48-6D213AC2BB6130AD}\{12507465-D6D8-AFB1-97ED5D21195D77D5}\{90E47118-DD98-E716-1AABCD138C042D55}*]
"KGHQ1WVPMWYCTK5FHYUB2KQRGA1"=hex:01,00,01,00,00,00,00,00,61,e9,6d,81,db,39,d8,
7a,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F2F43379-985D-E7AE-2F5BD6B18999A07F}\{64C9A7C2-676E-3AEC-13AF6B278F65FD89}\{7B815B3C-162E-096A-EBEBEFD33B1AE416}*]
"KGHQ1WVPMWYCTK5FHYUB2KQRGA1"=hex:01,00,01,00,00,00,00,00,61,e9,6d,81,db,39,d8,
7a,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(628)
c:\windows\system32\lspcs.dll

- - - - - - - > 'explorer.exe'(1240)
c:\windows\system32\nview.dll
c:\windows\system32\nvwddi.dll
c:\program files\Windows Media Player\wmpband.dll
c:\windows\system32\lspcs.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Roxio\Easy Media Creator 7\Drag to Disc\Shellex.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\savedump.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\NovaStor\NovaStor NovaBACKUP\DR\CBP\DCSchdler.exe
c:\program files\Promise\FastTrak\FtrakSvc.exe
c:\program files\Symantec\Norton Ghost 2003\GhostStartService.exe
c:\progra~1\Iomega\System32\AppServices.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\nvsvc32.exe
c:\windows\System32\tcpsvcs.exe
c:\windows\System32\snmp.exe
c:\program files\Iomega\AutoDisk\ADService.exe
c:\program files\Internet Explorer\IEXPLORE.EXE
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Internet Explorer\IEXPLORE.EXE
.
**************************************************************************
.
Completion time: 2009-04-22 19:01 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-22 23:01

Pre-Run: 31,939,166,208 bytes free
Post-Run: 32,058,310,656 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

298 --- E O F --- 2009-03-15 07:03

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:13:06 PM, on 4/22/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\CBP\DCSchdler.exe
C:\Program Files\Promise\FastTrak\FtrakSvc.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\NovaStor\NovaStor NovaBACKUP\NsService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\Fsloader.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\PRISMSVR.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\cyb2k.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ezSP_Px.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.exe
C:\Program Files\TrayDay\TrayDay.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - E:\Program Files\GetRight\xx2gr.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\system32\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [C2K] C:\WINDOWS\cyb2k.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe
O4 - Startup: TrayDay.lnk = C:\Program Files\TrayDay\TrayDay.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Logitech Desktop Messenger.lnk = E:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: 2Wire Wireless Client.lnk = C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.exe
O8 - Extra context menu item: Download with GetRight - E:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Browser - E:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - http://www.net2phone.com/ (file missing)
O9 - Extra 'Tools' menuitem: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - http://www.net2phone.com/ (file missing)
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - E:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - E:\Program Files\ICQ\ICQ.exe
O9 - Extra button: Share in Hello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll
O9 - Extra 'Tools' menuitem: Share in H&ello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {16BF42FD-CA0A-4f48-819D-B0343254DD67} - file://C:\Program Files\UpromiseRemindU\System\Temp\upromise_script0.htm (file missing) (HKCU)
O16 - DPF: Yahoo! Checkers - http://download.games.yahoo.com/games/clients/y/kt0_x.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://gulllake.gospelcom.net/unsecure/other_media/views/ipixx.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {40272BF7-4FF5-4D6F-9BAD-3C1D3CB32982} (Live365PlayerVIP Class) - http://www.live365.com/players/p365vip.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www2.snapfish.com/SnapfishActivia.cab
O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} (Microsoft.WinRep) - https://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab
O16 - DPF: {5197842F-0557-48AE-9552-7594F7C98F04} (PWReset Control) - http://www.cybersitter.com/recovery/ocx/PasswordReset.ocx
O16 - DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} (Install Class) - http://updates.lifescapeinc.com/installers/pinstall/pinstall.cab
O16 - DPF: {712362BF-E411-4F43-99D2-EB15F80AF1DB} (MsneDiag Class) - http://entimg.msn.com/client/msnediag3518.cab
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - http://picture.vzw.com/activex/VerizonWirelessUploadControl.cab
O16 - DPF: {A662DA7E-CCB7-4743-B71A-D817F6D575DF} (Autodesk DWF Viewer Control) - http://www.autodesk.com/global/dwfviewer/installer/DwfViewerSetup.cab
O16 - DPF: {A7E092C3-692A-11D0-A7E5-08002B322F3B} (WebResponseAttachments Control) - https://webresponse.one.microsoft.com/oas/ActiveX/FileXfer.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} (MsnMusicAx Class) - http://entimg.msn.com/client/msnmusax3518.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Backup Scheduler - Unknown owner - C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\CBP\DCSchdlerSRVC.exe
O23 - Service: Promise FastTrak Log Service (FastTrakSvc) - Promise Technology Inc. - C:\Program Files\Promise\FastTrak\FtrakSvc.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NovaStor NovaBACKUP Backup/Copy Engine (NsService) - NovaStor - C:\Program Files\NovaStor\NovaStor NovaBACKUP\NsService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe
O23 - Service: Real time Backup Loader - Unknown owner - C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\Fsloader.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\supportsoft\bin\ssrc.exe
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe

--
End of file - 10980 bytes

proskoma
2009-04-23, 01:14
... I'm still getting multiple instances of iExplorer.exe in my task manager.

Blade81
2009-04-23, 19:43
Hi again,


Generate an Uninstall List

* Open HijackThis
* Click on Open Misc Tools Section
* Click on Open Uninstall Manager
* Click on Save list
* Save it to your Desktop
* Post it on your next reply.


Upload following files to

Start hjt, do a system scan, check (if found):
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

Close browsers and fix checked.


Open notepad and copy/paste the text in the quotebox below into it:



http://forums.spybot.info/showthread.php?t=47863&page=2

Collect::
c:\windows\system32\co32andlo.dat
c:\windows\system32\gapiyshe.dat
c:\windows\system32\cocoerrfo.dat
c:\windows\system32\orptofo.dat
c:\windows\system32\dllto32to.dat

Driver::
efbDisk
dcsnap
DCDisk

File::
C:\diskfile1
C:\logicinf.bin

RegLock::
[HKEY_USERS\$$$\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E8066BAB-BCF1-46CA-D8AA-605D8DE00F6D}*]

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{210BD7C7-47ED-BBE9-95D0F9FAA3BD0E97}\{C5D4C247-F1D1-D183-A63FC2DFAAC29AA3}\{B55B3474-A2E6-F6F7-4AD088E6434601A2}*]

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{945169D7-C27E-315B-97A3E6913A1C7622}\{06C63AB7-5C18-FA8E-E5D32118C99A5B59}\{F7BD6AFF-A45B-6FB8-BB91AB79C0A3DA53}*]

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A73A7B6D-D5C7-2D01-6A3ED58A203D5FEA}\{958FE6C0-B367-4AD6-C310294BFC5DB709}\{E2E9EAF6-387C-4947-07B2C800F4ACC9F3}*]

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BF11F383-757D-CF48-6D213AC2BB6130AD}\{12507465-D6D8-AFB1-97ED5D21195D77D5}\{90E47118-DD98-E716-1AABCD138C042D55}*]

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F2F43379-985D-E7AE-2F5BD6B18999A07F}\{64C9A7C2-676E-3AEC-13AF6B278F65FD89}\{7B815B3C-162E-096A-EBEBEFD33B1AE416}*]



Save this as
CFScript

A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.

http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

Close all browser windows and refering to the picture above, drag CFScript into ComboFix.exe. You will be asked to submit some samples. Please follow the given instructions.
Then post the resultant log.


Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.


Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update to the latest version...

Updating Java:

Download the latest version of Java Runtime Environment (JRE) 6 Update 13 (http://java.sun.com/javase/downloads/index.jsp).
Click the
Download
button to the right.
Select Windows on platform combobox and check the box that says:
Accept License Agreement. Click continue.

The page will refresh.
Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
Close any programs you may have running - especially your web browser.
Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
Check any item with Java Runtime Environment (JRE or J2SE) in the name.
Click the Remove or Change/Remove button.
Repeat as many times as necessary to remove each Java versions.
Reboot your computer once all Java components are removed.
Then from your desktop double-click on jre-6u13-windows-i586-p.exe to install the newest version. Uncheck MSN toolbar if it's offered there.


Download ATF (Atribune Temp File) CleanerĐ by Atribune (http://www.atribune.org/ccount/click.php?id=1) to your desktop.

Double-click ATF Cleaner.exe to open it

Under Main choose:
Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Prefetch
Java Cache
*The other boxes are optional*
Then click the Empty Selected button.

If you use Firefox:
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

If you use Opera:
Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Click Exit on the Main menu to close the program.


Please run an online scan with Kaspersky Online Scanner (http://www.kaspersky.com/virusscanner) as instructed in the screenshot here (http://i275.photobucket.com/albums/jj285/Bleeping/KAS/KAS9.gif). If you get a message that latest Java must be installed "enable" the Java add-ons in IE7. Do that using "manage add-ons" from the IE7 toolbar.


Post back its report, a fresh hjt log and above mentioned ComboFix resultant log.

proskoma
2009-04-24, 02:56
Followed instructions as posted. Combo fix ran a scan (including deleting a few files and rebooted the computer. The result was a STOP error. I tried rebooting three times including turning the machine off and on. I also attempted to boot into safe mode. Each time gave the following:


A problem has been detected and windows has been shut down to prevent damage to your computer.

If this is the first time you've seen this Stop error screen, restart your computer. If this screen appears again, follow these steps:

Check for viruses on your computer. Remove any newly installed hard drives or hard drive controllers. Check your hard drive to make sure it is properly configured and terminated. Run CHKDSK /F to check for hard drive corruption, and then restart your computer.

Technical information:

*** STOP: 0x0000007B (0xF789E528,0xc0000034,0x00000000,0x00000000)

Blade81
2009-04-24, 08:33
Hi

We need to enter recovery console. Select Microsoft Windows Recovery Console -option in boot menu

After logging onto the Recovery Console, type each of the lines (press enter after each):

CD ERDNT
BATCH CFRECOVERY.BAT
BATCH CF_UNDO.BAT

After that type EXIT to exit Recovery Console. See if you can reboot now.

proskoma
2009-04-24, 11:56
Choosing the recovery console option in the boot menu was not successful. Screen went black, HD ran intensivly for a few seconds and returned to the OS selection screen. Attempted repeated times with the same result. Safe mode and full boot continue to give the stop screen.

Booted from the XP install CD and chose console option. My main drive is built on a RAID driven by the motherboard. A directory listing of the C drive in the recovery console showed no files. Going to have to find the RAID driver disc (or download), reattach my floppy drive (hope it still works) and load that driver with the recovery console from the CD before continuing.

Nothing is ever easy.

Any suggestions would be appreciated.

RAID: Promise Technology MB Fast Trak 133 "lite" BIOS Version - is what I see during the boot process.

Blade81
2009-04-24, 13:06
Hi

RAID makes this more complicated. Do you have driver floppy around? If not, driver should be found on motherboard manufacturer's web site.

When recovery console loads you should immediately press F6 to run that RAID driver from floppy (like when installing Windows).

proskoma
2009-04-26, 04:56
Successfully booted into recovery console from XP installation CD loading driver for the RAID from a floppy.

CD ERDNT worked and the first batch file worked, but the second batch file didn't exist in the directory.

Booting into windows took longer but ultimatly still gave the blue STOP screen error... same as before.

Does it make any difference that the recovery console mounts my main windows drive as e instead of c because of the RAID?

Discovered something odd... the CFrecovery.bat file was generated 4/22 6:56pm, but my recovery point was saved 4/23 in the evening. There is a directory called subs which seems to have a series of files which have the right time stamp for my backup.... as do the files in autobackup\4-23-2009. Are the batch files generic files that could be copied from a floppy into the directory and executed (he asked hopefully...).

Blade81
2009-04-26, 12:02
Hi

I think the drive appears as drive e: cos recovery console was launched from cd. That shouldn't affect here.

After logging onto the Recovery Console, type each of the lines (press enter after each):
CD ERDNT
BATCH CFRECOVERY.BAT

Then go to subs folder by giving command:
CD SUBS

In that folder should be ERDNT.CON file. Run following command:
BATCH ERDNT.CON

Then type EXIT to restart the machine.

proskoma
2009-04-27, 04:26
The ERDNT.CON file had all references to the c drive in it... so I manually executed each command in the batch file substituting the e drive for the c drive and rebooted. Windows still gave me the error.

I then copied the ERDNT.CON file to another computer - edited the file to change all reference of the c drive to the e drive moved it back to the infected machine... and executed the batch.

Same result.

ERDNT seems to have created a daily back-up as there is a series of directories named Autobackup with successive dates. My thought was to try and work backwards through successive dates to see if I can get Windows to come back up. My fear is that ComboFix deleted something Windows wants (I remember seeing the dialog box mention a few files it deleted - 4 I think) and this process will be futile since those important files are gone.

However, I'm hopeful that we will still find a solution through this mess.

One other note - when this happened, I drug the script file you provided over the ComboFix.exe icon to execute it... the first message I received was that ComboFix had a new version available so I updated it. Then it said ComboFix was restarting and went through the scan that has rendered Windows unbootable. Is it possible that when it restarted, it didn't follow your script and just ran a normal diagnostic?

I don't know if that's helpful but wanted to provide you with as much detail as possible to try and find a solution.

Blade81
2009-04-27, 18:33
Hi

I don't think ComboFix update caused the issue there. Since those recovery steps didn't work I'm afraid there's no other possibility left than reformat. You could try to attach the drive to other system as slave drive to backup pictures, music and videos.

proskoma
2009-04-28, 12:50
Thanks for your assistance with this attempt. Please post your standard advise on proper protective configuration so I will have it for when I complete a new Windows installation.

Also - I'm fortunate to have multiple drives connected to the computer with many of my important files residing off the c drive. What procedure should I follow to make sure the malware isn't hiding in any of those files once I begin rebuilding?

Blade81
2009-04-28, 15:25
Hi

Please, find below some tips to keep system safer in future:

UPDATING WINDOWS AND INTERNET EXPLORER

IMPORTANT: You Need to Update Windows and Internet Explorer to protect your computer from the malware that is around on the Internet. Please go to the windows update site (http://windowsupdate.microsoft.com/) to get the critical updates.

If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.


Make your Internet Explorer more secure

This can be done by following these simple instructions:
From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialize and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt
When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.



The following are recommended third party programs that are designed to keep your computer clean. A link as well as a brief description is included with each item.


Download Adaware
Adaware is a free program. It scans for known spyware on your computer. These scans should be run at least once every two weeks. For more information, see this tutorial (http://www.bleepingcomputer.com/forums/index.php?showtutorial=48)
The program is available for download here (http://www.download.com/Ad-Aware-Anniversary-Edition/3000-8022_4-10045910.html)
Download Spybot
Spybot is a scanner like adaware. It scans for spyware and other malicious programs. It is important to have both Adaware and Spybot on your computer because each program provides unique detection and pretection measures. Spybot has preventitive tools that stop programs from even installing on your computer.
To see how to set this up as well as more spybot features, see here (http://www.bleepingcomputer.com/forums/index.php?showtutorial=43)
Spybot can be downloaded at this location (http://www.download.com/Spybot-Search-Destroy/3000-8022-10122137.html?part=dl-spybot&subj=dl&tag=but)

hosts file:
Every version of windows has a hosts file as part of them. In a very basic sense, they are used to locate webpages. We can customize a hosts file so that it blocks certain webpages. However, it can slow down certain computers. This is why using a hosts file is optional!!
Download it here (http://www.mvps.org/winhelp2002/hosts.htm). Make sure you read the instructions on how to install the hosts file. There is a good tutorial here (http://www.bleepingcomputer.com/forums/tutorial51.html)
If you decide to download the hosts file, the slowdown problems can usually be avoided by following these steps:
Click the start button (at the lower left hand corner of your screen) Click run In the dialog box, type services.msc hit enter, then locate dns client Highlight it, then double-click it. On the dropdown box, change the setting from automatic to manual. Click ok

Get Anti Virus Software and keep it updated - Most AVs will update automatically, but if not I would recommend making updating the AV the first job every time the PC is connected to the internet. An AV that is using defs that are seven days old is not going to be much protection. If you do not update your anti virus software then it will not be able to catch any of the new variants that may come out. Good free antivirus programs are:
Antivir (http://free-av.com/en/download/1/download_avira_antivir_personal__free_antivirus.html)
Avast! (http://www.avast.com/eng/download-avast-home.html)

Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. For more info, check this (http://www.bleepingcomputer.com/forums/tutorial60.html) webpage out.
If you don't have a 3rd party firewall or a router behind NAT then I recommend getting one. I recommend either Online Armor Free (http://www.tallemu.com/free-firewall-protection-software.html) or Comodo Firewall Pro (http://www.personalfirewall.comodo.com/download_firewall.html#fw3.0) (If you choose Comodo: Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and install firewall ONLY!).



Just a final reminder for you. I am trying to stress these two points.
UPDATE UPDATE UPDATE!!! Make sure you do this about every 1-2 weeks.
Make sure all of your security programs are up to date.
Run the spybot and adaware regularly. (Once or twice a week minimum.)
Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.




What procedure should I follow to make sure the malware isn't hiding in any of those files once I begin rebuilding?
You should scan your other drives with antivirus scanner. Also, running an online scan (with Kaspersky Online Scanner (http://www.kaspersky.com/virusscanner) for example) wouldn't make any harm.

proskoma
2009-05-06, 05:49
Used recovery panel to restore autobackup by ERUNT from back a little further in time and was able to get Windows to start. Carefully ran instructions to run ComboFix and got the blue screen stop error again. Restored again and skipped the ComboFix step.

Deleted all old installations of Java and installed the JRE6 Update 13 as instructed.

Downloaded ATF and cleaned up all temp files.

The Kaspersky Online Scanner will not run. I get a script error in the bottom left hand corner of IE... when I double click that I get the standard script error window, but with no detail and I have to close the window multiple times to get back to IE7.

I currently get a single extra copy of iexplorer.exe in the processes Window. If I "end process" that process, it takes longer to come back, but still comes back. AND Microsoft Money still will not run.

What's my next step? -- a new hjt log follows in the next post.

Here's the uninstall file:
123 Free Solitaire
1Click DVD to Divx Avi 2.12
2Wire Wireless Client
AccuChef
Active Disk
Actual Checkers 2000 R
Adaptec EZ-SCSI Standard Edition 5.0
Adobe After Effects 5.5
Adobe Atmosphere Player for Acrobat and Adobe Reader
Adobe Flash Player 10 ActiveX
Adobe Flash Player Plugin
Adobe GoLive 6.0
Adobe Illustrator 10.0.3
Adobe PageMaker 6.5
Adobe Photoshop 6.0
Adobe Photoshop 7.0
Adobe Reader 7.0.5 Language Support
Adobe Reader 7.1.0
Adobe SVG Viewer 3.0
Adobe Type Manager Deluxe 4.1
AdobeŪ PhotoshopŪ Album Starter Edition 3.2
AniRez
Apple Mobile Device Support
Apple Software Update
ATI Display Driver
ATI Multimedia Center
Autodesk DWF Viewer
AWSPS 4.02
Beyond TV DVD Burning Foundation
Beyond TV DVD Burning Foundation
Calculator Powertoy for Windows XP
Chessmaster 8000
Command & Conquer Generals
Command & Conquer Red Alert 2
Command & Conquer Tiberian Sun
Command && Conquer Red Alert 2 - Yuri's Revenge
Command and ConquerTM Generals Zero Hour
Cover Art Downloader v1.2
Critical Update for Windows Media Player 11 (KB959772)
CuteFTP 5.0 XP
dBpowerAMP Music Converter
DesignPro 5.0 Limited Edition
Desktop Architect
Dialog Box Assistant 1.01
DING!
Director 8 Shockwave Studio
DirectVobSub (remove only)
DivX Codec
DivX Converter
DivX Player
DivX Web Player
Doppler 10 Pinpoint Alert
DR-92 Manager
Elecard MPEG Player
Empire Earth
Enable S3 for USB Device
ERUNT 1.1j
Eudora
FastTrak RAID controller utility
FontLook
getPlus(R) for Adobe
GetRight
GoldLeo DVD Ripper 2.2
Hauppauge WinTV Scheduler
Hauppauge WinTV2000
Hauppauge WinTV-PVR 150 Drivers
Hello (remove only)
HijackThis 2.0.2
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
hp deskjet 840c series
hp deskjet 840c series (Remove only)
HTMLPad 2004 Pro v5.0
HyperCD
ICQ
IKEA HomePlanner Kitchen
InterVideo FilterSDK for Hauppauge
Iomega App Services
IomegaWare
iSofter DVD Ripper Platinum 3.0.2007.228
iTunes
J2SE Runtime Environment 5.0 Update 2
J2SE Runtime Environment 5.0 Update 4
J2SE Runtime Environment 5.0 Update 6
Java 2 Runtime Environment Standard Edition v1.3.1
Java 2 Runtime Environment, SE v1.4.2_06
Java(TM) 6 Update 2
Java(TM) 6 Update 3
Java(TM) 6 Update 5
Java(TM) 6 Update 7
Java(TM) SE Runtime Environment 6 Update 1
JMail
LiveUpdate 2.5 (Symantec Corporation)
Logitech Desktop Messenger
Logitech MouseWare 9.41 .1
Macromedia Dreamweaver 4
Macromedia Extension Manager
Macromedia Flash 5
Macromedia FreeHand 9
Macromedia Generator 2
Macromedia Shockwave Player
Malwarebytes' Anti-Malware
Media Cleaner Pro
Media Library Management Wizard
microKORG SoundEditor
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft .NET Framework 3.0
Microsoft .NET Framework 3.0
Microsoft Age of Empires II
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Data Access Components KB870669
Microsoft Interactive CD Sampler
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Money Plus
Microsoft Money Shared Libraries
Microsoft National Language Support Downlevel APIs
Microsoft Office XP Professional with FrontPage
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Windows Media Video 9 VCM
Microsoft Windows XP Video Decoder Checkup Utility
Microsoft Word 97 Time Mgmt Wizard Pack (Remove only)
Movavi Video Converter 6
Movie Maker Background Music Files
Movie Maker Sound Effects
Movie Maker Title Images
Mozilla Firefox (2.0.0.8)
MSN Entertainment Download Troubleshooter
MSN Music Assistant
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 6.0 Parser (KB933579)
Multimedia Card Reader
MusicmatchŪ Jukebox
Musicnotes Player V1.23.1 and Viewer
MySQL Connector/ODBC 3.51
Myst IV - Revelation
nanoPEG-Editor 2.2 Hauppauge Edition
Napster
NEC-Mitsubishi NaViSet
NetAccountability
Netflix Movie Viewer
Norton Ghost
NovaBACKUP
NovaBACKUP
NVIDIA Drivers
OpenMG Limited Patch 3.4-04-16-16-01
OpenMG Secure Module 3.4.01
Opera 9.10
Palm Desktop
Personal Color Viewer 2.0
Plus! MP3 Audio Converter LE
PolderbitS Sound Recorder and Editor
QTam Bitmap to Icon 3.5
QuickTime
Ray Dream Studio v5.0
Real Alternative 1.52 Lite
REALmagic Hollywood Plus
Red Alert Windows 95
Roxio Burn Engine
Roxio Easy Media Creator 7
Safari
SCRABBLE
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953155)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Shockwave
Sid Meier's Alpha Centauri
SimCity 3000
SnapStream Beyond TV 4.6.1
SnapStream Firefly Mini 1.0.2
Solid Oak Software WhatsMyDNS 1.8.2.23
Sonic CinePlayer MPEG Combo Pack
Sound Blaster PCI128
Spybot - Search & Destroy
SuperDVD Player V4.0
SureThing CD Labeler 4 SE
Ten Thumbs 4.3
Ten Thumbs Typing Tutor
TPP Storage Class Driver
TrayDay
TWC Customer Controls
Tweaki...for Power Users
Tweakui Powertoy for Windows XP
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
USB 2.0 Host Controller Driver
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
Visual Studio 2005 Redist Package
VNC Free Edition 4.1.1
WavePad Uninstall
Westwood Shared Internet Components
Windows Communication Foundation
Windows Genuine Advantage v1.3.0254.0
Windows Imaging Component
Windows Media Bonus Pack for Windows XP
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows Media Player Playlist Import to Excel Wizard
Windows Media Player Skin Importer
Windows Media Player Tray Control
Windows Presentation Foundation
Windows Workflow Foundation
Windows XP Service Pack 3
WinRAR archiver
WinZip
WordPerfect Office 2002
WordPerfect Office 2002
Wtcc II
XviD MPEG-4 Video Codec

proskoma
2009-05-06, 05:50
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:50:00 PM, on 5/5/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\CBP\DCSchdler.exe
C:\Program Files\Promise\FastTrak\FtrakSvc.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\NovaStor\NovaStor NovaBACKUP\NsService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\Fsloader.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\PRISMSVR.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ezSP_Px.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.exe
C:\Program Files\TrayDay\TrayDay.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - E:\Program Files\GetRight\xx2gr.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\system32\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [C2K] C:\WINDOWS\cyb2k.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe
O4 - Startup: TrayDay.lnk = C:\Program Files\TrayDay\TrayDay.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Logitech Desktop Messenger.lnk = E:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: 2Wire Wireless Client.lnk = C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.exe
O9 - Extra button: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - http://www.net2phone.com/ (file missing)
O9 - Extra 'Tools' menuitem: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - http://www.net2phone.com/ (file missing)
O9 - Extra button: Share in Hello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll
O9 - Extra 'Tools' menuitem: Share in H&ello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {16BF42FD-CA0A-4f48-819D-B0343254DD67} - file://C:\Program Files\UpromiseRemindU\System\Temp\upromise_script0.htm (file missing) (HKCU)
O16 - DPF: Yahoo! Checkers - http://download.games.yahoo.com/games/clients/y/kt0_x.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://gulllake.gospelcom.net/unsecure/other_media/views/ipixx.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {40272BF7-4FF5-4D6F-9BAD-3C1D3CB32982} (Live365PlayerVIP Class) - http://www.live365.com/players/p365vip.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www2.snapfish.com/SnapfishActivia.cab
O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} (Microsoft.WinRep) - https://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab
O16 - DPF: {5197842F-0557-48AE-9552-7594F7C98F04} (PWReset Control) - http://www.cybersitter.com/recovery/ocx/PasswordReset.ocx
O16 - DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} (Install Class) - http://updates.lifescapeinc.com/installers/pinstall/pinstall.cab
O16 - DPF: {712362BF-E411-4F43-99D2-EB15F80AF1DB} (MsneDiag Class) - http://entimg.msn.com/client/msnediag3518.cab
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - http://picture.vzw.com/activex/VerizonWirelessUploadControl.cab
O16 - DPF: {9DBAFCCF-592F-FFFF-FFFF-00608CEC297C} -
O16 - DPF: {A662DA7E-CCB7-4743-B71A-D817F6D575DF} (Autodesk DWF Viewer Control) - http://www.autodesk.com/global/dwfviewer/installer/DwfViewerSetup.cab
O16 - DPF: {A7E092C3-692A-11D0-A7E5-08002B322F3B} (WebResponseAttachments Control) - https://webresponse.one.microsoft.com/oas/ActiveX/FileXfer.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} (MsnMusicAx Class) - http://entimg.msn.com/client/msnmusax3518.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Backup Scheduler - Unknown owner - C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\CBP\DCSchdlerSRVC.exe
O23 - Service: Promise FastTrak Log Service (FastTrakSvc) - Promise Technology Inc. - C:\Program Files\Promise\FastTrak\FtrakSvc.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NovaStor NovaBACKUP Backup/Copy Engine (NsService) - NovaStor - C:\Program Files\NovaStor\NovaStor NovaBACKUP\NsService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe
O23 - Service: Real time Backup Loader - Unknown owner - C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\Fsloader.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\supportsoft\bin\ssrc.exe
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe

--
End of file - 11132 bytes

Blade81
2009-05-06, 15:03
Hi

I assume that uninstall list was taken before all old Java removes etc. Is that right?

Start hjt, do a system scan, check (if found):
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

Close browsers and fix checked.



AND Microsoft Money still will not run.
Can't recall if this was mentioned earlier. Do you get any error message?


Please try download and run DDS. Post back dds.txt contents.

proskoma
2009-05-07, 00:47
Yes - uninstall list was generated before JAVA was removed.

hjt can not remove:

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

The rest of the lines deleted successfully.

Microsoft Money says:

Error - Shutting down...
Money has experienced a problem and cannot continue.
If you are running low on memory, try closing some programs and running Money again.

Memory is not an issue so I can't explain the error.

Here's the DDS log - please note, I uninstalled AVG during this process and wanted to get protection going so this didn't get any worse - so I installed avast.


DDS (Ver_09-03-16.01) - FAT32x86
Run by David Wilson at 18:41:18.01 on Wed 05/06/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1535.1134 [GMT -4:00]

AV: avast! antivirus 4.8.1335 [VPS 090506-0] *On-access scanning enabled* (Updated)

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\CBP\DCSchdler.exe
C:\Program Files\Promise\FastTrak\FtrakSvc.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\NovaStor\NovaStor NovaBACKUP\NsService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\Fsloader.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\PRISMSVR.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ezSP_Px.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.exe
C:\Program Files\TrayDay\TrayDay.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\David Wilson\Desktop\dds.scr

============== Pseudo HJT Report ===============

BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: bho2gr Class: {31ff080d-12a3-439a-a2ef-4ba95a3148e8} - e:\program files\getright\xx2gr.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
TB: Plaxo: {81ca3009-6200-4a6d-93c6-f1e9a6821c7f} -
TB: {724D43A0-0D85-11D4-9908-00400523E39A} - No File
TB: {06E58E5E-F8CB-4049-991E-A41C03BD419E} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [LDM] \Program\BackWeb-8876480.exe
mRun: [PRISMSVR.EXE] "c:\windows\system32\PRISMSVR.EXE" /APPLY
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [nwiz] nwiz.exe /install
mRun: [ezShieldProtector for Px] c:\windows\system32\ezSP_Px.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [C2K] c:\windows\cyb2k.exe
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
StartupFolder: c:\docume~1\davidw~1\startm~1\programs\startup\trayday.lnk - c:\program files\trayday\TrayDay.exe
StartupFolder: c:\docume~1\davidw~1\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - e:\program files\logitech\desktop messenger\8876480\program\LDMConf.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\2wirew~1.lnk - c:\program files\2wire 802.11g wireless\PRISMCFG.exe
uPolicies-explorer: NoFavoritesMenu = 1 (0x1)
dPolicies-explorer: NoFavoritesMenu = 1 (0x1)
IE: {4B30061A-5B39-11D3-80F8-0090276F843F} - http://www.net2phone.com/
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - c:\program files\hello\PicasaCapture.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: DirectAnimation Java Classes - file://c:\windows\system\dajava.cab
DPF: Internet Explorer Classes for Java - file://c:\windows\system\iejava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: Yahoo! Checkers - hxxp://download.games.yahoo.com/games/clients/y/kt0_x.cab
DPF: Yahoo! Chess - hxxp://download.yahoo.com/games/clients/y/cr1_x.cab
DPF: Yahoo! Hearts - hxxp://download.yahoo.com/games/clients/y/hr1_x.cab
DPF: Yahoo! Pool 2 - hxxp://download.yahoo.com/games/clients/y/por9_x.cab
DPF: {00000075-0000-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/voxmsdec.CAB
DPF: {00000160-0000-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/msaudio.cab
DPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxp://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} - hxxp://gulllake.gospelcom.net/unsecure/other_media/views/ipixx.cab
DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} - hxxp://www.musicnotes.com/download/mnviewer.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\yinsthelper.dll
DPF: {31564D57-0000-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/wmvax.cab
DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
DPF: {40272BF7-4FF5-4D6F-9BAD-3C1D3CB32982} - hxxp://www.live365.com/players/p365vip.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www2.snapfish.com/SnapfishActivia.cab
DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} - hxxps://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab
DPF: {5197842F-0557-48AE-9552-7594F7C98F04} - hxxp://www.cybersitter.com/recovery/ocx/PasswordReset.ocx
DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} - hxxp://updates.lifescapeinc.com/installers/pinstall/pinstall.cab
DPF: {712362BF-E411-4F43-99D2-EB15F80AF1DB} - hxxp://entimg.msn.com/client/msnediag3518.cab
DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} - hxxp://picture.vzw.com/activex/VerizonWirelessUploadControl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {924C1588-90C3-4910-B6CA-D57A1C0418FE} - hxxp://download.yahoo.com/dl/bookmarks/ybconvfav030408.cab
DPF: {94B82441-A413-4E43-8422-D49930E69764} - hxxp://rtc.webresponse.one.microsoft.com/media/xp/TLIEFlash.CAB
DPF: {9DBAFCCF-592F-FFFF-FFFF-00608CEC297C}
DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38079.8121527778
DPF: {A662DA7E-CCB7-4743-B71A-D817F6D575DF} - hxxp://www.autodesk.com/global/dwfviewer/installer/DwfViewerSetup.cab
DPF: {A7E092C3-692A-11D0-A7E5-08002B322F3B} - hxxps://webresponse.one.microsoft.com/oas/ActiveX/FileXfer.cab
DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - hxxp://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} - hxxp://support.f-secure.com/ols/fscax.cab
DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.4.0/jinstall-1_4_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} - hxxp://www.live365.com/players/play365.cab
DPF: {CEBC955E-58AF-11D2-A30A-00A0C903492B} - hxxp://windowsupdate.microsoft.com/R848/V31Controls/x86/w98/en/actsetup.cab
DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - hxxp://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - hxxp://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} - hxxp://entimg.msn.com/client/msnmusax3518.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Eudora's Shell Extension: {edb0e980-90bd-11d4-8599-0008c7d3b6f8} - e:\program files\eudora\EUSHLEXT.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\davidw~1\applic~1\mozilla\firefox\profiles\5nzx41m4.default\
FF - prefs.js: browser.search.selectedEngine - Google

============= SERVICES / DRIVERS ===============

R0 amdagp10;AMD IG AGP Bus Filter;c:\windows\system32\drivers\amdagp10.sys [2003-3-25 22994]
R0 dcsnap;dcsnap;c:\windows\system32\drivers\dcsnap.sys [2008-10-11 77472]
R0 fasttrak;fasttrak;c:\windows\system32\drivers\Fasttrak.sys [2005-1-14 70656]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-5-6 114768]
R1 Cinemsup;Cinemsup;c:\windows\system32\drivers\cinemsup.sys [2002-7-19 6656]
R1 DCDisk;DCDisk;c:\windows\system32\drivers\DCDisk.sys [2008-10-11 155648]
R1 GhPciScan;GhostPciScanner;c:\program files\symantec\norton ghost 2003\GhPciScan.sys [2003-12-17 5632]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-5-6 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-5-6 138680]
R2 Iprip;RIP Listener;c:\windows\system32\svchost.exe -k netsvcs [2001-8-23 14336]
R2 NsService;NovaStor NovaBACKUP Backup/Copy Engine;c:\program files\novastor\novastor novabackup\NsService.exe [2008-6-17 207936]
R2 Real time Backup Loader;Real time Backup Loader;c:\program files\novastor\novastor novabackup\dr\FsLoader.exe [2008-10-11 93248]
R3 4mmdat;4mmdat;c:\windows\system32\drivers\4mmdat.sys [2001-8-17 12288]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-5-6 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-5-6 352920]
S1 efbDisk;efbDisk; [x]
S2 Backup Scheduler;Backup Scheduler;c:\program files\novastor\novastor novabackup\dr\cbp\DCSchdlerSRVC.exe [2008-10-11 98304]
S3 ati2mpaa;ati2mpaa;c:\windows\system32\drivers\ati2mpaa.sys [2002-3-23 281856]
S3 ATIVRVXX;ATI Rage Theatre Video (ATIRTCAP);c:\windows\system32\drivers\atirtcap.sys [2002-3-23 49920]
S3 DDCCI;DDC/CI monitor;c:\windows\system32\drivers\Moni2c.sys [2003-3-30 6494]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\nos\bin\getPlus_HelperSvc.exe [2008-10-4 33752]
S3 hcwPVRP2;Hauppauge WinTV PVR PCI II (Encoder);c:\windows\system32\drivers\hcwPVRP2.sys [2005-5-22 814464]
S3 zremote;zremote;c:\windows\system32\drivers\zremote.sys [2005-5-22 10368]

=============== Created Last 30 ================

2009-05-06 00:03 147,100 a---h--- c:\windows\system32\mlfcache.dat
2009-05-05 22:38 410,984 a------- c:\windows\system32\deploytk.dll
2009-05-05 22:38 73,728 a------- c:\windows\system32\javacpl.cpl
2009-05-05 22:27 0 a------- c:\windows\system32\REN33.tmp
2009-05-05 22:27 0 a------- c:\windows\system32\REN32.tmp
2009-05-05 22:16 652 a------- c:\windows\system32\snetfil.dll
2009-05-05 22:16 540 a------- c:\windows\system32\srchfrgn.dll
2009-05-05 22:16 258 a------- c:\windows\system32\srchout.dll
2009-05-05 22:16 306 a------- c:\windows\system32\picsfil.dll
2009-05-05 22:16 194 a------- c:\windows\system32\igefil.dll
2009-05-05 22:16 116 a------- c:\windows\system32\nfil.dll
2009-05-05 22:16 34 a------- c:\windows\system32\macfil.dll
2009-05-05 22:16 18 a------- c:\windows\system32\lastupdate.dll
2009-05-05 22:16 400 a------- c:\windows\system32\bsnlst.dll
2009-05-05 22:16 100 a------- c:\windows\system32\bnrfil.dll
2009-05-05 22:11 2,709 a------- c:\windows\system32\gibbebx.dat
2009-05-05 22:10 1,024 ----h--- C:\diskfile1
2009-05-05 22:10 16,384 ----h--- C:\logicinf.bin
2009-05-05 22:01 60,416 a------- c:\windows\system32\drivers\Combo-Fix.sys
2009-05-05 21:58 389,120 a------- c:\windows\system32\CF11739.exe
2009-05-05 21:58 <DIR> --d----- C:\ComboFix
2009-05-05 21:58 389,120 a------- c:\windows\system32\CF11674.exe
2009-05-05 21:57 389,120 a------- c:\windows\system32\CF11570.exe
2009-05-05 21:53 2,709 a------- c:\windows\system32\dllgidoor.dat
2009-04-23 20:40 389,120 a------- c:\windows\system32\CF18599.exe
2009-04-23 20:39 389,120 a------- c:\windows\system32\CF18413.exe
2009-04-22 18:53 <DIR> a-dshr-- C:\cmdcons
2009-04-22 18:52 161,792 a------- c:\windows\SWREG.exe
2009-04-22 18:52 98,816 a------- c:\windows\sed.exe
2009-04-19 18:34 360,021 a------- C:\something.scr
2009-04-18 00:21 <DIR> --d----- c:\program files\Spybot - Search & Destroy
2009-04-18 00:21 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-04-17 21:04 <DIR> --d----- c:\docume~1\davidw~1\applic~1\Malwarebytes
2009-04-17 21:04 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-04-17 21:04 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-17 21:04 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-04-17 21:04 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-04-17 19:53 66 a------- c:\windows\wininit.ini
2009-04-17 08:22 <DIR> --d----- C:\!KillBox
2009-04-16 21:00 <DIR> --d----- c:\docume~1\alluse~1\applic~1\{A21E413E-98CC-4ABB-9843-E6AA4F456F61}
2009-04-14 09:44 <DIR> --d----- C:\fixwareout
2009-04-14 09:40 <DIR> --d----- c:\program files\Trend Micro
2009-04-13 21:09 <DIR> --d----- c:\program files\AVG
2009-04-13 21:09 <DIR> --d----- c:\docume~1\alluse~1\applic~1\avg8

==================== Find3M ====================

2009-04-22 19:04 5,880 a------- c:\windows\system32\wfileu.drv
2009-02-09 07:13 1,846,784 -------- c:\windows\system32\win32k.sys
2009-02-09 07:13 1,846,784 -------- c:\windows\system32\dllcache\win32k.sys
2008-12-16 19:23 726,008 a------- c:\documents and settings\david wilson\gotomypc_438.exe
2008-11-06 12:33 726,008 a------- c:\documents and settings\david wilson\gotomypc_437.exe
2001-11-06 00:23 266 ---sh--- c:\program files\desktop.ini
2001-11-06 00:23 11,079 ----h--- c:\program files\folder.htt
2001-01-19 12:04 21,841 a------- c:\program files\common files\tppupd2k.dll
2001-01-19 11:04 21,329 -------- c:\program files\common files\tppupd98.dll
2008-10-04 15:44 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008100420081005\index.dat
2001-11-13 10:18 8 ---sh--- c:\windows\all users\drm\pdrm.dat

============= FINISH: 18:41:57.28 ===============

Blade81
2009-05-07, 18:12
hjt can not remove:

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

The rest of the lines deleted successfully.
Hi

Those are not malicious so we can leave them there :)



Microsoft Money says:

Error - Shutting down...
Money has experienced a problem and cannot continue.
If you are running low on memory, try closing some programs and running Money again.
Could you try to reinstall MS Money? It's possible that infection has harmed it.

proskoma
2009-05-08, 04:12
New/continued symptoms:

1. Continued instance of IEXPLORE.EXE process in task manager - even when program is not running.

2. Executing commands in My Computer window causes Explorer.exe to re-start and triggers the execution of multiple instances of IEXPLORE.EXE. I can not copy and paste or drag files between folders without this happening. (Does windows XP use IEXPLORE to navigate folders??)

3. When typing in a web address, about half the time I get a white screen with the message (your explorer window is blocking attempts to redirect, please click here). If I don't click, the site I want eventually opens... if I do click, I end up somewhere else.

4. Uninstalling and then re-installing Money did not fix the problem with that program.

Blade81
2009-05-08, 16:33
Hi

Let's get some more info and after that run ComboFix again.

Download GMER (http://www.gmer.net/gmer.zip) and save it your desktop:
Extract it to your desktop and double-click GMER.exe
Click rootkit-tab and then scan.
Don't check
Show All
box while scanning in progress!
When scanning is ready, click Copy.
This copies log to clipboard
Post log in your reply.


Please run ComboFix normally by double clicking it (let it update if asked for a permission). Post back its log & a fresh dds.txt log.

proskoma
2009-05-13, 14:09
GMER ran successfully... log follows... but after a ComboFix scan got the blue screen of death again. Getting good at restore. At next available moment I'm planning to run ComboFix again and try to get a list of the .dll files it says it is deleating.

Note... though the subs folder under erdnt is the newest recovery file, it also results in a stop error. have to use a slightly older one. does this make sense?

GMER 1.0.15.14972 - http://www.gmer.net
Rootkit scan 2009-05-08 19:26:43
Windows 5.1.2600 Service Pack 3


---- System - GMER 1.0.15 ----

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xAC1306B8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xAC130574]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xAC130A52]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xAC13014C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xAC13064E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xAC13008C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xAC1300F0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xAC13076E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xAC13072E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xAC1308AE]

---- User code sections - GMER 1.0.15 ----

.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] USER32.dll!TranslateMessage 7E418BF6 6 Bytes PUSH 02C01430; RET
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 42F0F341 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] USER32.dll!DefWindowProcA 7E42C17E 6 Bytes PUSH 02C01770; RET
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 430A187F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 430A1800 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 430A1844 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 430A178C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 430A17C6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 430A18BA C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 42F316F6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] WININET.dll!InternetCloseHandle 7805DA59 6 Bytes PUSH 02BFFB38; RET
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] WININET.dll!HttpOpenRequestA 78064341 6 Bytes CALL 3B090335
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] WININET.dll!InternetConnectA 7806499A 6 Bytes PUSH 02BFED7C; RET
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] WININET.dll!InternetReadFile 7806ABB4 6 Bytes PUSH 02BFF2A8; RET
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] WININET.dll!InternetQueryDataAvailable 7806ADF5 6 Bytes PUSH 02BFF810; RET
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] WININET.dll!HttpSendRequestA 7806CD40 6 Bytes PUSH 02C00B84; RET
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[1844] WININET.dll!HttpSendRequestW 78080825 6 Bytes PUSH 02C00648; RET

---- User IAT/EAT - GMER 1.0.15 ----

IAT C:\WINDOWS\system32\services.exe[616] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00380002
IAT C:\WINDOWS\system32\services.exe[616] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 00380000

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)

---- Registry - GMER 1.0.15 ----

Reg HKLM\SOFTWARE\Classes\CLSID\{210BD7C7-47ED-BBE9-95D0F9FAA3BD0E97}\{C5D4C247-F1D1-D183-A63FC2DFAAC29AA3}\{B55B3474-A2E6-F6F7-4AD088E6434601A2}
Reg HKLM\SOFTWARE\Classes\CLSID\{210BD7C7-47ED-BBE9-95D0F9FAA3BD0E97}\{C5D4C247-F1D1-D183-A63FC2DFAAC29AA3}\{B55B3474-A2E6-F6F7-4AD088E6434601A2}@KGHQ1WVPMWYCTK5FHYUB2KQRGA1 0x01 0x00 0x01 0x00 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{945169D7-C27E-315B-97A3E6913A1C7622}\{06C63AB7-5C18-FA8E-E5D32118C99A5B59}\{F7BD6AFF-A45B-6FB8-BB91AB79C0A3DA53}
Reg HKLM\SOFTWARE\Classes\CLSID\{945169D7-C27E-315B-97A3E6913A1C7622}\{06C63AB7-5C18-FA8E-E5D32118C99A5B59}\{F7BD6AFF-A45B-6FB8-BB91AB79C0A3DA53}@KGHQ1WVPMWYCTK5FHYUB2KQRGA1 0x01 0x00 0x01 0x00 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{A73A7B6D-D5C7-2D01-6A3ED58A203D5FEA}\{958FE6C0-B367-4AD6-C310294BFC5DB709}\{E2E9EAF6-387C-4947-07B2C800F4ACC9F3}
Reg HKLM\SOFTWARE\Classes\CLSID\{A73A7B6D-D5C7-2D01-6A3ED58A203D5FEA}\{958FE6C0-B367-4AD6-C310294BFC5DB709}\{E2E9EAF6-387C-4947-07B2C800F4ACC9F3}@KGHQ1WVPMWYCTK5FHYUB2KQRGA1 0x01 0x00 0x01 0x00 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{BF11F383-757D-CF48-6D213AC2BB6130AD}\{12507465-D6D8-AFB1-97ED5D21195D77D5}\{90E47118-DD98-E716-1AABCD138C042D55}
Reg HKLM\SOFTWARE\Classes\CLSID\{BF11F383-757D-CF48-6D213AC2BB6130AD}\{12507465-D6D8-AFB1-97ED5D21195D77D5}\{90E47118-DD98-E716-1AABCD138C042D55}@KGHQ1WVPMWYCTK5FHYUB2KQRGA1 0x01 0x00 0x01 0x00 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{F2F43379-985D-E7AE-2F5BD6B18999A07F}\{64C9A7C2-676E-3AEC-13AF6B278F65FD89}\{7B815B3C-162E-096A-EBEBEFD33B1AE416}
Reg HKLM\SOFTWARE\Classes\CLSID\{F2F43379-985D-E7AE-2F5BD6B18999A07F}\{64C9A7C2-676E-3AEC-13AF6B278F65FD89}\{7B815B3C-162E-096A-EBEBEFD33B1AE416}@KGHQ1WVPMWYCTK5FHYUB2KQRGA1 0x01 0x00 0x01 0x00 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E8066BAB-BCF1-46CA-D8AA-605D8DE00F6D}

---- EOF - GMER 1.0.15 ----

Blade81
2009-05-13, 17:11
Hi

Did you run ComboFix without that cfscript? It's important that you don't use the script but run normally by double-clicking ComboFix.exe file.

proskoma
2009-05-14, 13:15
Yes - did not use the script... just double clicked the icon.

Blade81
2009-05-14, 15:58
Well, run ComboFix again and try to write down item names seen there during the run.

proskoma
2009-05-15, 05:17
Ran ComboFix - did not get any indication of deleted files.
Got Stop Error
Restored
Ran ComboFix - did not get any indication of deleted files.
Got Stop Error
Rebooted and chose last know settings during bootprocess.
Successfully booted into Windows. Here is the ComboFix log

ComboFix 09-05-14.03 - David Wilson 05/14/2009 22:42.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1535.1135 [GMT -4:00]
Running from: c:\documents and settings\David Wilson\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090514-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\diskfile1
C:\logicinf.bin
c:\windows\system32\bnrfil.dll
c:\windows\system32\bsnlst.dll
c:\windows\system32\co32andlo.dat
c:\windows\system32\cocoerrfo.dat
c:\windows\system32\dllto32to.dat
c:\windows\system32\gapiyshe.dat
c:\windows\system32\igefil.dll
c:\windows\system32\lastupdate.dll
c:\windows\system32\macfil.dll
c:\windows\system32\nfil.dll
c:\windows\system32\orptofo.dat
c:\windows\system32\picsfil.dll
c:\windows\system32\snetfil.dll
c:\windows\system32\srchfrgn.dll
c:\windows\system32\srchout.dll
c:\windows\system32\unicodem.exe
c:\windows\system32\usrgfil.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_DCDISK
-------\Service_DCDisk
-------\Service_dcsnap
-------\Service_efbDisk
-------\Legacy_DCDISK
-------\Legacy_IPRIP
-------\Service_DCDisk
-------\Service_dcsnap
-------\Service_efbDisk
-------\Service_Iprip
-------\Legacy_DCDISK
-------\Legacy_IDSVCSPTISRV
-------\Legacy_IPRIP
-------\Service_DCDisk
-------\Service_dcsnap
-------\Service_efbDisk
-------\Service_idsvcSPTISRV
-------\Service_Iprip
-------\Legacy_DCDISK
-------\Legacy_IDSVCSPTISRV
-------\Legacy_IPRIP
-------\Service_DCDisk
-------\Service_dcsnap
-------\Service_efbDisk
-------\Service_idsvcSPTISRV
-------\Service_Iprip
-------\Legacy_DCDISK
-------\Legacy_IDSVCSPTISRV
-------\Legacy_IPRIP
-------\Service_DCDisk
-------\Service_dcsnap
-------\Service_efbDisk
-------\Service_idsvcSPTISRV
-------\Service_Iprip


((((((((((((((((((((((((( Files Created from 2009-04-15 to 2009-05-15 )))))))))))))))))))))))))))))))
.

