Mdolph15
2010-03-23, 00:59
Here's the OTS log:
OTS logfile created on: 3/22/2010 5:31:18 PM - Run 1
OTS by OldTimer - Version 3.1.27.1 Folder = C:\Documents and Settings\ron\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,014.00 Mb Total Physical Memory | 510.00 Mb Available Physical Memory | 50.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 74.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.46 Gb Total Space | 48.64 Gb Free Space | 65.33% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 298.02 Gb Total Space | 177.59 Gb Free Space | 59.59% Space Free | Partition Type: FAT32
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: D6TVS3B1
Current User Name: ron
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
[Processes - Safe List]
ots(2).exe -> C:\Documents and Settings\ron\My Documents\Downloads\OTS(2).exe -> [2010/03/22 17:31:10 | 000,637,440 | ---- | M] (OldTimer Tools)
avgtray.exe -> C:\Program Files\AVG\AVG9\avgtray.exe -> [2010/03/13 09:59:29 | 002,059,544 | ---- | M] (AVG Technologies CZ, s.r.o.)
avgrsx.exe -> C:\Program Files\AVG\AVG9\avgrsx.exe -> [2010/03/13 09:59:22 | 000,508,184 | ---- | M] (AVG Technologies CZ, s.r.o.)
avgnsx.exe -> C:\Program Files\AVG\AVG9\avgnsx.exe -> [2010/03/13 09:59:18 | 000,617,752 | ---- | M] (AVG Technologies CZ, s.r.o.)
avgwdsvc.exe -> C:\Program Files\AVG\AVG9\avgwdsvc.exe -> [2010/03/13 09:59:07 | 000,308,064 | ---- | M] (AVG Technologies CZ, s.r.o.)
avgcsrvx.exe -> C:\Program Files\AVG\AVG9\avgcsrvx.exe -> [2010/03/13 09:57:58 | 000,710,424 | ---- | M] (AVG Technologies CZ, s.r.o.)
avgchsvx.exe -> C:\Program Files\AVG\AVG9\avgchsvx.exe -> [2010/03/13 09:57:53 | 001,086,744 | ---- | M] (AVG Technologies CZ, s.r.o.)
cfp.exe -> C:\Program Files\COMODO\COMODO Internet Security\cfp.exe -> [2010/01/30 11:07:10 | 001,800,464 | ---- | M] (COMODO)
cmdagent.exe -> C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe -> [2010/01/30 11:06:57 | 000,723,632 | ---- | M] (COMODO)
firefox.exe -> C:\Program Files\Mozilla Firefox\firefox.exe -> [2010/01/15 22:09:37 | 000,910,296 | ---- | M] (Mozilla Corporation)
ssscheduler.exe -> C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe -> [2009/07/27 19:19:10 | 000,199,184 | ---- | M] (McAfee, Inc.)
teatimer.exe -> C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe -> [2009/03/05 16:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.)
picturemover.exe -> C:\Program Files\PictureMover\Bin\PictureMover.exe -> [2008/08/13 09:11:00 | 000,413,696 | ---- | M] (Hewlett-Packard Company)
explorer.exe -> C:\WINDOWS\explorer.exe -> [2008/04/13 19:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation)
viewpointservice.exe -> C:\Program Files\Viewpoint\Common\ViewpointService.exe -> [2007/01/04 16:38:08 | 000,024,652 | ---- | M] (Viewpoint Corporation)
sprtcmd.exe -> C:\Program Files\Qwest\QuickCare\bin\sprtcmd.exe -> [2006/11/07 21:07:42 | 000,192,512 | ---- | M] (Qwest)
smax4pnp.exe -> C:\Program Files\Analog Devices\Core\smax4pnp.exe -> [2004/10/14 12:42:54 | 001,404,928 | ---- | M] (Analog Devices, Inc.)
hpzipm12.exe -> C:\WINDOWS\system32\HPZipm12.exe -> [2004/09/29 12:14:36 | 000,069,632 | ---- | M] (HP)
hphmon05.exe -> C:\WINDOWS\system32\hphmon05.exe -> [2003/08/20 16:15:48 | 000,483,328 | R--- | M] (Hewlett-Packard)
hpztsb09.exe -> C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe -> [2003/07/25 09:14:02 | 000,188,416 | ---- | M] (HP)
acrotray.exe -> C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe -> [2003/05/15 01:19:50 | 000,217,193 | ---- | M] (Adobe Systems Inc.)
[Modules - Safe List]
ots(2).exe -> C:\Documents and Settings\ron\My Documents\Downloads\OTS(2).exe -> [2010/03/22 17:31:10 | 000,637,440 | ---- | M] (OldTimer Tools)
guard32.dll -> C:\WINDOWS\system32\guard32.dll -> [2010/02/02 07:46:25 | 000,171,552 | ---- | M] (COMODO)
msvcp60.dll -> C:\WINDOWS\system32\msvcp60.dll -> [2008/04/13 19:12:01 | 000,413,696 | ---- | M] (Microsoft Corporation)
sprthook.dll -> C:\Program Files\Qwest\QuickCare\bin\sprthook.dll -> [2006/11/07 21:07:46 | 000,106,496 | ---- | M] (SupportSoft, Inc.)