2009-05-15 02:06 . 2009-05-15 02:06 -------- d-----w c:\documents and settings\David Wilson\Local Settings\Application Data\PCHealth
2009-05-13 11:50 . 2009-05-13 11:50 -------- d-sh--w C:\FOUND.043
2009-05-08 15:01 . 2009-05-08 15:01 0 --s-a-w c:\windows\system32\148114617.dat
2009-05-08 02:11 . 2009-05-08 02:11 -------- d-----w c:\program files\Microsoft Money Plus
2009-05-06 04:10 . 2009-05-06 04:10 -------- d-----w c:\program files\Alwil Software
2009-05-06 04:03 . 2009-05-06 04:03 147100 ---ha-w c:\windows\system32\mlfcache.dat
2009-05-06 02:38 . 2009-05-06 02:38 410984 ----a-w c:\windows\system32\deploytk.dll
2009-05-06 02:11 . 2009-05-06 02:11 2709 ----a-w c:\windows\system32\gibbebx.dat
2009-05-06 02:10 . 2009-05-15 03:07 15360 ---h--w C:\logicinf.bin
2009-05-06 01:53 . 2009-05-06 01:53 2709 ----a-w c:\windows\system32\dllgidoor.dat
2009-04-20 23:43 . 2009-04-20 23:43 -------- d-----w C:\rsit
2009-04-19 22:34 . 2009-04-19 22:29 360021 ----a-w C:\something.scr
2009-04-18 18:49 . 2009-04-18 18:49 -------- d-----w c:\program files\ERUNT
2009-04-18 14:09 . 2009-04-18 14:09 -------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2009-04-18 04:21 . 2009-04-18 04:21 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-04-18 04:21 . 2009-04-18 04:21 -------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-04-18 01:04 . 2009-04-18 01:04 -------- d-----w c:\documents and settings\David Wilson\Application Data\Malwarebytes
2009-04-18 01:04 . 2009-04-06 19:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-04-18 01:04 . 2009-04-06 19:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-18 01:04 . 2009-04-18 01:04 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-18 01:04 . 2009-04-18 01:04 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-04-17 12:22 . 2009-04-17 12:22 -------- d-----w C:\!KillBox
2009-04-17 01:53 . 2009-04-17 01:53 184304 ----a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-17 01:42 . 2009-04-17 01:42 -------- d-----w c:\documents and settings\Administrator\Local Settings\Application Data\Seven Zip
2009-04-17 01:28 . 2009-04-17 01:28 -------- d-----w c:\documents and settings\Administrator\Local Settings\Application Data\Apple Computer
2009-04-17 01:28 . 2009-04-17 01:28 -------- d-----w c:\documents and settings\Administrator\Application Data\Apple Computer
2009-04-17 01:19 . 2009-04-17 01:19 -------- d-----w c:\documents and settings\Guest\Local Settings\Application Data\Seven Zip
2009-04-17 01:18 . 2009-04-17 01:18 -------- d-----w c:\documents and settings\Guest\Application Data\Apple Computer
2009-04-17 01:18 . 2009-04-17 01:18 -------- d-----w c:\documents and settings\Guest\Local Settings\Application Data\Mozilla
2009-04-17 01:00 . 2009-04-17 01:00 -------- d-----w c:\documents and settings\All Users\Application Data\{A21E413E-98CC-4ABB-9843-E6AA4F456F61}
2009-04-17 00:59 . 2009-04-17 00:59 -------- d-----w c:\documents and settings\David Wilson\Local Settings\Application Data\Seven Zip

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-06 02:27 . 2009-05-06 02:27 0 ----a-w c:\windows\system32\REN33.tmp
2009-05-06 02:27 . 2009-05-06 02:27 0 ----a-w c:\windows\system32\REN32.tmp
2009-05-06 01:54 . 2002-08-14 03:28 39 ----a-w c:\windows\liccyval.dat
2009-04-22 23:05 . 2003-09-27 00:07 1222 ----a-w c:\windows\system32\usrfil.dll
2009-04-22 23:04 . 2002-08-14 03:28 5880 ----a-w c:\windows\system32\wfileu.drv
2009-04-14 13:40 . 2009-04-14 13:40 -------- d-----w c:\program files\Trend Micro
2009-04-14 01:09 . 2009-04-14 01:09 -------- d-----w c:\program files\AVG
2001-11-06 04:23 . 2000-05-13 03:43 266 --sh--w c:\program files\desktop.ini
2001-11-06 04:23 . 2000-05-13 03:43 11079 ---h--w c:\program files\folder.htt
2001-01-19 16:04 . 2005-02-06 20:12 21841 ----a-w c:\program files\Common Files\tppupd2k.dll
2001-01-19 15:04 . 2002-02-24 01:38 21329 ------w c:\program files\Common Files\tppupd98.dll
2007-10-09 05:33 . 2005-04-28 02:53 66408 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2007-10-09 05:33 . 2005-04-28 02:53 54112 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2007-10-09 05:33 . 2007-10-20 14:31 34688 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2007-10-09 05:33 . 2007-10-20 14:31 46456 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2007-10-09 05:33 . 2005-04-28 02:53 171880 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
2001-11-13 14:18 . 2001-11-13 14:18 8 --sh--w c:\windows\All Users\DRM\pdrm.dat
2008-05-19 02:07 . 2008-05-19 02:07 0 --sha-w c:\windows\All Users\DRM\Cache\Indiv02.tmp
.

------- Sigcheck -------

[-] 2008-06-20 11:51 361600 9425B72F40257B45D45D24773273DAD0 c:\windows\SYSTEM32\DRIVERS\tcpip.sys
[-] 2008-06-20 11:51 361600 9425B72F40257B45D45D24773273DAD0 c:\windows\SYSTEM32\dllcache\tcpip.sys
[-] 2008-04-13 19:20 361344 ACCF5A9A1FFAA490F33DBA1C632B95E1 c:\windows\ServicePackFiles\i386\tcpip.sys
[-] 2005-05-25 19:07 359936 63FDFEA54EB53DE2D863EE454937CE1E c:\windows\$hf_mig$\KB893066\SP2QFE\tcpip.sys
[-] 2006-01-13 16:07 360448 5562CC0A47B2AEF06D3417B733F3C195 c:\windows\$hf_mig$\KB913446\SP2QFE\tcpip.sys
[-] 2006-04-20 12:18 360576 B2220C618B42A2212A59D91EBD6FC4B4 c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys
[-] 2007-10-30 15:53 360832 64798ECFA43D78C7178375FCDD16D8C8 c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
[7] 2008-06-20 10:44 360960 744E57C99232201AE98C49168B918F48 c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[7] 2008-06-20 11:51 361600 9AEFA14BD6B182D61E3119FA5F436D3D c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[7] 2008-06-20 11:59 361600 AD978A1B783B5719720CFF204B666C8E c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 10:45 360320 2A5554FC5B1E04E131230E3CE035C3F9 c:\windows\$NtServicePackUninstall$\tcpip.sys
[7] 2004-08-04 06:14 359040 9F4B36614A0FC234525BA224957DE55C c:\windows\$NtUninstallKB893066$\tcpip.sys
[-] 2005-05-25 19:04 359808 88763A98A4C26C409741B4AA162720C9 c:\windows\$NtUninstallKB913446$\tcpip.sys
[-] 2006-01-13 01:28 359808 583E063FDC888CA30D05C2724B0D7EF4 c:\windows\$NtUninstallKB917953$\tcpip.sys
[-] 2006-04-20 11:51 359808 1DBF125862891817F374F407626967F4 c:\windows\$NtUninstallKB941644$\tcpip.sys
[-] 2007-10-30 16:20 360064 90CAFF4B094573449A0872A0F919B178 c:\windows\$NtUninstallKB951748_0$\tcpip.sys
[7] 2008-04-13 19:20 361344 93EA8D04EC73A85DB02EB8805988F733 c:\windows\$NtUninstallKB951748$\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"LDM"="\Program\BackWeb-8876480.exe" [BU]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PRISMSVR.EXE"="c:\windows\system32\PRISMSVR.EXE" [2004-04-13 290905]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-02-14 7700480]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-02-14 86016]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"ezShieldProtector for Px"="c:\windows\system32\ezSP_Px.exe" [2002-08-20 40960]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-06 148888]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"SpybotSnD"="c:\program files\Spybot - Search & Destroy\SpybotSD.exe" [2009-01-26 5365592]
"nwiz"="nwiz.exe" - c:\windows\SYSTEM32\nwiz.exe [2007-02-14 1622016]

c:\documents and settings\David Wilson\Start Menu\Programs\Startup\
TrayDay.lnk - c:\program files\TrayDay\TrayDay.exe [2003-12-6 204800]
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoFavoritesMenu"= 1 (0x1)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoFavoritesMenu"= 1 (0x1)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^CorelCENTRAL 10.lnk]
backup=c:\windows\pss\CorelCENTRAL 10.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^FastCheck Monitoring Utility.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\FastCheck Monitoring Utility.lnk
backup=c:\windows\pss\FastCheck Monitoring Utility.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Sonic CinePlayer Quick Launch.lnk]
backup=c:\windows\pss\Sonic CinePlayer Quick Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^David Wilson^Start Menu^Programs^Startup^Dialog Box Assistant.lnk]
path=c:\documents and settings\David Wilson\Start Menu\Programs\Startup\Dialog Box Assistant.lnk
backup=c:\windows\pss\Dialog Box Assistant.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^David Wilson^Start Menu^Programs^Startup^Webshots.lnk]
backup=c:\windows\pss\Webshots.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"LDM"=\Program\BackWeb-8876480.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"C2K"=c:\windows\cyb2k.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"EnsoniqMixer"=starter.exe
"AtiPTA"=Atiptaxx.exe
"AtiCwd32"=Aticwd32.exe
"AtiQiPcl"=AtiQiPcl.exe
"POINTER"=point32.exe
"LoadQM"=loadqm.exe
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
"QuickTime Task"=e:\program files\QuickTime\qttask.exe
"MMTray"=d:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Common Files\\Doppler 10 Pinpoint Alert\\TrueWeather.exe"=
"c:\\WINDOWS\\System32\\mmc.exe"=
"c:\\Program Files\\RealVNC\\VNC4\\vncviewer.exe"=
"f:\\Program Files\\Opera\\Opera.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\EA Games\\Command and Conquer Generals\\patchget.dat"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVRegistrationService.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVLibraryService.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVNetworkService.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVRecordingEngine.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVGuideDataLoader.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVSettingsService.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVTaskManagerService.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVD3DShell.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\SetupWizard.exe"=
"c:\\Program Files\\SnapStream Media\\Beyond TV\\BTVWebServiceProxy.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009

R0 amdagp10;AMD IG AGP Bus Filter;c:\windows\SYSTEM32\DRIVERS\amdagp10.sys [3/25/2003 11:19 PM 22994]
R0 fasttrak;fasttrak;c:\windows\SYSTEM32\DRIVERS\Fasttrak.sys [1/14/2005 11:33 PM 70656]
R1 aswSP;avast! Self Protection;c:\windows\SYSTEM32\DRIVERS\aswSP.sys [5/6/2009 12:10 AM 114768]
R1 GhPciScan;GhostPciScanner;c:\program files\Symantec\Norton Ghost 2003\GhPciScan.sys [12/17/2003 3:41 PM 5632]
R2 aswFsBlk;aswFsBlk;c:\windows\SYSTEM32\DRIVERS\aswFsBlk.sys [5/6/2009 12:10 AM 20560]
R2 NsService;NovaStor NovaBACKUP Backup/Copy Engine;c:\program files\NovaStor\NovaStor NovaBACKUP\NsService.exe [6/17/2008 4:56 PM 207936]
R2 Real time Backup Loader;Real time Backup Loader;c:\program files\NovaStor\NovaStor NovaBACKUP\DR\FsLoader.exe [10/11/2008 1:52 PM 93248]
R3 4mmdat;4mmdat;c:\windows\SYSTEM32\DRIVERS\4mmdat.sys [8/17/2001 1:52 PM 12288]
S2 Backup Scheduler;Backup Scheduler;c:\program files\NovaStor\NovaStor NovaBACKUP\DR\CBP\DCSchdlerSRVC.exe [10/11/2008 1:52 PM 98304]
S3 ati2mpaa;ati2mpaa;c:\windows\SYSTEM32\DRIVERS\ati2mpaa.sys [3/23/2002 9:50 AM 281856]
S3 ATIVRVXX;ATI Rage Theatre Video (ATIRTCAP);c:\windows\SYSTEM32\DRIVERS\atirtcap.sys [3/23/2002 9:51 AM 49920]
S3 DDCCI;DDC/CI monitor;c:\windows\SYSTEM32\DRIVERS\Moni2c.sys [3/30/2003 12:19 PM 6494]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [10/4/2008 3:20 PM 33752]
S3 zremote;zremote;c:\windows\SYSTEM32\DRIVERS\zremote.sys [5/22/2005 1:27 PM 10368]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\Shell\AutoRun\command - H:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e2de2786-6cdd-11db-97eb-00045a68bf2f}]
\Shell\AutoRun\command - H:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder

2009-05-08 c:\windows\Tasks\Uninstall Expiration Reminder.job
- c:\windows\System32\OOBE\oobebaln.exe [2003-01-09 00:12]

2009-04-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-07-25 16:34]
.
- - - - ORPHANS REMOVED - - - -

ShellIconOverlayIdentifiers-{7D688A77-C613-11D0-999B-00C04FD655E1} - (no file)
ShellExecuteHooks-{EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - e:\program files\EUDORA\EUSHLEXT.DLL
Notify-avgrsstarter - (no file)


.
------- Supplementary Scan -------
.
uStart Page = hxxp://my.yahoo.com/
IE: Download with GetRight
IE: E&xport to Microsoft Excel
IE: Open with GetRight Browser
DPF: DirectAnimation Java Classes - file://c:\windows\SYSTEM\dajava.cab
DPF: Internet Explorer Classes for Java - file://c:\windows\SYSTEM\iejava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {40272BF7-4FF5-4D6F-9BAD-3C1D3CB32982} - hxxp://www.live365.com/players/p365vip.cab
DPF: {5197842F-0557-48AE-9552-7594F7C98F04} - hxxp://www.cybersitter.com/recovery/ocx/PasswordReset.ocx
FF - ProfilePath - c:\documents and settings\David Wilson\Application Data\Mozilla\Firefox\Profiles\5nzx41m4.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-14 23:12
Windows 5.1.2600 Service Pack 3 FAT NTAPI

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Iomega Activity Disk2]
"ImagePath"="\"\""
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\$$$\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_USERS\$$$\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{E8066BAB-BCF1-46CA-D8AA-605D8DE00F6D}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{210BD7C7-47ED-BBE9-95D0F9FAA3BD0E97}\{C5D4C247-F1D1-D183-A63FC2DFAAC29AA3}\{B55B3474-A2E6-F6F7-4AD088E6434601A2}*]
"KGHQ1WVPMWYCTK5FHYUB2KQRGA1"=hex:01,00,01,00,00,00,00,00,61,e9,6d,81,db,39,d8,
7a,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{945169D7-C27E-315B-97A3E6913A1C7622}\{06C63AB7-5C18-FA8E-E5D32118C99A5B59}\{F7BD6AFF-A45B-6FB8-BB91AB79C0A3DA53}*]
"KGHQ1WVPMWYCTK5FHYUB2KQRGA1"=hex:01,00,01,00,00,00,00,00,61,e9,6d,81,db,39,d8,
7a,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A73A7B6D-D5C7-2D01-6A3ED58A203D5FEA}\{958FE6C0-B367-4AD6-C310294BFC5DB709}\{E2E9EAF6-387C-4947-07B2C800F4ACC9F3}*]
"KGHQ1WVPMWYCTK5FHYUB2KQRGA1"=hex:01,00,01,00,00,00,00,00,61,e9,6d,81,db,39,d8,
7a,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BF11F383-757D-CF48-6D213AC2BB6130AD}\{12507465-D6D8-AFB1-97ED5D21195D77D5}\{90E47118-DD98-E716-1AABCD138C042D55}*]
"KGHQ1WVPMWYCTK5FHYUB2KQRGA1"=hex:01,00,01,00,00,00,00,00,61,e9,6d,81,db,39,d8,
7a,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F2F43379-985D-E7AE-2F5BD6B18999A07F}\{64C9A7C2-676E-3AEC-13AF6B278F65FD89}\{7B815B3C-162E-096A-EBEBEFD33B1AE416}*]
"KGHQ1WVPMWYCTK5FHYUB2KQRGA1"=hex:01,00,01,00,00,00,00,00,61,e9,6d,81,db,39,d8,
7a,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(1268)
c:\windows\system32\nview.dll
c:\windows\system32\nvwddi.dll
c:\program files\Windows Media Player\wmpband.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Roxio\Easy Media Creator 7\Drag to Disc\Shellex.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\NovaStor\NovaStor NovaBACKUP\DR\CBP\DCSchdler.exe
c:\program files\Promise\FastTrak\FtrakSvc.exe
c:\program files\Symantec\Norton Ghost 2003\GhostStartService.exe
c:\progra~1\Iomega\System32\AppServices.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\nvsvc32.exe
c:\windows\System32\tcpsvcs.exe
c:\windows\System32\snmp.exe
c:\program files\Iomega\AutoDisk\ADService.exe
c:\program files\Internet Explorer\IEXPLORE.EXE
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\rundll32.exe
c:\program files\2Wire 802.11g Wireless\PRISMCFG.exe
.
**************************************************************************
.
Completion time: 2009-05-15 23:15 - machine was rebooted
ComboFix-quarantined-files.txt 2009-05-15 03:15
ComboFix2.txt 2009-04-22 23:01

Pre-Run: 32,170,213,376 bytes free
Post-Run: 32,158,941,184 bytes free

Current=1 Default=1 Failed=3 LastKnownGood=4 Sets=1,2,3,4
337 --- E O F --- 2009-03-15 07:03

proskoma
2009-05-15, 05:22
DDS (Ver_09-03-16.01) - FAT32x86
Run by David Wilson at 23:18:43.62 on Thu 05/14/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1535.1095 [GMT -4:00]

AV: avast! antivirus 4.8.1335 [VPS 090514-0] *On-access scanning disabled* (Updated)

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\CBP\DCSchdler.exe
C:\Program Files\Promise\FastTrak\FtrakSvc.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\NovaStor\NovaStor NovaBACKUP\NsService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\Fsloader.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\PRISMSVR.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.exe
C:\Program Files\TrayDay\TrayDay.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\David Wilson\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://my.yahoo.com/
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: bho2gr Class: {31ff080d-12a3-439a-a2ef-4ba95a3148e8} - e:\program files\getright\xx2gr.dll
BHO: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - __BHODemonDisabled
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} -
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
TB: Plaxo: {81ca3009-6200-4a6d-93c6-f1e9a6821c7f} -
TB: {724D43A0-0D85-11D4-9908-00400523E39A} - No File
TB: {06E58E5E-F8CB-4049-991E-A41C03BD419E} - No File
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [LDM] \Program\BackWeb-8876480.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [PRISMSVR.EXE] "c:\windows\system32\PRISMSVR.EXE" /APPLY
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [nwiz] nwiz.exe /install
mRun: [ezShieldProtector for Px] c:\windows\system32\ezSP_Px.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [SpybotSnD] "c:\program files\spybot - search & destroy\SpybotSD.exe"
StartupFolder: c:\docume~1\davidw~1\startm~1\programs\startup\trayday.lnk - c:\program files\trayday\TrayDay.exe
StartupFolder: c:\docume~1\davidw~1\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - e:\program files\logitech\desktop messenger\8876480\program\LDMConf.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\2wirew~1.lnk - c:\program files\2wire 802.11g wireless\PRISMCFG.exe
uPolicies-explorer: NoFavoritesMenu = 1 (0x1)
dPolicies-explorer: NoFavoritesMenu = 1 (0x1)
IE: Download with GetRight
IE: E&xport to Microsoft Excel
IE: Open with GetRight Browser
IE: {4B30061A-5B39-11D3-80F8-0090276F843F} - http://www.net2phone.com/
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - c:\program files\hello\PicasaCapture.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: DirectAnimation Java Classes - file://c:\windows\system\dajava.cab
DPF: Internet Explorer Classes for Java - file://c:\windows\system\iejava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: Yahoo! Checkers - hxxp://download.games.yahoo.com/games/clients/y/kt0_x.cab
DPF: Yahoo! Chess - hxxp://download.yahoo.com/games/clients/y/cr1_x.cab
DPF: Yahoo! Hearts - hxxp://download.yahoo.com/games/clients/y/hr1_x.cab
DPF: Yahoo! Pool 2 - hxxp://download.yahoo.com/games/clients/y/por9_x.cab
DPF: {00000075-0000-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/voxmsdec.CAB
DPF: {00000160-0000-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/msaudio.cab
DPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxp://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} - hxxp://gulllake.gospelcom.net/unsecure/other_media/views/ipixx.cab
DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} - hxxp://www.musicnotes.com/download/mnviewer.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\yinsthelper.dll
DPF: {31564D57-0000-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/wmvax.cab
DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
DPF: {40272BF7-4FF5-4D6F-9BAD-3C1D3CB32982} - hxxp://www.live365.com/players/p365vip.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www2.snapfish.com/SnapfishActivia.cab
DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} - hxxps://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab
DPF: {5197842F-0557-48AE-9552-7594F7C98F04} - hxxp://www.cybersitter.com/recovery/ocx/PasswordReset.ocx
DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} - hxxp://updates.lifescapeinc.com/installers/pinstall/pinstall.cab
DPF: {712362BF-E411-4F43-99D2-EB15F80AF1DB} - hxxp://entimg.msn.com/client/msnediag3518.cab
DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} - hxxp://picture.vzw.com/activex/VerizonWirelessUploadControl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {924C1588-90C3-4910-B6CA-D57A1C0418FE} - hxxp://download.yahoo.com/dl/bookmarks/ybconvfav030408.cab
DPF: {94B82441-A413-4E43-8422-D49930E69764} - hxxp://rtc.webresponse.one.microsoft.com/media/xp/TLIEFlash.CAB
DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38079.8121527778
DPF: {A662DA7E-CCB7-4743-B71A-D817F6D575DF} - hxxp://www.autodesk.com/global/dwfviewer/installer/DwfViewerSetup.cab
DPF: {A7E092C3-692A-11D0-A7E5-08002B322F3B} - hxxps://webresponse.one.microsoft.com/oas/ActiveX/FileXfer.cab
DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - hxxp://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} - hxxp://support.f-secure.com/ols/fscax.cab
DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.4.0/jinstall-1_4_0-windows-i586.cab
DPF: {CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} - hxxp://www.live365.com/players/play365.cab
DPF: {CEBC955E-58AF-11D2-A30A-00A0C903492B} - hxxp://windowsupdate.microsoft.com/R848/V31Controls/x86/w98/en/actsetup.cab
DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - hxxp://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - hxxp://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} - hxxp://entimg.msn.com/client/msnmusax3518.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\davidw~1\applic~1\mozilla\firefox\profiles\5nzx41m4.default\
FF - prefs.js: browser.search.selectedEngine - Google

============= SERVICES / DRIVERS ===============

R0 amdagp10;AMD IG AGP Bus Filter;c:\windows\system32\drivers\amdagp10.sys [2003-3-25 22994]
R0 fasttrak;fasttrak;c:\windows\system32\drivers\Fasttrak.sys [2005-1-14 70656]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-5-6 114768]
R1 Cinemsup;Cinemsup;c:\windows\system32\drivers\cinemsup.sys [2002-7-19 6656]
R1 GhPciScan;GhostPciScanner;c:\program files\symantec\norton ghost 2003\GhPciScan.sys [2003-12-17 5632]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-5-6 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-5-6 138680]
R2 NsService;NovaStor NovaBACKUP Backup/Copy Engine;c:\program files\novastor\novastor novabackup\NsService.exe [2008-6-17 207936]
R2 Real time Backup Loader;Real time Backup Loader;c:\program files\novastor\novastor novabackup\dr\FsLoader.exe [2008-10-11 93248]
R3 4mmdat;4mmdat;c:\windows\system32\drivers\4mmdat.sys [2001-8-17 12288]
RUnknown DCDisk;DCDisk; [x]
RUnknown dcsnap;dcsnap; [x]
RUnknown Iprip;Iprip; [x]
S2 Backup Scheduler;Backup Scheduler;c:\program files\novastor\novastor novabackup\dr\cbp\DCSchdlerSRVC.exe [2008-10-11 98304]
S3 ati2mpaa;ati2mpaa;c:\windows\system32\drivers\ati2mpaa.sys [2002-3-23 281856]
S3 ATIVRVXX;ATI Rage Theatre Video (ATIRTCAP);c:\windows\system32\drivers\atirtcap.sys [2002-3-23 49920]
S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-5-6 254040]
S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-5-6 352920]
S3 DDCCI;DDC/CI monitor;c:\windows\system32\drivers\Moni2c.sys [2003-3-30 6494]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\nos\bin\getPlus_HelperSvc.exe [2008-10-4 33752]
S3 hcwPVRP2;Hauppauge WinTV PVR PCI II (Encoder);c:\windows\system32\drivers\hcwPVRP2.sys [2005-5-22 814464]
S3 zremote;zremote;c:\windows\system32\drivers\zremote.sys [2005-5-22 10368]
SUnknown idsvcSPTISRV;idsvcSPTISRV; [x]
UnknownUnknown efbDisk;efbDisk; [x]

=============== Created Last 30 ================

2009-05-13 07:50 <DIR> --dsh--- C:\FOUND.043
2009-05-08 11:01 0 a--s---- c:\windows\system32\148114617.dat
2009-05-07 22:11 <DIR> --d----- c:\program files\Microsoft Money Plus
2009-05-06 00:03 147,100 a---h--- c:\windows\system32\mlfcache.dat
2009-05-05 22:38 410,984 a------- c:\windows\system32\deploytk.dll
2009-05-05 22:38 73,728 a------- c:\windows\system32\javacpl.cpl
2009-05-05 22:27 0 a------- c:\windows\system32\REN33.tmp
2009-05-05 22:27 0 a------- c:\windows\system32\REN32.tmp
2009-05-05 22:11 2,709 a------- c:\windows\system32\gibbebx.dat
2009-05-05 22:10 1,024 ----h--- C:\diskfile1
2009-05-05 22:10 15,360 ----h--- C:\logicinf.bin
2009-05-05 21:53 2,709 a------- c:\windows\system32\dllgidoor.dat
2009-04-22 18:53 <DIR> a-dshr-- C:\cmdcons
2009-04-22 18:52 161,792 a------- c:\windows\SWREG.exe
2009-04-22 18:52 98,816 a------- c:\windows\sed.exe
2009-04-19 18:34 360,021 a------- C:\something.scr
2009-04-18 00:21 <DIR> --d----- c:\program files\Spybot - Search & Destroy
2009-04-18 00:21 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-04-17 21:04 <DIR> --d----- c:\docume~1\davidw~1\applic~1\Malwarebytes
2009-04-17 21:04 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-04-17 21:04 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-17 21:04 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-04-17 21:04 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-04-17 19:53 66 a------- c:\windows\wininit.ini
2009-04-17 08:22 <DIR> --d----- C:\!KillBox
2009-04-16 21:00 <DIR> --d----- c:\docume~1\alluse~1\applic~1\{A21E413E-98CC-4ABB-9843-E6AA4F456F61}

==================== Find3M ====================

2009-04-22 19:04 5,880 a------- c:\windows\system32\wfileu.drv
2008-12-16 19:23 726,008 a------- c:\documents and settings\david wilson\gotomypc_438.exe
2008-11-06 12:33 726,008 a------- c:\documents and settings\david wilson\gotomypc_437.exe
2001-11-06 00:23 266 ---sh--- c:\program files\desktop.ini
2001-11-06 00:23 11,079 ----h--- c:\program files\folder.htt
2001-01-19 12:04 21,841 a------- c:\program files\common files\tppupd2k.dll
2001-01-19 11:04 21,329 -------- c:\program files\common files\tppupd98.dll
2008-10-04 15:44 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008100420081005\index.dat
2001-11-13 10:18 8 ---sh--- c:\windows\all users\drm\pdrm.dat

============= FINISH: 23:19:14.06 ===============

proskoma
2009-05-15, 05:44
IEXPLORE.EXE still starts with OS. End Process turns it off and it stays off - but process iexplore.ex1 turns on and off continuously.

Double click My Computer/double click a HD and the IEXPLORE.EXE process starts multiple times again. And if force quite, will start again.

Script errors continue in IE... for example... if I choose Tools/Organize Favorites - I get an Internet Explorer Script Error... An error has occurred in the script on this page... but no detail in any of the Line/Char/Error/Code/URL fields. Choosing Yes or No has little effect as the box stays in place - clicking on the X in the RH corner about 30 times finally closes the dialog box.

proskoma
2009-05-15, 13:09
Avast just found a Trojan Horse - Win32:Delf-MBA -- but it's struggling to remove it.

I also noticed after e-mailing last night that my computer is running Internet Explorer from c:/Program Files/Internet Explorer and NOT from c:/Windows/IE7. It's the first directory that has a file called iexplore.ex1. My task manager continues to have an ever expanding number of instances of iexplore.ex1 which start up and then shut down and then start up and then shut down.

Blade81
2009-05-15, 19:43
Hi,


Avast just found a Trojan Horse - Win32:Delf-MBA -- but it's struggling to remove it.
Where does Avast see the infection in?


Let's uninstall IE7 for now.

After that, please download OTListIt2 (http://oldtimer.geekstogo.com/OTListIt2.exe)
Save it to the Desktop
Close all windows and double-click on the OTListIt2.exe file
OK any warning about running OTListIt.
Place a check in the Scan All Users checkbox
Click the Run Scan button
When the scan is complete, two text files are produced on the Desktop: OTListIt.txt , and Extras.txt

Please post the OTListIt.txt and Extras.txt in your reply.

proskoma
2009-05-16, 13:43
Sign of "win32:Delf-MBA [Trj]" has been found in "C:\WINDOWS\MEMORY.DMP" file.

Blade81
2009-05-16, 14:00
Sign of "win32:Delf-MBA [Trj]" has been found in "C:\WINDOWS\MEMORY.DMP" file.
Hi

By looking at the location seems to be a false positive.

proskoma
2009-05-16, 14:29
OTListIt logfile created on: 5/16/2009 8:21:00 AM - Run 1
OTListIt2 by OldTimer - Version 2.0.15.8 Folder = C:\Documents and Settings\David Wilson\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: enu | Date Format: M/d/yyyy

1.50 Gb Total Physical Memory | 0.98 Gb Available Physical Memory | 65.64% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): [Binary data over 100 bytes]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 109.82 Gb Total Space | 30.66 Gb Free Space | 27.92% Space Free | Partition Type: FAT32
Drive D: | 8.09 Gb Total Space | 6.72 Gb Free Space | 83.06% Space Free | Partition Type: FAT32
Drive E: | 55.88 Gb Total Space | 30.61 Gb Free Space | 54.77% Space Free | Partition Type: FAT32
Drive F: | 39.21 Gb Total Space | 25.54 Gb Free Space | 65.13% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DAVEHOME
Current User Name: David Wilson
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - [2009/02/05 16:01:26 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2009/02/05 16:08:40 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2008/11/07 14:28:16 | 00,132,424 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2008/06/17 16:16:32 | 00,176,128 | ---- | M] () -- C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\CBP\DCSchdler.exe
PRC - [2000/11/15 18:53:04 | 00,237,568 | ---- | M] (Promise Technology Inc.) -- C:\Program Files\Promise\FastTrak\FtrakSvc.exe
PRC - [2003/12/17 15:51:44 | 00,200,704 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
PRC - [2002/01/14 07:49:38 | 00,073,728 | ---- | M] (Iomega Corporation) -- C:\Program Files\Iomega\System32\AppServices.exe
PRC - [2009/05/05 22:38:38 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2005/02/22 16:32:14 | 00,038,912 | ---- | M] () -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe
PRC - [2008/06/17 16:56:16 | 00,207,936 | ---- | M] (NovaStor) -- C:\Program Files\NovaStor\NovaStor NovaBACKUP\NsService.exe
PRC - [2007/02/14 01:32:36 | 00,159,811 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe
PRC - [2008/06/17 16:23:48 | 00,093,248 | ---- | M] () -- C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\Fsloader.exe
PRC - [2001/08/23 12:00:00 | 00,019,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\tcpsvcs.exe
PRC - [2006/11/20 03:42:46 | 00,033,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\snmp.exe
PRC - [2002/01/24 16:10:40 | 00,126,976 | ---- | M] (Iomega Corporation) -- C:\Program Files\Iomega\AutoDisk\ADService.exe
PRC - [2009/02/05 16:08:26 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
PRC - [2009/02/05 16:06:04 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PRC - [2007/06/13 06:23:08 | 01,033,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2004/04/13 19:45:30 | 00,290,905 | ---- | M] (Conexant Systems, Inc.) -- C:\WINDOWS\system32\PRISMSVR.EXE
PRC - [2008/11/20 13:20:54 | 00,290,088 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2002/08/20 10:29:26 | 00,040,960 | ---- | M] (Easy Systems Japan Ltd.) -- C:\WINDOWS\system32\ezSP_Px.exe
PRC - [2009/05/05 22:38:38 | 00,148,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2009/02/05 16:08:46 | 00,081,000 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashDisp.exe
PRC - [2009/03/05 16:07:20 | 02,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2004/04/13 20:47:56 | 00,335,979 | ---- | M] (2Wire Inc.) -- C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.exe
PRC - [2002/10/22 06:50:00 | 00,204,800 | ---- | M] (MJMSoft Design Limited) -- C:\Program Files\TrayDay\TrayDay.exe
PRC - [2008/11/20 13:20:44 | 00,536,872 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe
PRC - [2004/08/04 03:56:50 | 00,093,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\iexplore.exe
PRC - [2004/08/04 03:56:50 | 00,093,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\iexplore.exe
PRC - [2004/08/04 03:56:50 | 00,093,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\iexplore.exe
PRC - [2009/05/16 08:20:16 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\David Wilson\Desktop\OTListIt2.exe

========== Win32 Services (SafeList) ==========

SRV - [2008/11/07 14:28:16 | 00,132,424 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running])
SRV - [2007/10/24 01:47:22 | 00,033,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2009/02/05 16:01:26 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv [Auto | Running])
SRV - [2000/11/30 14:30:40 | 00,057,344 | ---- | M] () -- C:\WINDOWS\System32\Ati2evxx.exe -- (Ati HotKey Poller [Auto | Stopped])
SRV - [2009/02/05 16:08:40 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus [Auto | Running])
SRV - [2009/02/05 16:08:26 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner [On_Demand | Running])
SRV - [2009/02/05 16:06:04 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner [On_Demand | Running])
SRV - [2008/06/17 16:16:36 | 00,098,304 | ---- | M] () -- C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\CBP\DCSchdlerSRVC.exe -- (Backup Scheduler [Auto | Stopped])
SRV - [2007/10/24 01:47:40 | 00,070,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2000/11/15 18:53:04 | 00,237,568 | ---- | M] (Promise Technology Inc.) -- C:\Program Files\Promise\FastTrak\FtrakSvc.exe -- (FastTrakSvc [Auto | Running])
SRV - [2006/10/20 21:21:24 | 00,036,864 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008/08/29 10:00:30 | 00,033,752 | ---- | M] (NOS Microsystems Ltd.) -- C:\Program Files\NOS\bin\getPlus_HelperSvc.exe -- (getPlus(R) Helper [On_Demand | Stopped])
SRV - [2003/12/17 15:51:44 | 00,200,704 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe -- (GhostStartService [Auto | Running])
SRV - [2004/08/04 03:56:44 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2005/04/04 00:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
SRV - [2006/10/30 03:33:58 | 00,741,376 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
SRV - File not found -- -- (idsvcSPTISRV [Auto | Stopped])
SRV - File not found -- -- (Iomega Activity Disk2 [Disabled | Stopped])
SRV - [2002/01/14 07:49:38 | 00,073,728 | ---- | M] (Iomega Corporation) -- C:\Program Files\Iomega\System32\AppServices.exe -- (Iomega App Services [Auto | Running])
SRV - [2008/11/20 13:20:44 | 00,536,872 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Running])
SRV - [2004/08/04 03:56:42 | 00,035,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\iprip.dll -- (Iprip [Auto | Running])
SRV - [2009/05/05 22:38:38 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
SRV - [2005/02/22 16:32:14 | 00,038,912 | ---- | M] () -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe -- (LightScribeService [Auto | Running])
SRV - [2001/08/23 12:00:00 | 00,019,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\tcpsvcs.exe -- (LPDSVC [On_Demand | Stopped])
SRV - [2006/10/30 03:34:02 | 00,122,880 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
SRV - [2008/06/17 16:56:16 | 00,207,936 | ---- | M] (NovaStor) -- C:\Program Files\NovaStor\NovaStor NovaBACKUP\NsService.exe -- (NsService [Auto | Running])
SRV - [2007/02/14 01:32:36 | 00,159,811 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc [Auto | Running])
SRV - [2004/01/30 15:19:20 | 00,065,625 | ---- | M] (Sony Corporation) -- C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe -- (PACSPTISVR [On_Demand | Stopped])
SRV - [2008/06/17 16:23:48 | 00,093,248 | ---- | M] () -- C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\Fsloader.exe -- (Real time Backup Loader [Auto | Running])
SRV - [2001/08/23 12:00:00 | 00,019,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\tcpsvcs.exe -- (SimpTcp [Auto | Running])
SRV - [2006/11/20 03:42:46 | 00,033,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\snmp.exe -- (SNMP [Auto | Running])
SRV - [2004/01/30 15:16:06 | 00,065,622 | ---- | M] (Sony Corporation) -- C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe -- (SPTISRV [On_Demand | Stopped])
SRV - [2008/07/15 17:38:32 | 00,394,608 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Common Files\supportsoft\bin\ssrc.exe -- (SupportSoft RemoteAssist [On_Demand | Stopped])
SRV - [2004/08/04 03:56:44 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (uploadmgr [Auto | Stopped])
SRV - [2006/10/18 20:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])
SRV - [2002/01/24 16:10:40 | 00,126,976 | ---- | M] (Iomega Corporation) -- C:\Program Files\Iomega\AutoDisk\ADService.exe -- (_IOMEGA_ACTIVE_DISK_SERVICE_ [Auto | Running])

========== Driver Services (SafeList) ==========

DRV - [2004/08/04 02:00:04 | 00,012,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\DRIVERS\4mmdat.sys -- (4mmdat [On_Demand | Running])
DRV - [2009/02/05 16:05:12 | 00,026,944 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4 [System | Running])
DRV - [2004/08/04 02:07:42 | 00,043,008 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\System32\DRIVERS\amdagp.sys -- (amdagp [Boot | Running])
DRV - [2000/06/27 14:39:16 | 00,022,994 | ---- | M] (AMD Corporation) -- C:\WINDOWS\System32\DRIVERS\amdagp10.sys -- (amdagp10 [Boot | Running])
DRV - [2002/08/29 00:59:12 | 00,036,224 | ---- | M] (ADMtek Incorporated.) -- C:\WINDOWS\System32\DRIVERS\AN983.sys -- (AN983 [On_Demand | Running])
DRV - [2007/02/06 15:01:48 | 00,016,512 | ---- | M] (Adaptec) -- C:\WINDOWS\System32\drivers\aspi32.sys -- (Aspi32 [System | Running])
DRV - [2009/02/05 16:07:12 | 00,020,560 | ---- | M] (ALWIL Software) -- C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys -- (aswFsBlk [Auto | Running])
DRV - [2009/02/05 16:08:10 | 00,094,032 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2 [Auto | Running])
DRV - [2009/02/05 16:06:10 | 00,023,152 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr [On_Demand | Running])
DRV - [2009/02/05 16:07:24 | 00,114,768 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP [System | Running])
DRV - [2009/02/05 16:06:20 | 00,051,376 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi [System | Running])
DRV - [2001/08/17 12:48:52 | 00,281,856 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\DRIVERS\ati2mpaa.sys -- (ati2mpaa [On_Demand | Stopped])
DRV - [2001/09/26 23:32:38 | 00,285,088 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\DRIVERS\ati2mtaa.sys -- (ati2mtaa [On_Demand | Stopped])
DRV - [2004/08/04 01:29:30 | 00,104,960 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\DRIVERS\atinrvxx.sys -- (atinrvxx [On_Demand | Stopped])
DRV - [2001/08/17 12:49:12 | 00,049,920 | ---- | M] () -- C:\WINDOWS\System32\DRIVERS\atirtcap.sys -- (ATIVRVXX [On_Demand | Stopped])
DRV - [2006/05/04 02:00:00 | 00,002,432 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\drivers\cdr4_xp.sys -- (Cdr4_xp [System | Stopped])
DRV - [2006/05/04 02:00:00 | 00,002,560 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\drivers\cdralw2k.sys -- (Cdralw2k [System | Stopped])
DRV - [2004/04/13 15:37:56 | 00,285,824 | ---- | M] (Roxio) -- C:\WINDOWS\System32\drivers\Cdudf_xp.sys -- (cdudf_xp [System | Running])
DRV - [2002/07/19 08:10:20 | 00,006,656 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\drivers\cinemsup.sys -- (Cinemsup [System | Running])
DRV - [2008/06/17 16:16:46 | 00,155,648 | ---- | M] () -- C:\WINDOWS\System32\drivers\DCDisk.sys -- (DCDisk [System | Running])
DRV - [2008/06/17 16:16:46 | 00,077,472 | ---- | M] () -- C:\WINDOWS\System32\drivers\dcsnap.sys -- (dcsnap [Boot | Running])
DRV - [2003/03/30 12:19:20 | 00,006,494 | ---- | M] (Mitsubishi Electric , NEC-Mitsubishi Electric Visual Systems) -- C:\WINDOWS\System32\DRIVERS\Moni2c.sys -- (DDCCI [On_Demand | Stopped])
DRV - [2004/04/15 22:57:26 | 00,140,416 | ---- | M] (Windows (R) 2000 DDK provider) -- C:\WINDOWS\System32\drivers\DVDVRRdr_xp.sys -- (DVDVRRdr_xp [System | Running])
DRV - [2004/04/13 15:37:30 | 00,023,680 | ---- | M] (Roxio) -- C:\WINDOWS\System32\drivers\dvd_2k.sys -- (dvd_2K [On_Demand | Running])
DRV - [2002/06/03 11:18:32 | 00,040,832 | ---- | M] (Creative Technology Ltd.) -- C:\WINDOWS\system32\drivers\es1371mp.sys -- (es1371 [On_Demand | Running])
DRV - [2002/05/23 11:28:56 | 00,070,656 | ---- | M] (Promise Technology, Inc.) -- C:\WINDOWS\system32\DRIVERS\fasttrak.sys -- (fasttrak [Boot | Running])
DRV - [2004/08/04 02:08:22 | 00,010,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\DRIVERS\gameenum.sys -- (gameenum [On_Demand | Running])
DRV - [2008/04/17 13:12:54 | 00,015,464 | ---- | M] (GEAR Software Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys -- (GEARAspiWDM [On_Demand | Running])
DRV - [2003/12/17 15:41:38 | 00,005,632 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Norton Ghost 2003\ghpciscan.sys -- (GhPciScan [System | Running])
DRV - [2007/02/06 13:27:04 | 00,185,728 | ---- | M] (Hauppauge Computer Works, Inc.) -- C:\WINDOWS\system32\DRIVERS\hcwPP2.sys -- (hcwPP2 [On_Demand | Running])
DRV - [2004/09/22 09:01:20 | 00,814,464 | R--- | M] (Hauppauge Computer Works, Inc.) -- C:\WINDOWS\system32\DRIVERS\hcwPVRP2.sys -- (hcwPVRP2 [On_Demand | Stopped])
DRV - [2002/01/14 07:49:38 | 00,033,602 | ---- | M] (Iomega Corporation) -- C:\WINDOWS\System32\DRIVERS\iomdisk.sys -- (iomdisk [Boot | Running])
DRV - [2001/09/19 06:11:00 | 00,050,432 | ---- | M] (Logitech) -- C:\WINDOWS\System32\DRIVERS\L8042Pr2.sys -- (l8042pr2 [On_Demand | Stopped])
DRV - [2001/09/19 06:11:00 | 00,022,064 | ---- | M] (Logitech) -- C:\WINDOWS\System32\DRIVERS\LHidFlt2.sys -- (LHidFlt2 [On_Demand | Running])
DRV - [2001/09/19 06:11:00 | 00,037,822 | ---- | M] (Logitech) -- C:\WINDOWS\system32\drivers\LHidUsb.Sys -- (LHidUsb [On_Demand | Running])
DRV - [2001/09/19 06:11:00 | 00,005,840 | ---- | M] (Logitech) -- C:\WINDOWS\System32\DRIVERS\LKbdFlt2.sys -- (LKbdFlt2 [On_Demand | Running])
DRV - [2001/09/19 06:11:00 | 00,067,440 | ---- | M] (Logitech) -- C:\WINDOWS\System32\DRIVERS\LMouFlt2.sys -- (LMouFlt2 [On_Demand | Running])
DRV - [2004/04/13 19:20:08 | 00,015,781 | R--- | M] (Meetinghouse Data Communications) -- C:\WINDOWS\system32\DRIVERS\mdc8021x.sys -- (MDC8021X [Auto | Running])
DRV - [2004/04/13 15:29:22 | 00,023,680 | ---- | M] (Roxio) -- C:\WINDOWS\System32\drivers\mmc_2k.sys -- (mmc_2K [On_Demand | Stopped])
DRV - [2004/08/04 01:29:28 | 00,013,824 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\DRIVERS\atinmdxx.sys -- (MVDCODEC [Auto | Stopped])
DRV - [2007/02/14 01:32:32 | 03,983,872 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\nv4_mini.sys -- (nv [On_Demand | Running])
DRV - [2003/04/16 14:21:30 | 00,004,228 | ---- | M] (PowerQuest Corporation) -- C:\WINDOWS\System32\drivers\PQNTDRV.sys -- (PQNTDrv [System | Running])
DRV - [2001/08/23 12:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
DRV - [2004/04/13 15:23:58 | 00,117,248 | ---- | M] (Roxio) -- C:\WINDOWS\System32\drivers\Pwd_2k.sys -- (pwd_2k [System | Running])
DRV - [2008/05/22 18:22:16 | 00,043,528 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\DRIVERS\PxHelp20.sys -- (PxHelp20 [Boot | Running])
DRV - [2007/11/13 05:25:54 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys -- (Secdrv [Auto | Running])
DRV - [2005/10/07 16:42:14 | 00,038,468 | ---- | M] (Alcor Micro Corp.) -- C:\WINDOWS\System32\Drivers\sunkfilt.sys -- (SunkFilt [On_Demand | Stopped])
DRV - [2004/04/15 22:53:40 | 00,198,528 | ---- | M] (Roxio) -- C:\WINDOWS\System32\drivers\Udfreadr.sys -- (UDFReadr [System | Running])
DRV - [2001/08/17 13:52:22 | 00,036,736 | ---- | M] (Promise Technology, Inc.) -- C:\WINDOWS\System32\DRIVERS\ultra.sys -- (ultra [Boot | Running])
DRV - [2004/05/16 20:46:18 | 00,390,752 | R--- | M] ( ) -- C:\WINDOWS\system32\DRIVERS\wlanCIG.sys -- (wlanCIG [On_Demand | Running])
DRV - [2004/03/01 14:57:04 | 00,010,368 | ---- | M] (Streamzap, Inc.) -- C:\WINDOWS\system32\drivers\zremote.sys -- (zremote [On_Demand | Stopped])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://my.yahoo.com/index.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/index.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Update_Check_Page = http://www.microsoft.com/isapi/redir.dll?Prd=ie&Pver=5.0&Ar=ie5update
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://red.clientapps.yahoo.com/customize/ie/defaults/cs/ymsgr6/*http://www.yahoo.com/ext/search/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ams-server*

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ams-server*

IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = about:blank
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
IE - HKU\S-1-5-19\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ams-server*

IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = about:blank
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
IE - HKU\S-1-5-20\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ams-server*

IE - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\S-1-5-21-1547161642-1580436667-1708537768-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Google"

FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/05/05 22:38:40 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.8\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2005/04/27 22:53:28 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.8\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2005/04/27 22:53:26 | 00,000,000 | ---D | M]

[2005/04/30 10:59:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\David Wilson\Application Data\mozilla\Firefox\Profiles\5nzx41m4.default\extensions
[2005/04/27 22:53:52 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2005/04/27 22:53:52 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/05/05 22:49:12 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
[2009/05/05 22:49:12 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
[2009/05/05 22:49:12 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
[2009/05/05 22:49:12 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2009/05/05 22:38:48 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2007/10/20 10:31:58 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\talkback@mozilla.org
[2007/10/09 01:33:30 | 00,066,408 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\jar50.dll
[2007/10/09 01:33:30 | 00,054,112 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\jsd3250.dll
[2007/10/09 01:33:32 | 00,034,688 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\myspell.dll
[2007/10/09 01:33:32 | 00,046,456 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\spellchk.dll
[2007/10/09 01:33:32 | 00,171,880 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\xpinstal.dll
[2007/10/08 20:39:56 | 00,001,514 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2007/10/08 20:39:56 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2007/10/08 20:39:56 | 00,001,038 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2007/10/08 20:39:56 | 00,001,046 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2007/10/08 20:39:56 | 00,002,351 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2007/10/08 20:39:56 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (bho2gr Class) - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - E:\Program Files\GetRight\xx2gr.dll (Headlight Software, Inc.)
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - File not found
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - File not found
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (no name) - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - Reg Error: Key error. File not found
O3 - HKLM\..\Toolbar: (no name) - {724d43a0-0d85-11d4-9908-00400523e39a} - Reg Error: Key error. File not found
O3 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\..\Toolbar\ShellBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
O3 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\..\Toolbar\WebBrowser: (no name) - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - Reg Error: Key error. File not found
O3 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Error: Key error. File not found
O3 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\..\Toolbar\WebBrowser: (no name) - {724D43A0-0D85-11D4-9908-00400523E39A} - Reg Error: Key error. File not found
O3 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\..\Toolbar\WebBrowser: (no name) - {81CA3009-6200-4A6D-93C6-F1E9A6821C7F} - Reg Error: Value error. File not found
O3 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\..\Toolbar\WebBrowser: (no name) - {F2CF5485-4E02-4F68-819C-B92DE9277049} - Reg Error: Key error. File not found
O3 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\..\Toolbar\WebBrowser: (no name) - {FE6BC4EF-5676-484B-88AE-883323913256} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe (Easy Systems Japan Ltd.)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install File not found
O4 - HKLM..\Run: [PRISMSVR.EXE] "C:\WINDOWS\system32\PRISMSVR.EXE" /APPLY (Conexant Systems, Inc.)
O4 - HKLM..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" (Safer Networking Limited)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004..\Run: [LDM] \Program\BackWeb-8876480.exe File not found
O4 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk = E:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\2Wire Wireless Client.lnk = C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.exe (2Wire Inc.)
O4 - Startup: C:\Documents and Settings\David Wilson\Start Menu\Programs\Startup\TrayDay.lnk = C:\Program Files\TrayDay\TrayDay.exe (MJMSoft Design Limited)
O4 - Startup: C:\Documents and Settings\David Wilson\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Advanced\Folder\Hidden\SHOWALL: CheckedValue = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartBanner = 01 00 00 00 [binary data]
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogOff = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Advanced\Folder\Hidden\SHOWALL: CheckedValue = 1
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartBanner = 01 00 00 00 [binary data]
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogOff = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Advanced\Folder\Hidden\SHOWALL: CheckedValue = 1
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 95 00 00 00 [binary data]
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartBanner = 01 00 00 00 [binary data]
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogOff = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = [binary data]
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 95 00 00 00 [binary data]
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartBanner = 01 00 00 00 [binary data]
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogOff = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = [binary data]
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 1
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartBanner = 01 00 00 00 [binary data]
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 1
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 1
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogOff = 0
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = [binary data]
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Advanced\Folder\Hidden\SHOWALL: CheckedValue = 1
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004_Classes\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O8 - Extra context menu item: Download with GetRight - Reg Error: Value error. File not found
O8 - Extra context menu item: E&xport to Microsoft Excel - Reg Error: Value error. File not found
O8 - Extra context menu item: Open with GetRight Browser - Reg Error: Value error. File not found
O9 - Extra Button: Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - File not found
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - File not found
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - File not found
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - File not found
O9 - Extra Button: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - File not found
O9 - Extra 'Tools' menuitem : Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - File not found
O9 - Extra Button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - E:\Program Files\ICQ\ICQ.exe File not found
O9 - Extra 'Tools' menuitem : ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - E:\Program Files\ICQ\ICQ.exe File not found
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - File not found
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - File not found
O9 - Extra Button: Share in Hello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll (Picasa, Inc.)
O9 - Extra 'Tools' menuitem : Share in H&ello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll (Picasa, Inc.)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\.DEFAULT\..Trusted Domains: aol.com ([free] http in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: 50 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-18\..Trusted Domains: aol.com ([free] http in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: 50 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-19\..Trusted Domains: aol.com ([free] http in Trusted sites)
O15 - HKU\S-1-5-19\..Trusted Domains: 2 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-20\..Trusted Domains: aol.com ([free] http in Trusted sites)
O15 - HKU\S-1-5-20\..Trusted Domains: 2 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\..Trusted Domains: 48 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {00000075-0000-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/voxmsdec.CAB (Reg Error: Key error.)
O16 - DPF: {00000160-0000-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/msaudio.cab (Reg Error: Key error.)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab (Support.com Configuration Class)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} http://gulllake.gospelcom.net/unsecure/other_media/views/ipixx.cab (iPIX ActiveX Control)
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} http://www.musicnotes.com/download/mnviewer.cab (Musicnotes Viewer)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {31564D57-0000-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/wmvax.cab (Reg Error: Key error.)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {40272BF7-4FF5-4D6F-9BAD-3C1D3CB32982} http://www.live365.com/players/p365vip.cab (Live365PlayerVIP Class)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://www2.snapfish.com/SnapfishActivia.cab (Snapfish Activia)
O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} https://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab (Microsoft.WinRep)
O16 - DPF: {5197842F-0557-48AE-9552-7594F7C98F04} http://www.cybersitter.com/recovery/ocx/PasswordReset.ocx (PWReset Control)
O16 - DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} http://updates.lifescapeinc.com/installers/pinstall/pinstall.cab (Install Class)
O16 - DPF: {712362BF-E411-4F43-99D2-EB15F80AF1DB} http://entimg.msn.com/client/msnediag3518.cab (MsneDiag Class)
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} http://picture.vzw.com/activex/VerizonWirelessUploadControl.cab (Verizon Wireless Media Upload)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {924C1588-90C3-4910-B6CA-D57A1C0418FE} http://download.yahoo.com/dl/bookmarks/ybconvfav030408.cab (YbUploadFavsCtl Class)
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} http://rtc.webresponse.one.microsoft.com/media/xp/TLIEFlash.CAB (TLIEFlashObj Class)
O16 - DPF: {9DBAFCCF-592F-FFFF-FFFF-00608CEC297C} (Reg Error: Key error.)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38079.8121527778 (Reg Error: Key error.)
O16 - DPF: {A662DA7E-CCB7-4743-B71A-D817F6D575DF} http://www.autodesk.com/global/dwfviewer/installer/DwfViewerSetup.cab (Autodesk DWF Viewer Control)
O16 - DPF: {A7E092C3-692A-11D0-A7E5-08002B322F3B} https://webresponse.one.microsoft.com/oas/ActiveX/FileXfer.cab (WebResponseAttachments Control)
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab (Reg Error: Key error.)
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} http://support.f-secure.com/ols/fscax.cab (F-Secure Online Scanner 3.3)
O16 - DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.4.0/jinstall-1_4_0-windows-i586.cab (Java Plug-in 1.4.0)
O16 - DPF: {CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} http://www.live365.com/players/play365.cab (Live365Player Class)
O16 - DPF: {CEBC955E-58AF-11D2-A30A-00A0C903492B} http://windowsupdate.microsoft.com/R848/V31Controls/x86/w98/en/actsetup.cab (Reg Error: Key error.)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab (get_atlcom Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab (iTunesDetector Class)
O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} http://entimg.msn.com/client/msnmusax3518.cab (MsnMusicAx Class)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\SYSTEM\dajava.cab (Reg Error: Key error.)
O16 - DPF: Internet Explorer Classes for Java file://C:\WINDOWS\SYSTEM\iejava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Checkers http://download.games.yahoo.com/games/clients/y/kt0_x.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Chess http://download.yahoo.com/games/clients/y/cr1_x.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Hearts http://download.yahoo.com/games/clients/y/hr1_x.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Pool 2 http://download.yahoo.com/games/clients/y/por9_x.cab (Reg Error: Key error.)
O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O20 - Winlogon\Notify\dimsntfy: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\gibbebx.dll ()
O24 - Desktop Components:0 (Internet Explorer Channel Bar) - 131A6951-7F78-11D0-A979-00C04FD705A2
O24 - Desktop Components:1 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/03/23 09:33:06 | 00,000,099 | ---- | M] () - C:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2001/11/04 15:42:42 | 00,000,095 | -HS- | M] () - C:\AUTOEXEC.DOS -- [ FAT32 ]
O32 - AutoRun File - [2001/11/05 23:02:34 | 00,000,095 | -HS- | M] () - C:\AUTOEXEC.BAK -- [ FAT32 ]
O33 - MountPoints2\{e2de2786-6cdd-11db-97eb-00045a68bf2f}\Shell - "" = AutoRun
O33 - MountPoints2\{e2de2786-6cdd-11db-97eb-00045a68bf2f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{e2de2786-6cdd-11db-97eb-00045a68bf2f}\Shell\AutoRun\command - "" = H:\LaunchU3.exe -- File not found
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\LaunchU3.exe -- File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2002/03/23 10:06:56 | 00,000,000 | ---D | M]

proskoma
2009-05-16, 14:32
========== Files/Folders - Created Within 30 Days ==========

[9 C:\WINDOWS\*.tmp files]
[2009/05/16 08:20:17 | 00,501,248 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\David Wilson\Desktop\OTListIt2.exe
[2009/05/16 08:14:12 | 00,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2009/05/16 08:09:32 | 00,000,230 | ---- | C] () -- C:\WINDOWS\System32\spupdsvc.inf
[2009/05/16 08:09:19 | 00,066,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\ieResetIcons.exe
[2009/05/16 08:05:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2009/05/13 07:50:42 | 00,000,000 | -HSD | C] -- C:\FOUND.043
[2009/05/08 11:01:12 | 00,000,000 | --S- | C] () -- C:\WINDOWS\System32\148114617.dat
[2009/05/07 23:33:17 | 16,101,45792 | -HS- | C] () -- C:\hiberfil.sys
[2009/05/07 22:28:26 | 01,080,054 | ---- | C] () -- C:\Documents and Settings\David Wilson\Desktop\Aquarium 1.bmp
[2009/05/07 22:24:10 | 01,080,056 | ---- | C] () -- C:\Documents and Settings\David Wilson\Desktop\bach.bmp
[2009/05/07 22:11:31 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Money Plus
[2009/05/06 18:41:05 | 00,360,021 | ---- | C] () -- C:\Documents and Settings\David Wilson\Desktop\dds.scr
[2009/05/06 00:10:58 | 00,001,621 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/05/06 00:10:57 | 00,114,768 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2009/05/06 00:10:57 | 00,097,480 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\AvastSS.scr
[2009/05/06 00:10:57 | 00,094,032 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2009/05/06 00:10:57 | 00,093,296 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2009/05/06 00:10:57 | 00,051,376 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2009/05/06 00:10:57 | 00,026,944 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2009/05/06 00:10:57 | 00,023,152 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2009/05/06 00:10:57 | 00,020,560 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2009/05/06 00:10:41 | 01,256,296 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\aswBoot.exe
[2009/05/06 00:10:41 | 00,380,928 | ---- | C] () -- C:\WINDOWS\System32\actskin4.ocx
[2009/05/06 00:10:39 | 00,000,000 | ---D | C] -- C:\Program Files\Alwil Software
[2009/05/06 00:03:40 | 00,147,100 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2009/05/05 22:11:10 | 00,002,709 | ---- | C] () -- C:\WINDOWS\System32\gibbebx.dat
[2009/05/05 22:10:14 | 00,001,024 | -H-- | C] () -- C:\diskfile1
[2009/05/05 22:10:13 | 00,016,384 | -H-- | C] () -- C:\logicinf.bin
[2009/05/05 21:53:01 | 00,002,709 | ---- | C] () -- C:\WINDOWS\System32\dllgidoor.dat
[2009/04/28 19:05:04 | 00,286,208 | ---- | C] () -- C:\Documents and Settings\David Wilson\Desktop\gmer.exe
[2009/04/23 20:39:11 | 02,988,491 | R--- | C] () -- C:\Documents and Settings\David Wilson\Desktop\ComboFix.exe
[2009/04/22 18:53:37 | 00,000,211 | ---- | C] () -- C:\Boot.bak
[2009/04/22 18:53:35 | 00,260,272 | ---- | C] () -- C:\cmldr
[2009/04/22 18:53:35 | 00,000,000 | RHSD | C] -- C:\cmdcons
[2009/04/22 18:52:40 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2009/04/22 18:52:40 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2009/04/22 18:52:40 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2009/04/22 18:52:40 | 00,117,248 | ---- | C] () -- C:\WINDOWS\vFind.exe
[2009/04/22 18:52:40 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2009/04/22 18:52:40 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2009/04/22 18:52:40 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2009/04/22 18:52:40 | 00,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2009/04/22 18:52:28 | 00,000,000 | ---D | C] -- C:\Qoobox
[2009/04/20 19:43:08 | 00,000,000 | ---D | C] -- C:\rsit
[2009/04/19 18:34:48 | 00,360,021 | ---- | C] () -- C:\something.scr
[2009/04/18 14:49:36 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/04/18 14:49:17 | 00,000,679 | ---- | C] () -- C:\Documents and Settings\David Wilson\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/04/18 14:49:07 | 00,000,523 | ---- | C] () -- C:\Documents and Settings\David Wilson\Desktop\NTREGOPT.lnk
[2009/04/18 14:49:05 | 00,000,504 | ---- | C] () -- C:\Documents and Settings\David Wilson\Desktop\ERUNT.lnk
[2009/04/18 14:49:00 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/04/18 10:10:52 | 00,000,472 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/04/18 10:09:25 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Lavasoft
[2009/04/18 00:21:42 | 00,000,875 | ---- | C] () -- C:\Documents and Settings\David Wilson\Desktop\Spybot - Search & Destroy.lnk
[2009/04/18 00:21:35 | 00,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2009/04/18 00:21:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/04/17 21:04:13 | 00,000,000 | ---D | C] -- C:\Documents and Settings\David Wilson\Application Data\Malwarebytes
[2009/04/17 21:04:10 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/04/17 21:04:10 | 00,000,608 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/04/17 21:04:08 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/04/17 21:04:06 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/04/17 21:04:06 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/04/17 19:53:43 | 00,000,066 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2009/04/17 08:22:21 | 00,000,000 | ---D | C] -- C:\!KillBox
[2009/04/16 21:00:04 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{A21E413E-98CC-4ABB-9843-E6AA4F456F61}
[2008/12/20 18:15:42 | 03,421,371 | ---- | C] () -- C:\WINDOWS\System32\gibbebx.dll
[2008/12/20 18:15:42 | 03,048,796 | ---- | C] () -- C:\WINDOWS\System32\dllgidoor.dll
[2008/10/11 13:52:43 | 00,155,648 | ---- | C] () -- C:\WINDOWS\System32\drivers\DCDisk.sys
[2008/10/11 13:52:43 | 00,077,472 | ---- | C] () -- C:\WINDOWS\System32\drivers\dcsnap.sys
[2008/10/04 12:00:34 | 00,139,430 | ---- | C] () -- C:\WINDOWS\System32\urifil.dll
[2008/10/04 12:00:31 | 00,039,360 | ---- | C] () -- C:\WINDOWS\System32\bugreport.dll
[2008/05/22 18:22:18 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2008/05/22 18:19:46 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dtu100.dll.manifest
[2008/05/22 18:19:46 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dpl100.dll.manifest
[2008/05/22 18:18:54 | 00,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll
[2007/12/08 09:37:39 | 00,000,782 | ---- | C] () -- C:\WINDOWS\System32\snetbonly.dll
[2007/10/21 19:14:25 | 00,334,174 | ---- | C] () -- C:\WINDOWS\sqlite3.dll
[2007/08/18 08:33:06 | 00,390,752 | R--- | C] ( ) -- C:\WINDOWS\System32\drivers\wlanCIG.sys
[2007/08/12 18:04:09 | 00,158,856 | ---- | C] () -- C:\WINDOWS\System32\pxyfil.dll
[2007/07/25 15:24:30 | 01,559,040 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2007/02/14 01:32:38 | 01,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2007/02/14 01:32:38 | 01,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2007/02/14 01:32:36 | 01,470,464 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2007/02/14 01:32:36 | 00,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2007/02/14 01:32:36 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2007/02/14 01:32:36 | 00,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2007/02/14 01:32:32 | 00,212,992 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2007/02/03 12:23:24 | 00,000,004 | -H-- | C] () -- C:\WINDOWS\uccspecb.sys
[2006/02/26 16:08:28 | 00,585,728 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2006/02/22 00:36:14 | 00,000,252 | ---- | C] () -- C:\WINDOWS\System32\SNet.dll
[2006/02/05 19:01:10 | 00,066,048 | ---- | C] () -- C:\WINDOWS\System32\hcwXDS.dll
[2005/07/10 19:34:23 | 00,000,037 | ---- | C] () -- C:\WINDOWS\ipixActivex.ini
[2005/05/22 15:22:22 | 00,000,281 | ---- | C] () -- C:\WINDOWS\irremote.ini
[2005/05/22 15:21:38 | 00,065,536 | ---- | C] () -- C:\WINDOWS\System32\dmcrypto.dll
[2005/05/22 15:21:24 | 00,000,211 | ---- | C] () -- C:\WINDOWS\nanoPEG.ini
[2005/05/22 14:48:36 | 00,002,586 | ---- | C] () -- C:\WINDOWS\HCWPNP.INI
[2005/01/26 17:07:33 | 00,000,000 | ---- | C] () -- C:\WINDOWS\QuickInstall.INI
[2005/01/15 12:23:28 | 00,000,479 | ---- | C] () -- C:\WINDOWS\RAIDeUtility.ini
[2004/12/20 10:59:02 | 00,000,119 | ---- | C] () -- C:\WINDOWS\WSST_Screen_Saver.ini
[2004/10/10 19:32:29 | 00,000,000 | ---- | C] () -- C:\WINDOWS\iPlayer.INI
[2004/08/04 03:56:42 | 00,081,920 | ---- | C] () -- C:\WINDOWS\System32\ieencode.dll
[2004/07/27 16:34:09 | 00,000,031 | ---- | C] () -- C:\WINDOWS\oupdate.INI
[2004/07/25 22:32:36 | 00,524,288 | ---- | C] () -- C:\WINDOWS\System32\TDI-SonyOMG.dll
[2004/07/12 17:38:44 | 00,000,011 | ---- | C] () -- C:\WINDOWS\wanpatan.ini
[2004/07/12 17:38:15 | 00,028,672 | ---- | C] () -- C:\WINDOWS\gscr.dll
[2004/05/15 21:33:31 | 00,001,100 | ---- | C] () -- C:\WINDOWS\System32\imgfil.dll
[2004/04/27 17:49:59 | 00,000,100 | ---- | C] () -- C:\WINDOWS\System32\UNWISE.INI
[2003/11/30 14:39:16 | 00,000,222 | ---- | C] () -- C:\WINDOWS\hpbafd.ini
[2003/09/26 20:07:47 | 00,001,222 | ---- | C] () -- C:\WINDOWS\System32\usrfil.dll
[2003/06/11 18:32:46 | 00,001,842 | ---- | C] () -- C:\WINDOWS\System32\csnews.dll
[2003/03/01 08:08:20 | 00,000,348 | ---- | C] () -- C:\WINDOWS\hegames.ini
[2002/12/10 13:13:32 | 00,172,032 | ---- | C] () -- C:\WINDOWS\System32\GSnap.dll
[2002/12/10 13:13:32 | 00,040,960 | ---- | C] () -- C:\WINDOWS\System32\atlcontrol.dll
[2002/12/10 13:13:32 | 00,036,864 | ---- | C] () -- C:\WINDOWS\System32\UninstGMT.dll
[2002/12/10 13:12:24 | 00,000,494 | ---- | C] () -- C:\WINDOWS\demo.INI
[2002/12/10 01:36:34 | 00,036,864 | ---- | C] () -- C:\WINDOWS\System32\gbttk.dll
[2002/11/11 19:45:00 | 00,036,864 | ---- | C] () -- C:\WINDOWS\System32\NetStat32.dll
[2002/09/25 21:48:36 | 00,109,056 | ---- | C] () -- C:\WINDOWS\System32\LGUICOM.DLL
[2002/09/25 21:48:36 | 00,000,488 | ---- | C] () -- C:\WINDOWS\Cmousecc.ini
[2002/08/15 07:32:26 | 00,022,618 | ---- | C] () -- C:\WINDOWS\System32\perfil.dll
[2002/08/15 07:32:26 | 00,017,672 | ---- | C] () -- C:\WINDOWS\System32\nvgamfil.dll
[2002/08/15 07:32:26 | 00,016,802 | ---- | C] () -- C:\WINDOWS\System32\popfil.dll
[2002/08/15 07:32:26 | 00,014,712 | ---- | C] () -- C:\WINDOWS\System32\tafil.dll
[2002/08/15 07:32:26 | 00,012,730 | ---- | C] () -- C:\WINDOWS\System32\psyfil.dll
[2002/08/15 07:32:26 | 00,012,266 | ---- | C] () -- C:\WINDOWS\System32\sporfil.dll
[2002/08/15 07:32:26 | 00,009,634 | ---- | C] () -- C:\WINDOWS\System32\pkmon.dll
[2002/08/15 07:32:26 | 00,006,830 | ---- | C] () -- C:\WINDOWS\System32\swfil.dll
[2002/08/15 07:32:26 | 00,006,050 | ---- | C] () -- C:\WINDOWS\System32\wrestfil.dll
[2002/08/15 07:32:26 | 00,002,246 | ---- | C] () -- C:\WINDOWS\System32\wzfil.dll
[2002/08/15 07:32:26 | 00,001,656 | ---- | C] () -- C:\WINDOWS\System32\tapfil.dll
[2002/08/15 07:32:26 | 00,000,778 | ---- | C] () -- C:\WINDOWS\System32\mp3fil.dll
[2002/08/15 07:32:26 | 00,000,733 | ---- | C] () -- C:\WINDOWS\System32\spmfil.dll
[2002/08/15 07:32:24 | 00,013,154 | ---- | C] () -- C:\WINDOWS\System32\finfil.dll
[2002/08/15 07:32:24 | 00,012,422 | ---- | C] () -- C:\WINDOWS\System32\entfil.dll
[2002/08/15 07:32:24 | 00,011,338 | ---- | C] () -- C:\WINDOWS\System32\fmfil.dll
[2002/08/15 07:32:24 | 00,009,796 | ---- | C] () -- C:\WINDOWS\System32\gnfil.dll
[2002/08/15 07:32:24 | 00,008,652 | ---- | C] () -- C:\WINDOWS\System32\jbfil.dll
[2002/08/15 07:32:24 | 00,007,778 | ---- | C] () -- C:\WINDOWS\System32\movfil.dll
[2002/08/15 07:32:24 | 00,007,642 | ---- | C] () -- C:\WINDOWS\System32\Auctfil.dll
[2002/08/15 07:32:24 | 00,001,816 | ---- | C] () -- C:\WINDOWS\System32\fshrfil.dll
[2002/08/13 23:28:02 | 00,094,996 | ---- | C] () -- C:\WINDOWS\System32\adwfil.dll
[2002/08/13 23:28:02 | 00,013,034 | ---- | C] () -- C:\WINDOWS\System32\gblfil.dll
[2002/08/13 23:28:02 | 00,010,862 | ---- | C] () -- C:\WINDOWS\System32\chtfil.dll
[2002/08/13 23:28:02 | 00,005,880 | ---- | C] () -- C:\WINDOWS\System32\wfileu.drv
[2002/08/13 23:28:02 | 00,005,260 | ---- | C] () -- C:\WINDOWS\System32\iawfil.dll
[2002/08/13 23:28:02 | 00,004,826 | ---- | C] () -- C:\WINDOWS\System32\vgamfil.dll
[2002/08/13 23:28:02 | 00,004,442 | ---- | C] () -- C:\WINDOWS\System32\hatfil.dll
[2002/08/13 23:28:02 | 00,003,818 | ---- | C] () -- C:\WINDOWS\System32\viofil.dll
[2002/08/13 23:28:02 | 00,003,444 | ---- | C] () -- C:\WINDOWS\System32\srchin.dll
[2002/08/13 23:28:02 | 00,003,360 | ---- | C] () -- C:\WINDOWS\System32\lgwfil.dll
[2002/08/13 23:28:02 | 00,001,830 | ---- | C] () -- C:\WINDOWS\System32\cultfil.dll
[2002/08/13 23:28:02 | 00,001,468 | ---- | C] () -- C:\WINDOWS\System32\gdwfil.dll
[2002/08/13 23:28:02 | 00,000,400 | ---- | C] () -- C:\WINDOWS\bsnlst.dll
[2002/06/04 23:55:32 | 00,000,119 | ---- | C] () -- C:\WINDOWS\NNS.INI
[2002/04/28 14:54:12 | 00,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll
[2002/03/23 11:39:16 | 00,000,011 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.ini
[2002/03/23 10:08:10 | 00,076,659 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2002/03/23 10:08:08 | 00,373,248 | ---- | C] () -- C:\WINDOWS\EyeCand3.INI
[2002/03/23 10:08:08 | 00,003,598 | ---- | C] () -- C:\WINDOWS\HTMLHELP.INI
[2002/03/23 10:08:08 | 00,001,467 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2002/03/23 10:08:08 | 00,000,924 | ---- | C] () -- C:\WINDOWS\fauve.ini
[2002/03/23 10:08:08 | 00,000,787 | ---- | C] () -- C:\WINDOWS\SCANREG.INI
[2002/03/23 10:08:08 | 00,000,677 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2002/03/23 10:08:08 | 00,000,509 | ---- | C] () -- C:\WINDOWS\FS.INI
[2002/03/23 10:08:08 | 00,000,470 | ---- | C] () -- C:\WINDOWS\net2fone.ini
[2002/03/23 10:08:08 | 00,000,459 | ---- | C] () -- C:\WINDOWS\YACHT-Z.INI
[2002/03/23 10:08:08 | 00,000,277 | ---- | C] () -- C:\WINDOWS\SBWIN.INI
[2002/03/23 10:08:08 | 00,000,277 | ---- | C] () -- C:\WINDOWS\AATOOLS.INI
[2002/03/23 10:08:08 | 00,000,233 | ---- | C] () -- C:\WINDOWS\NETSCAPE.INI
[2002/03/23 10:08:08 | 00,000,226 | ---- | C] () -- C:\WINDOWS\QTW.INI
[2002/03/23 10:08:08 | 00,000,221 | ---- | C] () -- C:\WINDOWS\emsoft.ini
[2002/03/23 10:08:08 | 00,000,199 | ---- | C] () -- C:\WINDOWS\swacnfg.ini
[2002/03/23 10:08:08 | 00,000,192 | ---- | C] () -- C:\WINDOWS\mb.ini
[2002/03/23 10:08:08 | 00,000,152 | ---- | C] () -- C:\WINDOWS\LODERUNN.INI
[2002/03/23 10:08:08 | 00,000,149 | ---- | C] () -- C:\WINDOWS\XDCS_DO2.INI
[2002/03/23 10:08:08 | 00,000,144 | ---- | C] () -- C:\WINDOWS\INDEO.INI
[2002/03/23 10:08:08 | 00,000,131 | ---- | C] () -- C:\WINDOWS\chess.ini
[2002/03/23 10:08:08 | 00,000,122 | ---- | C] () -- C:\WINDOWS\PROTOCOL.INI
[2002/03/23 10:08:08 | 00,000,105 | ---- | C] () -- C:\WINDOWS\mapiuid.ini
[2002/03/23 10:08:08 | 00,000,095 | ---- | C] () -- C:\WINDOWS\winamp.ini
[2002/03/23 10:08:08 | 00,000,095 | ---- | C] () -- C:\WINDOWS\icewin.INI
[2002/03/23 10:08:08 | 00,000,089 | ---- | C] () -- C:\WINDOWS\KingsC.ini
[2002/03/23 10:08:08 | 00,000,080 | ---- | C] () -- C:\WINDOWS\entpack.ini
[2002/03/23 10:08:08 | 00,000,072 | ---- | C] () -- C:\WINDOWS\boxworld.ini
[2002/03/23 10:08:08 | 00,000,050 | ---- | C] () -- C:\WINDOWS\winfile.ini
[2002/03/23 10:08:08 | 00,000,042 | ---- | C] () -- C:\WINDOWS\CRISPY.INI
[2002/03/23 10:08:08 | 00,000,031 | ---- | C] () -- C:\WINDOWS\MSCHOMP.INI
[2002/03/23 10:08:08 | 00,000,026 | ---- | C] () -- C:\WINDOWS\MSOFFICE.INI
[2002/03/23 10:08:08 | 00,000,025 | ---- | C] () -- C:\WINDOWS\SOL.INI
[2002/03/23 10:08:08 | 00,000,000 | ---- | C] () -- C:\WINDOWS\SYSCHECK.INI
[2002/03/23 10:08:08 | 00,000,000 | ---- | C] () -- C:\WINDOWS\RESMNGR.INI
[2002/03/23 10:08:08 | 00,000,000 | ---- | C] () -- C:\WINDOWS\progman.ini
[2002/03/23 10:08:08 | 00,000,000 | ---- | C] () -- C:\WINDOWS\PCFRIEND.INI
[2002/03/23 10:08:08 | 00,000,000 | ---- | C] () -- C:\WINDOWS\MSINFO32.INI
[2002/03/23 10:08:08 | 00,000,000 | ---- | C] () -- C:\WINDOWS\hjbrowse.ini
[2002/03/23 10:08:08 | 00,000,000 | ---- | C] () -- C:\WINDOWS\DXINFO.INI
[2002/03/23 10:08:06 | 00,012,327 | ---- | C] () -- C:\WINDOWS\IOS.INI
[2002/03/23 10:08:06 | 00,008,405 | ---- | C] () -- C:\WINDOWS\NETDET.INI
[2002/03/23 10:08:06 | 00,005,068 | ---- | C] () -- C:\WINDOWS\DELETEFI.INI
[2002/03/23 10:08:06 | 00,000,865 | ---- | C] () -- C:\WINDOWS\DOSREP.INI
[2002/03/23 10:08:06 | 00,000,225 | ---- | C] () -- C:\WINDOWS\TELEPHON.INI
[2002/03/23 10:08:06 | 00,000,180 | ---- | C] () -- C:\WINDOWS\winmine.ini
[2002/03/23 10:08:06 | 00,000,127 | ---- | C] () -- C:\WINDOWS\KPCMS.INI
[2002/03/23 10:08:06 | 00,000,068 | ---- | C] () -- C:\WINDOWS\FPXPRESS.INI
[2002/03/23 10:08:06 | 00,000,060 | ---- | C] () -- C:\WINDOWS\POWERPNT.INI
[2002/03/23 10:08:06 | 00,000,054 | ---- | C] () -- C:\WINDOWS\WAVEMIX.INI
[2002/03/23 09:51:34 | 00,049,920 | ---- | C] () -- C:\WINDOWS\System32\drivers\atirtcap.sys
[2002/03/23 09:51:32 | 00,009,472 | ---- | C] () -- C:\WINDOWS\System32\drivers\ativmdcd.sys
[2001/12/27 23:55:26 | 00,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll
[2001/12/27 23:55:26 | 00,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll
[2001/12/17 07:22:30 | 00,210,944 | ---- | C] () -- C:\WINDOWS\System32\MSVCRT10.DLL
[2001/12/17 07:22:28 | 00,027,648 | ---- | C] () -- C:\WINDOWS\PFPICK.DLL
[2001/08/26 15:08:16 | 00,057,344 | ---- | C] () -- C:\WINDOWS\System32\icmfilter.dll
[2001/08/23 12:00:04 | 00,003,166 | ---- | C] () -- C:\WINDOWS\win.ini
[2001/08/23 12:00:04 | 00,000,638 | ---- | C] () -- C:\WINDOWS\system.ini
[2001/05/06 23:59:46 | 00,149,504 | ---- | C] () -- C:\WINDOWS\unwise32.dll
[2001/01/29 00:43:42 | 00,161,792 | ---- | C] () -- C:\WINDOWS\System32\nfsspi.dll
[2001/01/29 00:00:58 | 00,002,048 | ---- | C] () -- C:\WINDOWS\MNMGM32.DLL
[2000/06/22 14:34:24 | 00,088,064 | ---- | C] () -- C:\WINDOWS\System32\AudioExCtl.dll
[2000/06/22 14:33:36 | 00,024,576 | ---- | C] () -- C:\WINDOWS\System32\HcdDll32.dll
[2000/06/22 14:33:36 | 00,005,120 | ---- | C] () -- C:\WINDOWS\System32\HWDll.dll
[2000/06/20 13:11:02 | 00,110,592 | ---- | C] () -- C:\WINDOWS\System32\cdtool.dll
[2000/05/13 16:59:44 | 00,054,266 | ---- | C] () -- C:\WINDOWS\ATM.INI
[2000/05/13 10:27:11 | 00,020,992 | ---- | C] () -- C:\WINDOWS\System32\PFMAPI32.DLL
[2000/05/13 01:08:06 | 00,187,392 | ---- | C] () -- C:\WINDOWS\System32\LTANN62N.DLL
[2000/05/13 01:08:06 | 00,076,288 | ---- | C] () -- C:\WINDOWS\System32\LTIMG62N.DLL
[2000/05/13 01:08:06 | 00,047,616 | ---- | C] () -- C:\WINDOWS\System32\Lftif62n.dll
[2000/05/13 01:08:06 | 00,043,008 | ---- | C] () -- C:\WINDOWS\System32\ltfil62n.dll
[2000/05/13 01:08:06 | 00,029,184 | ---- | C] () -- C:\WINDOWS\System32\LTWND62N.DLL
[2000/05/13 01:08:06 | 00,024,064 | ---- | C] () -- C:\WINDOWS\System32\LTTWN62N.DLL
[2000/05/13 01:08:06 | 00,022,528 | ---- | C] () -- C:\WINDOWS\System32\tvcntl32.dll
[2000/05/13 01:08:06 | 00,020,480 | ---- | C] () -- C:\WINDOWS\System32\Lfpsd62n.dll
[2000/05/13 01:08:06 | 00,019,968 | ---- | C] () -- C:\WINDOWS\System32\Lfwmf62n.dll
[2000/05/13 01:08:06 | 00,019,968 | ---- | C] () -- C:\WINDOWS\System32\Lftga62n.dll
[2000/05/13 01:08:06 | 00,019,456 | ---- | C] () -- C:\WINDOWS\System32\Lfwpg62n.dll
[2000/05/13 01:08:06 | 00,018,432 | ---- | C] () -- C:\WINDOWS\System32\Lfras62n.dll
[2000/05/13 01:08:06 | 00,017,408 | ---- | C] () -- C:\WINDOWS\System32\Lfwfx62n.dll
[2000/05/13 01:08:05 | 00,175,616 | ---- | C] () -- C:\WINDOWS\System32\Lffax62n.dll
[2000/05/13 01:08:05 | 00,158,720 | ---- | C] () -- C:\WINDOWS\System32\Lfcmp62n.dll
[2000/05/13 01:08:05 | 00,110,080 | ---- | C] () -- C:\WINDOWS\System32\Lfpng62n.dll
[2000/05/13 01:08:05 | 00,027,136 | ---- | C] () -- C:\WINDOWS\System32\Lflma62n.dll
[2000/05/13 01:08:05 | 00,024,576 | ---- | C] () -- C:\WINDOWS\System32\Lfica62n.dll
[2000/05/13 01:08:05 | 00,023,552 | ---- | C] () -- C:\WINDOWS\System32\Lfpcx62n.dll
[2000/05/13 01:08:05 | 00,023,552 | ---- | C] () -- C:\WINDOWS\System32\Lflmb62n.dll
[2000/05/13 01:08:05 | 00,022,528 | ---- | C] () -- C:\WINDOWS\System32\Lfeps62n.dll
[2000/05/13 01:08:05 | 00,022,016 | ---- | C] () -- C:\WINDOWS\System32\Lfpct62n.dll
[2000/05/13 01:08:05 | 00,022,016 | ---- | C] () -- C:\WINDOWS\System32\Lfgif62n.dll
[2000/05/13 01:08:05 | 00,022,016 | ---- | C] () -- C:\WINDOWS\System32\Lfbmp62n.dll
[2000/05/13 01:08:05 | 00,018,944 | ---- | C] () -- C:\WINDOWS\System32\Lfimg62n.dll
[2000/05/13 01:08:05 | 00,018,432 | ---- | C] () -- C:\WINDOWS\System32\Lfmsp62n.dll
[2000/05/13 01:08:05 | 00,017,920 | ---- | C] () -- C:\WINDOWS\System32\Lfmac62n.dll
[2000/05/13 01:08:05 | 00,017,920 | ---- | C] () -- C:\WINDOWS\System32\Lfcal62n.dll
[2000/05/13 01:08:05 | 00,017,408 | ---- | C] () -- C:\WINDOWS\System32\Lfpcd62n.dll
[2000/05/13 01:08:00 | 00,162,816 | ---- | C] () -- C:\WINDOWS\System32\ccmpeg.dll
[1999/09/20 10:05:32 | 00,013,387 | ---- | C] () -- C:\WINDOWS\System32\CinemSup.sys
[1998/10/11 00:07:38 | 00,088,576 | ---- | C] () -- C:\WINDOWS\System32\Iticheck.dll
[1998/03/18 02:57:02 | 00,021,504 | ---- | C] () -- C:\WINDOWS\System32\ThmUninst.dll
[1997/07/11 00:00:00 | 00,022,016 | ---- | C] () -- C:\WINDOWS\System32\ODBCSTF.DLL
[1997/07/11 00:00:00 | 00,022,016 | ---- | C] () -- C:\WINDOWS\System32\DOCOBJ.DLL
[1997/07/11 00:00:00 | 00,012,288 | ---- | C] () -- C:\WINDOWS\System32\HLINKPRX.DLL
[1997/06/13 20:56:08 | 00,056,832 | ---- | C] () -- C:\WINDOWS\System32\Iyvu9_32.dll
[1980/01/01 00:00:00 | 00,188,416 | ---- | C] () -- C:\WINDOWS\System32\MEMBG.DLL
[1980/01/01 00:00:00 | 00,129,080 | ---- | C] () -- C:\WINDOWS\Logow.sys.bak
[1980/01/01 00:00:00 | 00,129,078 | ---- | C] () -- C:\WINDOWS\Logos.sys.bak
[1980/01/01 00:00:00 | 00,000,025 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI

========== Files - Modified Within 30 Days ==========

[9 C:\WINDOWS\*.tmp files]
[2009/05/16 08:20:16 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\David Wilson\Desktop\OTListIt2.exe
[2009/05/16 08:16:56 | 00,421,976 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/05/16 08:16:56 | 00,343,762 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/05/16 08:16:56 | 00,069,018 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/05/16 08:14:38 | 00,088,566 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2009/05/16 08:14:10 | 00,012,208 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/05/16 08:14:10 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\David Wilson\Local Settings\desktop.ini
[2009/05/16 08:12:46 | 00,016,384 | -H-- | M] () -- C:\logicinf.bin
[2009/05/16 08:12:44 | 00,001,024 | -H-- | M] () -- C:\diskfile1
[2009/05/16 08:12:36 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/05/16 08:12:30 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/05/16 08:12:28 | 16,101,45792 | -HS- | M] () -- C:\hiberfil.sys
[2009/05/16 08:09:34 | 00,000,230 | ---- | M] () -- C:\WINDOWS\System32\spupdsvc.inf
[2009/05/16 08:06:42 | 00,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2009/05/16 08:06:42 | 00,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2009/05/16 08:05:20 | 03,579,072 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/05/16 08:02:34 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009/05/16 07:53:46 | 00,222,368 | ---- | M] () -- C:\ntldr
[2009/05/15 06:29:02 | 00,000,258 | ---- | M] () -- C:\WINDOWS\tasks\Uninstall Expiration Reminder.job
[2009/05/14 23:12:32 | 00,000,638 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/05/14 22:38:54 | 00,000,875 | ---- | M] () -- C:\Documents and Settings\David Wilson\Desktop\Spybot - Search & Destroy.lnk
[2009/05/14 22:24:26 | 02,988,491 | R--- | M] () -- C:\Documents and Settings\David Wilson\Desktop\ComboFix.exe
[2009/05/14 17:50:10 | 00,117,248 | ---- | M] () -- C:\WINDOWS\vFind.exe
[2009/05/08 11:01:14 | 00,000,000 | --S- | M] () -- C:\WINDOWS\System32\148114617.dat
[2009/05/07 23:33:16 | 16,100,76160 | ---- | M] () -- C:\WINDOWS\MEMORY.DMP
[2009/05/07 22:28:26 | 01,080,054 | ---- | M] () -- C:\Documents and Settings\David Wilson\Desktop\Aquarium 1.bmp
[2009/05/07 22:24:14 | 01,080,056 | ---- | M] () -- C:\Documents and Settings\David Wilson\Desktop\bach.bmp
[2009/05/06 18:41:06 | 00,360,021 | ---- | M] () -- C:\Documents and Settings\David Wilson\Desktop\dds.scr
[2009/05/06 00:11:00 | 00,001,621 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/05/06 00:10:58 | 00,003,021 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2009/05/06 00:03:42 | 00,147,100 | -H-- | M] () -- C:\WINDOWS\System32\mlfcache.dat
[2009/05/05 23:52:10 | 00,003,166 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/05/05 22:16:22 | 00,390,777 | ---- | M] () -- C:\WINDOWS\csfilts.cab
[2009/05/05 22:11:12 | 00,002,709 | ---- | M] () -- C:\WINDOWS\System32\gibbebx.dat
[2009/05/05 21:54:18 | 00,000,039 | ---- | M] () -- C:\WINDOWS\liccyval.dat
[2009/05/05 21:53:02 | 00,002,709 | ---- | M] () -- C:\WINDOWS\System32\dllgidoor.dat
[2009/04/28 19:05:04 | 00,286,208 | ---- | M] () -- C:\Documents and Settings\David Wilson\Desktop\gmer.exe
[2009/04/22 19:05:44 | 00,001,222 | ---- | M] () -- C:\WINDOWS\System32\usrfil.dll
[2009/04/22 19:04:10 | 00,005,880 | ---- | M] () -- C:\WINDOWS\System32\wfileu.drv
[2009/04/22 18:53:38 | 00,000,281 | RHS- | M] () -- C:\boot.ini
[2009/04/20 12:56:28 | 00,031,232 | ---- | M] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2009/04/19 18:29:52 | 00,360,021 | ---- | M] () -- C:\something.scr
[2009/04/18 21:23:04 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/04/18 14:49:18 | 00,000,679 | ---- | M] () -- C:\Documents and Settings\David Wilson\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/04/18 14:49:08 | 00,000,523 | ---- | M] () -- C:\Documents and Settings\David Wilson\Desktop\NTREGOPT.lnk
[2009/04/18 14:49:06 | 00,000,504 | ---- | M] () -- C:\Documents and Settings\David Wilson\Desktop\ERUNT.lnk
[2009/04/18 10:10:54 | 00,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/04/17 21:04:12 | 00,000,608 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/04/17 19:53:44 | 00,000,066 | ---- | M] () -- C:\WINDOWS\wininit.ini
< End of report >

proskoma
2009-05-16, 14:33
OTListIt Extras logfile created on: 5/16/2009 8:21:00 AM - Run 1
OTListIt2 by OldTimer - Version 2.0.15.8 Folder = C:\Documents and Settings\David Wilson\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: enu | Date Format: M/d/yyyy

1.50 Gb Total Physical Memory | 0.98 Gb Available Physical Memory | 65.64% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): [Binary data over 100 bytes]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 109.82 Gb Total Space | 30.66 Gb Free Space | 27.92% Space Free | Partition Type: FAT32
Drive D: | 8.09 Gb Total Space | 6.72 Gb Free Space | 83.06% Space Free | Partition Type: FAT32
Drive E: | 55.88 Gb Total Space | 30.61 Gb Free Space | 54.77% Space Free | Partition Type: FAT32
Drive F: | 39.21 Gb Total Space | 25.54 Gb Free Space | 65.13% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DAVEHOME
Current User Name: David Wilson
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l
.js [@ = JSFile] -- E:\Program Files\Macromedia\Dreamweaver 4\Dreamweaver.exe (Macromedia, Inc.)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"3389:TCP" = 3389:TCP:*:Disabled:@xpsp2res.dll,-22009

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[2006/10/10 08:44:50 | 00,557,568 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
File not found -- C:\WINDOWS\Cyb2k.exe:*:Enabled:CYBERsitter Control Panel
[2006/12/10 17:06:56 | 03,364,168 | ---- | M] (Headlight Software, Inc.) -- E:\Program Files\GetRight\getright.exe:*:Enabled:GetRightŪ www.getright.com
[2000/06/27 16:09:58 | 02,695,213 | ---- | M] (Microsoft Corporation) -- E:\Age of Empires II\Age2_X1\AGE2_X1.ICD:*:Enabled:Age of Empires II Expansion
[2000/11/20 18:53:28 | 06,483,968 | ---- | M] (Macromedia, Inc.) -- E:\Program Files\Macromedia\Dreamweaver 4\Dreamweaver.exe:*:Enabled:Dreamweaver
[2006/12/02 09:21:20 | 02,672,640 | ---- | M] (Digital Information Network) -- C:\Program Files\Common Files\Doppler 10 Pinpoint Alert\TrueWeather.exe:*:Enabled:TrueWeather
File not found -- C:\Program Files\SnapStream Media\Beyond TV 3\PVSLibraryAppService.exe:*:Enabled:Beyond TV Library Service
File not found -- C:\Program Files\SnapStream Media\Beyond TV 3\BTVWebServer.exe:*:Enabled:Beyond TV Web Server
File not found -- C:\Program Files\SnapStream Media\Beyond TV 3\BTVRecordingEngine.exe:*:Enabled:Beyond TV Recording Engine
File not found -- C:\Program Files\SnapStream Media\Beyond TV 3\BTVGuideDataLoader.exe:*:Enabled:Beyond TV Guide Data Loader
File not found -- C:\Program Files\SnapStream Media\Beyond TV 3\PVSConfigService.exe:*:Enabled:Beyond TV Settings Service
File not found -- C:\Program Files\SnapStream Media\Beyond TV 3\BTVD3DShell.exe:*:Enabled:Beyond TV ViewScape
[2004/08/04 03:56:52 | 00,815,104 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\mmc.exe:*:Enabled:Microsoft Management Console
File not found -- E:\Program Files\ICQ\Icq.exe:*:Enabled:ICQ
File not found -- C:\Program Files\SnapStream Media\Beyond TV 3\BTVRegistrationService.exe:*:Enabled:Beyond TV Registration Service
File not found -- C:\Program Files\SnapStream Media\Beyond TV 3\BTVWebServiceProxy.exe:*:Enabled:Beyond TV Web Service Proxy
File not found -- C:\Program Files\SnapStream Media\Beyond TV 3\BTVLibraryService.exe:*:Enabled:Beyond TV Library Service
File not found -- C:\Program Files\SnapStream Media\Beyond TV 3\BTVNetworkService.exe:*:Enabled:Beyond TV Network Service
File not found -- C:\Program Files\Grisoft\AVG Free\avgw.exe:*:Enabled:AVG Free Edition for Windows
File not found -- C:\Program Files\Grisoft\AVG Free\avgvv.exe:*:Enabled:AVG Free Virus Vault
File not found -- C:\Program Files\SnapStream Media\Beyond TV 3\BTVSettingsService.exe:*:Enabled:Beyond TV Settings Service
File not found -- C:\Program Files\SnapStream Media\Beyond TV 3\BTVTaskManagerService.exe:*:Enabled:Beyond TV Task Manager Service
[2001/10/12 20:36:42 | 04,102,275 | ---- | M] () -- E:\Program Files\Sierra\Empire Earth\Empire Earth.exe:*:Enabled:Empire Earth
[2005/03/11 14:40:32 | 00,291,792 | ---- | M] (RealVNC Ltd.) -- C:\Program Files\RealVNC\VNC4\vncviewer.exe:*:Enabled:VNC Viewer Free Edition for Win32
[2006/12/13 17:48:32 | 00,079,360 | ---- | M] (Opera Software) -- F:\Program Files\Opera\Opera.exe:*:Enabled:Opera Internet Browser
[2006/10/10 08:44:50 | 00,557,568 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
File not found -- C:\Program Files\Grisoft\AVG7\avginet.exe:*:Enabled:avginet.exe
File not found -- C:\Program Files\Grisoft\AVG7\avgamsvr.exe:*:Enabled:avgamsvr.exe
File not found -- C:\Program Files\Grisoft\AVG7\avgcc.exe:*:Enabled:avgcc.exe
File not found -- C:\Program Files\Grisoft\AVG7\avgemc.exe:*:Enabled:avgemc.exe
[2003/01/13 03:50:18 | 00,122,880 | R--- | M] (Electronic Arts) -- C:\Program Files\EA Games\Command and Conquer Generals\patchget.dat:*:Disabled:patchgrabber
File not found -- E:\Program Files\Real\RealOne Player\realplay.exe:*:Disabled:RealOne Player
File not found -- C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Disabled:Yahoo! FT Server
[2004/08/06 15:33:46 | 02,502,656 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\Messenger\YPager.exe:*:Disabled:Yahoo! Messenger
File not found -- C:\Program Files\SnapStream Media\Beyond TV 3\SetupWizard.exe:*:Enabled:Beyond TV Setup Wizard
[2007/04/02 12:23:34 | 00,035,160 | ---- | M] (SnapStream Media) -- C:\Program Files\SnapStream Media\Beyond TV\BTVRegistrationService.exe:*:Enabled:Beyond TV Registration Service
[2007/04/02 12:20:58 | 00,057,344 | ---- | M] (SnapStream Media) -- C:\Program Files\SnapStream Media\Beyond TV\BTVLibraryService.exe:*:Enabled:Beyond TV Library Service
[2007/04/02 12:20:54 | 00,065,536 | ---- | M] (SnapStream Media) -- C:\Program Files\SnapStream Media\Beyond TV\BTVNetworkService.exe:*:Enabled:Beyond TV Network Service
[2007/04/02 12:15:56 | 00,065,536 | ---- | M] (SnapStream Media) -- C:\Program Files\SnapStream Media\Beyond TV\BTVRecordingEngine.exe:*:Enabled:Beyond TV Recording Engine
[2007/04/02 12:16:36 | 00,139,264 | ---- | M] (SnapStream Media) -- C:\Program Files\SnapStream Media\Beyond TV\BTVGuideDataLoader.exe:*:Enabled:Beyond TV Guide Data Loader
[2007/04/02 12:13:38 | 00,086,016 | ---- | M] (SnapStream Media) -- C:\Program Files\SnapStream Media\Beyond TV\BTVSettingsService.exe:*:Enabled:Beyond TV Settings Service
[2007/04/02 12:20:42 | 00,204,800 | ---- | M] (SnapStream Media) -- C:\Program Files\SnapStream Media\Beyond TV\BTVTaskManagerService.exe:*:Enabled:Beyond TV Task Manager Service
[2007/04/02 12:22:42 | 00,180,224 | ---- | M] (SnapStream Media, Inc.) -- C:\Program Files\SnapStream Media\Beyond TV\BTVD3DShell.exe:*:Enabled:Beyond TV ViewScape
[2007/04/02 12:23:34 | 07,761,224 | ---- | M] (SnapStream Media, Inc.) -- C:\Program Files\SnapStream Media\Beyond TV\SetupWizard.exe:*:Enabled:Beyond TV Setup Wizard
[2007/04/02 12:21:18 | 00,031,232 | ---- | M] (SnapStream Media) -- C:\Program Files\SnapStream Media\Beyond TV\BTVWebServiceProxy.exe:*:Enabled:Beyond TV Web Service Proxy
File not found -- C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour
[2008/11/20 13:20:48 | 14,294,824 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{06F80017-8F98-4C94-B868-52358569FC32}" = Command & Conquer Generals
"{07B02BD4-E799-4945-B240-166CA9A9BE2D}" = Multimedia Card Reader
"{0C3B9465-E882-11D3-BF71-00C04FA0D6AE}" = NovaBACKUP
"{15095BF3-A3D7-4DDF-B193-3A496881E003}" = Microsoft .NET Framework 3.0
"{15D91706-6ADF-44CF-9D7D-FF2D8ACD2C6F}" = LS_HSI
"{179C8887-E768-4FF6-9008-1F665AD9F6FC}" = TPP Storage Class Driver
"{17F44736-17BF-4ACE-910E-A743C5D55129}" = Sonic CinePlayer MPEG Combo Pack
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{18DF995F-2ACC-47E4-A33B-A703F4D39E92}" = CuteFTP 5.0 XP
"{2227E1FA-01F5-483C-AB0E-2A308E900B3D}" = InterVideo FilterSDK for Hauppauge
"{2447500B-22D7-47BD-9B13-1A927F43A267}" = Empire Earth
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java(TM) 6 Update 13
"{26C849AB-1865-412D-B87D-B18BC5CB6C60}" = OpenMG Secure Module 3.4.01
"{28638102-02DB-43C5-9358-7596ED0FCBC2}" = Ten Thumbs Typing Tutor
"{312DFE8A-7B3A-41D4-AB00-52ACDB05ABE2}" = Ten Thumbs 4.3
"{31851B85-C98E-44DE-8750-9843BCD63963}" = Adobe After Effects 5.5
"{318AB667-3230-41B5-A617-CB3BF748D371}" = iTunes
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{372FB8CA-E690-4FB2-B2DB-649768691561}" = NovaBACKUP
"{3EDFFD11-B9AB-4296-9757-B5AF1F2B8E5C}" = Beyond TV DVD Burning Foundation
"{412033BC-44CF-48D9-B813-4B835101F4D3}" = Adobe Illustrator 10.0.3
"{491DD792-AD81-429C-9EB4-86DD3D22E333}" = Windows Communication Foundation
"{4C93C363-414E-11D4-9756-00C04F8EEB39}" = Macromedia Flash 5
"{5809E7CF-4DCF-11D4-9875-00105ACE7734}" = Logitech MouseWare 9.41 .1
"{582D2A53-F426-4C5E-A2E6-43C1AB36B907}" = Safari
"{5D312C74-93CA-4B79-BEBB-95D3982379E1}" = VBA (3821h)
"{5D582D33-EB35-4D77-B7AF-403322D947E6}" = Opera 9.10
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6A750221-B84D-419D-B11C-5F597FDBA826}" = Movavi Video Converter 6
"{6BE2A4A4-99FB-48ED-AE1E-4E850389F804}" = PartitionMagic
"{71AE4702-5C47-43BB-BDD6-21C84D086B82}" = Tweaki...for Power Users
"{71D6CE84-B7DC-4166-8E0D-56C1C37BFB5A}" = SonicStage
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7D1B85BD-AA07-48B8-808D-67A4067FC6BD}" = Windows Workflow Foundation
"{7F1B3341-A94E-4F5C-B587-CA0EB964221E}" = Microsoft Money Shared Libraries
"{8287E5A6-A0D1-4074-B149-F6157EE0DEEB}" = NEC-Mitsubishi NaViSet
"{84031A18-BA9A-4156-A74F-E05B52DDFCE2}" = DING!
"{87F93AA6-C062-40AC-970F-DEE3628548D9}" = CYBERsitter 10
"{89818D7D-C128-4DC2-8DC8-326DC904969C}" = Roxio Easy Media Creator 7
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8DCE550C-CA43-4E82-92DF-FFC4A48F5BE1}" = Roxio Burn Engine
"{8EF1122E-E90C-4EE9-AB0C-7FDE2BA42C26}" = MusicmatchŪ Jukebox
"{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{96F702F3-7CA4-41B5-A70A-4F348DF99A9A}" = Myst IV - Revelation
"{97AE00A8-1336-410F-B467-1C6623127BD6}" = DesignPro 5.0 Limited Edition
"{97E38F11-0FBE-4BC2-9EE1-5B1421C76F27}" = Adobe GoLive 6.0
"{9CD51F8E-A936-46D2-93BA-140D3F08BDD6}" = Eudora
"{A0B295C3-FD3C-11D4-A811-0090279106C3}" = WordPerfect Office 2002
"{A36BE275-BD22-406C-8D2D-ED99F9E6C0B4}" = IKEA HomePlanner Kitchen
"{A3BC5D37-30F9-4CF7-BD5C-0DFF063E4B6D}" = 2Wire Wireless Client
"{A5BA14E0-7384-11D4-BAE7-00409631A2C8}" = Macromedia Extension Manager
"{A654A805-41D9-40C7-AA46-4AF04F044D61}" = AdobeŪ PhotoshopŪ Album Starter Edition 3.2
"{ABDA9912-5D00-11D4-BAE7-9367CA097955}" = Macromedia Dreamweaver 4
"{AC76BA86-7AD7-1033-7B44-A71000000002}" = Adobe Reader 7.1.0
"{AC76BA86-7AD7-5464-3428-7050000000A7}" = Adobe Reader 7.0.5 Language Support
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B37C842A-B624-46B8-A727-654E72F1C91A}" = Calculator Powertoy for Windows XP
"{B3E3EAEC-A20E-48EE-B161-A43B552D5465}" = Personal Color Viewer 2.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BBAAACFA-B012-4367-ADDA-4DDCDFD48F96}" = Norton Ghost
"{BBBCAE4B-B416-4182-A6F2-438180894A81}" = Napster
"{BCE72AED-3332-4863-9567-C5DCB9052CA2}" = Netflix Movie Viewer
"{C7793EE8-F666-4E6B-9827-76468679480E}" = Tweakui Powertoy for Windows XP
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}" = getPlus(R) for Adobe
"{D8C2C5B1-1A88-4B87-9116-59D082B1CE30}" = Visual Studio 2005 Redist Package
"{E86496D9-5009-4FFF-AABD-6E62CDFAC7B7}" = Beyond TV DVD Burning Foundation
"{E89D78B8-28F7-412F-8B26-C684739CBBDC}" = Palm Desktop
"{EB091860-8C2B-4E49-A543-666373C39E6F}" = microKORG SoundEditor
"{EC4455AB-F155-4CC1-A4C5-88F3777F9886}" = Apple Mobile Device Support
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F3E9C243-122E-4D6B-ACC1-E1FEC02F6CA1}" = Command and ConquerTM Generals Zero Hour
"{F8722041-B63A-47FB-82A8-5F0977E1CF45}" = TWC Customer Controls
"{F958CA02-BB40-4007-894B-258729456EE4}" = QuickTime
"123 Free Solitaire" = 123 Free Solitaire
"1Click DVD to Divx Avi 2.12_is1" = 1Click DVD to Divx Avi 2.12
"AccuChef" = AccuChef
"Active Disk" = Active Disk
"Actual Checkers 2000 R_is1" = Actual Checkers 2000 R
"Adaptec EZ-SCSI Standard Edition 5.0" = Adaptec EZ-SCSI Standard Edition 5.0
"Adobe Atmosphere Player" = Adobe Atmosphere Player for Acrobat and Adobe Reader
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player Plugin
"Adobe PageMaker 6.5" = Adobe PageMaker 6.5
"Adobe Photoshop 6.0" = Adobe Photoshop 6.0
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"Adobe SVG Viewer" = Adobe SVG Viewer 3.0
"Adobe Type Manager Deluxe 4.1" = Adobe Type Manager Deluxe 4.1
"AdobeŪ PhotoshopŪ Album Starter Edition 3.2" = AdobeŪ PhotoshopŪ Album Starter Edition 3.2
"Age of Empires 2.0" = Microsoft Age of Empires II
"AniRez" = AniRez
"ATI Display Driver" = ATI Display Driver
"ATI Multimedia Center" = ATI Multimedia Center
"audcle" = Plus! MP3 Audio Converter LE
"Autodesk DWF Viewer" = Autodesk DWF Viewer
"avast!" = avast! Antivirus
"AWSPS 4.02" = AWSPS 4.02
"Beyond TV" = SnapStream Beyond TV 4.6.1
"Chessmaster 8000" = Chessmaster 8000
"Cover Art Downloader_is1" = Cover Art Downloader v1.2
"c--program files-readmagic" = REALmagic Hollywood Plus
"dBpowerAMP Music Converter" = dBpowerAMP Music Converter
"DECCHECK" = Microsoft Windows XP Video Decoder Checkup Utility
"Desktop Architect" = Desktop Architect
"Dialog Box Assistant_is1" = Dialog Box Assistant 1.01
"Director 8 Shockwave Studio" = Director 8 Shockwave Studio
"DirectVobSub" = DirectVobSub (remove only)
"Doppler 10 Pinpoint Alert" = Doppler 10 Pinpoint Alert
"DR-92 Manager" = DR-92 Manager
"Elecard MPEG Player 5.3.80624" = Elecard MPEG Player
"Enable S3 for USB Device" = Enable S3 for USB Device
"ERUNT_is1" = ERUNT 1.1j
"FastTrak RAID controller utility" = FastTrak RAID controller utility
"Firefly Mini" = SnapStream Firefly Mini 1.0.2
"FontLook" = FontLook
"GetRight" = GetRight
"GoldLeo DVD Ripper_is1" = GoldLeo DVD Ripper 2.2
"Hauppauge WinTV Scheduler" = Hauppauge WinTV Scheduler
"Hauppauge WinTV2000" = Hauppauge WinTV2000
"Hauppauge WinTV-PVR 150 Drivers" = Hauppauge WinTV-PVR 150 Drivers
"HijackThis" = HijackThis 2.0.2
"hp deskjet 840c series" = hp deskjet 840c series (Remove only)
"hp deskjet 840c series_Driver" = hp deskjet 840c series
"HTMLPad 2004 Pro_is1" = HTMLPad 2004 Pro v5.0
"HyperCD" = HyperCD
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"InstallShield_{06F80017-8F98-4C94-B868-52358569FC32}" = Command & Conquer Generals
"InstallShield_{07B02BD4-E799-4945-B240-166CA9A9BE2D}" = Multimedia Card Reader
"InstallShield_{8287E5A6-A0D1-4074-B149-F6157EE0DEEB}" = NEC-Mitsubishi NaViSet
"InstallShield_{97AE00A8-1336-410F-B467-1C6623127BD6}" = DesignPro 5.0 Limited Edition
"InstallShield_{F3E9C243-122E-4D6B-ACC1-E1FEC02F6CA1}" = Command and ConquerTM Generals Zero Hour
"Iomega App Services" = Iomega App Services
"IomegaWare" = IomegaWare
"iSofter DVD Ripper Platinum_is1" = iSofter DVD Ripper Platinum 3.0.2007.228
"LiveUpdate" = LiveUpdate 2.5 (Symantec Corporation)
"Macromedia FreeHand 9" = Macromedia FreeHand 9
"Macromedia Generator 2" = Macromedia Generator 2
"Macromedia Shockwave Player" = Macromedia Shockwave Player
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Media Cleaner Pro402a" = Media Cleaner Pro
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.0" = Microsoft .NET Framework 3.0
"Microsoft Interactive CD Sampler" = Microsoft Interactive CD Sampler
"mmmusic" = Movie Maker Background Music Files
"mmsounds" = Movie Maker Sound Effects
"mmtitle" = Movie Maker Title Images
"Money2008b" = Microsoft Money Plus
"Mozilla Firefox (2.0.0.8)" = Mozilla Firefox (2.0.0.8)
"mplibwiz.inf" = Media Library Management Wizard
"mpxlswiz.inf" = Windows Media Player Playlist Import to Excel Wizard
"mpxptray.inf" = Windows Media Player Tray Control
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSN Entertainment Download Troubleshooter" = MSN Entertainment Download Troubleshooter
"MSN Music Assistant" = MSN Music Assistant
"Musicnotes Player_is1" = Musicnotes Player V1.23.1 and Viewer
"MVApplication1" = SureThing CD Labeler 4 SE
"MySQL Connector/ODBC 3.51" = MySQL Connector/ODBC 3.51
"nanoPEG-Editor 2.2 Hauppauge Edition_is1" = nanoPEG-Editor 2.2 Hauppauge Edition
"NetAccountability" = NetAccountability
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"OpenMG HotFix3.4-04-14-17-01" = OpenMG Limited Patch 3.4-04-16-16-01
"PicasaNet" = Hello (remove only)
"PolderbitSRecorder" = PolderbitS Sound Recorder and Editor
"QTam Bitmap to Icon_is1" = QTam Bitmap to Icon 3.5
"RDStudio5" = Ray Dream Studio v5.0
"RealAlt_is1" = Real Alternative 1.52 Lite
"REALmagic Hollywood Plus" = REALmagic Hollywood Plus
"RealVNC_is1" = VNC Free Edition 4.1.1
"Red Alert" = Red Alert Windows 95
"Red Alert 2" = Command & Conquer Red Alert 2
"SCRABBLE" = SCRABBLE
"Shockwave" = Shockwave
"Sid Meier's Alpha Centauri" = Sid Meier's Alpha Centauri
"SimCity 3000" = SimCity 3000
"Sound Blaster PCI128" = Sound Blaster PCI128
"SuperDVD Player_is1" = SuperDVD Player V4.0
"Tiberian Sun" = Command & Conquer Tiberian Sun
"TrayDay" = TrayDay
"USB 2.0 Host Controller Driver" = USB 2.0 Host Controller Driver
"wa2wmp" = Windows Media Player Skin Importer
"WavePad" = WavePad Uninstall
"wdtmgmt" = Microsoft Word 97 Time Mgmt Wizard Pack (Remove only)
"WhatsMyDNS" = Solid Oak Software WhatsMyDNS 1.8.2.23
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinRAR archiver" = WinRAR archiver
"WinZip" = WinZip
"WMBK2" = Windows Media Bonus Pack for Windows XP
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"WMV9_VCM" = Microsoft Windows Media Video 9 VCM
"WOLAPI" = Westwood Shared Internet Components
"WordPerfect Office 2002" = WordPerfect Office 2002
"Wtcc II" = Wtcc II
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"XviD_is1" = XviD MPEG-4 Video Codec
"Yuri's Revenge" = Command && Conquer Red Alert 2 - Yuri's Revenge

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer

========== Last 10 Event Log Errors ==========

[ Antivirus Events ]
Error - 5/15/2009 7:03:09 AM | Computer Name = DAVEHOME | Source = avast! | ID = 33554522
Description = Error in aswChestS: chest s_NewFile Error 112.

Error - 5/15/2009 7:03:09 AM | Computer Name = DAVEHOME | Source = avast! | ID = 33554522
Description = Error in aswChestC: chestAddFile Error 112.

Error - 5/15/2009 7:03:59 AM | Computer Name = DAVEHOME | Source = avast! | ID = 33554522
Description = Error in aswChestS: chest s_NewFile Error 112.

Error - 5/15/2009 7:03:59 AM | Computer Name = DAVEHOME | Source = avast! | ID = 33554522
Description = Error in aswChestC: chestAddFile Error 112.

Error - 5/15/2009 7:04:02 AM | Computer Name = DAVEHOME | Source = avast! | ID = 33554522
Description = Error in aswChestS: chest s_NewFile Error 112.

Error - 5/15/2009 7:04:02 AM | Computer Name = DAVEHOME | Source = avast! | ID = 33554522
Description = Error in aswChestC: chestAddFile Error 112.

Error - 5/15/2009 7:07:59 AM | Computer Name = DAVEHOME | Source = avast! | ID = 33554522
Description = Error in aswChestS: chest s_NewFile Error 112.

Error - 5/15/2009 7:07:59 AM | Computer Name = DAVEHOME | Source = avast! | ID = 33554522
Description = Error in aswChestC: chestAddFile Error 112.

[ Application Events ]
Error - 5/15/2009 7:12:47 AM | Computer Name = DAVEHOME | Source = nview_info | ID = 11141121
Description =

Error - 5/15/2009 7:12:47 AM | Computer Name = DAVEHOME | Source = nview_info | ID = 11141121
Description =

Error - 5/15/2009 7:12:47 AM | Computer Name = DAVEHOME | Source = nview_info | ID = 11141121
Description =

Error - 5/15/2009 7:12:49 AM | Computer Name = DAVEHOME | Source = nview_info | ID = 11141121
Description =

Error - 5/15/2009 7:12:49 AM | Computer Name = DAVEHOME | Source = nview_info | ID = 11141121
Description =

Error - 5/15/2009 7:12:49 AM | Computer Name = DAVEHOME | Source = nview_info | ID = 11141121
Description =

Error - 5/15/2009 7:12:49 AM | Computer Name = DAVEHOME | Source = nview_info | ID = 11141121
Description =

Error - 5/15/2009 7:12:49 AM | Computer Name = DAVEHOME | Source = nview_info | ID = 11141121
Description =

Error - 5/15/2009 7:12:49 AM | Computer Name = DAVEHOME | Source = nview_info | ID = 11141121
Description =

Error - 5/15/2009 7:12:58 AM | Computer Name = DAVEHOME | Source = nview_info | ID = 11141121
Description =

[ System Events ]
Error - 5/16/2009 8:06:18 AM | Computer Name = DAVEHOME | Source = SRService | ID = 104
Description = The System Restore initialization process failed.

Error - 5/16/2009 8:06:28 AM | Computer Name = DAVEHOME | Source = Service Control Manager | ID = 7000
Description = The ATI WDM Specialized MVD Codec service failed to start due to the
following error: %%1058

Error - 5/16/2009 8:06:28 AM | Computer Name = DAVEHOME | Source = Service Control Manager | ID = 7000
Description = The Upload Manager service failed to start due to the following error:
%%1079

Error - 5/16/2009 8:06:28 AM | Computer Name = DAVEHOME | Source = Service Control Manager | ID = 7023
Description = The System Restore Service service terminated with the following error:
%%1359

Error - 5/16/2009 8:06:34 AM | Computer Name = DAVEHOME | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Cdr4_xp

Error - 5/16/2009 8:12:51 AM | Computer Name = DAVEHOME | Source = SRService | ID = 104
Description = The System Restore initialization process failed.

Error - 5/16/2009 8:12:57 AM | Computer Name = DAVEHOME | Source = Service Control Manager | ID = 7000
Description = The ATI WDM Specialized MVD Codec service failed to start due to the
following error: %%1058

Error - 5/16/2009 8:12:57 AM | Computer Name = DAVEHOME | Source = Service Control Manager | ID = 7000
Description = The Upload Manager service failed to start due to the following error:
%%1079

Error - 5/16/2009 8:12:57 AM | Computer Name = DAVEHOME | Source = Service Control Manager | ID = 7023
Description = The System Restore Service service terminated with the following error:
%%1359

Error - 5/16/2009 8:13:04 AM | Computer Name = DAVEHOME | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Cdr4_xp


< End of report >

Blade81
2009-05-16, 18:27
Hi

Uninstall Firefox 2.0.0.8 since 2.x.x.x series is not supported anymore. If you still want to use Firefox then you may get the latest version here (http://getfirefox.net/) later.

Uninstall old Adobe Reader versions and get the latest one here (http://www.filehippo.com/download_adobe_reader/) or get Foxit Reader here (http://www.foxitsoftware.com/pdf/reader_2/down_reader.htm). Make sure you don't install toolbar if choose Foxit Reader! You may also check free readers introduced here (http://pdfreaders.org/).

Uninstall also CYBERsitter.

Reboot and create new OTListIt.txt log. Has the issue status changed after IE7 uninstallation?

proskoma
2009-05-18, 04:59
uninstalling IE7 made no alteration to the problems - cybersitter was uninstalled a few weeks ago - any references to it in logs are bits it left behind

Should we not be working on figuring out what exactly is launching the instance of the iexplore.exe process which appears at each launch of windows?

I still have a directory c:\Program Files\Internet Explorer even after the uninstall. I tried renaming the iexplore.exe application in that directory to another name and a few seconds later iexplore.exe appeared again in that same directory.

Windows continues to start with one instance of iexplore.exe which then multiplies with each navigation double-click my computer and the various hard drives.

This link describes part of my problem - any thots on the solution it suggests:

http://dly.free.fr/site/spip.php?article2


Followed your advise - uninstalled and then installed newest versions of Firefox and Acrobat Reader. New OT List follows.

proskoma
2009-05-18, 05:00
OTListIt logfile created on: 5/17/2009 10:55:55 PM - Run 2
OTListIt2 by OldTimer - Version 2.0.15.8 Folder = C:\Documents and Settings\David Wilson\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: enu | Date Format: M/d/yyyy

1.50 Gb Total Physical Memory | 0.99 Gb Available Physical Memory | 66.08% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): [Binary data over 100 bytes]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 109.82 Gb Total Space | 30.65 Gb Free Space | 27.91% Space Free | Partition Type: FAT32
Drive D: | 8.09 Gb Total Space | 6.72 Gb Free Space | 83.06% Space Free | Partition Type: FAT32
Drive E: | 55.88 Gb Total Space | 30.61 Gb Free Space | 54.77% Space Free | Partition Type: FAT32
Drive F: | 39.21 Gb Total Space | 25.50 Gb Free Space | 65.05% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DAVEHOME
Current User Name: David Wilson
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - [2009/02/05 16:01:26 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2009/02/05 16:08:40 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2008/11/07 14:28:16 | 00,132,424 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2008/06/17 16:16:32 | 00,176,128 | ---- | M] () -- C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\CBP\DCSchdler.exe
PRC - [2000/11/15 18:53:04 | 00,237,568 | ---- | M] (Promise Technology Inc.) -- C:\Program Files\Promise\FastTrak\FtrakSvc.exe
PRC - [2003/12/17 15:51:44 | 00,200,704 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
PRC - [2002/01/14 07:49:38 | 00,073,728 | ---- | M] (Iomega Corporation) -- C:\Program Files\Iomega\System32\AppServices.exe
PRC - [2009/05/05 22:38:38 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2005/02/22 16:32:14 | 00,038,912 | ---- | M] () -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe
PRC - [2008/06/17 16:56:16 | 00,207,936 | ---- | M] (NovaStor) -- C:\Program Files\NovaStor\NovaStor NovaBACKUP\NsService.exe
PRC - [2007/02/14 01:32:36 | 00,159,811 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe
PRC - [2008/06/17 16:23:48 | 00,093,248 | ---- | M] () -- C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\Fsloader.exe
PRC - [2001/08/23 12:00:00 | 00,019,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\tcpsvcs.exe
PRC - [2006/11/20 03:42:46 | 00,033,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\snmp.exe
PRC - [2002/01/24 16:10:40 | 00,126,976 | ---- | M] (Iomega Corporation) -- C:\Program Files\Iomega\AutoDisk\ADService.exe
PRC - [2009/02/05 16:08:26 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
PRC - [2009/02/05 16:06:04 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PRC - [2007/06/13 06:23:08 | 01,033,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2004/08/04 03:56:58 | 00,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wscntfy.exe
PRC - [2004/04/13 19:45:30 | 00,290,905 | ---- | M] (Conexant Systems, Inc.) -- C:\WINDOWS\system32\PRISMSVR.EXE
PRC - [2008/11/20 13:20:54 | 00,290,088 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2002/08/20 10:29:26 | 00,040,960 | ---- | M] (Easy Systems Japan Ltd.) -- C:\WINDOWS\system32\ezSP_Px.exe
PRC - [2009/05/05 22:38:38 | 00,148,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2009/02/05 16:08:46 | 00,081,000 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashDisp.exe
PRC - [2009/02/27 17:10:28 | 00,035,696 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
PRC - [2009/03/05 16:07:20 | 02,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2004/04/13 20:47:56 | 00,335,979 | ---- | M] (2Wire Inc.) -- C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.exe
PRC - [2002/10/22 06:50:00 | 00,204,800 | ---- | M] (MJMSoft Design Limited) -- C:\Program Files\TrayDay\TrayDay.exe
PRC - [2008/11/20 13:20:44 | 00,536,872 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe
PRC - [2004/08/04 03:56:58 | 00,135,680 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\taskmgr.exe
PRC - [2004/08/04 03:56:50 | 00,093,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\iexplore.exe
PRC - [2009/05/16 08:20:16 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\David Wilson\Desktop\OTListIt2.exe

========== Win32 Services (SafeList) ==========

SRV - [2008/11/07 14:28:16 | 00,132,424 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running])
SRV - [2007/10/24 01:47:22 | 00,033,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2009/02/05 16:01:26 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv [Auto | Running])
SRV - [2000/11/30 14:30:40 | 00,057,344 | ---- | M] () -- C:\WINDOWS\System32\Ati2evxx.exe -- (Ati HotKey Poller [Auto | Stopped])
SRV - [2009/02/05 16:08:40 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus [Auto | Running])
SRV - [2009/02/05 16:08:26 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner [On_Demand | Running])
SRV - [2009/02/05 16:06:04 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner [On_Demand | Running])
SRV - [2008/06/17 16:16:36 | 00,098,304 | ---- | M] () -- C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\CBP\DCSchdlerSRVC.exe -- (Backup Scheduler [Auto | Stopped])
SRV - [2007/10/24 01:47:40 | 00,070,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2000/11/15 18:53:04 | 00,237,568 | ---- | M] (Promise Technology Inc.) -- C:\Program Files\Promise\FastTrak\FtrakSvc.exe -- (FastTrakSvc [Auto | Running])
SRV - [2006/10/20 21:21:24 | 00,036,864 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008/08/29 10:00:30 | 00,033,752 | ---- | M] (NOS Microsystems Ltd.) -- C:\Program Files\NOS\bin\getPlus_HelperSvc.exe -- (getPlus(R) Helper [On_Demand | Stopped])
SRV - [2003/12/17 15:51:44 | 00,200,704 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe -- (GhostStartService [Auto | Running])
SRV - [2004/08/04 03:56:44 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2005/04/04 00:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
SRV - [2006/10/30 03:33:58 | 00,741,376 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
SRV - File not found -- -- (idsvcSPTISRV [Auto | Stopped])
SRV - File not found -- -- (Iomega Activity Disk2 [Disabled | Stopped])
SRV - [2002/01/14 07:49:38 | 00,073,728 | ---- | M] (Iomega Corporation) -- C:\Program Files\Iomega\System32\AppServices.exe -- (Iomega App Services [Auto | Running])
SRV - [2008/11/20 13:20:44 | 00,536,872 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Running])
SRV - [2004/08/04 03:56:42 | 00,035,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\iprip.dll -- (Iprip [Auto | Running])
SRV - [2009/05/05 22:38:38 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
SRV - [2005/02/22 16:32:14 | 00,038,912 | ---- | M] () -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe -- (LightScribeService [Auto | Running])
SRV - [2001/08/23 12:00:00 | 00,019,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\tcpsvcs.exe -- (LPDSVC [On_Demand | Stopped])
SRV - [2006/10/30 03:34:02 | 00,122,880 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
SRV - [2008/06/17 16:56:16 | 00,207,936 | ---- | M] (NovaStor) -- C:\Program Files\NovaStor\NovaStor NovaBACKUP\NsService.exe -- (NsService [Auto | Running])
SRV - [2007/02/14 01:32:36 | 00,159,811 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc [Auto | Running])
SRV - [2004/01/30 15:19:20 | 00,065,625 | ---- | M] (Sony Corporation) -- C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe -- (PACSPTISVR [On_Demand | Stopped])
SRV - [2008/06/17 16:23:48 | 00,093,248 | ---- | M] () -- C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\Fsloader.exe -- (Real time Backup Loader [Auto | Running])
SRV - [2001/08/23 12:00:00 | 00,019,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\tcpsvcs.exe -- (SimpTcp [Auto | Running])
SRV - [2006/11/20 03:42:46 | 00,033,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\snmp.exe -- (SNMP [Auto | Running])
SRV - [2004/01/30 15:16:06 | 00,065,622 | ---- | M] (Sony Corporation) -- C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe -- (SPTISRV [On_Demand | Stopped])
SRV - [2008/07/15 17:38:32 | 00,394,608 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Common Files\supportsoft\bin\ssrc.exe -- (SupportSoft RemoteAssist [On_Demand | Stopped])
SRV - [2004/08/04 03:56:44 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (uploadmgr [Auto | Stopped])
SRV - [2006/10/18 20:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])
SRV - [2002/01/24 16:10:40 | 00,126,976 | ---- | M] (Iomega Corporation) -- C:\Program Files\Iomega\AutoDisk\ADService.exe -- (_IOMEGA_ACTIVE_DISK_SERVICE_ [Auto | Running])

========== Driver Services (SafeList) ==========

DRV - [2004/08/04 02:00:04 | 00,012,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\DRIVERS\4mmdat.sys -- (4mmdat [On_Demand | Running])
DRV - [2009/02/05 16:05:12 | 00,026,944 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4 [System | Running])
DRV - [2004/08/04 02:07:42 | 00,043,008 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\System32\DRIVERS\amdagp.sys -- (amdagp [Boot | Running])
DRV - [2000/06/27 14:39:16 | 00,022,994 | ---- | M] (AMD Corporation) -- C:\WINDOWS\System32\DRIVERS\amdagp10.sys -- (amdagp10 [Boot | Running])
DRV - [2002/08/29 00:59:12 | 00,036,224 | ---- | M] (ADMtek Incorporated.) -- C:\WINDOWS\System32\DRIVERS\AN983.sys -- (AN983 [On_Demand | Running])
DRV - [2007/02/06 15:01:48 | 00,016,512 | ---- | M] (Adaptec) -- C:\WINDOWS\System32\drivers\aspi32.sys -- (Aspi32 [System | Running])
DRV - [2009/02/05 16:07:12 | 00,020,560 | ---- | M] (ALWIL Software) -- C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys -- (aswFsBlk [Auto | Running])
DRV - [2009/02/05 16:08:10 | 00,094,032 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2 [Auto | Running])
DRV - [2009/02/05 16:06:10 | 00,023,152 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr [On_Demand | Running])
DRV - [2009/02/05 16:07:24 | 00,114,768 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP [System | Running])
DRV - [2009/02/05 16:06:20 | 00,051,376 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi [System | Running])
DRV - [2001/08/17 12:48:52 | 00,281,856 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\DRIVERS\ati2mpaa.sys -- (ati2mpaa [On_Demand | Stopped])
DRV - [2001/09/26 23:32:38 | 00,285,088 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\DRIVERS\ati2mtaa.sys -- (ati2mtaa [On_Demand | Stopped])
DRV - [2004/08/04 01:29:30 | 00,104,960 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\DRIVERS\atinrvxx.sys -- (atinrvxx [On_Demand | Stopped])
DRV - [2001/08/17 12:49:12 | 00,049,920 | ---- | M] () -- C:\WINDOWS\System32\DRIVERS\atirtcap.sys -- (ATIVRVXX [On_Demand | Stopped])
DRV - [2006/05/04 02:00:00 | 00,002,432 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\drivers\cdr4_xp.sys -- (Cdr4_xp [System | Stopped])
DRV - [2006/05/04 02:00:00 | 00,002,560 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\drivers\cdralw2k.sys -- (Cdralw2k [System | Stopped])
DRV - [2004/04/13 15:37:56 | 00,285,824 | ---- | M] (Roxio) -- C:\WINDOWS\System32\drivers\Cdudf_xp.sys -- (cdudf_xp [System | Running])
DRV - [2002/07/19 08:10:20 | 00,006,656 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\drivers\cinemsup.sys -- (Cinemsup [System | Running])
DRV - [2008/06/17 16:16:46 | 00,155,648 | ---- | M] () -- C:\WINDOWS\System32\drivers\DCDisk.sys -- (DCDisk [System | Running])
DRV - [2008/06/17 16:16:46 | 00,077,472 | ---- | M] () -- C:\WINDOWS\System32\drivers\dcsnap.sys -- (dcsnap [Boot | Running])
DRV - [2003/03/30 12:19:20 | 00,006,494 | ---- | M] (Mitsubishi Electric , NEC-Mitsubishi Electric Visual Systems) -- C:\WINDOWS\System32\DRIVERS\Moni2c.sys -- (DDCCI [On_Demand | Stopped])
DRV - [2004/04/15 22:57:26 | 00,140,416 | ---- | M] (Windows (R) 2000 DDK provider) -- C:\WINDOWS\System32\drivers\DVDVRRdr_xp.sys -- (DVDVRRdr_xp [System | Running])
DRV - [2004/04/13 15:37:30 | 00,023,680 | ---- | M] (Roxio) -- C:\WINDOWS\System32\drivers\dvd_2k.sys -- (dvd_2K [On_Demand | Running])
DRV - [2002/06/03 11:18:32 | 00,040,832 | ---- | M] (Creative Technology Ltd.) -- C:\WINDOWS\system32\drivers\es1371mp.sys -- (es1371 [On_Demand | Running])
DRV - [2002/05/23 11:28:56 | 00,070,656 | ---- | M] (Promise Technology, Inc.) -- C:\WINDOWS\system32\DRIVERS\fasttrak.sys -- (fasttrak [Boot | Running])
DRV - [2004/08/04 02:08:22 | 00,010,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\DRIVERS\gameenum.sys -- (gameenum [On_Demand | Running])
DRV - [2008/04/17 13:12:54 | 00,015,464 | ---- | M] (GEAR Software Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys -- (GEARAspiWDM [On_Demand | Running])
DRV - [2003/12/17 15:41:38 | 00,005,632 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Norton Ghost 2003\ghpciscan.sys -- (GhPciScan [System | Running])
DRV - [2007/02/06 13:27:04 | 00,185,728 | ---- | M] (Hauppauge Computer Works, Inc.) -- C:\WINDOWS\system32\DRIVERS\hcwPP2.sys -- (hcwPP2 [On_Demand | Running])
DRV - [2004/09/22 09:01:20 | 00,814,464 | R--- | M] (Hauppauge Computer Works, Inc.) -- C:\WINDOWS\system32\DRIVERS\hcwPVRP2.sys -- (hcwPVRP2 [On_Demand | Stopped])
DRV - [2002/01/14 07:49:38 | 00,033,602 | ---- | M] (Iomega Corporation) -- C:\WINDOWS\System32\DRIVERS\iomdisk.sys -- (iomdisk [Boot | Running])
DRV - [2001/09/19 06:11:00 | 00,050,432 | ---- | M] (Logitech) -- C:\WINDOWS\System32\DRIVERS\L8042Pr2.sys -- (l8042pr2 [On_Demand | Stopped])
DRV - [2001/09/19 06:11:00 | 00,022,064 | ---- | M] (Logitech) -- C:\WINDOWS\System32\DRIVERS\LHidFlt2.sys -- (LHidFlt2 [On_Demand | Running])
DRV - [2001/09/19 06:11:00 | 00,037,822 | ---- | M] (Logitech) -- C:\WINDOWS\system32\drivers\LHidUsb.Sys -- (LHidUsb [On_Demand | Running])
DRV - [2001/09/19 06:11:00 | 00,005,840 | ---- | M] (Logitech) -- C:\WINDOWS\System32\DRIVERS\LKbdFlt2.sys -- (LKbdFlt2 [On_Demand | Running])
DRV - [2001/09/19 06:11:00 | 00,067,440 | ---- | M] (Logitech) -- C:\WINDOWS\System32\DRIVERS\LMouFlt2.sys -- (LMouFlt2 [On_Demand | Running])
DRV - [2004/04/13 19:20:08 | 00,015,781 | R--- | M] (Meetinghouse Data Communications) -- C:\WINDOWS\system32\DRIVERS\mdc8021x.sys -- (MDC8021X [Auto | Running])
DRV - [2004/04/13 15:29:22 | 00,023,680 | ---- | M] (Roxio) -- C:\WINDOWS\System32\drivers\mmc_2k.sys -- (mmc_2K [On_Demand | Stopped])
DRV - [2004/08/04 01:29:28 | 00,013,824 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\DRIVERS\atinmdxx.sys -- (MVDCODEC [Auto | Stopped])
DRV - [2007/02/14 01:32:32 | 03,983,872 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\nv4_mini.sys -- (nv [On_Demand | Running])
DRV - [2003/04/16 14:21:30 | 00,004,228 | ---- | M] (PowerQuest Corporation) -- C:\WINDOWS\System32\drivers\PQNTDRV.sys -- (PQNTDrv [System | Running])
DRV - [2001/08/23 12:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
DRV - [2004/04/13 15:23:58 | 00,117,248 | ---- | M] (Roxio) -- C:\WINDOWS\System32\drivers\Pwd_2k.sys -- (pwd_2k [System | Running])
DRV - [2008/05/22 18:22:16 | 00,043,528 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\DRIVERS\PxHelp20.sys -- (PxHelp20 [Boot | Running])
DRV - [2007/11/13 05:25:54 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys -- (Secdrv [Auto | Running])
DRV - [2005/10/07 16:42:14 | 00,038,468 | ---- | M] (Alcor Micro Corp.) -- C:\WINDOWS\System32\Drivers\sunkfilt.sys -- (SunkFilt [On_Demand | Stopped])
DRV - [2004/04/15 22:53:40 | 00,198,528 | ---- | M] (Roxio) -- C:\WINDOWS\System32\drivers\Udfreadr.sys -- (UDFReadr [System | Running])
DRV - [2001/08/17 13:52:22 | 00,036,736 | ---- | M] (Promise Technology, Inc.) -- C:\WINDOWS\System32\DRIVERS\ultra.sys -- (ultra [Boot | Running])
DRV - [2004/05/16 20:46:18 | 00,390,752 | R--- | M] ( ) -- C:\WINDOWS\system32\DRIVERS\wlanCIG.sys -- (wlanCIG [On_Demand | Running])
DRV - [2004/03/01 14:57:04 | 00,010,368 | ---- | M] (Streamzap, Inc.) -- C:\WINDOWS\system32\drivers\zremote.sys -- (zremote [On_Demand | Stopped])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://my.yahoo.com/index.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/index.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Update_Check_Page = http://www.microsoft.com/isapi/redir.dll?Prd=ie&Pver=5.0&Ar=ie5update
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://red.clientapps.yahoo.com/customize/ie/defaults/cs/ymsgr6/*http://www.yahoo.com/ext/search/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ams-server*

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ams-server*

IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = about:blank
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
IE - HKU\S-1-5-19\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ams-server*

IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = about:blank
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
IE - HKU\S-1-5-20\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ams-server*

IE - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\S-1-5-21-1547161642-1580436667-1708537768-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10

FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/05/05 22:38:40 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2005/04/27 22:53:28 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2005/04/27 22:53:26 | 00,000,000 | ---D | M]

[2009/05/17 22:44:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\David Wilson\Application Data\mozilla\Extensions
[2009/05/17 22:44:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\David Wilson\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2005/04/30 10:59:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\David Wilson\Application Data\mozilla\Firefox\Profiles\5nzx41m4.default\extensions
[2005/04/27 22:53:52 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2005/04/27 22:53:52 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/05/05 22:49:12 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
[2009/05/05 22:49:12 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
[2009/05/05 22:49:12 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
[2009/05/05 22:49:12 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2009/05/05 22:38:48 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/04/24 02:01:00 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/04/24 02:01:00 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2008/01/04 11:36:50 | 00,001,538 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2006/07/05 14:47:38 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2008/01/04 11:36:50 | 00,000,947 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2008/03/08 05:35:22 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2008/09/22 15:14:04 | 00,000,759 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2008/04/16 00:08:20 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008/03/28 14:11:14 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2008/01/04 11:36:50 | 00,000,831 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (bho2gr Class) - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - E:\Program Files\GetRight\xx2gr.dll (Headlight Software, Inc.)
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - File not found
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - File not found
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (no name) - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - Reg Error: Key error. File not found
O3 - HKLM\..\Toolbar: (no name) - {724d43a0-0d85-11d4-9908-00400523e39a} - Reg Error: Key error. File not found
O3 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\..\Toolbar\ShellBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
O3 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\..\Toolbar\WebBrowser: (no name) - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - Reg Error: Key error. File not found
O3 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Error: Key error. File not found
O3 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\..\Toolbar\WebBrowser: (no name) - {724D43A0-0D85-11D4-9908-00400523E39A} - Reg Error: Key error. File not found
O3 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\..\Toolbar\WebBrowser: (no name) - {81CA3009-6200-4A6D-93C6-F1E9A6821C7F} - Reg Error: Value error. File not found
O3 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\..\Toolbar\WebBrowser: (no name) - {F2CF5485-4E02-4F68-819C-B92DE9277049} - Reg Error: Key error. File not found
O3 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\..\Toolbar\WebBrowser: (no name) - {FE6BC4EF-5676-484B-88AE-883323913256} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe (Easy Systems Japan Ltd.)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install File not found
O4 - HKLM..\Run: [PRISMSVR.EXE] "C:\WINDOWS\system32\PRISMSVR.EXE" /APPLY (Conexant Systems, Inc.)
O4 - HKLM..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" (Safer Networking Limited)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004..\Run: [LDM] \Program\BackWeb-8876480.exe File not found
O4 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk = E:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\2Wire Wireless Client.lnk = C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.exe (2Wire Inc.)
O4 - Startup: C:\Documents and Settings\David Wilson\Start Menu\Programs\Startup\TrayDay.lnk = C:\Program Files\TrayDay\TrayDay.exe (MJMSoft Design Limited)
O4 - Startup: C:\Documents and Settings\David Wilson\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Advanced\Folder\Hidden\SHOWALL: CheckedValue = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartBanner = 01 00 00 00 [binary data]
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogOff = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Advanced\Folder\Hidden\SHOWALL: CheckedValue = 1
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartBanner = 01 00 00 00 [binary data]
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogOff = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Advanced\Folder\Hidden\SHOWALL: CheckedValue = 1
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 95 00 00 00 [binary data]
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartBanner = 01 00 00 00 [binary data]
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogOff = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = [binary data]
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 95 00 00 00 [binary data]
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartBanner = 01 00 00 00 [binary data]
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogOff = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = [binary data]
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 1
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartBanner = 01 00 00 00 [binary data]
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 1
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 1
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogOff = 0
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = [binary data]
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Advanced\Folder\Hidden\SHOWALL: CheckedValue = 1
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004_Classes\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O8 - Extra context menu item: Download with GetRight - Reg Error: Value error. File not found
O8 - Extra context menu item: E&xport to Microsoft Excel - Reg Error: Value error. File not found
O8 - Extra context menu item: Open with GetRight Browser - Reg Error: Value error. File not found
O9 - Extra Button: Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - File not found
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - File not found
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - File not found
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - File not found
O9 - Extra Button: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - File not found
O9 - Extra 'Tools' menuitem : Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - File not found
O9 - Extra Button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - E:\Program Files\ICQ\ICQ.exe File not found
O9 - Extra 'Tools' menuitem : ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - E:\Program Files\ICQ\ICQ.exe File not found
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - File not found
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - File not found
O9 - Extra Button: Share in Hello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll (Picasa, Inc.)
O9 - Extra 'Tools' menuitem : Share in H&ello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll (Picasa, Inc.)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\.DEFAULT\..Trusted Domains: aol.com ([free] http in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: 50 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-18\..Trusted Domains: aol.com ([free] http in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: 50 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-19\..Trusted Domains: aol.com ([free] http in Trusted sites)
O15 - HKU\S-1-5-19\..Trusted Domains: 2 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-20\..Trusted Domains: aol.com ([free] http in Trusted sites)
O15 - HKU\S-1-5-20\..Trusted Domains: 2 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\..Trusted Domains: 48 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {00000075-0000-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/voxmsdec.CAB (Reg Error: Key error.)
O16 - DPF: {00000160-0000-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/msaudio.cab (Reg Error: Key error.)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab (Support.com Configuration Class)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} http://gulllake.gospelcom.net/unsecure/other_media/views/ipixx.cab (iPIX ActiveX Control)
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} http://www.musicnotes.com/download/mnviewer.cab (Musicnotes Viewer)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {31564D57-0000-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/wmvax.cab (Reg Error: Key error.)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {40272BF7-4FF5-4D6F-9BAD-3C1D3CB32982} http://www.live365.com/players/p365vip.cab (Live365PlayerVIP Class)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://www2.snapfish.com/SnapfishActivia.cab (Snapfish Activia)
O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} https://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab (Microsoft.WinRep)
O16 - DPF: {5197842F-0557-48AE-9552-7594F7C98F04} http://www.cybersitter.com/recovery/ocx/PasswordReset.ocx (PWReset Control)
O16 - DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} http://updates.lifescapeinc.com/installers/pinstall/pinstall.cab (Install Class)
O16 - DPF: {712362BF-E411-4F43-99D2-EB15F80AF1DB} http://entimg.msn.com/client/msnediag3518.cab (MsneDiag Class)
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} http://picture.vzw.com/activex/VerizonWirelessUploadControl.cab (Verizon Wireless Media Upload)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {924C1588-90C3-4910-B6CA-D57A1C0418FE} http://download.yahoo.com/dl/bookmarks/ybconvfav030408.cab (YbUploadFavsCtl Class)
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} http://rtc.webresponse.one.microsoft.com/media/xp/TLIEFlash.CAB (TLIEFlashObj Class)
O16 - DPF: {9DBAFCCF-592F-FFFF-FFFF-00608CEC297C} (Reg Error: Key error.)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38079.8121527778 (Reg Error: Key error.)
O16 - DPF: {A662DA7E-CCB7-4743-B71A-D817F6D575DF} http://www.autodesk.com/global/dwfviewer/installer/DwfViewerSetup.cab (Autodesk DWF Viewer Control)
O16 - DPF: {A7E092C3-692A-11D0-A7E5-08002B322F3B} https://webresponse.one.microsoft.com/oas/ActiveX/FileXfer.cab (WebResponseAttachments Control)
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab (Reg Error: Key error.)
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} http://support.f-secure.com/ols/fscax.cab (F-Secure Online Scanner 3.3)
O16 - DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.4.0/jinstall-1_4_0-windows-i586.cab (Java Plug-in 1.4.0)
O16 - DPF: {CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} http://www.live365.com/players/play365.cab (Live365Player Class)
O16 - DPF: {CEBC955E-58AF-11D2-A30A-00A0C903492B} http://windowsupdate.microsoft.com/R848/V31Controls/x86/w98/en/actsetup.cab (Reg Error: Key error.)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab (get_atlcom Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab (iTunesDetector Class)
O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} http://entimg.msn.com/client/msnmusax3518.cab (MsnMusicAx Class)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\SYSTEM\dajava.cab (Reg Error: Key error.)
O16 - DPF: Internet Explorer Classes for Java file://C:\WINDOWS\SYSTEM\iejava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Checkers http://download.games.yahoo.com/games/clients/y/kt0_x.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Chess http://download.yahoo.com/games/clients/y/cr1_x.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Hearts http://download.yahoo.com/games/clients/y/hr1_x.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Pool 2 http://download.yahoo.com/games/clients/y/por9_x.cab (Reg Error: Key error.)
O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O20 - Winlogon\Notify\dimsntfy: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\gibbebx.dll ()
O24 - Desktop Components:0 (Internet Explorer Channel Bar) - 131A6951-7F78-11D0-A979-00C04FD705A2
O24 - Desktop Components:1 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/03/23 09:33:06 | 00,000,099 | ---- | M] () - C:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2001/11/04 15:42:42 | 00,000,095 | -HS- | M] () - C:\AUTOEXEC.DOS -- [ FAT32 ]
O32 - AutoRun File - [2001/11/05 23:02:34 | 00,000,095 | -HS- | M] () - C:\AUTOEXEC.BAK -- [ FAT32 ]
O33 - MountPoints2\{e2de2786-6cdd-11db-97eb-00045a68bf2f}\Shell - "" = AutoRun
O33 - MountPoints2\{e2de2786-6cdd-11db-97eb-00045a68bf2f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{e2de2786-6cdd-11db-97eb-00045a68bf2f}\Shell\AutoRun\command - "" = H:\LaunchU3.exe -- File not found
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\LaunchU3.exe -- File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2002/03/23 10:06:56 | 00,000,000 | ---D | M]

proskoma
2009-05-18, 05:01
========== Files/Folders - Created Within 30 Days ==========

[9 C:\WINDOWS\*.tmp files]
[2009/05/17 22:44:40 | 00,001,514 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/05/17 22:43:07 | 00,001,641 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2009/05/16 08:20:17 | 00,501,248 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\David Wilson\Desktop\OTListIt2.exe
[2009/05/16 08:09:32 | 00,000,230 | ---- | C] () -- C:\WINDOWS\System32\spupdsvc.inf
[2009/05/16 08:05:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2009/05/13 07:50:42 | 00,000,000 | -HSD | C] -- C:\FOUND.043
[2009/05/08 11:01:12 | 00,000,000 | --S- | C] () -- C:\WINDOWS\System32\148114617.dat
[2009/05/07 23:33:17 | 16,101,45792 | -HS- | C] () -- C:\hiberfil.sys
[2009/05/07 22:28:26 | 01,080,054 | ---- | C] () -- C:\Documents and Settings\David Wilson\Desktop\Aquarium 1.bmp
[2009/05/07 22:24:10 | 01,080,056 | ---- | C] () -- C:\Documents and Settings\David Wilson\Desktop\bach.bmp
[2009/05/07 22:11:31 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Money Plus
[2009/05/06 18:41:05 | 00,360,021 | ---- | C] () -- C:\Documents and Settings\David Wilson\Desktop\dds.scr
[2009/05/06 00:10:58 | 00,001,621 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/05/06 00:10:57 | 00,114,768 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2009/05/06 00:10:57 | 00,097,480 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\AvastSS.scr
[2009/05/06 00:10:57 | 00,094,032 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2009/05/06 00:10:57 | 00,093,296 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2009/05/06 00:10:57 | 00,051,376 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2009/05/06 00:10:57 | 00,026,944 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2009/05/06 00:10:57 | 00,023,152 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2009/05/06 00:10:57 | 00,020,560 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2009/05/06 00:10:41 | 01,256,296 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\aswBoot.exe
[2009/05/06 00:10:41 | 00,380,928 | ---- | C] () -- C:\WINDOWS\System32\actskin4.ocx
[2009/05/06 00:10:39 | 00,000,000 | ---D | C] -- C:\Program Files\Alwil Software
[2009/05/06 00:03:40 | 00,147,100 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2009/05/05 22:11:10 | 00,002,709 | ---- | C] () -- C:\WINDOWS\System32\gibbebx.dat
[2009/05/05 22:10:14 | 00,001,024 | -H-- | C] () -- C:\diskfile1
[2009/05/05 22:10:13 | 00,016,384 | -H-- | C] () -- C:\logicinf.bin
[2009/05/05 21:53:01 | 00,002,709 | ---- | C] () -- C:\WINDOWS\System32\dllgidoor.dat
[2009/04/28 19:05:04 | 00,286,208 | ---- | C] () -- C:\Documents and Settings\David Wilson\Desktop\gmer.exe
[2009/04/23 20:39:11 | 02,988,491 | R--- | C] () -- C:\Documents and Settings\David Wilson\Desktop\ComboFix.exe
[2009/04/22 18:53:37 | 00,000,211 | ---- | C] () -- C:\Boot.bak
[2009/04/22 18:53:35 | 00,260,272 | ---- | C] () -- C:\cmldr
[2009/04/22 18:53:35 | 00,000,000 | RHSD | C] -- C:\cmdcons
[2009/04/22 18:52:40 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2009/04/22 18:52:40 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2009/04/22 18:52:40 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2009/04/22 18:52:40 | 00,117,248 | ---- | C] () -- C:\WINDOWS\vFind.exe
[2009/04/22 18:52:40 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2009/04/22 18:52:40 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2009/04/22 18:52:40 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2009/04/22 18:52:40 | 00,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2009/04/22 18:52:28 | 00,000,000 | ---D | C] -- C:\Qoobox
[2009/04/20 19:43:08 | 00,000,000 | ---D | C] -- C:\rsit
[2009/04/19 18:34:48 | 00,360,021 | ---- | C] () -- C:\something.scr
[2009/04/18 14:49:36 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/04/18 14:49:17 | 00,000,679 | ---- | C] () -- C:\Documents and Settings\David Wilson\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/04/18 14:49:07 | 00,000,523 | ---- | C] () -- C:\Documents and Settings\David Wilson\Desktop\NTREGOPT.lnk
[2009/04/18 14:49:05 | 00,000,504 | ---- | C] () -- C:\Documents and Settings\David Wilson\Desktop\ERUNT.lnk
[2009/04/18 14:49:00 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/04/18 10:10:52 | 00,000,472 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/04/18 10:09:25 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Lavasoft
[2009/04/18 00:21:42 | 00,000,875 | ---- | C] () -- C:\Documents and Settings\David Wilson\Desktop\Spybot - Search & Destroy.lnk
[2009/04/18 00:21:35 | 00,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2009/04/18 00:21:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/04/17 19:53:43 | 00,000,066 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2008/12/20 18:15:42 | 03,421,371 | ---- | C] () -- C:\WINDOWS\System32\gibbebx.dll
[2008/12/20 18:15:42 | 03,048,796 | ---- | C] () -- C:\WINDOWS\System32\dllgidoor.dll
[2008/10/11 13:52:43 | 00,155,648 | ---- | C] () -- C:\WINDOWS\System32\drivers\DCDisk.sys
[2008/10/11 13:52:43 | 00,077,472 | ---- | C] () -- C:\WINDOWS\System32\drivers\dcsnap.sys
[2008/10/04 12:00:34 | 00,139,430 | ---- | C] () -- C:\WINDOWS\System32\urifil.dll
[2008/10/04 12:00:31 | 00,039,360 | ---- | C] () -- C:\WINDOWS\System32\bugreport.dll
[2008/05/22 18:22:18 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2008/05/22 18:19:46 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dtu100.dll.manifest
[2008/05/22 18:19:46 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dpl100.dll.manifest
[2008/05/22 18:18:54 | 00,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll
[2007/12/08 09:37:39 | 00,000,782 | ---- | C] () -- C:\WINDOWS\System32\snetbonly.dll
[2007/10/21 19:14:25 | 00,334,174 | ---- | C] () -- C:\WINDOWS\sqlite3.dll
[2007/08/18 08:33:06 | 00,390,752 | R--- | C] ( ) -- C:\WINDOWS\System32\drivers\wlanCIG.sys
[2007/08/12 18:04:09 | 00,158,856 | ---- | C] () -- C:\WINDOWS\System32\pxyfil.dll
[2007/07/25 15:24:30 | 01,559,040 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2007/02/14 01:32:38 | 01,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2007/02/14 01:32:38 | 01,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2007/02/14 01:32:36 | 01,470,464 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2007/02/14 01:32:36 | 00,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2007/02/14 01:32:36 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2007/02/14 01:32:36 | 00,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2007/02/14 01:32:32 | 00,212,992 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2007/02/03 12:23:24 | 00,000,004 | -H-- | C] () -- C:\WINDOWS\uccspecb.sys
[2006/02/26 16:08:28 | 00,585,728 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2006/02/22 00:36:14 | 00,000,252 | ---- | C] () -- C:\WINDOWS\System32\SNet.dll
[2006/02/05 19:01:10 | 00,066,048 | ---- | C] () -- C:\WINDOWS\System32\hcwXDS.dll
[2005/07/10 19:34:23 | 00,000,037 | ---- | C] () -- C:\WINDOWS\ipixActivex.ini
[2005/05/22 15:22:22 | 00,000,281 | ---- | C] () -- C:\WINDOWS\irremote.ini
[2005/05/22 15:21:38 | 00,065,536 | ---- | C] () -- C:\WINDOWS\System32\dmcrypto.dll
[2005/05/22 15:21:24 | 00,000,211 | ---- | C] () -- C:\WINDOWS\nanoPEG.ini
[2005/05/22 14:48:36 | 00,002,586 | ---- | C] () -- C:\WINDOWS\HCWPNP.INI
[2005/01/26 17:07:33 | 00,000,000 | ---- | C] () -- C:\WINDOWS\QuickInstall.INI
[2005/01/15 12:23:28 | 00,000,479 | ---- | C] () -- C:\WINDOWS\RAIDeUtility.ini
[2004/12/20 10:59:02 | 00,000,119 | ---- | C] () -- C:\WINDOWS\WSST_Screen_Saver.ini
[2004/10/10 19:32:29 | 00,000,000 | ---- | C] () -- C:\WINDOWS\iPlayer.INI
[2004/08/04 03:56:42 | 00,081,920 | ---- | C] () -- C:\WINDOWS\System32\ieencode.dll
[2004/07/27 16:34:09 | 00,000,031 | ---- | C] () -- C:\WINDOWS\oupdate.INI
[2004/07/25 22:32:36 | 00,524,288 | ---- | C] () -- C:\WINDOWS\System32\TDI-SonyOMG.dll
[2004/07/12 17:38:44 | 00,000,011 | ---- | C] () -- C:\WINDOWS\wanpatan.ini
[2004/07/12 17:38:15 | 00,028,672 | ---- | C] () -- C:\WINDOWS\gscr.dll
[2004/05/15 21:33:31 | 00,001,100 | ---- | C] () -- C:\WINDOWS\System32\imgfil.dll
[2004/04/27 17:49:59 | 00,000,100 | ---- | C] () -- C:\WINDOWS\System32\UNWISE.INI
[2003/11/30 14:39:16 | 00,000,222 | ---- | C] () -- C:\WINDOWS\hpbafd.ini
[2003/09/26 20:07:47 | 00,001,222 | ---- | C] () -- C:\WINDOWS\System32\usrfil.dll
[2003/06/11 18:32:46 | 00,001,842 | ---- | C] () -- C:\WINDOWS\System32\csnews.dll
[2003/03/01 08:08:20 | 00,000,348 | ---- | C] () -- C:\WINDOWS\hegames.ini
[2002/12/10 13:13:32 | 00,172,032 | ---- | C] () -- C:\WINDOWS\System32\GSnap.dll
[2002/12/10 13:13:32 | 00,040,960 | ---- | C] () -- C:\WINDOWS\System32\atlcontrol.dll
[2002/12/10 13:13:32 | 00,036,864 | ---- | C] () -- C:\WINDOWS\System32\UninstGMT.dll
[2002/12/10 13:12:24 | 00,000,494 | ---- | C] () -- C:\WINDOWS\demo.INI
[2002/12/10 01:36:34 | 00,036,864 | ---- | C] () -- C:\WINDOWS\System32\gbttk.dll
[2002/11/11 19:45:00 | 00,036,864 | ---- | C] () -- C:\WINDOWS\System32\NetStat32.dll
[2002/09/25 21:48:36 | 00,109,056 | ---- | C] () -- C:\WINDOWS\System32\LGUICOM.DLL
[2002/09/25 21:48:36 | 00,000,488 | ---- | C] () -- C:\WINDOWS\Cmousecc.ini
[2002/08/15 07:32:26 | 00,022,618 | ---- | C] () -- C:\WINDOWS\System32\perfil.dll
[2002/08/15 07:32:26 | 00,017,672 | ---- | C] () -- C:\WINDOWS\System32\nvgamfil.dll
[2002/08/15 07:32:26 | 00,016,802 | ---- | C] () -- C:\WINDOWS\System32\popfil.dll
[2002/08/15 07:32:26 | 00,014,712 | ---- | C] () -- C:\WINDOWS\System32\tafil.dll
[2002/08/15 07:32:26 | 00,012,730 | ---- | C] () -- C:\WINDOWS\System32\psyfil.dll
[2002/08/15 07:32:26 | 00,012,266 | ---- | C] () -- C:\WINDOWS\System32\sporfil.dll
[2002/08/15 07:32:26 | 00,009,634 | ---- | C] () -- C:\WINDOWS\System32\pkmon.dll
[2002/08/15 07:32:26 | 00,006,830 | ---- | C] () -- C:\WINDOWS\System32\swfil.dll
[2002/08/15 07:32:26 | 00,006,050 | ---- | C] () -- C:\WINDOWS\System32\wrestfil.dll
[2002/08/15 07:32:26 | 00,002,246 | ---- | C] () -- C:\WINDOWS\System32\wzfil.dll
[2002/08/15 07:32:26 | 00,001,656 | ---- | C] () -- C:\WINDOWS\System32\tapfil.dll
[2002/08/15 07:32:26 | 00,000,778 | ---- | C] () -- C:\WINDOWS\System32\mp3fil.dll
[2002/08/15 07:32:26 | 00,000,733 | ---- | C] () -- C:\WINDOWS\System32\spmfil.dll
[2002/08/15 07:32:24 | 00,013,154 | ---- | C] () -- C:\WINDOWS\System32\finfil.dll
[2002/08/15 07:32:24 | 00,012,422 | ---- | C] () -- C:\WINDOWS\System32\entfil.dll
[2002/08/15 07:32:24 | 00,011,338 | ---- | C] () -- C:\WINDOWS\System32\fmfil.dll
[2002/08/15 07:32:24 | 00,009,796 | ---- | C] () -- C:\WINDOWS\System32\gnfil.dll
[2002/08/15 07:32:24 | 00,008,652 | ---- | C] () -- C:\WINDOWS\System32\jbfil.dll
[2002/08/15 07:32:24 | 00,007,778 | ---- | C] () -- C:\WINDOWS\System32\movfil.dll
[2002/08/15 07:32:24 | 00,007,642 | ---- | C] () -- C:\WINDOWS\System32\Auctfil.dll
[2002/08/15 07:32:24 | 00,001,816 | ---- | C] () -- C:\WINDOWS\System32\fshrfil.dll
[2002/08/13 23:28:02 | 00,094,996 | ---- | C] () -- C:\WINDOWS\System32\adwfil.dll
[2002/08/13 23:28:02 | 00,013,034 | ---- | C] () -- C:\WINDOWS\System32\gblfil.dll
[2002/08/13 23:28:02 | 00,010,862 | ---- | C] () -- C:\WINDOWS\System32\chtfil.dll
[2002/08/13 23:28:02 | 00,005,880 | ---- | C] () -- C:\WINDOWS\System32\wfileu.drv
[2002/08/13 23:28:02 | 00,005,260 | ---- | C] () -- C:\WINDOWS\System32\iawfil.dll
[2002/08/13 23:28:02 | 00,004,826 | ---- | C] () -- C:\WINDOWS\System32\vgamfil.dll
[2002/08/13 23:28:02 | 00,004,442 | ---- | C] () -- C:\WINDOWS\System32\hatfil.dll
[2002/08/13 23:28:02 | 00,003,818 | ---- | C] () -- C:\WINDOWS\System32\viofil.dll
[2002/08/13 23:28:02 | 00,003,444 | ---- | C] () -- C:\WINDOWS\System32\srchin.dll
[2002/08/13 23:28:02 | 00,003,360 | ---- | C] () -- C:\WINDOWS\System32\lgwfil.dll
[2002/08/13 23:28:02 | 00,001,830 | ---- | C] () -- C:\WINDOWS\System32\cultfil.dll
[2002/08/13 23:28:02 | 00,001,468 | ---- | C] () -- C:\WINDOWS\System32\gdwfil.dll
[2002/08/13 23:28:02 | 00,000,400 | ---- | C] () -- C:\WINDOWS\bsnlst.dll
[2002/06/04 23:55:32 | 00,000,119 | ---- | C] () -- C:\WINDOWS\NNS.INI
[2002/04/28 14:54:12 | 00,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll
[2002/03/23 11:39:16 | 00,000,011 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.ini
[2002/03/23 10:08:10 | 00,076,659 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2002/03/23 10:08:08 | 00,373,248 | ---- | C] () -- C:\WINDOWS\EyeCand3.INI
[2002/03/23 10:08:08 | 00,003,598 | ---- | C] () -- C:\WINDOWS\HTMLHELP.INI
[2002/03/23 10:08:08 | 00,001,467 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2002/03/23 10:08:08 | 00,000,924 | ---- | C] () -- C:\WINDOWS\fauve.ini
[2002/03/23 10:08:08 | 00,000,787 | ---- | C] () -- C:\WINDOWS\SCANREG.INI
[2002/03/23 10:08:08 | 00,000,677 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2002/03/23 10:08:08 | 00,000,509 | ---- | C] () -- C:\WINDOWS\FS.INI
[2002/03/23 10:08:08 | 00,000,470 | ---- | C] () -- C:\WINDOWS\net2fone.ini
[2002/03/23 10:08:08 | 00,000,459 | ---- | C] () -- C:\WINDOWS\YACHT-Z.INI
[2002/03/23 10:08:08 | 00,000,277 | ---- | C] () -- C:\WINDOWS\SBWIN.INI
[2002/03/23 10:08:08 | 00,000,277 | ---- | C] () -- C:\WINDOWS\AATOOLS.INI
[2002/03/23 10:08:08 | 00,000,233 | ---- | C] () -- C:\WINDOWS\NETSCAPE.INI
[2002/03/23 10:08:08 | 00,000,226 | ---- | C] () -- C:\WINDOWS\QTW.INI
[2002/03/23 10:08:08 | 00,000,221 | ---- | C] () -- C:\WINDOWS\emsoft.ini
[2002/03/23 10:08:08 | 00,000,199 | ---- | C] () -- C:\WINDOWS\swacnfg.ini
[2002/03/23 10:08:08 | 00,000,192 | ---- | C] () -- C:\WINDOWS\mb.ini
[2002/03/23 10:08:08 | 00,000,152 | ---- | C] () -- C:\WINDOWS\LODERUNN.INI
[2002/03/23 10:08:08 | 00,000,149 | ---- | C] () -- C:\WINDOWS\XDCS_DO2.INI
[2002/03/23 10:08:08 | 00,000,144 | ---- | C] () -- C:\WINDOWS\INDEO.INI
[2002/03/23 10:08:08 | 00,000,131 | ---- | C] () -- C:\WINDOWS\chess.ini
[2002/03/23 10:08:08 | 00,000,122 | ---- | C] () -- C:\WINDOWS\PROTOCOL.INI
[2002/03/23 10:08:08 | 00,000,105 | ---- | C] () -- C:\WINDOWS\mapiuid.ini
[2002/03/23 10:08:08 | 00,000,095 | ---- | C] () -- C:\WINDOWS\winamp.ini
[2002/03/23 10:08:08 | 00,000,095 | ---- | C] () -- C:\WINDOWS\icewin.INI
[2002/03/23 10:08:08 | 00,000,089 | ---- | C] () -- C:\WINDOWS\KingsC.ini
[2002/03/23 10:08:08 | 00,000,080 | ---- | C] () -- C:\WINDOWS\entpack.ini
[2002/03/23 10:08:08 | 00,000,072 | ---- | C] () -- C:\WINDOWS\boxworld.ini
[2002/03/23 10:08:08 | 00,000,050 | ---- | C] () -- C:\WINDOWS\winfile.ini
[2002/03/23 10:08:08 | 00,000,042 | ---- | C] () -- C:\WINDOWS\CRISPY.INI
[2002/03/23 10:08:08 | 00,000,031 | ---- | C] () -- C:\WINDOWS\MSCHOMP.INI
[2002/03/23 10:08:08 | 00,000,026 | ---- | C] () -- C:\WINDOWS\MSOFFICE.INI
[2002/03/23 10:08:08 | 00,000,025 | ---- | C] () -- C:\WINDOWS\SOL.INI
[2002/03/23 10:08:08 | 00,000,000 | ---- | C] () -- C:\WINDOWS\SYSCHECK.INI
[2002/03/23 10:08:08 | 00,000,000 | ---- | C] () -- C:\WINDOWS\RESMNGR.INI
[2002/03/23 10:08:08 | 00,000,000 | ---- | C] () -- C:\WINDOWS\progman.ini
[2002/03/23 10:08:08 | 00,000,000 | ---- | C] () -- C:\WINDOWS\PCFRIEND.INI
[2002/03/23 10:08:08 | 00,000,000 | ---- | C] () -- C:\WINDOWS\MSINFO32.INI
[2002/03/23 10:08:08 | 00,000,000 | ---- | C] () -- C:\WINDOWS\hjbrowse.ini
[2002/03/23 10:08:08 | 00,000,000 | ---- | C] () -- C:\WINDOWS\DXINFO.INI
[2002/03/23 10:08:06 | 00,012,327 | ---- | C] () -- C:\WINDOWS\IOS.INI
[2002/03/23 10:08:06 | 00,008,405 | ---- | C] () -- C:\WINDOWS\NETDET.INI
[2002/03/23 10:08:06 | 00,005,068 | ---- | C] () -- C:\WINDOWS\DELETEFI.INI
[2002/03/23 10:08:06 | 00,000,865 | ---- | C] () -- C:\WINDOWS\DOSREP.INI
[2002/03/23 10:08:06 | 00,000,225 | ---- | C] () -- C:\WINDOWS\TELEPHON.INI
[2002/03/23 10:08:06 | 00,000,180 | ---- | C] () -- C:\WINDOWS\winmine.ini
[2002/03/23 10:08:06 | 00,000,127 | ---- | C] () -- C:\WINDOWS\KPCMS.INI
[2002/03/23 10:08:06 | 00,000,068 | ---- | C] () -- C:\WINDOWS\FPXPRESS.INI
[2002/03/23 10:08:06 | 00,000,060 | ---- | C] () -- C:\WINDOWS\POWERPNT.INI
[2002/03/23 10:08:06 | 00,000,054 | ---- | C] () -- C:\WINDOWS\WAVEMIX.INI
[2002/03/23 09:51:34 | 00,049,920 | ---- | C] () -- C:\WINDOWS\System32\drivers\atirtcap.sys
[2002/03/23 09:51:32 | 00,009,472 | ---- | C] () -- C:\WINDOWS\System32\drivers\ativmdcd.sys
[2001/12/27 23:55:26 | 00,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll
[2001/12/27 23:55:26 | 00,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll
[2001/12/17 07:22:30 | 00,210,944 | ---- | C] () -- C:\WINDOWS\System32\MSVCRT10.DLL
[2001/12/17 07:22:28 | 00,027,648 | ---- | C] () -- C:\WINDOWS\PFPICK.DLL
[2001/08/26 15:08:16 | 00,057,344 | ---- | C] () -- C:\WINDOWS\System32\icmfilter.dll
[2001/08/23 12:00:04 | 00,003,166 | ---- | C] () -- C:\WINDOWS\win.ini
[2001/08/23 12:00:04 | 00,000,638 | ---- | C] () -- C:\WINDOWS\system.ini
[2001/05/06 23:59:46 | 00,149,504 | ---- | C] () -- C:\WINDOWS\unwise32.dll
[2001/01/29 00:43:42 | 00,161,792 | ---- | C] () -- C:\WINDOWS\System32\nfsspi.dll
[2001/01/29 00:00:58 | 00,002,048 | ---- | C] () -- C:\WINDOWS\MNMGM32.DLL
[2000/06/22 14:34:24 | 00,088,064 | ---- | C] () -- C:\WINDOWS\System32\AudioExCtl.dll
[2000/06/22 14:33:36 | 00,024,576 | ---- | C] () -- C:\WINDOWS\System32\HcdDll32.dll
[2000/06/22 14:33:36 | 00,005,120 | ---- | C] () -- C:\WINDOWS\System32\HWDll.dll
[2000/06/20 13:11:02 | 00,110,592 | ---- | C] () -- C:\WINDOWS\System32\cdtool.dll
[2000/05/13 16:59:44 | 00,054,266 | ---- | C] () -- C:\WINDOWS\ATM.INI
[2000/05/13 10:27:11 | 00,020,992 | ---- | C] () -- C:\WINDOWS\System32\PFMAPI32.DLL
[2000/05/13 01:08:06 | 00,187,392 | ---- | C] () -- C:\WINDOWS\System32\LTANN62N.DLL
[2000/05/13 01:08:06 | 00,076,288 | ---- | C] () -- C:\WINDOWS\System32\LTIMG62N.DLL
[2000/05/13 01:08:06 | 00,047,616 | ---- | C] () -- C:\WINDOWS\System32\Lftif62n.dll
[2000/05/13 01:08:06 | 00,043,008 | ---- | C] () -- C:\WINDOWS\System32\ltfil62n.dll
[2000/05/13 01:08:06 | 00,029,184 | ---- | C] () -- C:\WINDOWS\System32\LTWND62N.DLL
[2000/05/13 01:08:06 | 00,024,064 | ---- | C] () -- C:\WINDOWS\System32\LTTWN62N.DLL
[2000/05/13 01:08:06 | 00,022,528 | ---- | C] () -- C:\WINDOWS\System32\tvcntl32.dll
[2000/05/13 01:08:06 | 00,020,480 | ---- | C] () -- C:\WINDOWS\System32\Lfpsd62n.dll
[2000/05/13 01:08:06 | 00,019,968 | ---- | C] () -- C:\WINDOWS\System32\Lfwmf62n.dll
[2000/05/13 01:08:06 | 00,019,968 | ---- | C] () -- C:\WINDOWS\System32\Lftga62n.dll
[2000/05/13 01:08:06 | 00,019,456 | ---- | C] () -- C:\WINDOWS\System32\Lfwpg62n.dll
[2000/05/13 01:08:06 | 00,018,432 | ---- | C] () -- C:\WINDOWS\System32\Lfras62n.dll
[2000/05/13 01:08:06 | 00,017,408 | ---- | C] () -- C:\WINDOWS\System32\Lfwfx62n.dll
[2000/05/13 01:08:05 | 00,175,616 | ---- | C] () -- C:\WINDOWS\System32\Lffax62n.dll
[2000/05/13 01:08:05 | 00,158,720 | ---- | C] () -- C:\WINDOWS\System32\Lfcmp62n.dll
[2000/05/13 01:08:05 | 00,110,080 | ---- | C] () -- C:\WINDOWS\System32\Lfpng62n.dll
[2000/05/13 01:08:05 | 00,027,136 | ---- | C] () -- C:\WINDOWS\System32\Lflma62n.dll
[2000/05/13 01:08:05 | 00,024,576 | ---- | C] () -- C:\WINDOWS\System32\Lfica62n.dll
[2000/05/13 01:08:05 | 00,023,552 | ---- | C] () -- C:\WINDOWS\System32\Lfpcx62n.dll
[2000/05/13 01:08:05 | 00,023,552 | ---- | C] () -- C:\WINDOWS\System32\Lflmb62n.dll
[2000/05/13 01:08:05 | 00,022,528 | ---- | C] () -- C:\WINDOWS\System32\Lfeps62n.dll
[2000/05/13 01:08:05 | 00,022,016 | ---- | C] () -- C:\WINDOWS\System32\Lfpct62n.dll
[2000/05/13 01:08:05 | 00,022,016 | ---- | C] () -- C:\WINDOWS\System32\Lfgif62n.dll
[2000/05/13 01:08:05 | 00,022,016 | ---- | C] () -- C:\WINDOWS\System32\Lfbmp62n.dll
[2000/05/13 01:08:05 | 00,018,944 | ---- | C] () -- C:\WINDOWS\System32\Lfimg62n.dll
[2000/05/13 01:08:05 | 00,018,432 | ---- | C] () -- C:\WINDOWS\System32\Lfmsp62n.dll
[2000/05/13 01:08:05 | 00,017,920 | ---- | C] () -- C:\WINDOWS\System32\Lfmac62n.dll
[2000/05/13 01:08:05 | 00,017,920 | ---- | C] () -- C:\WINDOWS\System32\Lfcal62n.dll
[2000/05/13 01:08:05 | 00,017,408 | ---- | C] () -- C:\WINDOWS\System32\Lfpcd62n.dll
[2000/05/13 01:08:00 | 00,162,816 | ---- | C] () -- C:\WINDOWS\System32\ccmpeg.dll
[1999/09/20 10:05:32 | 00,013,387 | ---- | C] () -- C:\WINDOWS\System32\CinemSup.sys
[1998/10/11 00:07:38 | 00,088,576 | ---- | C] () -- C:\WINDOWS\System32\Iticheck.dll
[1998/03/18 02:57:02 | 00,021,504 | ---- | C] () -- C:\WINDOWS\System32\ThmUninst.dll
[1997/07/11 00:00:00 | 00,022,016 | ---- | C] () -- C:\WINDOWS\System32\ODBCSTF.DLL
[1997/07/11 00:00:00 | 00,022,016 | ---- | C] () -- C:\WINDOWS\System32\DOCOBJ.DLL
[1997/07/11 00:00:00 | 00,012,288 | ---- | C] () -- C:\WINDOWS\System32\HLINKPRX.DLL
[1997/06/13 20:56:08 | 00,056,832 | ---- | C] () -- C:\WINDOWS\System32\Iyvu9_32.dll
[1980/01/01 00:00:00 | 00,188,416 | ---- | C] () -- C:\WINDOWS\System32\MEMBG.DLL
[1980/01/01 00:00:00 | 00,129,080 | ---- | C] () -- C:\WINDOWS\Logow.sys.bak
[1980/01/01 00:00:00 | 00,129,078 | ---- | C] () -- C:\WINDOWS\Logos.sys.bak
[1980/01/01 00:00:00 | 00,000,025 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI

========== Files - Modified Within 30 Days ==========

[9 C:\WINDOWS\*.tmp files]
[2009/05/17 22:54:58 | 00,421,976 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/05/17 22:54:58 | 00,343,762 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/05/17 22:54:58 | 00,069,018 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/05/17 22:51:56 | 00,003,166 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/05/17 22:51:56 | 00,000,638 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/05/17 22:51:56 | 00,000,281 | RHS- | M] () -- C:\boot.ini
[2009/05/17 22:51:22 | 00,088,566 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2009/05/17 22:51:06 | 00,012,208 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/05/17 22:51:04 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\David Wilson\Local Settings\desktop.ini
[2009/05/17 22:50:54 | 00,016,384 | -H-- | M] () -- C:\logicinf.bin
[2009/05/17 22:50:54 | 00,001,024 | -H-- | M] () -- C:\diskfile1
[2009/05/17 22:50:44 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/05/17 22:50:36 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/05/17 22:50:34 | 16,101,45792 | -HS- | M] () -- C:\hiberfil.sys
[2009/05/17 22:50:34 | 03,579,072 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/05/17 22:44:42 | 00,001,514 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/05/17 22:43:08 | 00,001,641 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2009/05/17 22:29:02 | 00,000,258 | ---- | M] () -- C:\WINDOWS\tasks\Uninstall Expiration Reminder.job
[2009/05/17 21:58:48 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009/05/16 08:20:16 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\David Wilson\Desktop\OTListIt2.exe
[2009/05/16 08:09:34 | 00,000,230 | ---- | M] () -- C:\WINDOWS\System32\spupdsvc.inf
[2009/05/16 08:06:42 | 00,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2009/05/16 08:06:42 | 00,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2009/05/16 07:53:46 | 00,222,368 | ---- | M] () -- C:\ntldr
[2009/05/14 22:38:54 | 00,000,875 | ---- | M] () -- C:\Documents and Settings\David Wilson\Desktop\Spybot - Search & Destroy.lnk
[2009/05/14 22:24:26 | 02,988,491 | R--- | M] () -- C:\Documents and Settings\David Wilson\Desktop\ComboFix.exe
[2009/05/14 17:50:10 | 00,117,248 | ---- | M] () -- C:\WINDOWS\vFind.exe
[2009/05/08 11:01:14 | 00,000,000 | --S- | M] () -- C:\WINDOWS\System32\148114617.dat
[2009/05/07 23:33:16 | 16,100,76160 | ---- | M] () -- C:\WINDOWS\MEMORY.DMP
[2009/05/07 22:28:26 | 01,080,054 | ---- | M] () -- C:\Documents and Settings\David Wilson\Desktop\Aquarium 1.bmp
[2009/05/07 22:24:14 | 01,080,056 | ---- | M] () -- C:\Documents and Settings\David Wilson\Desktop\bach.bmp
[2009/05/06 18:41:06 | 00,360,021 | ---- | M] () -- C:\Documents and Settings\David Wilson\Desktop\dds.scr
[2009/05/06 00:11:00 | 00,001,621 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/05/06 00:10:58 | 00,003,021 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2009/05/06 00:03:42 | 00,147,100 | -H-- | M] () -- C:\WINDOWS\System32\mlfcache.dat
[2009/05/05 22:16:22 | 00,390,777 | ---- | M] () -- C:\WINDOWS\csfilts.cab
[2009/05/05 22:11:12 | 00,002,709 | ---- | M] () -- C:\WINDOWS\System32\gibbebx.dat
[2009/05/05 21:54:18 | 00,000,039 | ---- | M] () -- C:\WINDOWS\liccyval.dat
[2009/05/05 21:53:02 | 00,002,709 | ---- | M] () -- C:\WINDOWS\System32\dllgidoor.dat
[2009/04/28 19:05:04 | 00,286,208 | ---- | M] () -- C:\Documents and Settings\David Wilson\Desktop\gmer.exe
[2009/04/22 19:05:44 | 00,001,222 | ---- | M] () -- C:\WINDOWS\System32\usrfil.dll
[2009/04/22 19:04:10 | 00,005,880 | ---- | M] () -- C:\WINDOWS\System32\wfileu.drv
[2009/04/20 12:56:28 | 00,031,232 | ---- | M] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2009/04/19 18:29:52 | 00,360,021 | ---- | M] () -- C:\something.scr
[2009/04/18 21:23:04 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/04/18 14:49:18 | 00,000,679 | ---- | M] () -- C:\Documents and Settings\David Wilson\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/04/18 14:49:08 | 00,000,523 | ---- | M] () -- C:\Documents and Settings\David Wilson\Desktop\NTREGOPT.lnk
[2009/04/18 14:49:06 | 00,000,504 | ---- | M] () -- C:\Documents and Settings\David Wilson\Desktop\ERUNT.lnk
[2009/04/18 10:10:54 | 00,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
< End of report >

proskoma
2009-05-18, 05:26
One more note: as an experiment I tried using the command line interface to delete the iexplore.exe files. I deleted iedw.exe & iexplore.exe after force quitting the iexplore.exe process in the task manager. Seconds later the instance of IEXPLORE.exe was back in the task manager processes and both .exe files were back in the c:\Program Files\Internet Explorer directory.

Blade81
2009-05-18, 21:13
Hi

First of all, c:\Program Files\Internet Explorer folder is legit folder for IE.


Disable Spybot's TeaTimer to make sure it won't interfere with fixes. You can re-enable it when you're clean again:
Run Spybot-S&D in Advanced Mode
If it is not already set to do this, go to the Mode menu
select
Advanced Mode

On the left hand side, click on Tools
Then click on the Resident icon in the list
Uncheck
Resident TeaTimer
and OK any prompts.
Restart your computer


Run OTListIt2.exe

Under the Custom Scans/Fixes box at the bottom, paste in the following


:OTLI
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://red.clientapps.yahoo.com/cust...ch/search.html
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - File not found
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - File not found
O16 - DPF: {5197842F-0557-48AE-9552-7594F7C98F04} http://www.cybersitter.com/recovery/...swordReset.ocx (PWReset Control)
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\gibbebx.dll ()

:Files
C:\WINDOWS\System32\148114617.dat
C:\WINDOWS\System32\gibbebx.dat
C:\WINDOWS\System32\dllgidoor.dat
C:\WINDOWS\System32\gibbebx.dll
C:\WINDOWS\System32\dllgidoor.dll
C:\WINDOWS\System32\urifil.dll
C:\WINDOWS\System32\bugreport.dll
C:\WINDOWS\System32\snetbonly.dll
C:\WINDOWS\System32\pxyfil.dll
C:\WINDOWS\System32\hcwXDS.dll
C:\WINDOWS\csfilts.cab
C:\WINDOWS\liccyval.dat
C:\WINDOWS\System32\usrfil.dll
C:\WINDOWS\System32\wfileu.drv
:Commands
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
Let the program run unhindered, reboot when it is done
Then post a new OTL2 log


To generate a HijackThis Startup list:

1. Open HijackThis by double-clicking the desktop shortcut or HijackThis.exe
2. Click on Open the Misc Tools Section
3. Make sure that both boxes to the right of
Generate StartupList Log
are checked:

* List also minor sections (Full)
* List empty sections (Complete)

4. Click Generate StartupListLog
5. Click Yes at the prompt.
6. A Notepad window will open with the contents of the HijackThis Startup list displayed


Let Malwarebytes' Anti-Malware update itself and then run a full scan with it. Post back its report among other reports listed above.

proskoma
2009-05-19, 14:03
========== OTLISTIT ==========
Process explorer.exe killed successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\CustomSearch| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\ deleted successfully.
Starting removal of ActiveX control {5197842F-0557-48AE-9552-7594F7C98F04}
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{5197842F-0557-48AE-9552-7594F7C98F04}\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{5197842F-0557-48AE-9552-7594F7C98F04}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5197842F-0557-48AE-9552-7594F7C98F04}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5197842F-0557-48AE-9552-7594F7C98F04}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5197842F-0557-48AE-9552-7594F7C98F04}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\CDBurn deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\ deleted successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\gibbebx.dll
C:\WINDOWS\system32\gibbebx.dll NOT unregistered.
C:\WINDOWS\system32\gibbebx.dll moved successfully.
========== FILES ==========
C:\WINDOWS\System32\148114617.dat moved successfully.
C:\WINDOWS\System32\gibbebx.dat moved successfully.
C:\WINDOWS\System32\dllgidoor.dat moved successfully.
File\Folder C:\WINDOWS\System32\gibbebx.dll not found.
DllUnregisterServer procedure not found in C:\WINDOWS\System32\dllgidoor.dll
C:\WINDOWS\System32\dllgidoor.dll NOT unregistered.
C:\WINDOWS\System32\dllgidoor.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\urifil.dll
C:\WINDOWS\System32\urifil.dll NOT unregistered.
C:\WINDOWS\System32\urifil.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\bugreport.dll
C:\WINDOWS\System32\bugreport.dll NOT unregistered.
C:\WINDOWS\System32\bugreport.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\snetbonly.dll
C:\WINDOWS\System32\snetbonly.dll NOT unregistered.
C:\WINDOWS\System32\snetbonly.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\pxyfil.dll
C:\WINDOWS\System32\pxyfil.dll NOT unregistered.
C:\WINDOWS\System32\pxyfil.dll moved successfully.
C:\WINDOWS\System32\hcwXDS.dll unregistered successfully.
C:\WINDOWS\System32\hcwXDS.dll moved successfully.
C:\WINDOWS\csfilts.cab moved successfully.
C:\WINDOWS\liccyval.dat moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\usrfil.dll
C:\WINDOWS\System32\usrfil.dll NOT unregistered.
C:\WINDOWS\System32\usrfil.dll moved successfully.
C:\WINDOWS\System32\wfileu.drv moved successfully.
========== COMMANDS ==========
File delete failed. C:\Documents and Settings\David Wilson\Local Settings\Temp\~DF9977.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\David Wilson\Local Settings\Temp\~DF9997.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\regkern.log scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrt63sec.log scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_514.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_20c.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_758.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.
Explorer started successfully

OTListIt2 by OldTimer - Version 2.0.15.8 log created on 05192009_075752

Files moved on Reboot...
File C:\Documents and Settings\David Wilson\Local Settings\Temp\~DF9977.tmp not found!
File C:\Documents and Settings\David Wilson\Local Settings\Temp\~DF9997.tmp not found!
File C:\WINDOWS\temp\_avast4_\Webshlock.txt not found!
File move failed. C:\WINDOWS\temp\regkern.log scheduled to be moved on reboot.
File move failed. C:\WINDOWS\temp\wrt63sec.log scheduled to be moved on reboot.
C:\WINDOWS\temp\Perflib_Perfdata_514.dat moved successfully.
C:\WINDOWS\temp\Perflib_Perfdata_20c.dat moved successfully.
File C:\WINDOWS\temp\Perflib_Perfdata_758.dat not found!

Registry entries deleted on Reboot...

proskoma
2009-05-19, 14:05
========== OTLISTIT ==========
Process explorer.exe killed successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\CustomSearch| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\ deleted successfully.
Starting removal of ActiveX control {5197842F-0557-48AE-9552-7594F7C98F04}
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{5197842F-0557-48AE-9552-7594F7C98F04}\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{5197842F-0557-48AE-9552-7594F7C98F04}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5197842F-0557-48AE-9552-7594F7C98F04}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{5197842F-0557-48AE-9552-7594F7C98F04}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5197842F-0557-48AE-9552-7594F7C98F04}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\CDBurn deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\ deleted successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\gibbebx.dll
C:\WINDOWS\system32\gibbebx.dll NOT unregistered.
C:\WINDOWS\system32\gibbebx.dll moved successfully.
========== FILES ==========
C:\WINDOWS\System32\148114617.dat moved successfully.
C:\WINDOWS\System32\gibbebx.dat moved successfully.
C:\WINDOWS\System32\dllgidoor.dat moved successfully.
File\Folder C:\WINDOWS\System32\gibbebx.dll not found.
DllUnregisterServer procedure not found in C:\WINDOWS\System32\dllgidoor.dll
C:\WINDOWS\System32\dllgidoor.dll NOT unregistered.
C:\WINDOWS\System32\dllgidoor.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\urifil.dll
C:\WINDOWS\System32\urifil.dll NOT unregistered.
C:\WINDOWS\System32\urifil.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\bugreport.dll
C:\WINDOWS\System32\bugreport.dll NOT unregistered.
C:\WINDOWS\System32\bugreport.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\snetbonly.dll
C:\WINDOWS\System32\snetbonly.dll NOT unregistered.
C:\WINDOWS\System32\snetbonly.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\pxyfil.dll
C:\WINDOWS\System32\pxyfil.dll NOT unregistered.
C:\WINDOWS\System32\pxyfil.dll moved successfully.
C:\WINDOWS\System32\hcwXDS.dll unregistered successfully.
C:\WINDOWS\System32\hcwXDS.dll moved successfully.
C:\WINDOWS\csfilts.cab moved successfully.
C:\WINDOWS\liccyval.dat moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\usrfil.dll
C:\WINDOWS\System32\usrfil.dll NOT unregistered.
C:\WINDOWS\System32\usrfil.dll moved successfully.
C:\WINDOWS\System32\wfileu.drv moved successfully.
========== COMMANDS ==========
File delete failed. C:\Documents and Settings\David Wilson\Local Settings\Temp\~DF9977.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\David Wilson\Local Settings\Temp\~DF9997.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\regkern.log scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrt63sec.log scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_514.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_20c.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_758.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.
Explorer started successfully

OTListIt2 by OldTimer - Version 2.0.15.8 log created on 05192009_075752

Files moved on Reboot...
File C:\Documents and Settings\David Wilson\Local Settings\Temp\~DF9977.tmp not found!
File C:\Documents and Settings\David Wilson\Local Settings\Temp\~DF9997.tmp not found!
File C:\WINDOWS\temp\_avast4_\Webshlock.txt not found!
File move failed. C:\WINDOWS\temp\regkern.log scheduled to be moved on reboot.
File move failed. C:\WINDOWS\temp\wrt63sec.log scheduled to be moved on reboot.
C:\WINDOWS\temp\Perflib_Perfdata_514.dat moved successfully.
C:\WINDOWS\temp\Perflib_Perfdata_20c.dat moved successfully.
File C:\WINDOWS\temp\Perflib_Perfdata_758.dat not found!

Registry entries deleted on Reboot...

proskoma
2009-05-19, 14:07
OTListIt logfile created on: 5/19/2009 8:03:55 AM - Run 3
OTListIt2 by OldTimer - Version 2.0.15.8 Folder = C:\Documents and Settings\David Wilson\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: enu | Date Format: M/d/yyyy

1.50 Gb Total Physical Memory | 1.02 Gb Available Physical Memory | 68.07% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): [Binary data over 100 bytes]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 109.82 Gb Total Space | 30.61 Gb Free Space | 27.87% Space Free | Partition Type: FAT32
Drive D: | 8.09 Gb Total Space | 6.72 Gb Free Space | 83.06% Space Free | Partition Type: FAT32
Drive E: | 55.88 Gb Total Space | 30.61 Gb Free Space | 54.78% Space Free | Partition Type: FAT32
Drive F: | 39.21 Gb Total Space | 25.50 Gb Free Space | 65.05% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DAVEHOME
Current User Name: David Wilson
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - [2009/02/05 16:01:26 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2009/02/05 16:08:40 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2007/06/13 06:23:08 | 01,033,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2008/11/07 14:28:16 | 00,132,424 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2000/11/15 18:53:04 | 00,237,568 | ---- | M] (Promise Technology Inc.) -- C:\Program Files\Promise\FastTrak\FtrakSvc.exe
PRC - [2008/06/17 16:16:32 | 00,176,128 | ---- | M] () -- C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\CBP\DCSchdler.exe
PRC - [2003/12/17 15:51:44 | 00,200,704 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
PRC - [2002/01/14 07:49:38 | 00,073,728 | ---- | M] (Iomega Corporation) -- C:\Program Files\Iomega\System32\AppServices.exe
PRC - [2009/05/05 22:38:38 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2005/02/22 16:32:14 | 00,038,912 | ---- | M] () -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe
PRC - [2008/06/17 16:56:16 | 00,207,936 | ---- | M] (NovaStor) -- C:\Program Files\NovaStor\NovaStor NovaBACKUP\NsService.exe
PRC - [2007/02/14 01:32:36 | 00,159,811 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe
PRC - [2008/06/17 16:23:48 | 00,093,248 | ---- | M] () -- C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\Fsloader.exe
PRC - [2001/08/23 12:00:00 | 00,019,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\tcpsvcs.exe
PRC - [2006/11/20 03:42:46 | 00,033,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\snmp.exe
PRC - [2002/01/24 16:10:40 | 00,126,976 | ---- | M] (Iomega Corporation) -- C:\Program Files\Iomega\AutoDisk\ADService.exe
PRC - [2004/04/13 19:45:30 | 00,290,905 | ---- | M] (Conexant Systems, Inc.) -- C:\WINDOWS\system32\PRISMSVR.EXE
PRC - [2008/11/20 13:20:54 | 00,290,088 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2002/08/20 10:29:26 | 00,040,960 | ---- | M] (Easy Systems Japan Ltd.) -- C:\WINDOWS\system32\ezSP_Px.exe
PRC - [2009/05/05 22:38:38 | 00,148,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2009/02/05 16:08:46 | 00,081,000 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashDisp.exe
PRC - [2004/08/04 03:56:50 | 00,093,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\iexplore.exe
PRC - [2009/02/27 17:10:28 | 00,035,696 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
PRC - [2009/02/05 16:08:26 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
PRC - [2009/02/05 16:06:04 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PRC - [2004/04/13 20:47:56 | 00,335,979 | ---- | M] (2Wire Inc.) -- C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.exe
PRC - [2002/10/22 06:50:00 | 00,204,800 | ---- | M] (MJMSoft Design Limited) -- C:\Program Files\TrayDay\TrayDay.exe
PRC - [2008/11/20 13:20:44 | 00,536,872 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe
PRC - [2009/04/24 02:00:58 | 00,307,704 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009/05/16 08:20:16 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\David Wilson\Desktop\OTListIt2.exe

========== Win32 Services (SafeList) ==========

SRV - [2008/11/07 14:28:16 | 00,132,424 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running])
SRV - [2007/10/24 01:47:22 | 00,033,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2009/02/05 16:01:26 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv [Auto | Running])
SRV - [2000/11/30 14:30:40 | 00,057,344 | ---- | M] () -- C:\WINDOWS\System32\Ati2evxx.exe -- (Ati HotKey Poller [Auto | Stopped])
SRV - [2009/02/05 16:08:40 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus [Auto | Running])
SRV - [2009/02/05 16:08:26 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner [On_Demand | Running])
SRV - [2009/02/05 16:06:04 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner [On_Demand | Running])
SRV - [2008/06/17 16:16:36 | 00,098,304 | ---- | M] () -- C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\CBP\DCSchdlerSRVC.exe -- (Backup Scheduler [Auto | Stopped])
SRV - [2007/10/24 01:47:40 | 00,070,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2000/11/15 18:53:04 | 00,237,568 | ---- | M] (Promise Technology Inc.) -- C:\Program Files\Promise\FastTrak\FtrakSvc.exe -- (FastTrakSvc [Auto | Running])
SRV - [2006/10/20 21:21:24 | 00,036,864 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008/08/29 10:00:30 | 00,033,752 | ---- | M] (NOS Microsystems Ltd.) -- C:\Program Files\NOS\bin\getPlus_HelperSvc.exe -- (getPlus(R) Helper [On_Demand | Stopped])
SRV - [2003/12/17 15:51:44 | 00,200,704 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe -- (GhostStartService [Auto | Running])
SRV - [2004/08/04 03:56:44 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2005/04/04 00:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
SRV - [2006/10/30 03:33:58 | 00,741,376 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
SRV - File not found -- -- (idsvcSPTISRV [Auto | Stopped])
SRV - File not found -- -- (Iomega Activity Disk2 [Disabled | Stopped])
SRV - [2002/01/14 07:49:38 | 00,073,728 | ---- | M] (Iomega Corporation) -- C:\Program Files\Iomega\System32\AppServices.exe -- (Iomega App Services [Auto | Running])
SRV - [2008/11/20 13:20:44 | 00,536,872 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Running])
SRV - [2004/08/04 03:56:42 | 00,035,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\iprip.dll -- (Iprip [Auto | Running])
SRV - [2009/05/05 22:38:38 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
SRV - [2005/02/22 16:32:14 | 00,038,912 | ---- | M] () -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe -- (LightScribeService [Auto | Running])
SRV - [2001/08/23 12:00:00 | 00,019,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\tcpsvcs.exe -- (LPDSVC [On_Demand | Stopped])
SRV - [2006/10/30 03:34:02 | 00,122,880 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
SRV - [2008/06/17 16:56:16 | 00,207,936 | ---- | M] (NovaStor) -- C:\Program Files\NovaStor\NovaStor NovaBACKUP\NsService.exe -- (NsService [Auto | Running])
SRV - [2007/02/14 01:32:36 | 00,159,811 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc [Auto | Running])
SRV - [2004/01/30 15:19:20 | 00,065,625 | ---- | M] (Sony Corporation) -- C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe -- (PACSPTISVR [On_Demand | Stopped])
SRV - [2008/06/17 16:23:48 | 00,093,248 | ---- | M] () -- C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\Fsloader.exe -- (Real time Backup Loader [Auto | Running])
SRV - [2001/08/23 12:00:00 | 00,019,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\tcpsvcs.exe -- (SimpTcp [Auto | Running])
SRV - [2006/11/20 03:42:46 | 00,033,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\snmp.exe -- (SNMP [Auto | Running])
SRV - [2004/01/30 15:16:06 | 00,065,622 | ---- | M] (Sony Corporation) -- C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe -- (SPTISRV [On_Demand | Stopped])
SRV - [2008/07/15 17:38:32 | 00,394,608 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Common Files\supportsoft\bin\ssrc.exe -- (SupportSoft RemoteAssist [On_Demand | Stopped])
SRV - [2004/08/04 03:56:44 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (uploadmgr [Auto | Stopped])
SRV - [2006/10/18 20:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])
SRV - [2002/01/24 16:10:40 | 00,126,976 | ---- | M] (Iomega Corporation) -- C:\Program Files\Iomega\AutoDisk\ADService.exe -- (_IOMEGA_ACTIVE_DISK_SERVICE_ [Auto | Running])

========== Driver Services (SafeList) ==========

DRV - [2004/08/04 02:00:04 | 00,012,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\DRIVERS\4mmdat.sys -- (4mmdat [On_Demand | Running])
DRV - [2009/02/05 16:05:12 | 00,026,944 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4 [System | Running])
DRV - [2004/08/04 02:07:42 | 00,043,008 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\System32\DRIVERS\amdagp.sys -- (amdagp [Boot | Running])
DRV - [2000/06/27 14:39:16 | 00,022,994 | ---- | M] (AMD Corporation) -- C:\WINDOWS\System32\DRIVERS\amdagp10.sys -- (amdagp10 [Boot | Running])
DRV - [2002/08/29 00:59:12 | 00,036,224 | ---- | M] (ADMtek Incorporated.) -- C:\WINDOWS\System32\DRIVERS\AN983.sys -- (AN983 [On_Demand | Running])
DRV - [2007/02/06 15:01:48 | 00,016,512 | ---- | M] (Adaptec) -- C:\WINDOWS\System32\drivers\aspi32.sys -- (Aspi32 [System | Running])
DRV - [2009/02/05 16:07:12 | 00,020,560 | ---- | M] (ALWIL Software) -- C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys -- (aswFsBlk [Auto | Running])
DRV - [2009/02/05 16:08:10 | 00,094,032 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2 [Auto | Running])
DRV - [2009/02/05 16:06:10 | 00,023,152 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr [On_Demand | Running])
DRV - [2009/02/05 16:07:24 | 00,114,768 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP [System | Running])
DRV - [2009/02/05 16:06:20 | 00,051,376 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi [System | Running])
DRV - [2001/08/17 12:48:52 | 00,281,856 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\DRIVERS\ati2mpaa.sys -- (ati2mpaa [On_Demand | Stopped])
DRV - [2001/09/26 23:32:38 | 00,285,088 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\DRIVERS\ati2mtaa.sys -- (ati2mtaa [On_Demand | Stopped])
DRV - [2004/08/04 01:29:30 | 00,104,960 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\DRIVERS\atinrvxx.sys -- (atinrvxx [On_Demand | Stopped])
DRV - [2001/08/17 12:49:12 | 00,049,920 | ---- | M] () -- C:\WINDOWS\System32\DRIVERS\atirtcap.sys -- (ATIVRVXX [On_Demand | Stopped])
DRV - [2006/05/04 02:00:00 | 00,002,432 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\drivers\cdr4_xp.sys -- (Cdr4_xp [System | Stopped])
DRV - [2006/05/04 02:00:00 | 00,002,560 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\drivers\cdralw2k.sys -- (Cdralw2k [System | Stopped])
DRV - [2004/04/13 15:37:56 | 00,285,824 | ---- | M] (Roxio) -- C:\WINDOWS\System32\drivers\Cdudf_xp.sys -- (cdudf_xp [System | Running])
DRV - [2002/07/19 08:10:20 | 00,006,656 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\drivers\cinemsup.sys -- (Cinemsup [System | Running])
DRV - [2008/06/17 16:16:46 | 00,155,648 | ---- | M] () -- C:\WINDOWS\System32\drivers\DCDisk.sys -- (DCDisk [System | Running])
DRV - [2008/06/17 16:16:46 | 00,077,472 | ---- | M] () -- C:\WINDOWS\System32\drivers\dcsnap.sys -- (dcsnap [Boot | Running])
DRV - [2003/03/30 12:19:20 | 00,006,494 | ---- | M] (Mitsubishi Electric , NEC-Mitsubishi Electric Visual Systems) -- C:\WINDOWS\System32\DRIVERS\Moni2c.sys -- (DDCCI [On_Demand | Stopped])
DRV - [2004/04/15 22:57:26 | 00,140,416 | ---- | M] (Windows (R) 2000 DDK provider) -- C:\WINDOWS\System32\drivers\DVDVRRdr_xp.sys -- (DVDVRRdr_xp [System | Running])
DRV - [2004/04/13 15:37:30 | 00,023,680 | ---- | M] (Roxio) -- C:\WINDOWS\System32\drivers\dvd_2k.sys -- (dvd_2K [On_Demand | Running])
DRV - [2002/06/03 11:18:32 | 00,040,832 | ---- | M] (Creative Technology Ltd.) -- C:\WINDOWS\system32\drivers\es1371mp.sys -- (es1371 [On_Demand | Running])
DRV - [2002/05/23 11:28:56 | 00,070,656 | ---- | M] (Promise Technology, Inc.) -- C:\WINDOWS\system32\DRIVERS\fasttrak.sys -- (fasttrak [Boot | Running])
DRV - [2004/08/04 02:08:22 | 00,010,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\DRIVERS\gameenum.sys -- (gameenum [On_Demand | Running])
DRV - [2008/04/17 13:12:54 | 00,015,464 | ---- | M] (GEAR Software Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys -- (GEARAspiWDM [On_Demand | Running])
DRV - [2003/12/17 15:41:38 | 00,005,632 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Norton Ghost 2003\ghpciscan.sys -- (GhPciScan [System | Running])
DRV - [2007/02/06 13:27:04 | 00,185,728 | ---- | M] (Hauppauge Computer Works, Inc.) -- C:\WINDOWS\system32\DRIVERS\hcwPP2.sys -- (hcwPP2 [On_Demand | Running])
DRV - [2004/09/22 09:01:20 | 00,814,464 | R--- | M] (Hauppauge Computer Works, Inc.) -- C:\WINDOWS\system32\DRIVERS\hcwPVRP2.sys -- (hcwPVRP2 [On_Demand | Stopped])
DRV - [2002/01/14 07:49:38 | 00,033,602 | ---- | M] (Iomega Corporation) -- C:\WINDOWS\System32\DRIVERS\iomdisk.sys -- (iomdisk [Boot | Running])
DRV - [2001/09/19 06:11:00 | 00,050,432 | ---- | M] (Logitech) -- C:\WINDOWS\System32\DRIVERS\L8042Pr2.sys -- (l8042pr2 [On_Demand | Stopped])
DRV - [2001/09/19 06:11:00 | 00,022,064 | ---- | M] (Logitech) -- C:\WINDOWS\System32\DRIVERS\LHidFlt2.sys -- (LHidFlt2 [On_Demand | Running])
DRV - [2001/09/19 06:11:00 | 00,037,822 | ---- | M] (Logitech) -- C:\WINDOWS\system32\drivers\LHidUsb.Sys -- (LHidUsb [On_Demand | Running])
DRV - [2001/09/19 06:11:00 | 00,005,840 | ---- | M] (Logitech) -- C:\WINDOWS\System32\DRIVERS\LKbdFlt2.sys -- (LKbdFlt2 [On_Demand | Running])
DRV - [2001/09/19 06:11:00 | 00,067,440 | ---- | M] (Logitech) -- C:\WINDOWS\System32\DRIVERS\LMouFlt2.sys -- (LMouFlt2 [On_Demand | Running])
DRV - [2004/04/13 19:20:08 | 00,015,781 | R--- | M] (Meetinghouse Data Communications) -- C:\WINDOWS\system32\DRIVERS\mdc8021x.sys -- (MDC8021X [Auto | Running])
DRV - [2004/04/13 15:29:22 | 00,023,680 | ---- | M] (Roxio) -- C:\WINDOWS\System32\drivers\mmc_2k.sys -- (mmc_2K [On_Demand | Stopped])
DRV - [2004/08/04 01:29:28 | 00,013,824 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\DRIVERS\atinmdxx.sys -- (MVDCODEC [Auto | Stopped])
DRV - [2007/02/14 01:32:32 | 03,983,872 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\nv4_mini.sys -- (nv [On_Demand | Running])
DRV - [2003/04/16 14:21:30 | 00,004,228 | ---- | M] (PowerQuest Corporation) -- C:\WINDOWS\System32\drivers\PQNTDRV.sys -- (PQNTDrv [System | Running])
DRV - [2001/08/23 12:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
DRV - [2004/04/13 15:23:58 | 00,117,248 | ---- | M] (Roxio) -- C:\WINDOWS\System32\drivers\Pwd_2k.sys -- (pwd_2k [System | Running])
DRV - [2008/05/22 18:22:16 | 00,043,528 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\DRIVERS\PxHelp20.sys -- (PxHelp20 [Boot | Running])
DRV - [2007/11/13 05:25:54 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys -- (Secdrv [Auto | Running])
DRV - [2005/10/07 16:42:14 | 00,038,468 | ---- | M] (Alcor Micro Corp.) -- C:\WINDOWS\System32\Drivers\sunkfilt.sys -- (SunkFilt [On_Demand | Stopped])
DRV - [2004/04/15 22:53:40 | 00,198,528 | ---- | M] (Roxio) -- C:\WINDOWS\System32\drivers\Udfreadr.sys -- (UDFReadr [System | Running])
DRV - [2001/08/17 13:52:22 | 00,036,736 | ---- | M] (Promise Technology, Inc.) -- C:\WINDOWS\System32\DRIVERS\ultra.sys -- (ultra [Boot | Running])
DRV - [2004/05/16 20:46:18 | 00,390,752 | R--- | M] ( ) -- C:\WINDOWS\system32\DRIVERS\wlanCIG.sys -- (wlanCIG [On_Demand | Running])
DRV - [2004/03/01 14:57:04 | 00,010,368 | ---- | M] (Streamzap, Inc.) -- C:\WINDOWS\system32\drivers\zremote.sys -- (zremote [On_Demand | Stopped])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://my.yahoo.com/index.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/index.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Update_Check_Page = http://www.microsoft.com/isapi/redir.dll?Prd=ie&Pver=5.0&Ar=ie5update
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ams-server*

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ams-server*

IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = about:blank
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
IE - HKU\S-1-5-19\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ams-server*

IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = about:blank
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
IE - HKU\S-1-5-20\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ams-server*

IE - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\S-1-5-21-1547161642-1580436667-1708537768-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10

FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/05/05 22:38:40 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2005/04/27 22:53:28 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2005/04/27 22:53:26 | 00,000,000 | ---D | M]

[2009/05/17 22:44:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\David Wilson\Application Data\mozilla\Extensions
[2009/05/17 22:44:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\David Wilson\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2005/04/30 10:59:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\David Wilson\Application Data\mozilla\Firefox\Profiles\5nzx41m4.default\extensions
[2005/04/27 22:53:52 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2005/04/27 22:53:52 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/05/05 22:49:12 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
[2009/05/05 22:49:12 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
[2009/05/05 22:49:12 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
[2009/05/05 22:49:12 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2009/05/05 22:38:48 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/04/24 02:01:00 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/04/24 02:01:00 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2008/01/04 11:36:50 | 00,001,538 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2006/07/05 14:47:38 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2008/01/04 11:36:50 | 00,000,947 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2008/03/08 05:35:22 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2008/09/22 15:14:04 | 00,000,759 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2008/04/16 00:08:20 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008/03/28 14:11:14 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2008/01/04 11:36:50 | 00,000,831 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (bho2gr Class) - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - E:\Program Files\GetRight\xx2gr.dll (Headlight Software, Inc.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (no name) - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - Reg Error: Key error. File not found
O3 - HKLM\..\Toolbar: (no name) - {724d43a0-0d85-11d4-9908-00400523e39a} - Reg Error: Key error. File not found
O3 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\..\Toolbar\ShellBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
O3 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\..\Toolbar\WebBrowser: (no name) - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - Reg Error: Key error. File not found
O3 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Error: Key error. File not found
O3 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\..\Toolbar\WebBrowser: (no name) - {724D43A0-0D85-11D4-9908-00400523E39A} - Reg Error: Key error. File not found
O3 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\..\Toolbar\WebBrowser: (no name) - {81CA3009-6200-4A6D-93C6-F1E9A6821C7F} - Reg Error: Value error. File not found
O3 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\..\Toolbar\WebBrowser: (no name) - {F2CF5485-4E02-4F68-819C-B92DE9277049} - Reg Error: Key error. File not found
O3 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\..\Toolbar\WebBrowser: (no name) - {FE6BC4EF-5676-484B-88AE-883323913256} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe (Easy Systems Japan Ltd.)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install File not found
O4 - HKLM..\Run: [PRISMSVR.EXE] "C:\WINDOWS\system32\PRISMSVR.EXE" /APPLY (Conexant Systems, Inc.)
O4 - HKLM..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" (Safer Networking Limited)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004..\Run: [LDM] \Program\BackWeb-8876480.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk = E:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\2Wire Wireless Client.lnk = C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.exe (2Wire Inc.)
O4 - Startup: C:\Documents and Settings\David Wilson\Start Menu\Programs\Startup\TrayDay.lnk = C:\Program Files\TrayDay\TrayDay.exe (MJMSoft Design Limited)
O4 - Startup: C:\Documents and Settings\David Wilson\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Advanced\Folder\Hidden\SHOWALL: CheckedValue = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartBanner = 01 00 00 00 [binary data]
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogOff = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Advanced\Folder\Hidden\SHOWALL: CheckedValue = 1
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartBanner = 01 00 00 00 [binary data]
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogOff = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Advanced\Folder\Hidden\SHOWALL: CheckedValue = 1
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 95 00 00 00 [binary data]
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartBanner = 01 00 00 00 [binary data]
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogOff = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = [binary data]
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 95 00 00 00 [binary data]
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartBanner = 01 00 00 00 [binary data]
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogOff = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = [binary data]
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 1
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartBanner = 01 00 00 00 [binary data]
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 1
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 1
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogOff = 0
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = [binary data]
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Advanced\Folder\Hidden\SHOWALL: CheckedValue = 1
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004_Classes\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O8 - Extra context menu item: Download with GetRight - Reg Error: Value error. File not found
O8 - Extra context menu item: E&xport to Microsoft Excel - Reg Error: Value error. File not found
O8 - Extra context menu item: Open with GetRight Browser - Reg Error: Value error. File not found
O9 - Extra Button: Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - File not found
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - File not found
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - File not found
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - File not found
O9 - Extra Button: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - File not found
O9 - Extra 'Tools' menuitem : Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - File not found
O9 - Extra Button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - E:\Program Files\ICQ\ICQ.exe File not found
O9 - Extra 'Tools' menuitem : ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - E:\Program Files\ICQ\ICQ.exe File not found
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - File not found
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - File not found
O9 - Extra Button: Share in Hello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll (Picasa, Inc.)
O9 - Extra 'Tools' menuitem : Share in H&ello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll (Picasa, Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\.DEFAULT\..Trusted Domains: aol.com ([free] http in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: 50 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-18\..Trusted Domains: aol.com ([free] http in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: 50 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-19\..Trusted Domains: aol.com ([free] http in Trusted sites)
O15 - HKU\S-1-5-19\..Trusted Domains: 2 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-20\..Trusted Domains: aol.com ([free] http in Trusted sites)
O15 - HKU\S-1-5-20\..Trusted Domains: 2 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\..Trusted Domains: 48 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {00000075-0000-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/voxmsdec.CAB (Reg Error: Key error.)
O16 - DPF: {00000160-0000-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/msaudio.cab (Reg Error: Key error.)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab (Support.com Configuration Class)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} http://gulllake.gospelcom.net/unsecure/other_media/views/ipixx.cab (iPIX ActiveX Control)
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} http://www.musicnotes.com/download/mnviewer.cab (Musicnotes Viewer)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {31564D57-0000-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/wmvax.cab (Reg Error: Key error.)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {40272BF7-4FF5-4D6F-9BAD-3C1D3CB32982} http://www.live365.com/players/p365vip.cab (Live365PlayerVIP Class)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://www2.snapfish.com/SnapfishActivia.cab (Snapfish Activia)
O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} https://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab (Microsoft.WinRep)
O16 - DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} http://updates.lifescapeinc.com/installers/pinstall/pinstall.cab (Install Class)
O16 - DPF: {712362BF-E411-4F43-99D2-EB15F80AF1DB} http://entimg.msn.com/client/msnediag3518.cab (MsneDiag Class)
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} http://picture.vzw.com/activex/VerizonWirelessUploadControl.cab (Verizon Wireless Media Upload)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {924C1588-90C3-4910-B6CA-D57A1C0418FE} http://download.yahoo.com/dl/bookmarks/ybconvfav030408.cab (YbUploadFavsCtl Class)
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} http://rtc.webresponse.one.microsoft.com/media/xp/TLIEFlash.CAB (TLIEFlashObj Class)
O16 - DPF: {9DBAFCCF-592F-FFFF-FFFF-00608CEC297C} (Reg Error: Key error.)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38079.8121527778 (Reg Error: Key error.)
O16 - DPF: {A662DA7E-CCB7-4743-B71A-D817F6D575DF} http://www.autodesk.com/global/dwfviewer/installer/DwfViewerSetup.cab (Autodesk DWF Viewer Control)
O16 - DPF: {A7E092C3-692A-11D0-A7E5-08002B322F3B} https://webresponse.one.microsoft.com/oas/ActiveX/FileXfer.cab (WebResponseAttachments Control)
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab (Reg Error: Key error.)
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} http://support.f-secure.com/ols/fscax.cab (F-Secure Online Scanner 3.3)
O16 - DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.4.0/jinstall-1_4_0-windows-i586.cab (Java Plug-in 1.4.0)
O16 - DPF: {CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} http://www.live365.com/players/play365.cab (Live365Player Class)
O16 - DPF: {CEBC955E-58AF-11D2-A30A-00A0C903492B} http://windowsupdate.microsoft.com/R848/V31Controls/x86/w98/en/actsetup.cab (Reg Error: Key error.)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab (get_atlcom Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab (iTunesDetector Class)
O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} http://entimg.msn.com/client/msnmusax3518.cab (MsnMusicAx Class)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\SYSTEM\dajava.cab (Reg Error: Key error.)
O16 - DPF: Internet Explorer Classes for Java file://C:\WINDOWS\SYSTEM\iejava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Checkers http://download.games.yahoo.com/games/clients/y/kt0_x.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Chess http://download.yahoo.com/games/clients/y/cr1_x.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Hearts http://download.yahoo.com/games/clients/y/hr1_x.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Pool 2 http://download.yahoo.com/games/clients/y/por9_x.cab (Reg Error: Key error.)
O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O20 - Winlogon\Notify\dimsntfy: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\andpripas.dll ()
O24 - Desktop Components:0 (Internet Explorer Channel Bar) - 131A6951-7F78-11D0-A979-00C04FD705A2
O24 - Desktop Components:1 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/03/23 09:33:06 | 00,000,099 | ---- | M] () - C:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2001/11/04 15:42:42 | 00,000,095 | -HS- | M] () - C:\AUTOEXEC.DOS -- [ FAT32 ]
O32 - AutoRun File - [2001/11/05 23:02:34 | 00,000,095 | -HS- | M] () - C:\AUTOEXEC.BAK -- [ FAT32 ]
O33 - MountPoints2\{e2de2786-6cdd-11db-97eb-00045a68bf2f}\Shell - "" = AutoRun
O33 - MountPoints2\{e2de2786-6cdd-11db-97eb-00045a68bf2f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{e2de2786-6cdd-11db-97eb-00045a68bf2f}\Shell\AutoRun\command - "" = H:\LaunchU3.exe -- File not found
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\LaunchU3.exe -- File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2002/03/23 10:06:56 | 00,000,000 | ---D | M]

proskoma
2009-05-19, 14:11
========== Files/Folders - Created Within 30 Days ==========

[9 C:\WINDOWS\*.tmp files]
[2009/05/19 07:58:19 | 00,002,709 | ---- | C] () -- C:\WINDOWS\System32\andpripas.dat
[2009/05/19 07:57:52 | 00,000,000 | ---D | C] -- C:\_OTListIt
[2009/05/17 22:44:40 | 00,001,514 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/05/17 22:43:07 | 00,001,641 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2009/05/16 08:20:17 | 00,501,248 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\David Wilson\Desktop\OTListIt2.exe
[2009/05/16 08:09:32 | 00,000,230 | ---- | C] () -- C:\WINDOWS\System32\spupdsvc.inf
[2009/05/16 08:05:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2009/05/13 07:50:42 | 00,000,000 | -HSD | C] -- C:\FOUND.043
[2009/05/07 23:33:17 | 16,101,45792 | -HS- | C] () -- C:\hiberfil.sys
[2009/05/07 22:28:26 | 01,080,054 | ---- | C] () -- C:\Documents and Settings\David Wilson\Desktop\Aquarium 1.bmp
[2009/05/07 22:24:10 | 01,080,056 | ---- | C] () -- C:\Documents and Settings\David Wilson\Desktop\bach.bmp
[2009/05/07 22:11:31 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Money Plus
[2009/05/06 18:41:05 | 00,360,021 | ---- | C] () -- C:\Documents and Settings\David Wilson\Desktop\dds.scr
[2009/05/06 00:10:58 | 00,001,621 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/05/06 00:10:57 | 00,114,768 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2009/05/06 00:10:57 | 00,097,480 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\AvastSS.scr
[2009/05/06 00:10:57 | 00,094,032 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2009/05/06 00:10:57 | 00,093,296 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2009/05/06 00:10:57 | 00,051,376 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2009/05/06 00:10:57 | 00,026,944 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2009/05/06 00:10:57 | 00,023,152 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2009/05/06 00:10:57 | 00,020,560 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2009/05/06 00:10:41 | 01,256,296 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\aswBoot.exe
[2009/05/06 00:10:41 | 00,380,928 | ---- | C] () -- C:\WINDOWS\System32\actskin4.ocx
[2009/05/06 00:10:39 | 00,000,000 | ---D | C] -- C:\Program Files\Alwil Software
[2009/05/06 00:03:40 | 00,147,100 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2009/05/05 22:10:14 | 00,001,024 | -H-- | C] () -- C:\diskfile1
[2009/05/05 22:10:13 | 00,016,384 | -H-- | C] () -- C:\logicinf.bin
[2009/04/28 19:05:04 | 00,286,208 | ---- | C] () -- C:\Documents and Settings\David Wilson\Desktop\gmer.exe
[2009/04/23 20:39:11 | 02,988,491 | R--- | C] () -- C:\Documents and Settings\David Wilson\Desktop\ComboFix.exe
[2009/04/22 18:53:37 | 00,000,211 | ---- | C] () -- C:\Boot.bak
[2009/04/22 18:53:35 | 00,260,272 | ---- | C] () -- C:\cmldr
[2009/04/22 18:53:35 | 00,000,000 | RHSD | C] -- C:\cmdcons
[2009/04/22 18:52:40 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2009/04/22 18:52:40 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2009/04/22 18:52:40 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2009/04/22 18:52:40 | 00,117,248 | ---- | C] () -- C:\WINDOWS\vFind.exe
[2009/04/22 18:52:40 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2009/04/22 18:52:40 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2009/04/22 18:52:40 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2009/04/22 18:52:40 | 00,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2009/04/22 18:52:28 | 00,000,000 | ---D | C] -- C:\Qoobox
[2009/04/20 19:43:08 | 00,000,000 | ---D | C] -- C:\rsit
[2009/04/19 18:34:48 | 00,360,021 | ---- | C] () -- C:\something.scr
[2009/04/17 19:53:43 | 00,000,066 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2008/10/11 13:52:43 | 00,155,648 | ---- | C] () -- C:\WINDOWS\System32\drivers\DCDisk.sys
[2008/10/11 13:52:43 | 00,077,472 | ---- | C] () -- C:\WINDOWS\System32\drivers\dcsnap.sys
[2008/05/22 18:22:18 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2008/05/22 18:19:46 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dtu100.dll.manifest
[2008/05/22 18:19:46 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dpl100.dll.manifest
[2008/05/22 18:18:54 | 00,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll
[2007/10/21 19:14:25 | 00,334,174 | ---- | C] () -- C:\WINDOWS\sqlite3.dll
[2007/08/18 08:33:06 | 00,390,752 | R--- | C] ( ) -- C:\WINDOWS\System32\drivers\wlanCIG.sys
[2007/07/25 15:24:30 | 01,559,040 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2007/02/14 01:32:38 | 01,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2007/02/14 01:32:38 | 01,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2007/02/14 01:32:36 | 01,470,464 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2007/02/14 01:32:36 | 00,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2007/02/14 01:32:36 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2007/02/14 01:32:36 | 00,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2007/02/14 01:32:32 | 00,212,992 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2007/02/03 12:23:24 | 00,000,004 | -H-- | C] () -- C:\WINDOWS\uccspecb.sys
[2006/06/23 07:02:52 | 05,087,560 | ---- | C] () -- C:\WINDOWS\System32\andpripas.dll
[2006/02/26 16:08:28 | 00,585,728 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2006/02/22 00:36:14 | 00,000,252 | ---- | C] () -- C:\WINDOWS\System32\SNet.dll
[2005/07/10 19:34:23 | 00,000,037 | ---- | C] () -- C:\WINDOWS\ipixActivex.ini
[2005/05/22 15:22:22 | 00,000,281 | ---- | C] () -- C:\WINDOWS\irremote.ini
[2005/05/22 15:21:38 | 00,065,536 | ---- | C] () -- C:\WINDOWS\System32\dmcrypto.dll
[2005/05/22 15:21:24 | 00,000,211 | ---- | C] () -- C:\WINDOWS\nanoPEG.ini
[2005/05/22 14:48:36 | 00,002,586 | ---- | C] () -- C:\WINDOWS\HCWPNP.INI
[2005/01/26 17:07:33 | 00,000,000 | ---- | C] () -- C:\WINDOWS\QuickInstall.INI
[2005/01/15 12:23:28 | 00,000,479 | ---- | C] () -- C:\WINDOWS\RAIDeUtility.ini
[2004/12/20 10:59:02 | 00,000,119 | ---- | C] () -- C:\WINDOWS\WSST_Screen_Saver.ini
[2004/10/10 19:32:29 | 00,000,000 | ---- | C] () -- C:\WINDOWS\iPlayer.INI
[2004/08/04 03:56:42 | 00,081,920 | ---- | C] () -- C:\WINDOWS\System32\ieencode.dll
[2004/07/27 16:34:09 | 00,000,031 | ---- | C] () -- C:\WINDOWS\oupdate.INI
[2004/07/25 22:32:36 | 00,524,288 | ---- | C] () -- C:\WINDOWS\System32\TDI-SonyOMG.dll
[2004/07/12 17:38:44 | 00,000,011 | ---- | C] () -- C:\WINDOWS\wanpatan.ini
[2004/07/12 17:38:15 | 00,028,672 | ---- | C] () -- C:\WINDOWS\gscr.dll
[2004/05/15 21:33:31 | 00,001,100 | ---- | C] () -- C:\WINDOWS\System32\imgfil.dll
[2004/04/27 17:49:59 | 00,000,100 | ---- | C] () -- C:\WINDOWS\System32\UNWISE.INI
[2003/11/30 14:39:16 | 00,000,222 | ---- | C] () -- C:\WINDOWS\hpbafd.ini
[2003/06/11 18:32:46 | 00,001,842 | ---- | C] () -- C:\WINDOWS\System32\csnews.dll
[2003/03/01 08:08:20 | 00,000,348 | ---- | C] () -- C:\WINDOWS\hegames.ini
[2002/12/10 13:13:32 | 00,172,032 | ---- | C] () -- C:\WINDOWS\System32\GSnap.dll
[2002/12/10 13:13:32 | 00,040,960 | ---- | C] () -- C:\WINDOWS\System32\atlcontrol.dll
[2002/12/10 13:13:32 | 00,036,864 | ---- | C] () -- C:\WINDOWS\System32\UninstGMT.dll
[2002/12/10 13:12:24 | 00,000,494 | ---- | C] () -- C:\WINDOWS\demo.INI
[2002/12/10 01:36:34 | 00,036,864 | ---- | C] () -- C:\WINDOWS\System32\gbttk.dll
[2002/11/11 19:45:00 | 00,036,864 | ---- | C] () -- C:\WINDOWS\System32\NetStat32.dll
[2002/09/25 21:48:36 | 00,109,056 | ---- | C] () -- C:\WINDOWS\System32\LGUICOM.DLL
[2002/09/25 21:48:36 | 00,000,488 | ---- | C] () -- C:\WINDOWS\Cmousecc.ini
[2002/08/15 07:32:26 | 00,022,618 | ---- | C] () -- C:\WINDOWS\System32\perfil.dll
[2002/08/15 07:32:26 | 00,017,672 | ---- | C] () -- C:\WINDOWS\System32\nvgamfil.dll
[2002/08/15 07:32:26 | 00,016,802 | ---- | C] () -- C:\WINDOWS\System32\popfil.dll
[2002/08/15 07:32:26 | 00,014,712 | ---- | C] () -- C:\WINDOWS\System32\tafil.dll
[2002/08/15 07:32:26 | 00,012,730 | ---- | C] () -- C:\WINDOWS\System32\psyfil.dll
[2002/08/15 07:32:26 | 00,012,266 | ---- | C] () -- C:\WINDOWS\System32\sporfil.dll
[2002/08/15 07:32:26 | 00,009,634 | ---- | C] () -- C:\WINDOWS\System32\pkmon.dll
[2002/08/15 07:32:26 | 00,006,830 | ---- | C] () -- C:\WINDOWS\System32\swfil.dll
[2002/08/15 07:32:26 | 00,006,050 | ---- | C] () -- C:\WINDOWS\System32\wrestfil.dll
[2002/08/15 07:32:26 | 00,002,246 | ---- | C] () -- C:\WINDOWS\System32\wzfil.dll
[2002/08/15 07:32:26 | 00,001,656 | ---- | C] () -- C:\WINDOWS\System32\tapfil.dll
[2002/08/15 07:32:26 | 00,000,778 | ---- | C] () -- C:\WINDOWS\System32\mp3fil.dll
[2002/08/15 07:32:26 | 00,000,733 | ---- | C] () -- C:\WINDOWS\System32\spmfil.dll
[2002/08/15 07:32:24 | 00,013,154 | ---- | C] () -- C:\WINDOWS\System32\finfil.dll
[2002/08/15 07:32:24 | 00,012,422 | ---- | C] () -- C:\WINDOWS\System32\entfil.dll
[2002/08/15 07:32:24 | 00,011,338 | ---- | C] () -- C:\WINDOWS\System32\fmfil.dll
[2002/08/15 07:32:24 | 00,009,796 | ---- | C] () -- C:\WINDOWS\System32\gnfil.dll
[2002/08/15 07:32:24 | 00,008,652 | ---- | C] () -- C:\WINDOWS\System32\jbfil.dll
[2002/08/15 07:32:24 | 00,007,778 | ---- | C] () -- C:\WINDOWS\System32\movfil.dll
[2002/08/15 07:32:24 | 00,007,642 | ---- | C] () -- C:\WINDOWS\System32\Auctfil.dll
[2002/08/15 07:32:24 | 00,001,816 | ---- | C] () -- C:\WINDOWS\System32\fshrfil.dll
[2002/08/13 23:28:02 | 00,094,996 | ---- | C] () -- C:\WINDOWS\System32\adwfil.dll
[2002/08/13 23:28:02 | 00,013,034 | ---- | C] () -- C:\WINDOWS\System32\gblfil.dll
[2002/08/13 23:28:02 | 00,010,862 | ---- | C] () -- C:\WINDOWS\System32\chtfil.dll
[2002/08/13 23:28:02 | 00,005,260 | ---- | C] () -- C:\WINDOWS\System32\iawfil.dll
[2002/08/13 23:28:02 | 00,004,826 | ---- | C] () -- C:\WINDOWS\System32\vgamfil.dll
[2002/08/13 23:28:02 | 00,004,442 | ---- | C] () -- C:\WINDOWS\System32\hatfil.dll
[2002/08/13 23:28:02 | 00,003,818 | ---- | C] () -- C:\WINDOWS\System32\viofil.dll
[2002/08/13 23:28:02 | 00,003,444 | ---- | C] () -- C:\WINDOWS\System32\srchin.dll
[2002/08/13 23:28:02 | 00,003,360 | ---- | C] () -- C:\WINDOWS\System32\lgwfil.dll
[2002/08/13 23:28:02 | 00,001,830 | ---- | C] () -- C:\WINDOWS\System32\cultfil.dll
[2002/08/13 23:28:02 | 00,001,468 | ---- | C] () -- C:\WINDOWS\System32\gdwfil.dll
[2002/08/13 23:28:02 | 00,000,400 | ---- | C] () -- C:\WINDOWS\bsnlst.dll
[2002/06/04 23:55:32 | 00,000,119 | ---- | C] () -- C:\WINDOWS\NNS.INI
[2002/04/28 14:54:12 | 00,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll
[2002/03/23 11:39:16 | 00,000,011 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.ini
[2002/03/23 10:08:10 | 00,076,659 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2002/03/23 10:08:08 | 00,373,248 | ---- | C] () -- C:\WINDOWS\EyeCand3.INI
[2002/03/23 10:08:08 | 00,003,598 | ---- | C] () -- C:\WINDOWS\HTMLHELP.INI
[2002/03/23 10:08:08 | 00,001,467 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2002/03/23 10:08:08 | 00,000,924 | ---- | C] () -- C:\WINDOWS\fauve.ini
[2002/03/23 10:08:08 | 00,000,787 | ---- | C] () -- C:\WINDOWS\SCANREG.INI
[2002/03/23 10:08:08 | 00,000,677 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2002/03/23 10:08:08 | 00,000,509 | ---- | C] () -- C:\WINDOWS\FS.INI
[2002/03/23 10:08:08 | 00,000,470 | ---- | C] () -- C:\WINDOWS\net2fone.ini
[2002/03/23 10:08:08 | 00,000,459 | ---- | C] () -- C:\WINDOWS\YACHT-Z.INI
[2002/03/23 10:08:08 | 00,000,277 | ---- | C] () -- C:\WINDOWS\SBWIN.INI
[2002/03/23 10:08:08 | 00,000,277 | ---- | C] () -- C:\WINDOWS\AATOOLS.INI
[2002/03/23 10:08:08 | 00,000,233 | ---- | C] () -- C:\WINDOWS\NETSCAPE.INI
[2002/03/23 10:08:08 | 00,000,226 | ---- | C] () -- C:\WINDOWS\QTW.INI
[2002/03/23 10:08:08 | 00,000,221 | ---- | C] () -- C:\WINDOWS\emsoft.ini
[2002/03/23 10:08:08 | 00,000,199 | ---- | C] () -- C:\WINDOWS\swacnfg.ini
[2002/03/23 10:08:08 | 00,000,192 | ---- | C] () -- C:\WINDOWS\mb.ini
[2002/03/23 10:08:08 | 00,000,152 | ---- | C] () -- C:\WINDOWS\LODERUNN.INI
[2002/03/23 10:08:08 | 00,000,149 | ---- | C] () -- C:\WINDOWS\XDCS_DO2.INI
[2002/03/23 10:08:08 | 00,000,144 | ---- | C] () -- C:\WINDOWS\INDEO.INI
[2002/03/23 10:08:08 | 00,000,131 | ---- | C] () -- C:\WINDOWS\chess.ini
[2002/03/23 10:08:08 | 00,000,122 | ---- | C] () -- C:\WINDOWS\PROTOCOL.INI
[2002/03/23 10:08:08 | 00,000,105 | ---- | C] () -- C:\WINDOWS\mapiuid.ini
[2002/03/23 10:08:08 | 00,000,095 | ---- | C] () -- C:\WINDOWS\winamp.ini
[2002/03/23 10:08:08 | 00,000,095 | ---- | C] () -- C:\WINDOWS\icewin.INI
[2002/03/23 10:08:08 | 00,000,089 | ---- | C] () -- C:\WINDOWS\KingsC.ini
[2002/03/23 10:08:08 | 00,000,080 | ---- | C] () -- C:\WINDOWS\entpack.ini
[2002/03/23 10:08:08 | 00,000,072 | ---- | C] () -- C:\WINDOWS\boxworld.ini
[2002/03/23 10:08:08 | 00,000,050 | ---- | C] () -- C:\WINDOWS\winfile.ini
[2002/03/23 10:08:08 | 00,000,042 | ---- | C] () -- C:\WINDOWS\CRISPY.INI
[2002/03/23 10:08:08 | 00,000,031 | ---- | C] () -- C:\WINDOWS\MSCHOMP.INI
[2002/03/23 10:08:08 | 00,000,026 | ---- | C] () -- C:\WINDOWS\MSOFFICE.INI
[2002/03/23 10:08:08 | 00,000,025 | ---- | C] () -- C:\WINDOWS\SOL.INI
[2002/03/23 10:08:08 | 00,000,000 | ---- | C] () -- C:\WINDOWS\SYSCHECK.INI
[2002/03/23 10:08:08 | 00,000,000 | ---- | C] () -- C:\WINDOWS\RESMNGR.INI
[2002/03/23 10:08:08 | 00,000,000 | ---- | C] () -- C:\WINDOWS\progman.ini
[2002/03/23 10:08:08 | 00,000,000 | ---- | C] () -- C:\WINDOWS\PCFRIEND.INI
[2002/03/23 10:08:08 | 00,000,000 | ---- | C] () -- C:\WINDOWS\MSINFO32.INI
[2002/03/23 10:08:08 | 00,000,000 | ---- | C] () -- C:\WINDOWS\hjbrowse.ini
[2002/03/23 10:08:08 | 00,000,000 | ---- | C] () -- C:\WINDOWS\DXINFO.INI
[2002/03/23 10:08:06 | 00,012,327 | ---- | C] () -- C:\WINDOWS\IOS.INI
[2002/03/23 10:08:06 | 00,008,405 | ---- | C] () -- C:\WINDOWS\NETDET.INI
[2002/03/23 10:08:06 | 00,005,068 | ---- | C] () -- C:\WINDOWS\DELETEFI.INI
[2002/03/23 10:08:06 | 00,000,865 | ---- | C] () -- C:\WINDOWS\DOSREP.INI
[2002/03/23 10:08:06 | 00,000,225 | ---- | C] () -- C:\WINDOWS\TELEPHON.INI
[2002/03/23 10:08:06 | 00,000,180 | ---- | C] () -- C:\WINDOWS\winmine.ini
[2002/03/23 10:08:06 | 00,000,127 | ---- | C] () -- C:\WINDOWS\KPCMS.INI
[2002/03/23 10:08:06 | 00,000,068 | ---- | C] () -- C:\WINDOWS\FPXPRESS.INI
[2002/03/23 10:08:06 | 00,000,060 | ---- | C] () -- C:\WINDOWS\POWERPNT.INI
[2002/03/23 10:08:06 | 00,000,054 | ---- | C] () -- C:\WINDOWS\WAVEMIX.INI
[2002/03/23 09:51:34 | 00,049,920 | ---- | C] () -- C:\WINDOWS\System32\drivers\atirtcap.sys
[2002/03/23 09:51:32 | 00,009,472 | ---- | C] () -- C:\WINDOWS\System32\drivers\ativmdcd.sys
[2001/12/27 23:55:26 | 00,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll
[2001/12/27 23:55:26 | 00,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll
[2001/12/17 07:22:30 | 00,210,944 | ---- | C] () -- C:\WINDOWS\System32\MSVCRT10.DLL
[2001/12/17 07:22:28 | 00,027,648 | ---- | C] () -- C:\WINDOWS\PFPICK.DLL
[2001/08/26 15:08:16 | 00,057,344 | ---- | C] () -- C:\WINDOWS\System32\icmfilter.dll
[2001/08/23 12:00:04 | 00,003,166 | ---- | C] () -- C:\WINDOWS\win.ini
[2001/08/23 12:00:04 | 00,000,638 | ---- | C] () -- C:\WINDOWS\system.ini
[2001/05/06 23:59:46 | 00,149,504 | ---- | C] () -- C:\WINDOWS\unwise32.dll
[2001/01/29 00:43:42 | 00,161,792 | ---- | C] () -- C:\WINDOWS\System32\nfsspi.dll
[2001/01/29 00:00:58 | 00,002,048 | ---- | C] () -- C:\WINDOWS\MNMGM32.DLL
[2000/06/22 14:34:24 | 00,088,064 | ---- | C] () -- C:\WINDOWS\System32\AudioExCtl.dll
[2000/06/22 14:33:36 | 00,024,576 | ---- | C] () -- C:\WINDOWS\System32\HcdDll32.dll
[2000/06/22 14:33:36 | 00,005,120 | ---- | C] () -- C:\WINDOWS\System32\HWDll.dll
[2000/06/20 13:11:02 | 00,110,592 | ---- | C] () -- C:\WINDOWS\System32\cdtool.dll
[2000/05/13 16:59:44 | 00,054,266 | ---- | C] () -- C:\WINDOWS\ATM.INI
[2000/05/13 10:27:11 | 00,020,992 | ---- | C] () -- C:\WINDOWS\System32\PFMAPI32.DLL
[2000/05/13 01:08:06 | 00,187,392 | ---- | C] () -- C:\WINDOWS\System32\LTANN62N.DLL
[2000/05/13 01:08:06 | 00,076,288 | ---- | C] () -- C:\WINDOWS\System32\LTIMG62N.DLL
[2000/05/13 01:08:06 | 00,047,616 | ---- | C] () -- C:\WINDOWS\System32\Lftif62n.dll
[2000/05/13 01:08:06 | 00,043,008 | ---- | C] () -- C:\WINDOWS\System32\ltfil62n.dll
[2000/05/13 01:08:06 | 00,029,184 | ---- | C] () -- C:\WINDOWS\System32\LTWND62N.DLL
[2000/05/13 01:08:06 | 00,024,064 | ---- | C] () -- C:\WINDOWS\System32\LTTWN62N.DLL
[2000/05/13 01:08:06 | 00,022,528 | ---- | C] () -- C:\WINDOWS\System32\tvcntl32.dll
[2000/05/13 01:08:06 | 00,020,480 | ---- | C] () -- C:\WINDOWS\System32\Lfpsd62n.dll
[2000/05/13 01:08:06 | 00,019,968 | ---- | C] () -- C:\WINDOWS\System32\Lfwmf62n.dll
[2000/05/13 01:08:06 | 00,019,968 | ---- | C] () -- C:\WINDOWS\System32\Lftga62n.dll
[2000/05/13 01:08:06 | 00,019,456 | ---- | C] () -- C:\WINDOWS\System32\Lfwpg62n.dll
[2000/05/13 01:08:06 | 00,018,432 | ---- | C] () -- C:\WINDOWS\System32\Lfras62n.dll
[2000/05/13 01:08:06 | 00,017,408 | ---- | C] () -- C:\WINDOWS\System32\Lfwfx62n.dll
[2000/05/13 01:08:05 | 00,175,616 | ---- | C] () -- C:\WINDOWS\System32\Lffax62n.dll
[2000/05/13 01:08:05 | 00,158,720 | ---- | C] () -- C:\WINDOWS\System32\Lfcmp62n.dll
[2000/05/13 01:08:05 | 00,110,080 | ---- | C] () -- C:\WINDOWS\System32\Lfpng62n.dll
[2000/05/13 01:08:05 | 00,027,136 | ---- | C] () -- C:\WINDOWS\System32\Lflma62n.dll
[2000/05/13 01:08:05 | 00,024,576 | ---- | C] () -- C:\WINDOWS\System32\Lfica62n.dll
[2000/05/13 01:08:05 | 00,023,552 | ---- | C] () -- C:\WINDOWS\System32\Lfpcx62n.dll
[2000/05/13 01:08:05 | 00,023,552 | ---- | C] () -- C:\WINDOWS\System32\Lflmb62n.dll
[2000/05/13 01:08:05 | 00,022,528 | ---- | C] () -- C:\WINDOWS\System32\Lfeps62n.dll
[2000/05/13 01:08:05 | 00,022,016 | ---- | C] () -- C:\WINDOWS\System32\Lfpct62n.dll
[2000/05/13 01:08:05 | 00,022,016 | ---- | C] () -- C:\WINDOWS\System32\Lfgif62n.dll
[2000/05/13 01:08:05 | 00,022,016 | ---- | C] () -- C:\WINDOWS\System32\Lfbmp62n.dll
[2000/05/13 01:08:05 | 00,018,944 | ---- | C] () -- C:\WINDOWS\System32\Lfimg62n.dll
[2000/05/13 01:08:05 | 00,018,432 | ---- | C] () -- C:\WINDOWS\System32\Lfmsp62n.dll
[2000/05/13 01:08:05 | 00,017,920 | ---- | C] () -- C:\WINDOWS\System32\Lfmac62n.dll
[2000/05/13 01:08:05 | 00,017,920 | ---- | C] () -- C:\WINDOWS\System32\Lfcal62n.dll
[2000/05/13 01:08:05 | 00,017,408 | ---- | C] () -- C:\WINDOWS\System32\Lfpcd62n.dll
[2000/05/13 01:08:00 | 00,162,816 | ---- | C] () -- C:\WINDOWS\System32\ccmpeg.dll
[1999/09/20 10:05:32 | 00,013,387 | ---- | C] () -- C:\WINDOWS\System32\CinemSup.sys
[1998/10/11 00:07:38 | 00,088,576 | ---- | C] () -- C:\WINDOWS\System32\Iticheck.dll
[1998/03/18 02:57:02 | 00,021,504 | ---- | C] () -- C:\WINDOWS\System32\ThmUninst.dll
[1997/07/11 00:00:00 | 00,022,016 | ---- | C] () -- C:\WINDOWS\System32\ODBCSTF.DLL
[1997/07/11 00:00:00 | 00,022,016 | ---- | C] () -- C:\WINDOWS\System32\DOCOBJ.DLL
[1997/07/11 00:00:00 | 00,012,288 | ---- | C] () -- C:\WINDOWS\System32\HLINKPRX.DLL
[1997/06/13 20:56:08 | 00,056,832 | ---- | C] () -- C:\WINDOWS\System32\Iyvu9_32.dll
[1980/01/01 00:00:00 | 00,188,416 | ---- | C] () -- C:\WINDOWS\System32\MEMBG.DLL
[1980/01/01 00:00:00 | 00,129,080 | ---- | C] () -- C:\WINDOWS\Logow.sys.bak
[1980/01/01 00:00:00 | 00,129,078 | ---- | C] () -- C:\WINDOWS\Logos.sys.bak
[1980/01/01 00:00:00 | 00,000,025 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI

========== Files - Modified Within 30 Days ==========

[9 C:\WINDOWS\*.tmp files]
[2009/05/19 08:04:50 | 00,421,976 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/05/19 08:04:50 | 00,343,762 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/05/19 08:04:50 | 00,069,018 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/05/19 08:00:54 | 00,088,566 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2009/05/19 08:00:46 | 00,016,384 | -H-- | M] () -- C:\logicinf.bin
[2009/05/19 08:00:46 | 00,001,024 | -H-- | M] () -- C:\diskfile1
[2009/05/19 08:00:40 | 00,012,208 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/05/19 08:00:38 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\David Wilson\Local Settings\desktop.ini
[2009/05/19 08:00:34 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/05/19 08:00:28 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/05/19 08:00:26 | 16,101,45792 | -HS- | M] () -- C:\hiberfil.sys
[2009/05/19 07:59:02 | 00,002,709 | ---- | M] () -- C:\WINDOWS\System32\andpripas.dat
[2009/05/19 07:56:08 | 00,003,166 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/05/19 07:56:08 | 00,000,638 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/05/19 07:56:08 | 00,000,281 | RHS- | M] () -- C:\boot.ini
[2009/05/17 23:29:02 | 00,000,258 | ---- | M] () -- C:\WINDOWS\tasks\Uninstall Expiration Reminder.job
[2009/05/17 22:50:34 | 03,579,072 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/05/17 22:44:42 | 00,001,514 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/05/17 22:43:08 | 00,001,641 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2009/05/17 21:58:48 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009/05/16 08:20:16 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\David Wilson\Desktop\OTListIt2.exe
[2009/05/16 08:09:34 | 00,000,230 | ---- | M] () -- C:\WINDOWS\System32\spupdsvc.inf
[2009/05/16 08:06:42 | 00,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2009/05/16 08:06:42 | 00,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2009/05/16 07:53:46 | 00,222,368 | ---- | M] () -- C:\ntldr
[2009/05/14 22:38:54 | 00,000,875 | ---- | M] () -- C:\Documents and Settings\David Wilson\Desktop\Spybot - Search & Destroy.lnk
[2009/05/14 22:24:26 | 02,988,491 | R--- | M] () -- C:\Documents and Settings\David Wilson\Desktop\ComboFix.exe
[2009/05/14 17:50:10 | 00,117,248 | ---- | M] () -- C:\WINDOWS\vFind.exe
[2009/05/07 23:33:16 | 16,100,76160 | ---- | M] () -- C:\WINDOWS\MEMORY.DMP
[2009/05/07 22:28:26 | 01,080,054 | ---- | M] () -- C:\Documents and Settings\David Wilson\Desktop\Aquarium 1.bmp
[2009/05/07 22:24:14 | 01,080,056 | ---- | M] () -- C:\Documents and Settings\David Wilson\Desktop\bach.bmp
[2009/05/06 18:41:06 | 00,360,021 | ---- | M] () -- C:\Documents and Settings\David Wilson\Desktop\dds.scr
[2009/05/06 00:11:00 | 00,001,621 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/05/06 00:10:58 | 00,003,021 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2009/05/06 00:03:42 | 00,147,100 | -H-- | M] () -- C:\WINDOWS\System32\mlfcache.dat
[2009/04/28 19:05:04 | 00,286,208 | ---- | M] () -- C:\Documents and Settings\David Wilson\Desktop\gmer.exe
[2009/04/20 12:56:28 | 00,031,232 | ---- | M] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2009/04/19 18:29:52 | 00,360,021 | ---- | M] () -- C:\something.scr
< End of report >

proskoma
2009-05-19, 14:12
StartupList report, 5/19/2009, 8:11:56 AM
StartupList version: 1.52.2
Started from : C:\Program Files\Trend Micro\HijackThis\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Unable to get Internet Explorer version!
* Using default options
* Including empty and uninteresting sections
* Showing rarely important sections
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Promise\FastTrak\FtrakSvc.exe
C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\CBP\DCSchdler.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\NovaStor\NovaStor NovaBACKUP\NsService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\Fsloader.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\WINDOWS\system32\PRISMSVR.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ezSP_Px.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.exe
C:\Program Files\TrayDay\TrayDay.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

--------------------------------------------------

Listing of startup folders:

Shell folders Startup:
[C:\Documents and Settings\David Wilson\Start Menu\Programs\Startup]
TrayDay.lnk = C:\Program Files\TrayDay\TrayDay.exe
ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE

Shell folders AltStartup:
*Folder not found*

User shell folders Startup:
*Folder not found*

User shell folders AltStartup:
*Folder not found*

Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
Logitech Desktop Messenger.lnk = E:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
2Wire Wireless Client.lnk = C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.exe

Shell folders Common AltStartup:
*Folder not found*

User shell folders Common Startup:
*Folder not found*

User shell folders Alternate Common Startup:
*Folder not found*

--------------------------------------------------

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

[HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*

[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
*Registry value not found*

[HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

PRISMSVR.EXE = "C:\WINDOWS\system32\PRISMSVR.EXE" /APPLY
NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
NvMediaCenter = RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
iTunesHelper = "C:\Program Files\iTunes\iTunesHelper.exe"
nwiz = nwiz.exe /install
ezShieldProtector for Px = C:\WINDOWS\system32\ezSP_Px.exe
SunJavaUpdateSched = "C:\Program Files\Java\jre6\bin\jusched.exe"
avast! = C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
SpybotSnD = "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
MSConfig = C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto
Adobe Reader Speed Launcher = "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
LDM = \Program\BackWeb-8876480.exe

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run

*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

[OptionalComponents]
=

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*

--------------------------------------------------

File association entry for .EXE:
HKEY_CLASSES_ROOT\exefile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .COM:
HKEY_CLASSES_ROOT\ComFile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .BAT:
HKEY_CLASSES_ROOT\batfile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .PIF:
HKEY_CLASSES_ROOT\piffile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .SCR:
HKEY_CLASSES_ROOT\scrfile\shell\open\command

(Default) = "%1" /S

--------------------------------------------------

File association entry for .HTA:
HKEY_CLASSES_ROOT\htafile\shell\open\command

(Default) = C:\WINDOWS\System32\mshta.exe "%1" %*

--------------------------------------------------

File association entry for .TXT:
HKEY_CLASSES_ROOT\txtfile\shell\open\command

(Default) = %SystemRoot%\system32\NOTEPAD.EXE %1

--------------------------------------------------

Enumerating Active Setup stub paths:
HKLM\Software\Microsoft\Active Setup\Installed Components
(* = disabled by HKCU twin)

[<{12d0ed0d-0ee0-4f90-8827-78cefb8f4988}]
StubPath = C:\WINDOWS\system32\ieudinit.exe

[>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
StubPath = C:\WINDOWS\inf\unregmp2.exe /ShowWMP

[>{26923b43-4d38-484f-9b9e-de460746276c}] *
StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE

[>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] *
StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP

[>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}]
StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE

[{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] *
StubPath = %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll

[{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install

[{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT

[{5945c046-1e7d-11d1-bc44-00c04fd912be}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser

[{6BF52A52-394A-11d3-B153-00C04F79FAA6}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp11.inf,PerUserStub

[{7790769C-0471-11d2-AF11-00C04FA35D02}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install

[{89820200-ECBD-11cf-8B85-00AA005B4340}] *
StubPath = regsvr32.exe /s /n /i:U shell32.dll

[{89820200-ECBD-11cf-8B85-00AA005B4383}] *
StubPath = %SystemRoot%\system32\ie4uinit.exe

[{89B4C1CD-B018-4511-B0A1-5476DBF70820}] *
StubPath = C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install

[{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}] *
StubPath = %SystemRoot%\System32\updcrl.exe -e -u %SystemRoot%\System32\verisignpub1.crl

[{CA0A4247-44BE-11d1-A005-00805F8ABE06}] *
StubPath = RunDLL setupx.dll,InstallHinfSection PowerCfg.user 0 powercfg.inf

--------------------------------------------------

Enumerating ICQ Agent Autostart apps:
HKCU\Software\Mirabilis\ICQ\Agent\Apps

*Registry key not found*

--------------------------------------------------

Load/Run keys from C:\WINDOWS\WIN.INI:

load=*INI section not found*
run=*INI section not found*

Load/Run keys from Registry:

HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=*Registry value not found*

--------------------------------------------------

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*

--------------------------------------------------

Checking for EXPLORER.EXE instances:

C:\WINDOWS\Explorer.exe: PRESENT!

C:\Explorer.exe: not present
C:\WINDOWS\Explorer\Explorer.exe: not present
C:\WINDOWS\System\Explorer.exe: not present
C:\WINDOWS\System32\Explorer.exe: not present
C:\WINDOWS\Command\Explorer.exe: not present
C:\WINDOWS\Fonts\Explorer.exe: not present

--------------------------------------------------

Checking for superhidden extensions:

.lnk: HIDDEN! (arrow overlay: yes)
.pif: HIDDEN! (arrow overlay: yes)
.exe: not hidden
.com: not hidden
.bat: not hidden
.hta: not hidden
.scr: not hidden
.shs: HIDDEN!
.shb: *Registry key not found*
.vbs: not hidden
.vbe: not hidden
.wsh: not hidden
.scf: HIDDEN! (arrow overlay: NO!)
.url: HIDDEN! (arrow overlay: yes)
.js: not hidden
.jse: not hidden

--------------------------------------------------

Verifying REGEDIT.EXE integrity:

- Regedit.exe found in C:\WINDOWS
- .reg open command is normal (regedit.exe %1)
- Company name OK: 'Microsoft Corporation'
- Original filename OK: 'REGEDIT.EXE'
- File description: 'Registry Editor'

Registry check passed

--------------------------------------------------

Enumerating Browser Helper Objects:

AcroIEHelperStub - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll - {18DF081C-E8AD-4283-A596-FA578C2EBDC3}
(no name) - E:\Program Files\GetRight\xx2gr.dll - {31FF080D-12A3-439A-A2EF-4BA95A3148E8}
(no name) - C:\PROGRA~1\SPYBOT~1\SDHelper.dll - {53707962-6F74-2D53-2644-206D7942484F}
(no name) - C:\Program Files\Java\jre6\bin\jp2ssv.dll - {DBC80044-A445-435b-BC74-9C25C1C588A9}
JQSIEStartDetectorImpl - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll - {E7E6F031-17CE-4C07-BC86-EABFE594F69C}

--------------------------------------------------

Enumerating Task Scheduler jobs:

Uninstall Expiration Reminder.job
AppleSoftwareUpdate.job
Ad-Aware Update (Weekly).job

--------------------------------------------------

Enumerating Download Program Files:

[DirectAnimation Java Classes]
CODEBASE = file://C:\WINDOWS\SYSTEM\dajava.cab
OSD = C:\WINDOWS\Downloaded Program Files\DirectAnimation Java Classes.osd

[Internet Explorer Classes for Java]
CODEBASE = file://C:\WINDOWS\SYSTEM\iejava.cab
OSD = C:\WINDOWS\Downloaded Program Files\Internet Explorer Classes for Java.osd

[Microsoft XML Parser for Java]
CODEBASE = file://C:\WINDOWS\Java\classes\xmldso.cab
OSD = C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd

[Yahoo! Checkers]
CODEBASE = http://download.games.yahoo.com/games/clients/y/kt0_x.cab
OSD = C:\WINDOWS\Downloaded Program Files\Yahoo! Checkers.osd

[Yahoo! Chess]
CODEBASE = http://download.yahoo.com/games/clients/y/cr1_x.cab
OSD = C:\WINDOWS\Downloaded Program Files\Yahoo! Chess.osd

[Yahoo! Hearts]
CODEBASE = http://download.yahoo.com/games/clients/y/hr1_x.cab
OSD = C:\WINDOWS\Downloaded Program Files\Yahoo! Hearts.osd

[Yahoo! Pool 2]
CODEBASE = http://download.yahoo.com/games/clients/y/por9_x.cab
OSD = C:\WINDOWS\Downloaded Program Files\Yahoo! Pool 2.osd

[{00000075-0000-0010-8000-00AA00389B71}]
CODEBASE = http://codecs.microsoft.com/codecs/i386/voxmsdec.CAB

[{00000160-0000-0010-8000-00AA00389B71}]
CODEBASE = http://codecs.microsoft.com/codecs/i386/msaudio.cab

[Support.com Configuration Class]
InProcServer32 = C:\Program Files\Common Files\supportsoft\bin\tgctlcm.dll
CODEBASE = http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab

[Microsoft Office Template and Media Control]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\IEAWSDC.DLL
CODEBASE = http://office.microsoft.com/templates/ieawsdc.cab

[QuickTime Object]
InProcServer32 = E:\Program Files\QuickTime\QTPlugin.ocx
CODEBASE = http://www.apple.com/qtactivex/qtplugin.cab

[Facebook Photo Uploader 5 Control]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\PhotoUploader5.ocx
CODEBASE = http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab

[iPIX ActiveX Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\ipixx.ocx
CODEBASE = http://gulllake.gospelcom.net/unsecure/other_media/views/ipixx.cab

[Musicnotes Viewer]
InProcServer32 = C:\Program Files\Musicnotes\Player\Mnviewer.dll
CODEBASE = http://www.musicnotes.com/download/mnviewer.cab

[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\SYSTEM32\MACROMED\DIRECTOR\SWDIR.DLL
CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab

[Windows Genuine Advantage Validation Tool]
InProcServer32 = C:\WINDOWS\system32\legitcheckcontrol.dll
CODEBASE = http://go.microsoft.com/fwlink/?linkid=39204

[YInstStarter Class]
InProcServer32 = C:\PROGRA~1\YAHOO!\COMMON\yinsthelper.dll
CODEBASE = C:\Program Files\Yahoo!\common\yinsthelper.dll

[{31564D57-0000-0010-8000-00AA00389B71}]
CODEBASE = http://codecs.microsoft.com/codecs/i386/wmvax.cab

[{33564D57-0000-0010-8000-00AA00389B71}]
CODEBASE = http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB

[Live365PlayerVIP Class]
InProcServer32 = C:\WINDOWS\SYSTEM32\p365vip.dll
CODEBASE = http://www.live365.com/players/p365vip.cab

[Snapfish Activia]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\SnapfishActivia1000.ocx
CODEBASE = http://www2.snapfish.com/SnapfishActivia.cab

[Microsoft.WinRep]
InProcServer32 = C:\WINDOWS\System32\Winrep.dll
CODEBASE = https://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab

[Install Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\pinstall.dll
CODEBASE = http://updates.lifescapeinc.com/installers/pinstall/pinstall.cab

[MsneDiag Class]
InProcServer32 = C:\Progra~1\MsnMusic\diag\4226180\msnediag.ocx
CODEBASE = http://entimg.msn.com/client/msnediag3518.cab

[Verizon Wireless Media Upload]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\VerizonWirelessUploadControl.dll
CODEBASE = http://picture.vzw.com/activex/VerizonWirelessUploadControl.cab

[Java Plug-in 1.6.0_13]
InProcServer32 = C:\Program Files\Java\jre6\bin\jp2iexp.dll
CODEBASE = http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab

[{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}]
CODEBASE = http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab

[YbUploadFavsCtl Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\YbConvFav030408.dll
CODEBASE = http://download.yahoo.com/dl/bookmarks/ybconvfav030408.cab

[TLIEFlashObj Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\TLFlsCtl.dll
CODEBASE = http://rtc.webresponse.one.microsoft.com/media/xp/TLIEFlash.CAB

[{9DBAFCCF-592F-FFFF-FFFF-00608CEC297C}]

[{9F1C11AA-197B-4942-BA54-47A8489BB47F}]
CODEBASE = http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38079.8121527778

[Autodesk DWF Viewer Control]
InProcServer32 = C:\Program Files\Common Files\Autodesk Shared\dwf common\AdView.dll
CODEBASE = http://www.autodesk.com/global/dwfviewer/installer/DwfViewerSetup.cab

[WebResponseAttachments Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\FILETR~1.OCX
CODEBASE = https://webresponse.one.microsoft.com/oas/ActiveX/FileXfer.cab

[{B9191F79-5613-4C76-AA2A-398534BB8999}]
CODEBASE = http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab

[F-Secure Online Scanner 3.3]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\fscax.dll
CODEBASE = http://support.f-secure.com/ols/fscax.cab

[Java Plug-in 1.4.0]
InProcServer32 = C:\Program Files\Java\jre6\bin\jp2iexp.dll
CODEBASE = http://java.sun.com/update/1.4.0/jinstall-1_4_0-windows-i586.cab

[Java Plug-in 1.4.2_06]
InProcServer32 = C:\Program Files\Java\jre6\bin\jp2iexp.dll

[Java Plug-in 1.5.0_02]
InProcServer32 = C:\Program Files\Java\jre6\bin\jp2iexp.dll

[Java Plug-in 1.5.0_04]
InProcServer32 = C:\Program Files\Java\jre6\bin\jp2iexp.dll

[Java Plug-in 1.5.0_06]
InProcServer32 = C:\Program Files\Java\jre6\bin\jp2iexp.dll

[Java Plug-in 1.6.0_01]
InProcServer32 = C:\Program Files\Java\jre6\bin\jp2iexp.dll

[Java Plug-in 1.6.0_02]
InProcServer32 = C:\Program Files\Java\jre6\bin\jp2iexp.dll

[Java Plug-in 1.6.0_03]
InProcServer32 = C:\Program Files\Java\jre6\bin\jp2iexp.dll

[Java Plug-in 1.6.0_05]
InProcServer32 = C:\Program Files\Java\jre6\bin\jp2iexp.dll

[Java Plug-in 1.6.0_07]
InProcServer32 = C:\Program Files\Java\jre6\bin\jp2iexp.dll

[Java Plug-in 1.6.0_13]
InProcServer32 = C:\Program Files\Java\jre6\bin\jp2iexp.dll
CODEBASE = http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab

[Java Plug-in 1.6.0_13]
InProcServer32 = C:\Program Files\Java\jre6\bin\npjpi160_13.dll
CODEBASE = http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab

[Live365Player Class]
InProcServer32 = C:\WINDOWS\DOWNLO~1\Play365.dll
CODEBASE = http://www.live365.com/players/play365.cab

[{CEBC955E-58AF-11D2-A30A-00A0C903492B}]
CODEBASE = http://windowsupdate.microsoft.com/R848/V31Controls/x86/w98/en/actsetup.cab

[get_atlcom Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\gp.ocx
CODEBASE = http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash10b.ocx
CODEBASE = http://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab

[iTunesDetector Class]
InProcServer32 = C:\Program Files\iTunes\ITDetector.ocx
CODEBASE = http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab

[MsnMusicAx Class]
InProcServer32 = C:\Progra~1\MsnMusic\4226251\msnmusax.ocx
CODEBASE = http://entimg.msn.com/client/msnmusax3518.cab

--------------------------------------------------

Enumerating Winsock LSP files:

NameSpace #1: C:\WINDOWS\System32\mswsock.dll
NameSpace #2: C:\WINDOWS\System32\winrnr.dll
NameSpace #3: C:\WINDOWS\System32\mswsock.dll
Protocol #1: C:\WINDOWS\system32\mswsock.dll
Protocol #2: C:\WINDOWS\system32\mswsock.dll
Protocol #3: C:\WINDOWS\system32\mswsock.dll
Protocol #4: C:\WINDOWS\system32\rsvpsp.dll
Protocol #5: C:\WINDOWS\system32\rsvpsp.dll
Protocol #6: C:\WINDOWS\system32\mswsock.dll
Protocol #7: C:\WINDOWS\system32\mswsock.dll
Protocol #8: C:\WINDOWS\system32\mswsock.dll
Protocol #9: C:\WINDOWS\system32\mswsock.dll
Protocol #10: C:\WINDOWS\system32\mswsock.dll
Protocol #11: C:\WINDOWS\system32\mswsock.dll
Protocol #12: C:\WINDOWS\system32\mswsock.dll
Protocol #13: C:\WINDOWS\system32\mswsock.dll
Protocol #14: C:\WINDOWS\system32\mswsock.dll
Protocol #15: C:\WINDOWS\system32\mswsock.dll
Protocol #16: C:\WINDOWS\system32\mswsock.dll
Protocol #17: C:\WINDOWS\system32\mswsock.dll
Protocol #18: C:\WINDOWS\system32\mswsock.dll
Protocol #19: C:\WINDOWS\system32\mswsock.dll
Protocol #20: C:\WINDOWS\system32\mswsock.dll
Protocol #21: C:\WINDOWS\system32\mswsock.dll
Protocol #22: C:\WINDOWS\system32\mswsock.dll
Protocol #23: C:\WINDOWS\system32\mswsock.dll
Protocol #24: C:\WINDOWS\system32\mswsock.dll
Protocol #25: C:\WINDOWS\system32\mswsock.dll
Protocol #26: C:\WINDOWS\system32\mswsock.dll
Protocol #27: C:\WINDOWS\system32\mswsock.dll
Protocol #28: C:\WINDOWS\system32\mswsock.dll
Protocol #29: C:\WINDOWS\system32\mswsock.dll

--------------------------------------------------

Enumerating Windows NT/2000/XP services

4mmdat: System32\DRIVERS\4mmdat.sys (manual start)
Microsoft ACPI Driver: System32\DRIVERS\ACPI.sys (system)
Microsoft Kernel Acoustic Echo Canceller: system32\drivers\aec.sys (manual start)
AFD Networking Support Environment: \SystemRoot\System32\drivers\afd.sys (system)
aic78xx: System32\DRIVERS\aic78xx.sys (system)
Alerter: %SystemRoot%\System32\svchost.exe -k LocalService (autostart)
Application Layer Gateway Service: %SystemRoot%\System32\alg.exe (manual start)
AMD AGP Bus Filter Driver: System32\DRIVERS\amdagp.sys (system)
AMD IG AGP Bus Filter: System32\DRIVERS\amdagp10.sys (system)
AMDPCI: \??\C:\DOCUME~1\DAVIDW~1\LOCALS~1\Temp\AMDPCI.sys (manual start)
ADMtek AN983/AN985/ADM951X 10/100Mbps Fast Ethernet Adapter: System32\DRIVERS\AN983.sys (manual start)
Apple Mobile Device: "C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe" (autostart)
Application Management: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
1394 ARP Client Protocol: System32\DRIVERS\arp1394.sys (manual start)
ASP.NET State Service: %SystemRoot%\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (manual start)
aswFsBlk: system32\DRIVERS\aswFsBlk.sys (autostart)
avast! iAVS4 Control Service: "C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe" (autostart)
RAS Asynchronous Media Driver: System32\DRIVERS\asyncmac.sys (manual start)
Standard IDE/ESDI Hard Disk Controller: System32\DRIVERS\atapi.sys (system)
Ati HotKey Poller: %SystemRoot%\System32\Ati2evxx.exe (autostart)
ati2mpaa: System32\DRIVERS\ati2mpaa.sys (manual start)
ati2mtaa: System32\DRIVERS\ati2mtaa.sys (manual start)
ATI WDM Rage Theater Video: System32\DRIVERS\atinrvxx.sys (manual start)
ATI Rage Theatre Video (ATIRTCAP): System32\DRIVERS\atirtcap.sys (manual start)
ATM ARP Client Protocol: System32\DRIVERS\atmarpc.sys (manual start)
Windows Audio: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Audio Stub Driver: System32\DRIVERS\audstub.sys (manual start)
avast! Antivirus: "C:\Program Files\Alwil Software\Avast4\ashServ.exe" (autostart)
avast! Mail Scanner: "C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (manual start)
avast! Web Scanner: "C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (manual start)
Backup Scheduler: C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\CBP\DCSchdlerSRVC.exe (autostart)
Background Intelligent Transfer Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Computer Browser: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
catchme: \??\C:\DOCUME~1\DAVIDW~1\LOCALS~1\Temp\catchme.sys (manual start)
Closed Caption Decoder: System32\DRIVERS\CCDECODE.sys (manual start)
CD-ROM Driver: System32\DRIVERS\cdrom.sys (system)
Indexing Service: %SystemRoot%\system32\cisvc.exe (manual start)
ClipBook: %SystemRoot%\system32\clipsrv.exe (disabled)
.NET Runtime Optimization Service v2.0.50727_X86: C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (manual start)
COM+ System Application: C:\WINDOWS\System32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} (manual start)
Cryptographic Services: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
DCOM Server Process Launcher: %SystemRoot%\system32\svchost -k DcomLaunch (autostart)
DDC/CI monitor: System32\DRIVERS\Moni2c.sys (manual start)
DHCP Client: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Disk Driver: System32\DRIVERS\disk.sys (system)
Logical Disk Manager Administrative Service: %SystemRoot%\System32\dmadmin.exe /com (manual start)
dmboot: System32\drivers\dmboot.sys (disabled)
Logical Disk Manager: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Microsoft Kernel DLS Syntheiszer: system32\drivers\DMusic.sys (manual start)
DNS Client: %SystemRoot%\System32\svchost.exe -k NetworkService (autostart)
Microsoft Kernel DRM Audio Descrambler: system32\drivers\drmkaud.sys (manual start)
DVDRC: System32\drivers\DVDRC.sys (system)
Error Reporting Service: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Creative AudioPCI (ES1371,ES1373) (WDM): system32\drivers\es1371mp.sys (manual start)
Event Log: %SystemRoot%\system32\services.exe (autostart)
COM+ Event System: C:\WINDOWS\System32\svchost.exe -k netsvcs (manual start)
fasttrak: system32\DRIVERS\fasttrak.sys (system)
Promise FastTrak Log Service: "C:\Program Files\Promise\FastTrak\FtrakSvc.exe" (autostart)
Fast User Switching Compatibility: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Floppy Disk Controller Driver: System32\DRIVERS\fdc.sys (manual start)
Floppy Disk Driver: System32\DRIVERS\flpydisk.sys (manual start)
FltMgr: system32\drivers\fltmgr.sys (system)
Windows Presentation Foundation Font Cache 3.0.0.0: C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (manual start)
Volume Manager Driver: System32\DRIVERS\ftdisk.sys (system)
Game Port Enumerator: System32\DRIVERS\gameenum.sys (manual start)
GEAR ASPI Filter Driver: SYSTEM32\DRIVERS\GEARAspiWDM.sys (manual start)
getPlus(R) Helper: C:\Program Files\NOS\bin\getPlus_HelperSvc.exe (manual start)
GhostStartService: C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe (autostart)
GhostPciScanner: \??\C:\Program Files\Symantec\Norton Ghost 2003\ghpciscan.sys (system)
Generic Packet Classifier: System32\DRIVERS\msgpc.sys (manual start)
Hauppauge WinTV PVR PCI II ([23|25|26]xxx): system32\DRIVERS\hcwPP2.sys (manual start)
Hauppauge WinTV PVR PCI II (Encoder): system32\DRIVERS\hcwPVRP2.sys (manual start)
Help and Support: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Human Interface Device Access: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
HTTP: System32\Drivers\HTTP.sys (manual start)
HTTP SSL: %SystemRoot%\System32\svchost.exe -k HTTPFilter (manual start)
i8042 Keyboard and PS/2 Mouse Port Driver: System32\DRIVERS\i8042prt.sys (system)
InstallDriver Table Manager: "C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe" (manual start)
Windows CardSpace: "C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe" (manual start)
Windows CardSpace idsvcSPTISRV: C:\WINDOWS\system32\unicodem.exe srv (autostart)
CD-Burning Filter Driver: system32\drivers\Imapi.sys (system)
IMAPI CD-Burning COM Service: C:\WINDOWS\system32\Imapi.exe (manual start)
Iomega Devices Disk Filter Services: System32\DRIVERS\iomdisk.sys (system)
Iomega Activity Disk2: "" (disabled)
Iomega App Services: "C:\PROGRA~1\Iomega\System32\AppServices.exe" (autostart)
IPv6 Windows Firewall Driver: system32\drivers\ip6fw.sys (manual start)
IP Traffic Filter Driver: System32\DRIVERS\ipfltdrv.sys (manual start)
IP in IP Tunnel Driver: System32\DRIVERS\ipinip.sys (manual start)
IP Network Address Translator: System32\DRIVERS\ipnat.sys (manual start)
iPod Service: "C:\Program Files\iPod\bin\iPodService.exe" (manual start)
RIP Listener: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
IPSEC driver: System32\DRIVERS\ipsec.sys (system)
IR Enumerator Service: System32\DRIVERS\irenum.sys (manual start)
PnP ISA/EISA Bus Driver: System32\DRIVERS\isapnp.sys (system)
Java Quick Starter: "C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf" (autostart)
Keyboard Class Driver: System32\DRIVERS\kbdclass.sys (system)
Microsoft Kernel Wave Audio Mixer: system32\drivers\kmixer.sys (manual start)
Logitech PS/2 Mouse Filter Driver: System32\DRIVERS\L8042Pr2.sys (manual start)
Server: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Workstation: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Logitech HID/USB Mouse Filter Driver: System32\DRIVERS\LHidFlt2.sys (manual start)
Logitech USB Receiver device driver: system32\drivers\LHidUsb.Sys (manual start)
LightScribeService Direct Disc Labeling Service: "C:\Program Files\Common Files\LightScribe\LSSrvc.exe" (autostart)
Logitech Keyboard Class Filter Driver: System32\DRIVERS\LKbdFlt2.sys (manual start)
TCP/IP NetBIOS Helper: %SystemRoot%\System32\svchost.exe -k LocalService (autostart)
Logitech Mouse Class Filter Driver: System32\DRIVERS\LMouFlt2.sys (manual start)
TCP/IP Print Server: %SystemRoot%\System32\tcpsvcs.exe (manual start)
AEGIS Protocol (IEEE 802.1x) v2.3.1.9: system32\DRIVERS\mdc8021x.sys (autostart)
Messenger: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
NetMeeting Remote Desktop Sharing: C:\WINDOWS\System32\mnmsrvc.exe (manual start)
Mouse Class Driver: System32\DRIVERS\mouclass.sys (system)
Mouse HID Driver: System32\DRIVERS\mouhid.sys (manual start)
WebDav Client Redirector: System32\DRIVERS\mrxdav.sys (manual start)
MRXSMB: System32\DRIVERS\mrxsmb.sys (system)
Distributed Transaction Coordinator: C:\WINDOWS\System32\msdtc.exe (manual start)
Windows Installer: C:\WINDOWS\system32\msiexec.exe /V (manual start)
Microsoft Streaming Service Proxy: system32\drivers\MSKSSRV.sys (manual start)
Microsoft Streaming Clock Proxy: system32\drivers\MSPCLOCK.sys (manual start)
Microsoft Streaming Quality Manager Proxy: system32\drivers\MSPQM.sys (manual start)
Microsoft System Management BIOS Driver: System32\DRIVERS\mssmbios.sys (manual start)
Microsoft Streaming Tee/Sink-to-Sink Converter: system32\drivers\MSTEE.sys (manual start)
ATI WDM Specialized MVD Codec: System32\DRIVERS\atinmdxx.sys (autostart)
NABTS/FEC VBI Codec: System32\DRIVERS\NABTSFEC.sys (manual start)
Microsoft TV/Video Connection: System32\DRIVERS\NdisIP.sys (manual start)
Remote Access NDIS TAPI Driver: System32\DRIVERS\ndistapi.sys (manual start)
NDIS Usermode I/O Protocol: System32\DRIVERS\ndisuio.sys (manual start)
Remote Access NDIS WAN Driver: System32\DRIVERS\ndiswan.sys (manual start)
NetBIOS Interface: System32\DRIVERS\netbios.sys (system)
NetBios over Tcpip: System32\DRIVERS\netbt.sys (system)
Network DDE: %SystemRoot%\system32\netdde.exe (disabled)
Network DDE DSDM: %SystemRoot%\system32\netdde.exe (disabled)
Net Logon: %SystemRoot%\System32\lsass.exe (manual start)
Network Connections: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Net.Tcp Port Sharing Service: "C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe" (disabled)
1394 Net Driver: System32\DRIVERS\nic1394.sys (manual start)
Network Location Awareness (NLA): %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
NovaStor NovaBACKUP Backup/Copy Engine: "C:\Program Files\NovaStor\NovaStor NovaBACKUP\NsService.exe" (autostart)
NT LM Security Support Provider: %SystemRoot%\System32\lsass.exe (manual start)
Removable Storage: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
nv: system32\DRIVERS\nv4_mini.sys (manual start)
NVIDIA Display Driver Service: %SystemRoot%\system32\nvsvc32.exe (autostart)
IPX Traffic Filter Driver: System32\DRIVERS\nwlnkflt.sys (manual start)
IPX Traffic Forwarder Driver: System32\DRIVERS\nwlnkfwd.sys (manual start)
Texas Instruments OHCI Compliant IEEE 1394 Host Controller: System32\DRIVERS\ohci1394.sys (system)
PACSPTISVR: C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe (manual start)
Parallel port driver: System32\DRIVERS\parport.sys (manual start)
PCI Bus Driver: System32\DRIVERS\pci.sys (system)
Plug and Play: %SystemRoot%\system32\services.exe (autostart)
IPSEC Services: %SystemRoot%\System32\lsass.exe (autostart)
WAN Miniport (PPTP): System32\DRIVERS\raspptp.sys (manual start)
Processor Driver: System32\DRIVERS\processr.sys (system)
Protected Storage: %SystemRoot%\system32\lsass.exe (autostart)
Direct Parallel Link Driver: System32\DRIVERS\ptilink.sys (manual start)
PxHelp20: System32\DRIVERS\PxHelp20.sys (system)
Remote Access Auto Connection Driver: System32\DRIVERS\rasacd.sys (system)
Remote Access Auto Connection Manager: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
WAN Miniport (L2TP): System32\DRIVERS\rasl2tp.sys (manual start)
Remote Access Connection Manager: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Remote Access PPPOE Driver: System32\DRIVERS\raspppoe.sys (manual start)
Direct Parallel: System32\DRIVERS\raspti.sys (manual start)
Rdbss: System32\DRIVERS\rdbss.sys (system)
RDPCDD: System32\DRIVERS\RDPCDD.sys (system)
Remote Desktop Help Session Manager: C:\WINDOWS\system32\sessmgr.exe (manual start)
Real time Backup Loader: "C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\Fsloader.exe" (autostart)
Digital CD Audio Playback Filter Driver: System32\DRIVERS\redbook.sys (system)
Routing and Remote Access: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
Remote Procedure Call (RPC) Locator: %SystemRoot%\System32\locator.exe (manual start)
Remote Procedure Call (RPC): %SystemRoot%\system32\svchost -k rpcss (autostart)
QoS RSVP: %SystemRoot%\System32\rsvp.exe (manual start)
Security Accounts Manager: %SystemRoot%\system32\lsass.exe (autostart)
SBP-2 Transport/Protocol Bus Driver: System32\DRIVERS\sbp2port.sys (system)
Smart Card: %SystemRoot%\System32\SCardSvr.exe (manual start)
Task Scheduler: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Secdrv: System32\DRIVERS\secdrv.sys (autostart)
Secondary Logon: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
System Event Notification: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Serenum Filter Driver: System32\DRIVERS\serenum.sys (manual start)
Serial port driver: System32\DRIVERS\serial.sys (system)
Windows Firewall/Internet Connection Sharing (ICS): %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Shell Hardware Detection: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Simple TCP/IP Services: %SystemRoot%\System32\tcpsvcs.exe (autostart)
BDA Slip De-Framer: System32\DRIVERS\SLIP.sys (manual start)
SNMP Service: %SystemRoot%\System32\snmp.exe (autostart)
SNMP Trap Service: %SystemRoot%\System32\snmptrap.exe (manual start)
Microsoft Kernel Audio Splitter: system32\drivers\splitter.sys (manual start)
Print Spooler: %SystemRoot%\system32\spoolsv.exe (autostart)
Sony SPTI Service: C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe (manual start)
System Restore Filter Driver: System32\DRIVERS\sr.sys (system)
System Restore Service: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Srv: System32\DRIVERS\srv.sys (manual start)
SSDP Discovery Service: %SystemRoot%\System32\svchost.exe -k LocalService (manual start)
Windows Image Acquisition (WIA): %SystemRoot%\System32\svchost.exe -k imgsvc (manual start)
BDA IPSink: System32\DRIVERS\StreamIP.sys (manual start)
Alcor Micro Corp Reader: \??\C:\WINDOWS\System32\Drivers\sunkfilt.sys (manual start)
SupportSoft RemoteAssist: C:\Program Files\Common Files\supportsoft\bin\ssrc.exe (manual start)
Software Bus Driver: System32\DRIVERS\swenum.sys (manual start)
Microsoft Kernel GS Wavetable Synthesizer: system32\drivers\swmidi.sys (manual start)
MS Software Shadow Copy Provider: C:\WINDOWS\System32\dllhost.exe /Processid:{E6B3FA06-8180-459F-8EDE-0A021C372798} (manual start)
Microsoft Kernel System Audio Device: system32\drivers\sysaudio.sys (manual start)
Performance Logs and Alerts: %SystemRoot%\system32\smlogsvc.exe (manual start)
Telephony: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
TCP/IP Protocol Driver: System32\DRIVERS\tcpip.sys (system)
Terminal Device Driver: System32\DRIVERS\termdd.sys (system)
Terminal Services: %SystemRoot%\System32\svchost -k DComLaunch (manual start)
Themes: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Distributed Link Tracking Client: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
ultra: System32\DRIVERS\ultra.sys (system)
Microcode Update Driver: System32\DRIVERS\update.sys (manual start)
Upload Manager: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Universal Plug and Play Device Host: %SystemRoot%\System32\svchost.exe -k LocalService (manual start)
Uninterruptible Power Supply: %SystemRoot%\System32\ups.exe (manual start)
Microsoft USB 2.0 Enhanced Host Controller Miniport Driver: system32\DRIVERS\usbehci.sys (manual start)
USB2 Enabled Hub: System32\DRIVERS\usbhub.sys (manual start)
Microsoft USB Open Host Controller Miniport Driver: System32\DRIVERS\usbohci.sys (manual start)
Microsoft USB PRINTER Class: System32\DRIVERS\usbprint.sys (manual start)
USB Mass Storage Driver: System32\DRIVERS\USBSTOR.SYS (manual start)
Microsoft USB Universal Host Controller Miniport Driver: System32\DRIVERS\usbuhci.sys (manual start)
VGA Display Controller.: \SystemRoot\System32\drivers\vga.sys (system)
VIA AGP Bus Filter: System32\DRIVERS\viaagp.sys (system)
ViaIde: System32\DRIVERS\viaide.sys (system)
Volume Shadow Copy: %SystemRoot%\System32\vssvc.exe (manual start)
Windows Time: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Remote Access IP ARP Driver: System32\DRIVERS\wanarp.sys (manual start)
Microsoft WINMM WDM Audio Compatibility Driver: system32\drivers\wdmaud.sys (manual start)
WebClient: %SystemRoot%\System32\svchost.exe -k LocalService (autostart)
Windows Management Instrumentation: %systemroot%\system32\svchost.exe -k netsvcs (autostart)
2Wire 802.11g Driver: system32\DRIVERS\wlanCIG.sys (manual start)
Portable Media Serial Number Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
WMI Performance Adapter: C:\WINDOWS\System32\wbem\wmiapsrv.exe (manual start)
Windows Media Player Network Sharing Service: "C:\Program Files\Windows Media Player\WMPNetwk.exe" (manual start)
Windows Socket 2.0 Non-IFS Service Provider Support Environment: \SystemRoot\System32\drivers\ws2ifsl.sys (system)
Security Center: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
World Standard Teletext Codec: System32\DRIVERS\WSTCODEC.SYS (manual start)
Automatic Updates: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Windows Driver Foundation - User-mode Driver Framework Platform Driver: system32\DRIVERS\WudfPf.sys (manual start)
Windows Driver Foundation - User-mode Driver Framework Reflector: system32\DRIVERS\wudfrd.sys (manual start)
Windows Driver Foundation - User-mode Driver Framework: %SystemRoot%\system32\svchost.exe -k WudfServiceGroup (manual start)
Wireless Zero Configuration: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Network Provisioning Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
zremote: system32\drivers\zremote.sys (manual start)
Iomega Active Disk: "C:\Program Files\Iomega\AutoDisk\ADService.exe" (autostart)


--------------------------------------------------

Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*

Windows NT checkdisk command:
BootExecute = autocheck autochk *

Windows NT 'Wininit.ini':
PendingFileRenameOperations: *Registry value not found*

--------------------------------------------------

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\andpripas.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\system32\stobject.dll
UPnPMonitor: C:\WINDOWS\system32\upnpui.dll
WPDShServiceObj: C:\WINDOWS\system32\WPDShServiceObj.dll

--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

*No values found*

--------------------------------------------------

End of report, 45,866 bytes
Report generated in 0.203 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only

proskoma
2009-05-19, 14:15
Will post Malwarebytes' log this evening.

proskoma
2009-05-19, 14:57
Malwarebytes' Anti-Malware 1.36
Database version: 2150
Windows 5.1.2600 Service Pack 2

5/19/2009 8:56:20 AM
mbam-log-2009-05-19 (08-56-20).txt

Scan type: Full Scan (C:\|D:\|E:\|F:\|)
Objects scanned: 224433
Time elapsed: 33 minute(s), 41 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Blade81
2009-05-19, 18:31
Show hidden files
-----------------
* Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Click Yes to confirm.
* Click OK.


Please upload these files:
C:\WINDOWS\system32\andpripas.dll
C:\WINDOWS\System32\andpripas.dat
C:\WINDOWS\win.ini
C:\WINDOWS\system.ini


to this (http://www.bleepingcomputer.com/submit-malware.php?channel=76) website.

Kindly include a link to this topic in the message. Let me know when that's been done.

proskoma
2009-05-20, 13:04
Files have been uploaded. Used Guest account, included

http://forums.spybot.info/showthread.php?t=47863&page=6

as the "link to topic where file was requested."

Blade81
2009-05-20, 19:09
Thanks for the files. Let's continue the hunting.

Upload following two files to Virustotal (http://www.virustotal.com) and post back the results or links to the results:
c:\windows\system32\shell32.dll
c:\windows\system32\user32.dll

proskoma
2009-05-21, 02:04
shell32.dll

http://www.virustotal.com/analisis/e434024c80780748a80985cc88f14773

user32.dll

http://www.virustotal.com/analisis/37376cd2264b53f0951f7113b8223306

proskoma
2009-05-21, 02:09
still get instance of iexplore.exe at windows start up - HOWEVER, it no longer duplicates itself when running My Computer!!! YEAH!!

Still having problems with Money - but I'm starting to think that's a whole separate issue and I'll simply need to re-install it once the rest of this is fixed.

Blade81
2009-05-21, 15:44
Hi

Re-run OTListIt2.exe

Under the Custom Scans/Fixes box at the bottom, paste in the following

:OTLI
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O16 - DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.4.0/jin...ndows-i586.cab (Java Plug-in 1.4.0)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\andpripas.dll ()

:Files
C:\WINDOWS\System32\andpripas.dat
C:\WINDOWS\System32\andpripas.dll
C:\WINDOWS\System32\perfil.dll
C:\WINDOWS\System32\nvgamfil.dll
C:\WINDOWS\System32\popfil.dll
C:\WINDOWS\System32\tafil.dll
C:\WINDOWS\System32\psyfil.dll
C:\WINDOWS\System32\sporfil.dll
C:\WINDOWS\System32\pkmon.dll
C:\WINDOWS\System32\swfil.dll
C:\WINDOWS\System32\wrestfil.dll
C:\WINDOWS\System32\wzfil.dll
C:\WINDOWS\System32\tapfil.dll
C:\WINDOWS\System32\mp3fil.dll
C:\WINDOWS\System32\spmfil.dll
C:\WINDOWS\System32\finfil.dll
C:\WINDOWS\System32\entfil.dll
C:\WINDOWS\System32\fmfil.dll
C:\WINDOWS\System32\gnfil.dll
C:\WINDOWS\System32\jbfil.dll
C:\WINDOWS\System32\movfil.dll
C:\WINDOWS\System32\Auctfil.dll
C:\WINDOWS\System32\fshrfil.dll
C:\WINDOWS\System32\adwfil.dll
C:\WINDOWS\System32\gblfil.dll
C:\WINDOWS\System32\chtfil.dll
C:\WINDOWS\System32\iawfil.dll
C:\WINDOWS\System32\vgamfil.dll
C:\WINDOWS\System32\hatfil.dll
C:\WINDOWS\System32\viofil.dll
C:\WINDOWS\System32\srchin.dll
C:\WINDOWS\System32\lgwfil.dll
C:\WINDOWS\System32\cultfil.dll
C:\WINDOWS\System32\gdwfil.dll
C:\WINDOWS\bsnlst.dll
:Commands
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
Let the program run unhindered, reboot when it is done
Then post a new OTL2 log

proskoma
2009-05-22, 00:15
========== OTLISTIT ==========
Process explorer.exe killed successfully!
Starting removal of ActiveX control {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\PostBootReminder deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7849596a-48ea-486e-8937-a2a3009f31a9}\ deleted successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\andpripas.dll
C:\WINDOWS\system32\andpripas.dll NOT unregistered.
C:\WINDOWS\system32\andpripas.dll moved successfully.
========== FILES ==========
C:\WINDOWS\System32\andpripas.dat moved successfully.
File\Folder C:\WINDOWS\System32\andpripas.dll not found.
LoadLibrary failed for C:\WINDOWS\System32\perfil.dll
C:\WINDOWS\System32\perfil.dll NOT unregistered.
C:\WINDOWS\System32\perfil.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\nvgamfil.dll
C:\WINDOWS\System32\nvgamfil.dll NOT unregistered.
C:\WINDOWS\System32\nvgamfil.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\popfil.dll
C:\WINDOWS\System32\popfil.dll NOT unregistered.
C:\WINDOWS\System32\popfil.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\tafil.dll
C:\WINDOWS\System32\tafil.dll NOT unregistered.
C:\WINDOWS\System32\tafil.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\psyfil.dll
C:\WINDOWS\System32\psyfil.dll NOT unregistered.
C:\WINDOWS\System32\psyfil.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\sporfil.dll
C:\WINDOWS\System32\sporfil.dll NOT unregistered.
C:\WINDOWS\System32\sporfil.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\pkmon.dll
C:\WINDOWS\System32\pkmon.dll NOT unregistered.
C:\WINDOWS\System32\pkmon.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\swfil.dll
C:\WINDOWS\System32\swfil.dll NOT unregistered.
C:\WINDOWS\System32\swfil.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\wrestfil.dll
C:\WINDOWS\System32\wrestfil.dll NOT unregistered.
C:\WINDOWS\System32\wrestfil.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\wzfil.dll
C:\WINDOWS\System32\wzfil.dll NOT unregistered.
C:\WINDOWS\System32\wzfil.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\tapfil.dll
C:\WINDOWS\System32\tapfil.dll NOT unregistered.
C:\WINDOWS\System32\tapfil.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\mp3fil.dll
C:\WINDOWS\System32\mp3fil.dll NOT unregistered.
C:\WINDOWS\System32\mp3fil.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\spmfil.dll
C:\WINDOWS\System32\spmfil.dll NOT unregistered.
C:\WINDOWS\System32\spmfil.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\finfil.dll
C:\WINDOWS\System32\finfil.dll NOT unregistered.
C:\WINDOWS\System32\finfil.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\entfil.dll
C:\WINDOWS\System32\entfil.dll NOT unregistered.
C:\WINDOWS\System32\entfil.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\fmfil.dll
C:\WINDOWS\System32\fmfil.dll NOT unregistered.
C:\WINDOWS\System32\fmfil.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\gnfil.dll
C:\WINDOWS\System32\gnfil.dll NOT unregistered.
C:\WINDOWS\System32\gnfil.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\jbfil.dll
C:\WINDOWS\System32\jbfil.dll NOT unregistered.
C:\WINDOWS\System32\jbfil.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\movfil.dll
C:\WINDOWS\System32\movfil.dll NOT unregistered.
C:\WINDOWS\System32\movfil.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\Auctfil.dll
C:\WINDOWS\System32\Auctfil.dll NOT unregistered.
C:\WINDOWS\System32\Auctfil.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\fshrfil.dll
C:\WINDOWS\System32\fshrfil.dll NOT unregistered.
C:\WINDOWS\System32\fshrfil.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\adwfil.dll
C:\WINDOWS\System32\adwfil.dll NOT unregistered.
C:\WINDOWS\System32\adwfil.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\gblfil.dll
C:\WINDOWS\System32\gblfil.dll NOT unregistered.
C:\WINDOWS\System32\gblfil.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\chtfil.dll
C:\WINDOWS\System32\chtfil.dll NOT unregistered.
C:\WINDOWS\System32\chtfil.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\iawfil.dll
C:\WINDOWS\System32\iawfil.dll NOT unregistered.
C:\WINDOWS\System32\iawfil.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\vgamfil.dll
C:\WINDOWS\System32\vgamfil.dll NOT unregistered.
C:\WINDOWS\System32\vgamfil.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\hatfil.dll
C:\WINDOWS\System32\hatfil.dll NOT unregistered.
C:\WINDOWS\System32\hatfil.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\viofil.dll
C:\WINDOWS\System32\viofil.dll NOT unregistered.
C:\WINDOWS\System32\viofil.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\srchin.dll
C:\WINDOWS\System32\srchin.dll NOT unregistered.
C:\WINDOWS\System32\srchin.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\lgwfil.dll
C:\WINDOWS\System32\lgwfil.dll NOT unregistered.
C:\WINDOWS\System32\lgwfil.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\cultfil.dll
C:\WINDOWS\System32\cultfil.dll NOT unregistered.
C:\WINDOWS\System32\cultfil.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\System32\gdwfil.dll
C:\WINDOWS\System32\gdwfil.dll NOT unregistered.
C:\WINDOWS\System32\gdwfil.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\bsnlst.dll
C:\WINDOWS\bsnlst.dll NOT unregistered.
C:\WINDOWS\bsnlst.dll moved successfully.
========== COMMANDS ==========
File delete failed. C:\Documents and Settings\David Wilson\Local Settings\Temp\~DF357F.tmp scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\David Wilson\Local Settings\Temp\~DF3A23.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\regkern.log scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\wrt63sec.log scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_520.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_758.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_14c.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.
Explorer started successfully

OTListIt2 by OldTimer - Version 2.0.15.8 log created on 05212009_180848

Files moved on Reboot...
File C:\Documents and Settings\David Wilson\Local Settings\Temp\~DF357F.tmp not found!
File C:\Documents and Settings\David Wilson\Local Settings\Temp\~DF3A23.tmp not found!
File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
File move failed. C:\WINDOWS\temp\regkern.log scheduled to be moved on reboot.
File move failed. C:\WINDOWS\temp\wrt63sec.log scheduled to be moved on reboot.
C:\WINDOWS\temp\Perflib_Perfdata_520.dat moved successfully.
File C:\WINDOWS\temp\Perflib_Perfdata_758.dat not found!
C:\WINDOWS\temp\Perflib_Perfdata_14c.dat moved successfully.

Registry entries deleted on Reboot...

proskoma
2009-05-22, 00:19
OTListIt logfile created on: 5/21/2009 6:15:34 PM - Run 4
OTListIt2 by OldTimer - Version 2.0.15.8 Folder = C:\Documents and Settings\David Wilson\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: enu | Date Format: M/d/yyyy

1.50 Gb Total Physical Memory | 0.99 Gb Available Physical Memory | 66.12% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): [Binary data over 100 bytes]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 109.82 Gb Total Space | 30.46 Gb Free Space | 27.74% Space Free | Partition Type: FAT32
Drive D: | 8.09 Gb Total Space | 6.72 Gb Free Space | 83.06% Space Free | Partition Type: FAT32
Drive E: | 55.88 Gb Total Space | 30.61 Gb Free Space | 54.78% Space Free | Partition Type: FAT32
Drive F: | 39.21 Gb Total Space | 25.50 Gb Free Space | 65.05% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: DAVEHOME
Current User Name: David Wilson
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - [2009/02/05 16:01:26 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2009/02/05 16:08:40 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2008/11/07 14:28:16 | 00,132,424 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2008/06/17 16:16:32 | 00,176,128 | ---- | M] () -- C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\CBP\DCSchdler.exe
PRC - [2000/11/15 18:53:04 | 00,237,568 | ---- | M] (Promise Technology Inc.) -- C:\Program Files\Promise\FastTrak\FtrakSvc.exe
PRC - [2003/12/17 15:51:44 | 00,200,704 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
PRC - [2002/01/14 07:49:38 | 00,073,728 | ---- | M] (Iomega Corporation) -- C:\Program Files\Iomega\System32\AppServices.exe
PRC - [2009/05/05 22:38:38 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2005/02/22 16:32:14 | 00,038,912 | ---- | M] () -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe
PRC - [2008/06/17 16:56:16 | 00,207,936 | ---- | M] (NovaStor) -- C:\Program Files\NovaStor\NovaStor NovaBACKUP\NsService.exe
PRC - [2007/02/14 01:32:36 | 00,159,811 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe
PRC - [2008/06/17 16:23:48 | 00,093,248 | ---- | M] () -- C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\Fsloader.exe
PRC - [2001/08/23 12:00:00 | 00,019,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\tcpsvcs.exe
PRC - [2006/11/20 03:42:46 | 00,033,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\snmp.exe
PRC - [2002/01/24 16:10:40 | 00,126,976 | ---- | M] (Iomega Corporation) -- C:\Program Files\Iomega\AutoDisk\ADService.exe
PRC - [2009/02/05 16:08:26 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
PRC - [2009/02/05 16:06:04 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PRC - [2007/06/13 06:23:08 | 01,033,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2004/04/13 19:45:30 | 00,290,905 | ---- | M] (Conexant Systems, Inc.) -- C:\WINDOWS\system32\PRISMSVR.EXE
PRC - [2008/11/20 13:20:54 | 00,290,088 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2002/08/20 10:29:26 | 00,040,960 | ---- | M] (Easy Systems Japan Ltd.) -- C:\WINDOWS\system32\ezSP_Px.exe
PRC - [2009/05/05 22:38:38 | 00,148,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2009/02/05 16:08:46 | 00,081,000 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashDisp.exe
PRC - [2009/02/27 17:10:28 | 00,035,696 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
PRC - [2004/04/13 20:47:56 | 00,335,979 | ---- | M] (2Wire Inc.) -- C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.exe
PRC - [2002/10/22 06:50:00 | 00,204,800 | ---- | M] (MJMSoft Design Limited) -- C:\Program Files\TrayDay\TrayDay.exe
PRC - [2008/11/20 13:20:44 | 00,536,872 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe
PRC - [2009/04/24 02:00:58 | 00,307,704 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009/05/06 00:10:42 | 02,527,280 | ---- | M] () -- C:\Program Files\Alwil Software\Avast4\setup\avast.setup
PRC - [2009/05/16 08:20:16 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\David Wilson\Desktop\OTListIt2.exe

========== Win32 Services (SafeList) ==========

SRV - [2008/11/07 14:28:16 | 00,132,424 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running])
SRV - [2007/10/24 01:47:22 | 00,033,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2009/02/05 16:01:26 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv [Auto | Running])
SRV - [2000/11/30 14:30:40 | 00,057,344 | ---- | M] () -- C:\WINDOWS\System32\Ati2evxx.exe -- (Ati HotKey Poller [Auto | Stopped])
SRV - [2009/02/05 16:08:40 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus [Auto | Running])
SRV - [2009/02/05 16:08:26 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner [On_Demand | Running])
SRV - [2009/02/05 16:06:04 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner [On_Demand | Running])
SRV - [2008/06/17 16:16:36 | 00,098,304 | ---- | M] () -- C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\CBP\DCSchdlerSRVC.exe -- (Backup Scheduler [Auto | Stopped])
SRV - [2007/10/24 01:47:40 | 00,070,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2000/11/15 18:53:04 | 00,237,568 | ---- | M] (Promise Technology Inc.) -- C:\Program Files\Promise\FastTrak\FtrakSvc.exe -- (FastTrakSvc [Auto | Running])
SRV - [2006/10/20 21:21:24 | 00,036,864 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008/08/29 10:00:30 | 00,033,752 | ---- | M] (NOS Microsystems Ltd.) -- C:\Program Files\NOS\bin\getPlus_HelperSvc.exe -- (getPlus(R) Helper [On_Demand | Stopped])
SRV - [2003/12/17 15:51:44 | 00,200,704 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe -- (GhostStartService [Auto | Running])
SRV - [2004/08/04 03:56:44 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2005/04/04 00:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
SRV - [2006/10/30 03:33:58 | 00,741,376 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
SRV - File not found -- -- (idsvcSPTISRV [Auto | Stopped])
SRV - File not found -- -- (Iomega Activity Disk2 [Disabled | Stopped])
SRV - [2002/01/14 07:49:38 | 00,073,728 | ---- | M] (Iomega Corporation) -- C:\Program Files\Iomega\System32\AppServices.exe -- (Iomega App Services [Auto | Running])
SRV - [2008/11/20 13:20:44 | 00,536,872 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Running])
SRV - [2004/08/04 03:56:42 | 00,035,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\iprip.dll -- (Iprip [Auto | Running])
SRV - [2009/05/05 22:38:38 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
SRV - [2005/02/22 16:32:14 | 00,038,912 | ---- | M] () -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe -- (LightScribeService [Auto | Running])
SRV - [2001/08/23 12:00:00 | 00,019,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\tcpsvcs.exe -- (LPDSVC [On_Demand | Stopped])
SRV - [2006/10/30 03:34:02 | 00,122,880 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
SRV - [2008/06/17 16:56:16 | 00,207,936 | ---- | M] (NovaStor) -- C:\Program Files\NovaStor\NovaStor NovaBACKUP\NsService.exe -- (NsService [Auto | Running])
SRV - [2007/02/14 01:32:36 | 00,159,811 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc [Auto | Running])
SRV - [2004/01/30 15:19:20 | 00,065,625 | ---- | M] (Sony Corporation) -- C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe -- (PACSPTISVR [On_Demand | Stopped])
SRV - [2008/06/17 16:23:48 | 00,093,248 | ---- | M] () -- C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\Fsloader.exe -- (Real time Backup Loader [Auto | Running])
SRV - [2001/08/23 12:00:00 | 00,019,456 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\tcpsvcs.exe -- (SimpTcp [Auto | Running])
SRV - [2006/11/20 03:42:46 | 00,033,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\snmp.exe -- (SNMP [Auto | Running])
SRV - [2004/01/30 15:16:06 | 00,065,622 | ---- | M] (Sony Corporation) -- C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe -- (SPTISRV [On_Demand | Stopped])
SRV - [2008/07/15 17:38:32 | 00,394,608 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Common Files\supportsoft\bin\ssrc.exe -- (SupportSoft RemoteAssist [On_Demand | Stopped])
SRV - [2004/08/04 03:56:44 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (uploadmgr [Auto | Stopped])
SRV - [2006/10/18 20:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])
SRV - [2002/01/24 16:10:40 | 00,126,976 | ---- | M] (Iomega Corporation) -- C:\Program Files\Iomega\AutoDisk\ADService.exe -- (_IOMEGA_ACTIVE_DISK_SERVICE_ [Auto | Running])

========== Driver Services (SafeList) ==========

DRV - [2004/08/04 02:00:04 | 00,012,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\DRIVERS\4mmdat.sys -- (4mmdat [On_Demand | Running])
DRV - [2009/02/05 16:05:12 | 00,026,944 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4 [System | Running])
DRV - [2004/08/04 02:07:42 | 00,043,008 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\System32\DRIVERS\amdagp.sys -- (amdagp [Boot | Running])
DRV - [2000/06/27 14:39:16 | 00,022,994 | ---- | M] (AMD Corporation) -- C:\WINDOWS\System32\DRIVERS\amdagp10.sys -- (amdagp10 [Boot | Running])
DRV - [2002/08/29 00:59:12 | 00,036,224 | ---- | M] (ADMtek Incorporated.) -- C:\WINDOWS\System32\DRIVERS\AN983.sys -- (AN983 [On_Demand | Running])
DRV - [2007/02/06 15:01:48 | 00,016,512 | ---- | M] (Adaptec) -- C:\WINDOWS\System32\drivers\aspi32.sys -- (Aspi32 [System | Running])
DRV - [2009/02/05 16:07:12 | 00,020,560 | ---- | M] (ALWIL Software) -- C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys -- (aswFsBlk [Auto | Running])
DRV - [2009/02/05 16:08:10 | 00,094,032 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2 [Auto | Running])
DRV - [2009/02/05 16:06:10 | 00,023,152 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr [On_Demand | Running])
DRV - [2009/02/05 16:07:24 | 00,114,768 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP [System | Running])
DRV - [2009/02/05 16:06:20 | 00,051,376 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi [System | Running])
DRV - [2001/08/17 12:48:52 | 00,281,856 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\DRIVERS\ati2mpaa.sys -- (ati2mpaa [On_Demand | Stopped])
DRV - [2001/09/26 23:32:38 | 00,285,088 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\DRIVERS\ati2mtaa.sys -- (ati2mtaa [On_Demand | Stopped])
DRV - [2004/08/04 01:29:30 | 00,104,960 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\DRIVERS\atinrvxx.sys -- (atinrvxx [On_Demand | Stopped])
DRV - [2001/08/17 12:49:12 | 00,049,920 | ---- | M] () -- C:\WINDOWS\System32\DRIVERS\atirtcap.sys -- (ATIVRVXX [On_Demand | Stopped])
DRV - [2006/05/04 02:00:00 | 00,002,432 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\drivers\cdr4_xp.sys -- (Cdr4_xp [System | Stopped])
DRV - [2006/05/04 02:00:00 | 00,002,560 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\drivers\cdralw2k.sys -- (Cdralw2k [System | Stopped])
DRV - [2004/04/13 15:37:56 | 00,285,824 | ---- | M] (Roxio) -- C:\WINDOWS\System32\drivers\Cdudf_xp.sys -- (cdudf_xp [System | Running])
DRV - [2002/07/19 08:10:20 | 00,006,656 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\drivers\cinemsup.sys -- (Cinemsup [System | Running])
DRV - [2008/06/17 16:16:46 | 00,155,648 | ---- | M] () -- C:\WINDOWS\System32\drivers\DCDisk.sys -- (DCDisk [System | Running])
DRV - [2008/06/17 16:16:46 | 00,077,472 | ---- | M] () -- C:\WINDOWS\System32\drivers\dcsnap.sys -- (dcsnap [Boot | Running])
DRV - [2003/03/30 12:19:20 | 00,006,494 | ---- | M] (Mitsubishi Electric , NEC-Mitsubishi Electric Visual Systems) -- C:\WINDOWS\System32\DRIVERS\Moni2c.sys -- (DDCCI [On_Demand | Stopped])
DRV - [2004/04/15 22:57:26 | 00,140,416 | ---- | M] (Windows (R) 2000 DDK provider) -- C:\WINDOWS\System32\drivers\DVDVRRdr_xp.sys -- (DVDVRRdr_xp [System | Running])
DRV - [2004/04/13 15:37:30 | 00,023,680 | ---- | M] (Roxio) -- C:\WINDOWS\System32\drivers\dvd_2k.sys -- (dvd_2K [On_Demand | Running])
DRV - [2002/06/03 11:18:32 | 00,040,832 | ---- | M] (Creative Technology Ltd.) -- C:\WINDOWS\system32\drivers\es1371mp.sys -- (es1371 [On_Demand | Running])
DRV - [2002/05/23 11:28:56 | 00,070,656 | ---- | M] (Promise Technology, Inc.) -- C:\WINDOWS\system32\DRIVERS\fasttrak.sys -- (fasttrak [Boot | Running])
DRV - [2004/08/04 02:08:22 | 00,010,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\DRIVERS\gameenum.sys -- (gameenum [On_Demand | Running])
DRV - [2008/04/17 13:12:54 | 00,015,464 | ---- | M] (GEAR Software Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys -- (GEARAspiWDM [On_Demand | Running])
DRV - [2003/12/17 15:41:38 | 00,005,632 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\Norton Ghost 2003\ghpciscan.sys -- (GhPciScan [System | Running])
DRV - [2007/02/06 13:27:04 | 00,185,728 | ---- | M] (Hauppauge Computer Works, Inc.) -- C:\WINDOWS\system32\DRIVERS\hcwPP2.sys -- (hcwPP2 [On_Demand | Running])
DRV - [2004/09/22 09:01:20 | 00,814,464 | R--- | M] (Hauppauge Computer Works, Inc.) -- C:\WINDOWS\system32\DRIVERS\hcwPVRP2.sys -- (hcwPVRP2 [On_Demand | Stopped])
DRV - [2002/01/14 07:49:38 | 00,033,602 | ---- | M] (Iomega Corporation) -- C:\WINDOWS\System32\DRIVERS\iomdisk.sys -- (iomdisk [Boot | Running])
DRV - [2001/09/19 06:11:00 | 00,050,432 | ---- | M] (Logitech) -- C:\WINDOWS\System32\DRIVERS\L8042Pr2.sys -- (l8042pr2 [On_Demand | Stopped])
DRV - [2001/09/19 06:11:00 | 00,022,064 | ---- | M] (Logitech) -- C:\WINDOWS\System32\DRIVERS\LHidFlt2.sys -- (LHidFlt2 [On_Demand | Running])
DRV - [2001/09/19 06:11:00 | 00,037,822 | ---- | M] (Logitech) -- C:\WINDOWS\system32\drivers\LHidUsb.Sys -- (LHidUsb [On_Demand | Running])
DRV - [2001/09/19 06:11:00 | 00,005,840 | ---- | M] (Logitech) -- C:\WINDOWS\System32\DRIVERS\LKbdFlt2.sys -- (LKbdFlt2 [On_Demand | Running])
DRV - [2001/09/19 06:11:00 | 00,067,440 | ---- | M] (Logitech) -- C:\WINDOWS\System32\DRIVERS\LMouFlt2.sys -- (LMouFlt2 [On_Demand | Running])
DRV - [2004/04/13 19:20:08 | 00,015,781 | R--- | M] (Meetinghouse Data Communications) -- C:\WINDOWS\system32\DRIVERS\mdc8021x.sys -- (MDC8021X [Auto | Running])
DRV - [2004/04/13 15:29:22 | 00,023,680 | ---- | M] (Roxio) -- C:\WINDOWS\System32\drivers\mmc_2k.sys -- (mmc_2K [On_Demand | Stopped])
DRV - [2004/08/04 01:29:28 | 00,013,824 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\DRIVERS\atinmdxx.sys -- (MVDCODEC [Auto | Stopped])
DRV - [2007/02/14 01:32:32 | 03,983,872 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\nv4_mini.sys -- (nv [On_Demand | Running])
DRV - [2003/04/16 14:21:30 | 00,004,228 | ---- | M] (PowerQuest Corporation) -- C:\WINDOWS\System32\drivers\PQNTDRV.sys -- (PQNTDrv [System | Running])
DRV - [2001/08/23 12:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
DRV - [2004/04/13 15:23:58 | 00,117,248 | ---- | M] (Roxio) -- C:\WINDOWS\System32\drivers\Pwd_2k.sys -- (pwd_2k [System | Running])
DRV - [2008/05/22 18:22:16 | 00,043,528 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\DRIVERS\PxHelp20.sys -- (PxHelp20 [Boot | Running])
DRV - [2007/11/13 05:25:54 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys -- (Secdrv [Auto | Running])
DRV - [2005/10/07 16:42:14 | 00,038,468 | ---- | M] (Alcor Micro Corp.) -- C:\WINDOWS\System32\Drivers\sunkfilt.sys -- (SunkFilt [On_Demand | Stopped])
DRV - [2004/04/15 22:53:40 | 00,198,528 | ---- | M] (Roxio) -- C:\WINDOWS\System32\drivers\Udfreadr.sys -- (UDFReadr [System | Running])
DRV - [2001/08/17 13:52:22 | 00,036,736 | ---- | M] (Promise Technology, Inc.) -- C:\WINDOWS\System32\DRIVERS\ultra.sys -- (ultra [Boot | Running])
DRV - [2004/05/16 20:46:18 | 00,390,752 | R--- | M] ( ) -- C:\WINDOWS\system32\DRIVERS\wlanCIG.sys -- (wlanCIG [On_Demand | Running])
DRV - [2004/03/01 14:57:04 | 00,010,368 | ---- | M] (Streamzap, Inc.) -- C:\WINDOWS\system32\drivers\zremote.sys -- (zremote [On_Demand | Stopped])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://my.yahoo.com/index.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/index.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Update_Check_Page = http://www.microsoft.com/isapi/redir.dll?Prd=ie&Pver=5.0&Ar=ie5update
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ams-server*

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ams-server*

IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = about:blank
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
IE - HKU\S-1-5-19\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ams-server*

IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = about:blank
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
IE - HKU\S-1-5-20\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ams-server*

IE - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
IE - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\S-1-5-21-1547161642-1580436667-1708537768-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10

FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/05/05 22:38:40 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2005/04/27 22:53:28 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2005/04/27 22:53:26 | 00,000,000 | ---D | M]

[2009/05/17 22:44:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\David Wilson\Application Data\mozilla\Extensions
[2009/05/17 22:44:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\David Wilson\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2005/04/30 10:59:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\David Wilson\Application Data\mozilla\Firefox\Profiles\5nzx41m4.default\extensions
[2005/04/27 22:53:52 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2005/04/27 22:53:52 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/05/05 22:49:12 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
[2009/05/05 22:49:12 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
[2009/05/05 22:49:12 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
[2009/05/05 22:49:12 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2009/05/05 22:38:48 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/04/24 02:01:00 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/04/24 02:01:00 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2008/01/04 11:36:50 | 00,001,538 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2006/07/05 14:47:38 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2008/01/04 11:36:50 | 00,000,947 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2008/03/08 05:35:22 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2008/09/22 15:14:04 | 00,000,759 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2008/04/16 00:08:20 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008/03/28 14:11:14 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2008/01/04 11:36:50 | 00,000,831 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (bho2gr Class) - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - E:\Program Files\GetRight\xx2gr.dll (Headlight Software, Inc.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (no name) - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - Reg Error: Key error. File not found
O3 - HKLM\..\Toolbar: (no name) - {724d43a0-0d85-11d4-9908-00400523e39a} - Reg Error: Key error. File not found
O3 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\..\Toolbar\ShellBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
O3 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\..\Toolbar\WebBrowser: (no name) - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - Reg Error: Key error. File not found
O3 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Error: Key error. File not found
O3 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\..\Toolbar\WebBrowser: (no name) - {724D43A0-0D85-11D4-9908-00400523E39A} - Reg Error: Key error. File not found
O3 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\..\Toolbar\WebBrowser: (no name) - {81CA3009-6200-4A6D-93C6-F1E9A6821C7F} - Reg Error: Value error. File not found
O3 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\..\Toolbar\WebBrowser: (no name) - {F2CF5485-4E02-4F68-819C-B92DE9277049} - Reg Error: Key error. File not found
O3 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\..\Toolbar\WebBrowser: (no name) - {FE6BC4EF-5676-484B-88AE-883323913256} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe (Easy Systems Japan Ltd.)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install File not found
O4 - HKLM..\Run: [PRISMSVR.EXE] "C:\WINDOWS\system32\PRISMSVR.EXE" /APPLY (Conexant Systems, Inc.)
O4 - HKLM..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" (Safer Networking Limited)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004..\Run: [LDM] \Program\BackWeb-8876480.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk = E:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\2Wire Wireless Client.lnk = C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.exe (2Wire Inc.)
O4 - Startup: C:\Documents and Settings\David Wilson\Start Menu\Programs\Startup\TrayDay.lnk = C:\Program Files\TrayDay\TrayDay.exe (MJMSoft Design Limited)
O4 - Startup: C:\Documents and Settings\David Wilson\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Advanced\Folder\Hidden\SHOWALL: CheckedValue = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartBanner = 01 00 00 00 [binary data]
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogOff = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Advanced\Folder\Hidden\SHOWALL: CheckedValue = 1
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartBanner = 01 00 00 00 [binary data]
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogOff = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Advanced\Folder\Hidden\SHOWALL: CheckedValue = 1
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 95 00 00 00 [binary data]
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartBanner = 01 00 00 00 [binary data]
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogOff = 0
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = [binary data]
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 95 00 00 00 [binary data]
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartBanner = 01 00 00 00 [binary data]
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogOff = 0
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = [binary data]
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoNetHood = 1
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartBanner = 01 00 00 00 [binary data]
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFavoritesMenu = 1
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 1
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogOff = 0
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = [binary data]
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Advanced\Folder\Hidden\SHOWALL: CheckedValue = 1
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004_Classes\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O8 - Extra context menu item: Download with GetRight - Reg Error: Value error. File not found
O8 - Extra context menu item: E&xport to Microsoft Excel - Reg Error: Value error. File not found
O8 - Extra context menu item: Open with GetRight Browser - Reg Error: Value error. File not found
O9 - Extra Button: Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : Upromise IE Toolbar - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - File not found
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - File not found
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - File not found
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - File not found
O9 - Extra Button: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - File not found
O9 - Extra 'Tools' menuitem : Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - File not found
O9 - Extra Button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - E:\Program Files\ICQ\ICQ.exe File not found
O9 - Extra 'Tools' menuitem : ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - E:\Program Files\ICQ\ICQ.exe File not found
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - File not found
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - File not found
O9 - Extra Button: Share in Hello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll (Picasa, Inc.)
O9 - Extra 'Tools' menuitem : Share in H&ello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll (Picasa, Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\.DEFAULT\..Trusted Domains: aol.com ([free] http in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: 50 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-18\..Trusted Domains: aol.com ([free] http in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: 50 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-19\..Trusted Domains: aol.com ([free] http in Trusted sites)
O15 - HKU\S-1-5-19\..Trusted Domains: 2 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-20\..Trusted Domains: aol.com ([free] http in Trusted sites)
O15 - HKU\S-1-5-20\..Trusted Domains: 2 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-21-1547161642-1580436667-1708537768-1004\..Trusted Domains: 48 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {00000075-0000-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/voxmsdec.CAB (Reg Error: Key error.)
O16 - DPF: {00000160-0000-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/msaudio.cab (Reg Error: Key error.)
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab (Support.com Configuration Class)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} http://gulllake.gospelcom.net/unsecure/other_media/views/ipixx.cab (iPIX ActiveX Control)
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} http://www.musicnotes.com/download/mnviewer.cab (Musicnotes Viewer)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {31564D57-0000-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/wmvax.cab (Reg Error: Key error.)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {40272BF7-4FF5-4D6F-9BAD-3C1D3CB32982} http://www.live365.com/players/p365vip.cab (Live365PlayerVIP Class)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} http://www2.snapfish.com/SnapfishActivia.cab (Snapfish Activia)
O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} https://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab (Microsoft.WinRep)
O16 - DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} http://updates.lifescapeinc.com/installers/pinstall/pinstall.cab (Install Class)
O16 - DPF: {712362BF-E411-4F43-99D2-EB15F80AF1DB} http://entimg.msn.com/client/msnediag3518.cab (MsneDiag Class)
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} http://picture.vzw.com/activex/VerizonWirelessUploadControl.cab (Verizon Wireless Media Upload)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {924C1588-90C3-4910-B6CA-D57A1C0418FE} http://download.yahoo.com/dl/bookmarks/ybconvfav030408.cab (YbUploadFavsCtl Class)
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} http://rtc.webresponse.one.microsoft.com/media/xp/TLIEFlash.CAB (TLIEFlashObj Class)
O16 - DPF: {9DBAFCCF-592F-FFFF-FFFF-00608CEC297C} (Reg Error: Key error.)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38079.8121527778 (Reg Error: Key error.)
O16 - DPF: {A662DA7E-CCB7-4743-B71A-D817F6D575DF} http://www.autodesk.com/global/dwfviewer/installer/DwfViewerSetup.cab (Autodesk DWF Viewer Control)
O16 - DPF: {A7E092C3-692A-11D0-A7E5-08002B322F3B} https://webresponse.one.microsoft.com/oas/ActiveX/FileXfer.cab (WebResponseAttachments Control)
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab (Reg Error: Key error.)
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} http://support.f-secure.com/ols/fscax.cab (F-Secure Online Scanner 3.3)
O16 - DPF: {CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} http://www.live365.com/players/play365.cab (Live365Player Class)
O16 - DPF: {CEBC955E-58AF-11D2-A30A-00A0C903492B} http://windowsupdate.microsoft.com/R848/V31Controls/x86/w98/en/actsetup.cab (Reg Error: Key error.)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab (get_atlcom Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab (iTunesDetector Class)
O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} http://entimg.msn.com/client/msnmusax3518.cab (MsnMusicAx Class)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\SYSTEM\dajava.cab (Reg Error: Key error.)
O16 - DPF: Internet Explorer Classes for Java file://C:\WINDOWS\SYSTEM\iejava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Checkers http://download.games.yahoo.com/games/clients/y/kt0_x.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Chess http://download.yahoo.com/games/clients/y/cr1_x.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Hearts http://download.yahoo.com/games/clients/y/hr1_x.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Pool 2 http://download.yahoo.com/games/clients/y/por9_x.cab (Reg Error: Key error.)
O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O20 - Winlogon\Notify\dimsntfy: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop Components:0 (Internet Explorer Channel Bar) - 131A6951-7F78-11D0-A979-00C04FD705A2
O24 - Desktop Components:1 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/03/23 09:33:06 | 00,000,099 | ---- | M] () - C:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2001/11/04 15:42:42 | 00,000,095 | -HS- | M] () - C:\AUTOEXEC.DOS -- [ FAT32 ]
O32 - AutoRun File - [2001/11/05 23:02:34 | 00,000,095 | -HS- | M] () - C:\AUTOEXEC.BAK -- [ FAT32 ]
O33 - MountPoints2\{e2de2786-6cdd-11db-97eb-00045a68bf2f}\Shell - "" = AutoRun
O33 - MountPoints2\{e2de2786-6cdd-11db-97eb-00045a68bf2f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{e2de2786-6cdd-11db-97eb-00045a68bf2f}\Shell\AutoRun\command - "" = H:\LaunchU3.exe -- File not found
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\LaunchU3.exe -- File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2002/03/23 10:06:56 | 00,000,000 | ---D | M]

proskoma
2009-05-22, 00:20
========== Files/Folders - Created Within 30 Days ==========

[9 C:\WINDOWS\*.tmp files]
[2009/05/19 07:57:52 | 00,000,000 | ---D | C] -- C:\_OTListIt
[2009/05/17 22:44:40 | 00,001,514 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/05/17 22:43:07 | 00,001,641 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2009/05/16 08:20:17 | 00,501,248 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\David Wilson\Desktop\OTListIt2.exe
[2009/05/16 08:09:32 | 00,000,230 | ---- | C] () -- C:\WINDOWS\System32\spupdsvc.inf
[2009/05/16 08:05:56 | 00,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2009/05/13 07:50:42 | 00,000,000 | -HSD | C] -- C:\FOUND.043
[2009/05/07 23:33:17 | 16,101,45792 | -HS- | C] () -- C:\hiberfil.sys
[2009/05/07 22:28:26 | 01,080,054 | ---- | C] () -- C:\Documents and Settings\David Wilson\Desktop\Aquarium 1.bmp
[2009/05/07 22:24:10 | 01,080,056 | ---- | C] () -- C:\Documents and Settings\David Wilson\Desktop\bach.bmp
[2009/05/07 22:11:31 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Money Plus
[2009/05/06 18:41:05 | 00,360,021 | ---- | C] () -- C:\Documents and Settings\David Wilson\Desktop\dds.scr
[2009/05/06 00:10:58 | 00,001,621 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/05/06 00:10:57 | 00,114,768 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2009/05/06 00:10:57 | 00,097,480 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\AvastSS.scr
[2009/05/06 00:10:57 | 00,094,032 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2009/05/06 00:10:57 | 00,093,296 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2009/05/06 00:10:57 | 00,051,376 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2009/05/06 00:10:57 | 00,026,944 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2009/05/06 00:10:57 | 00,023,152 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2009/05/06 00:10:57 | 00,020,560 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2009/05/06 00:10:41 | 01,256,296 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\aswBoot.exe
[2009/05/06 00:10:41 | 00,380,928 | ---- | C] () -- C:\WINDOWS\System32\actskin4.ocx
[2009/05/06 00:10:39 | 00,000,000 | ---D | C] -- C:\Program Files\Alwil Software
[2009/05/06 00:03:40 | 00,147,100 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2009/05/05 22:10:14 | 00,001,024 | -H-- | C] () -- C:\diskfile1
[2009/05/05 22:10:13 | 00,016,384 | -H-- | C] () -- C:\logicinf.bin
[2009/04/28 19:05:04 | 00,286,208 | ---- | C] () -- C:\Documents and Settings\David Wilson\Desktop\gmer.exe
[2009/04/23 20:39:11 | 02,988,491 | R--- | C] () -- C:\Documents and Settings\David Wilson\Desktop\ComboFix.exe
[2009/04/22 18:53:37 | 00,000,211 | ---- | C] () -- C:\Boot.bak
[2009/04/22 18:53:35 | 00,260,272 | ---- | C] () -- C:\cmldr
[2009/04/22 18:53:35 | 00,000,000 | RHSD | C] -- C:\cmdcons
[2009/04/22 18:52:40 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2009/04/22 18:52:40 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2009/04/22 18:52:40 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2009/04/22 18:52:40 | 00,117,248 | ---- | C] () -- C:\WINDOWS\vFind.exe
[2009/04/22 18:52:40 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2009/04/22 18:52:40 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2009/04/22 18:52:40 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2009/04/22 18:52:40 | 00,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2009/04/22 18:52:28 | 00,000,000 | ---D | C] -- C:\Qoobox
[2009/04/17 19:53:43 | 00,000,066 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2008/10/11 13:52:43 | 00,155,648 | ---- | C] () -- C:\WINDOWS\System32\drivers\DCDisk.sys
[2008/10/11 13:52:43 | 00,077,472 | ---- | C] () -- C:\WINDOWS\System32\drivers\dcsnap.sys
[2008/05/22 18:22:18 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2008/05/22 18:19:46 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dtu100.dll.manifest
[2008/05/22 18:19:46 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dpl100.dll.manifest
[2008/05/22 18:18:54 | 00,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll
[2007/10/21 19:14:25 | 00,334,174 | ---- | C] () -- C:\WINDOWS\sqlite3.dll
[2007/08/18 08:33:06 | 00,390,752 | R--- | C] ( ) -- C:\WINDOWS\System32\drivers\wlanCIG.sys
[2007/07/25 15:24:30 | 01,559,040 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2007/02/14 01:32:38 | 01,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2007/02/14 01:32:38 | 01,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2007/02/14 01:32:36 | 01,470,464 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2007/02/14 01:32:36 | 00,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2007/02/14 01:32:36 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2007/02/14 01:32:36 | 00,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2007/02/14 01:32:32 | 00,212,992 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2007/02/03 12:23:24 | 00,000,004 | -H-- | C] () -- C:\WINDOWS\uccspecb.sys
[2006/02/26 16:08:28 | 00,585,728 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2006/02/22 00:36:14 | 00,000,252 | ---- | C] () -- C:\WINDOWS\System32\SNet.dll
[2005/07/10 19:34:23 | 00,000,037 | ---- | C] () -- C:\WINDOWS\ipixActivex.ini
[2005/05/22 15:22:22 | 00,000,281 | ---- | C] () -- C:\WINDOWS\irremote.ini
[2005/05/22 15:21:38 | 00,065,536 | ---- | C] () -- C:\WINDOWS\System32\dmcrypto.dll
[2005/05/22 15:21:24 | 00,000,211 | ---- | C] () -- C:\WINDOWS\nanoPEG.ini
[2005/05/22 14:48:36 | 00,002,586 | ---- | C] () -- C:\WINDOWS\HCWPNP.INI
[2005/01/26 17:07:33 | 00,000,000 | ---- | C] () -- C:\WINDOWS\QuickInstall.INI
[2005/01/15 12:23:28 | 00,000,479 | ---- | C] () -- C:\WINDOWS\RAIDeUtility.ini
[2004/12/20 10:59:02 | 00,000,119 | ---- | C] () -- C:\WINDOWS\WSST_Screen_Saver.ini
[2004/10/10 19:32:29 | 00,000,000 | ---- | C] () -- C:\WINDOWS\iPlayer.INI
[2004/08/04 03:56:42 | 00,081,920 | ---- | C] () -- C:\WINDOWS\System32\ieencode.dll
[2004/07/27 16:34:09 | 00,000,031 | ---- | C] () -- C:\WINDOWS\oupdate.INI
[2004/07/25 22:32:36 | 00,524,288 | ---- | C] () -- C:\WINDOWS\System32\TDI-SonyOMG.dll
[2004/07/12 17:38:44 | 00,000,011 | ---- | C] () -- C:\WINDOWS\wanpatan.ini
[2004/07/12 17:38:15 | 00,028,672 | ---- | C] () -- C:\WINDOWS\gscr.dll
[2004/05/15 21:33:31 | 00,001,100 | ---- | C] () -- C:\WINDOWS\System32\imgfil.dll
[2004/04/27 17:49:59 | 00,000,100 | ---- | C] () -- C:\WINDOWS\System32\UNWISE.INI
[2003/11/30 14:39:16 | 00,000,222 | ---- | C] () -- C:\WINDOWS\hpbafd.ini
[2003/06/11 18:32:46 | 00,001,842 | ---- | C] () -- C:\WINDOWS\System32\csnews.dll
[2003/03/01 08:08:20 | 00,000,348 | ---- | C] () -- C:\WINDOWS\hegames.ini
[2002/12/10 13:13:32 | 00,172,032 | ---- | C] () -- C:\WINDOWS\System32\GSnap.dll
[2002/12/10 13:13:32 | 00,040,960 | ---- | C] () -- C:\WINDOWS\System32\atlcontrol.dll
[2002/12/10 13:13:32 | 00,036,864 | ---- | C] () -- C:\WINDOWS\System32\UninstGMT.dll
[2002/12/10 13:12:24 | 00,000,494 | ---- | C] () -- C:\WINDOWS\demo.INI
[2002/12/10 01:36:34 | 00,036,864 | ---- | C] () -- C:\WINDOWS\System32\gbttk.dll
[2002/11/11 19:45:00 | 00,036,864 | ---- | C] () -- C:\WINDOWS\System32\NetStat32.dll
[2002/09/25 21:48:36 | 00,109,056 | ---- | C] () -- C:\WINDOWS\System32\LGUICOM.DLL
[2002/09/25 21:48:36 | 00,000,488 | ---- | C] () -- C:\WINDOWS\Cmousecc.ini
[2002/06/04 23:55:32 | 00,000,119 | ---- | C] () -- C:\WINDOWS\NNS.INI
[2002/04/28 14:54:12 | 00,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll
[2002/03/23 11:39:16 | 00,000,011 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.ini
[2002/03/23 10:08:10 | 00,076,659 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2002/03/23 10:08:08 | 00,373,248 | ---- | C] () -- C:\WINDOWS\EyeCand3.INI
[2002/03/23 10:08:08 | 00,003,598 | ---- | C] () -- C:\WINDOWS\HTMLHELP.INI
[2002/03/23 10:08:08 | 00,001,467 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2002/03/23 10:08:08 | 00,000,924 | ---- | C] () -- C:\WINDOWS\fauve.ini
[2002/03/23 10:08:08 | 00,000,787 | ---- | C] () -- C:\WINDOWS\SCANREG.INI
[2002/03/23 10:08:08 | 00,000,677 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2002/03/23 10:08:08 | 00,000,509 | ---- | C] () -- C:\WINDOWS\FS.INI
[2002/03/23 10:08:08 | 00,000,470 | ---- | C] () -- C:\WINDOWS\net2fone.ini
[2002/03/23 10:08:08 | 00,000,459 | ---- | C] () -- C:\WINDOWS\YACHT-Z.INI
[2002/03/23 10:08:08 | 00,000,277 | ---- | C] () -- C:\WINDOWS\SBWIN.INI
[2002/03/23 10:08:08 | 00,000,277 | ---- | C] () -- C:\WINDOWS\AATOOLS.INI
[2002/03/23 10:08:08 | 00,000,233 | ---- | C] () -- C:\WINDOWS\NETSCAPE.INI
[2002/03/23 10:08:08 | 00,000,226 | ---- | C] () -- C:\WINDOWS\QTW.INI
[2002/03/23 10:08:08 | 00,000,221 | ---- | C] () -- C:\WINDOWS\emsoft.ini
[2002/03/23 10:08:08 | 00,000,199 | ---- | C] () -- C:\WINDOWS\swacnfg.ini
[2002/03/23 10:08:08 | 00,000,192 | ---- | C] () -- C:\WINDOWS\mb.ini
[2002/03/23 10:08:08 | 00,000,152 | ---- | C] () -- C:\WINDOWS\LODERUNN.INI
[2002/03/23 10:08:08 | 00,000,149 | ---- | C] () -- C:\WINDOWS\XDCS_DO2.INI
[2002/03/23 10:08:08 | 00,000,144 | ---- | C] () -- C:\WINDOWS\INDEO.INI
[2002/03/23 10:08:08 | 00,000,131 | ---- | C] () -- C:\WINDOWS\chess.ini
[2002/03/23 10:08:08 | 00,000,122 | ---- | C] () -- C:\WINDOWS\PROTOCOL.INI
[2002/03/23 10:08:08 | 00,000,105 | ---- | C] () -- C:\WINDOWS\mapiuid.ini
[2002/03/23 10:08:08 | 00,000,095 | ---- | C] () -- C:\WINDOWS\winamp.ini
[2002/03/23 10:08:08 | 00,000,095 | ---- | C] () -- C:\WINDOWS\icewin.INI
[2002/03/23 10:08:08 | 00,000,089 | ---- | C] () -- C:\WINDOWS\KingsC.ini
[2002/03/23 10:08:08 | 00,000,080 | ---- | C] () -- C:\WINDOWS\entpack.ini
[2002/03/23 10:08:08 | 00,000,072 | ---- | C] () -- C:\WINDOWS\boxworld.ini
[2002/03/23 10:08:08 | 00,000,050 | ---- | C] () -- C:\WINDOWS\winfile.ini
[2002/03/23 10:08:08 | 00,000,042 | ---- | C] () -- C:\WINDOWS\CRISPY.INI
[2002/03/23 10:08:08 | 00,000,031 | ---- | C] () -- C:\WINDOWS\MSCHOMP.INI
[2002/03/23 10:08:08 | 00,000,026 | ---- | C] () -- C:\WINDOWS\MSOFFICE.INI
[2002/03/23 10:08:08 | 00,000,025 | ---- | C] () -- C:\WINDOWS\SOL.INI
[2002/03/23 10:08:08 | 00,000,000 | ---- | C] () -- C:\WINDOWS\SYSCHECK.INI
[2002/03/23 10:08:08 | 00,000,000 | ---- | C] () -- C:\WINDOWS\RESMNGR.INI
[2002/03/23 10:08:08 | 00,000,000 | ---- | C] () -- C:\WINDOWS\progman.ini
[2002/03/23 10:08:08 | 00,000,000 | ---- | C] () -- C:\WINDOWS\PCFRIEND.INI
[2002/03/23 10:08:08 | 00,000,000 | ---- | C] () -- C:\WINDOWS\MSINFO32.INI
[2002/03/23 10:08:08 | 00,000,000 | ---- | C] () -- C:\WINDOWS\hjbrowse.ini
[2002/03/23 10:08:08 | 00,000,000 | ---- | C] () -- C:\WINDOWS\DXINFO.INI
[2002/03/23 10:08:06 | 00,012,327 | ---- | C] () -- C:\WINDOWS\IOS.INI
[2002/03/23 10:08:06 | 00,008,405 | ---- | C] () -- C:\WINDOWS\NETDET.INI
[2002/03/23 10:08:06 | 00,005,068 | ---- | C] () -- C:\WINDOWS\DELETEFI.INI
[2002/03/23 10:08:06 | 00,000,865 | ---- | C] () -- C:\WINDOWS\DOSREP.INI
[2002/03/23 10:08:06 | 00,000,225 | ---- | C] () -- C:\WINDOWS\TELEPHON.INI
[2002/03/23 10:08:06 | 00,000,180 | ---- | C] () -- C:\WINDOWS\winmine.ini
[2002/03/23 10:08:06 | 00,000,127 | ---- | C] () -- C:\WINDOWS\KPCMS.INI
[2002/03/23 10:08:06 | 00,000,068 | ---- | C] () -- C:\WINDOWS\FPXPRESS.INI
[2002/03/23 10:08:06 | 00,000,060 | ---- | C] () -- C:\WINDOWS\POWERPNT.INI
[2002/03/23 10:08:06 | 00,000,054 | ---- | C] () -- C:\WINDOWS\WAVEMIX.INI
[2002/03/23 09:51:34 | 00,049,920 | ---- | C] () -- C:\WINDOWS\System32\drivers\atirtcap.sys
[2002/03/23 09:51:32 | 00,009,472 | ---- | C] () -- C:\WINDOWS\System32\drivers\ativmdcd.sys
[2001/12/27 23:55:26 | 00,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll
[2001/12/27 23:55:26 | 00,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll
[2001/12/17 07:22:30 | 00,210,944 | ---- | C] () -- C:\WINDOWS\System32\MSVCRT10.DLL
[2001/12/17 07:22:28 | 00,027,648 | ---- | C] () -- C:\WINDOWS\PFPICK.DLL
[2001/08/26 15:08:16 | 00,057,344 | ---- | C] () -- C:\WINDOWS\System32\icmfilter.dll
[2001/08/23 12:00:04 | 00,003,166 | ---- | C] () -- C:\WINDOWS\win.ini
[2001/08/23 12:00:04 | 00,000,638 | ---- | C] () -- C:\WINDOWS\system.ini
[2001/05/06 23:59:46 | 00,149,504 | ---- | C] () -- C:\WINDOWS\unwise32.dll
[2001/01/29 00:43:42 | 00,161,792 | ---- | C] () -- C:\WINDOWS\System32\nfsspi.dll
[2001/01/29 00:00:58 | 00,002,048 | ---- | C] () -- C:\WINDOWS\MNMGM32.DLL
[2000/06/22 14:34:24 | 00,088,064 | ---- | C] () -- C:\WINDOWS\System32\AudioExCtl.dll
[2000/06/22 14:33:36 | 00,024,576 | ---- | C] () -- C:\WINDOWS\System32\HcdDll32.dll
[2000/06/22 14:33:36 | 00,005,120 | ---- | C] () -- C:\WINDOWS\System32\HWDll.dll
[2000/06/20 13:11:02 | 00,110,592 | ---- | C] () -- C:\WINDOWS\System32\cdtool.dll
[2000/05/13 16:59:44 | 00,054,266 | ---- | C] () -- C:\WINDOWS\ATM.INI
[2000/05/13 10:27:11 | 00,020,992 | ---- | C] () -- C:\WINDOWS\System32\PFMAPI32.DLL
[2000/05/13 01:08:06 | 00,187,392 | ---- | C] () -- C:\WINDOWS\System32\LTANN62N.DLL
[2000/05/13 01:08:06 | 00,076,288 | ---- | C] () -- C:\WINDOWS\System32\LTIMG62N.DLL
[2000/05/13 01:08:06 | 00,047,616 | ---- | C] () -- C:\WINDOWS\System32\Lftif62n.dll
[2000/05/13 01:08:06 | 00,043,008 | ---- | C] () -- C:\WINDOWS\System32\ltfil62n.dll
[2000/05/13 01:08:06 | 00,029,184 | ---- | C] () -- C:\WINDOWS\System32\LTWND62N.DLL
[2000/05/13 01:08:06 | 00,024,064 | ---- | C] () -- C:\WINDOWS\System32\LTTWN62N.DLL
[2000/05/13 01:08:06 | 00,022,528 | ---- | C] () -- C:\WINDOWS\System32\tvcntl32.dll
[2000/05/13 01:08:06 | 00,020,480 | ---- | C] () -- C:\WINDOWS\System32\Lfpsd62n.dll
[2000/05/13 01:08:06 | 00,019,968 | ---- | C] () -- C:\WINDOWS\System32\Lfwmf62n.dll
[2000/05/13 01:08:06 | 00,019,968 | ---- | C] () -- C:\WINDOWS\System32\Lftga62n.dll
[2000/05/13 01:08:06 | 00,019,456 | ---- | C] () -- C:\WINDOWS\System32\Lfwpg62n.dll
[2000/05/13 01:08:06 | 00,018,432 | ---- | C] () -- C:\WINDOWS\System32\Lfras62n.dll
[2000/05/13 01:08:06 | 00,017,408 | ---- | C] () -- C:\WINDOWS\System32\Lfwfx62n.dll
[2000/05/13 01:08:05 | 00,175,616 | ---- | C] () -- C:\WINDOWS\System32\Lffax62n.dll
[2000/05/13 01:08:05 | 00,158,720 | ---- | C] () -- C:\WINDOWS\System32\Lfcmp62n.dll
[2000/05/13 01:08:05 | 00,110,080 | ---- | C] () -- C:\WINDOWS\System32\Lfpng62n.dll
[2000/05/13 01:08:05 | 00,027,136 | ---- | C] () -- C:\WINDOWS\System32\Lflma62n.dll
[2000/05/13 01:08:05 | 00,024,576 | ---- | C] () -- C:\WINDOWS\System32\Lfica62n.dll
[2000/05/13 01:08:05 | 00,023,552 | ---- | C] () -- C:\WINDOWS\System32\Lfpcx62n.dll
[2000/05/13 01:08:05 | 00,023,552 | ---- | C] () -- C:\WINDOWS\System32\Lflmb62n.dll
[2000/05/13 01:08:05 | 00,022,528 | ---- | C] () -- C:\WINDOWS\System32\Lfeps62n.dll
[2000/05/13 01:08:05 | 00,022,016 | ---- | C] () -- C:\WINDOWS\System32\Lfpct62n.dll
[2000/05/13 01:08:05 | 00,022,016 | ---- | C] () -- C:\WINDOWS\System32\Lfgif62n.dll
[2000/05/13 01:08:05 | 00,022,016 | ---- | C] () -- C:\WINDOWS\System32\Lfbmp62n.dll
[2000/05/13 01:08:05 | 00,018,944 | ---- | C] () -- C:\WINDOWS\System32\Lfimg62n.dll
[2000/05/13 01:08:05 | 00,018,432 | ---- | C] () -- C:\WINDOWS\System32\Lfmsp62n.dll
[2000/05/13 01:08:05 | 00,017,920 | ---- | C] () -- C:\WINDOWS\System32\Lfmac62n.dll
[2000/05/13 01:08:05 | 00,017,920 | ---- | C] () -- C:\WINDOWS\System32\Lfcal62n.dll
[2000/05/13 01:08:05 | 00,017,408 | ---- | C] () -- C:\WINDOWS\System32\Lfpcd62n.dll
[2000/05/13 01:08:00 | 00,162,816 | ---- | C] () -- C:\WINDOWS\System32\ccmpeg.dll
[1999/09/20 10:05:32 | 00,013,387 | ---- | C] () -- C:\WINDOWS\System32\CinemSup.sys
[1998/10/11 00:07:38 | 00,088,576 | ---- | C] () -- C:\WINDOWS\System32\Iticheck.dll
[1998/03/18 02:57:02 | 00,021,504 | ---- | C] () -- C:\WINDOWS\System32\ThmUninst.dll
[1997/07/11 00:00:00 | 00,022,016 | ---- | C] () -- C:\WINDOWS\System32\ODBCSTF.DLL
[1997/07/11 00:00:00 | 00,022,016 | ---- | C] () -- C:\WINDOWS\System32\DOCOBJ.DLL
[1997/07/11 00:00:00 | 00,012,288 | ---- | C] () -- C:\WINDOWS\System32\HLINKPRX.DLL
[1997/06/13 20:56:08 | 00,056,832 | ---- | C] () -- C:\WINDOWS\System32\Iyvu9_32.dll
[1980/01/01 00:00:00 | 00,188,416 | ---- | C] () -- C:\WINDOWS\System32\MEMBG.DLL
[1980/01/01 00:00:00 | 00,129,080 | ---- | C] () -- C:\WINDOWS\Logow.sys.bak
[1980/01/01 00:00:00 | 00,129,078 | ---- | C] () -- C:\WINDOWS\Logos.sys.bak
[1980/01/01 00:00:00 | 00,000,025 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI

========== Files - Modified Within 30 Days ==========

[9 C:\WINDOWS\*.tmp files]
[2009/05/21 18:16:12 | 00,421,976 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/05/21 18:16:12 | 00,343,762 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/05/21 18:16:12 | 00,069,018 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/05/21 18:12:30 | 00,088,566 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2009/05/21 18:12:20 | 00,012,208 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/05/21 18:12:20 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\David Wilson\Local Settings\desktop.ini
[2009/05/21 18:12:08 | 00,016,384 | -H-- | M] () -- C:\logicinf.bin
[2009/05/21 18:12:08 | 00,001,024 | -H-- | M] () -- C:\diskfile1
[2009/05/21 18:11:58 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/05/21 18:11:52 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/05/21 18:11:50 | 16,101,45792 | -HS- | M] () -- C:\hiberfil.sys
[2009/05/20 21:29:02 | 00,000,258 | ---- | M] () -- C:\WINDOWS\tasks\Uninstall Expiration Reminder.job
[2009/05/19 07:56:08 | 00,003,166 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/05/19 07:56:08 | 00,000,638 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/05/19 07:56:08 | 00,000,281 | RHS- | M] () -- C:\boot.ini
[2009/05/17 22:50:34 | 03,579,072 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/05/17 22:44:42 | 00,001,514 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/05/17 22:43:08 | 00,001,641 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2009/05/17 21:58:48 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009/05/16 08:20:16 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\David Wilson\Desktop\OTListIt2.exe
[2009/05/16 08:09:34 | 00,000,230 | ---- | M] () -- C:\WINDOWS\System32\spupdsvc.inf
[2009/05/16 08:06:42 | 00,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2009/05/16 08:06:42 | 00,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2009/05/16 07:53:46 | 00,222,368 | ---- | M] () -- C:\ntldr
[2009/05/14 22:38:54 | 00,000,875 | ---- | M] () -- C:\Documents and Settings\David Wilson\Desktop\Spybot - Search & Destroy.lnk
[2009/05/14 22:24:26 | 02,988,491 | R--- | M] () -- C:\Documents and Settings\David Wilson\Desktop\ComboFix.exe
[2009/05/14 17:50:10 | 00,117,248 | ---- | M] () -- C:\WINDOWS\vFind.exe
[2009/05/07 23:33:16 | 16,100,76160 | ---- | M] () -- C:\WINDOWS\MEMORY.DMP
[2009/05/07 22:28:26 | 01,080,054 | ---- | M] () -- C:\Documents and Settings\David Wilson\Desktop\Aquarium 1.bmp
[2009/05/07 22:24:14 | 01,080,056 | ---- | M] () -- C:\Documents and Settings\David Wilson\Desktop\bach.bmp
[2009/05/06 18:41:06 | 00,360,021 | ---- | M] () -- C:\Documents and Settings\David Wilson\Desktop\dds.scr
[2009/05/06 00:11:00 | 00,001,621 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/05/06 00:10:58 | 00,003,021 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2009/05/06 00:03:42 | 00,147,100 | -H-- | M] () -- C:\WINDOWS\System32\mlfcache.dat
[2009/04/28 19:05:04 | 00,286,208 | ---- | M] () -- C:\Documents and Settings\David Wilson\Desktop\gmer.exe
< End of report >

proskoma
2009-05-22, 00:25
no iexplore.exe started with windows

Internet explorer 6 is on the computer in c:\program files\internet explorer and it starts and ends successfully as a single iexplore.exe process

I think you did it!!!!

Blade81
2009-05-22, 18:43
That's great news :laugh:

Maybe you could now try reinstall that MS Money to see if it works. I'll help you with the final cleaning steps then :)

proskoma
2009-05-25, 16:03
Turns out I had a missing DLL... had to follow the following instructions to get it working again.

http://support.microsoft.com/kb/305254

Blade81
2009-05-25, 19:55
Good. Looks like it's time to wrap this up :)

Well congrats, it appears your system is all clean Are you still noticing any problems? If not, it's time to secure your system to prevent against further intrusions.


THESE STEPS ARE VERY IMPORTANT

Let's reset system restore
Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: You will lose all previous restore points which are likely to be infected. Please note you need Administrator Access to do clean the restore points.

1. Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

2. Reboot.

3. Turn ON System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check *Turn off System Restore*.
Click Apply, and then click OK.
NOTE: only do this ONCE,NOT on a regular basis


Now lets uninstall ComboFix (copy-paste bolded command below):

Click START then RUN
Now type (or copy-paste to make sure /u parameter gets included) "c:\documents and settings\David Wilson\Desktop\ComboFix.exe" /u in the runbox and click OK


Delete dds.scr file and related dds.txt & attach.txt logs (if still present).

Next we remove other used tools.


Double-click OTListIt2.exe.
Click the CleanUp! button.
Select Yes when the
Begin cleanup Process?
prompt appears.
If you are prompted to Reboot during the cleanup, select Yes.
The tool will delete itself once it finishes, if not delete it by yourself.


Note: If you receive a warning from your firewall or other security programs regarding OTListIt2 attempting to contact the internet, please allow it to do so.


UPDATING WINDOWS AND INTERNET EXPLORER

IMPORTANT: You Need to Update Windows and Internet Explorer to protect your computer from the malware that is around on the Internet. Please go to the windows update site (http://windowsupdate.microsoft.com/) to get the critical updates.

If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.


Make your Internet Explorer more secure

This can be done by following these simple instructions:
From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialize and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt
When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.



The following are recommended third party programs that are designed to keep your computer clean. A link as well as a brief description is included with each item.


hosts file:
Every version of windows has a hosts file as part of them. In a very basic sense, they are used to locate webpages. We can customize a hosts file so that it blocks certain webpages. However, it can slow down certain computers. This is why using a hosts file is optional!!
Download it here (http://www.mvps.org/winhelp2002/hosts.htm). Make sure you read the instructions on how to install the hosts file. There is a good tutorial here (http://www.bleepingcomputer.com/forums/tutorial51.html)
If you decide to download the hosts file, the slowdown problems can usually be avoided by following these steps:
Click the start button (at the lower left hand corner of your screen) Click run In the dialog box, type services.msc hit enter, then locate dns client Highlight it, then double-click it. On the dropdown box, change the setting from automatic to manual. Click ok

Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. For more info, check this (http://www.bleepingcomputer.com/forums/tutorial60.html) webpage out.
If you don't have a 3rd party firewall or a router behind NAT then I recommend getting one. I recommend either Online Armor Free (http://www.tallemu.com/free-firewall-protection-software.html) or Comodo Firewall Pro (http://www.personalfirewall.comodo.com/download_firewall.html#fw3.0) (If you choose Comodo: Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and install firewall ONLY!). Both providers have support forums that help with configuration related questions.



Just a final reminder for you. I am trying to stress these two points.
UPDATE UPDATE UPDATE!!! Make sure you do this about every 1-2 weeks.
Make sure all of your security programs are up to date.
Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.


Once again, please post and tell me how things are going with your system... problems etc.

Have a great day,
Blade :cool:

proskoma
2009-05-27, 04:30
Thanks again for your assistance. I'm very grateful for the help you provided and the computer is running better than ever.

I have followed all updating instructions and everything updated perfectly.

One question, if I install a 3rd party firewall (my final step of your recommendations), do I disable the firewall that comes with windows or do the two run in tandom?

Blade81
2009-05-27, 15:23
You're welcome :)

Only one firewall should be active. Usually 3rd party firewall disables Windows own firewall when installed so you don't have to do any changes.

Blade81
2009-06-03, 17:20
Since this issue appears to be resolved ... this Topic has been closed. Glad I could help. :)

Note:If it has been four days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than four days since your last response and you need the thread re-opened, please send me or MOD a private message (pm). A valid, working link to the closed topic is required.