[Win32 Services - Safe List]
(avg9wd) AVG Free WatchDog [Auto | Running] -> C:\Program Files\AVG\AVG9\avgwdsvc.exe -> [2010/03/13 09:59:07 | 000,308,064 | ---- | M] (AVG Technologies CZ, s.r.o.)
(cmdAgent) COMODO Internet Security Helper Service [Auto | Running] -> C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe -> [2010/01/30 11:06:57 | 000,723,632 | ---- | M] (COMODO)
(usnjsvc) Messenger Sharing Folders USN Journal Reader service [On_Demand | Stopped] -> C:\Program Files\MSN Messenger\usnsvc.exe -> [2007/01/19 12:54:14 | 000,097,136 | ---- | M] (Microsoft Corporation)
(Viewpoint Manager Service) Viewpoint Manager Service [Auto | Running] -> C:\Program Files\Viewpoint\Common\ViewpointService.exe -> [2007/01/04 16:38:08 | 000,024,652 | ---- | M] (Viewpoint Corporation)
(WMConnectCDS) Windows Media Connect Service [On_Demand | Stopped] -> C:\Program Files\Windows Media Connect 2\wmccds.exe -> [2005/10/06 18:12:30 | 000,855,552 | ---- | M] (Microsoft Corporation)
(Pml Driver HPZ12) Pml Driver HPZ12 [Auto | Running] -> C:\WINDOWS\system32\HPZipm12.exe -> [2004/09/29 12:14:36 | 000,069,632 | ---- | M] (HP)
[Driver Services - Safe List]
(AvgTdiX) AVG Free Network Redirector [Kernel | System | Running] -> C:\WINDOWS\System32\Drivers\avgtdix.sys -> [2010/03/13 09:59:26 | 000,242,696 | ---- | M] (AVG Technologies CZ, s.r.o.)
(AvgMfx86) AVG Free On-access Scanner Minifilter Driver x86 [File_System | System | Running] -> C:\WINDOWS\System32\Drivers\avgmfx86.sys -> [2010/03/13 09:59:19 | 000,029,512 | ---- | M] (AVG Technologies CZ, s.r.o.)
(AvgLdx86) AVG Free AVI Loader Driver x86 [Kernel | System | Running] -> C:\WINDOWS\System32\Drivers\avgldx86.sys -> [2010/03/13 09:57:58 | 000,216,200 | ---- | M] (AVG Technologies CZ, s.r.o.)
(cmdGuard) COMODO Internet Security Sandbox Driver [File_System | System | Running] -> C:\WINDOWS\system32\drivers\cmdguard.sys -> [2010/02/02 07:46:21 | 000,134,344 | ---- | M] (COMODO)
(Inspect) COMODO Internet Security Firewall Driver [Kernel | Boot | Running] -> C:\WINDOWS\System32\DRIVERS\inspect.sys -> [2010/01/30 11:07:56 | 000,087,104 | ---- | M] (COMODO)
(cmdHlp) COMODO Internet Security Helper Driver [Kernel | System | Running] -> C:\WINDOWS\system32\drivers\cmdhlp.sys -> [2010/01/30 11:07:55 | 000,025,160 | ---- | M] (COMODO)
(amdagp) AMD AGP Bus Filter Driver [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\amdagp.sys -> [2008/04/13 13:36:39 | 000,043,008 | ---- | M] (Advanced Micro Devices, Inc.)
(sisagp) SIS AGP Bus Filter [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\sisagp.sys -> [2008/04/13 13:36:39 | 000,040,960 | ---- | M] (Silicon Integrated Systems Corporation)
(b57w2k) Broadcom NetXtreme 57xx Gigabit Controller [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\b57xp32.sys -> [2005/03/17 16:30:10 | 000,132,608 | ---- | M] (Broadcom Corporation)
(Afc) PPdus ASPI Shell [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\afc.sys -> [2005/02/23 14:58:56 | 000,011,776 | ---- | M] (Arcsoft, Inc.)
(senfilt) senfilt [Kernel | On_Demand | Running] -> C:\WINDOWS\system32\drivers\senfilt.sys -> [2004/09/17 07:02:54 | 000,732,928 | ---- | M] (Creative Technology Ltd.)
(nv) nv [Kernel | On_Demand | Stopped] -> C:\WINDOWS\system32\drivers\nv4_mini.sys -> [2004/08/03 22:29:56 | 001,897,408 | ---- | M] (NVIDIA Corporation)
(Sparrow) Sparrow [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\sparrow.sys -> [2001/08/17 14:07:44 | 000,019,072 | ---- | M] (Adaptec, Inc.)
(sym_u3) sym_u3 [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\sym_u3.sys -> [2001/08/17 14:07:42 | 000,030,688 | ---- | M] (LSI Logic)
(sym_hi) sym_hi [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\sym_hi.sys -> [2001/08/17 14:07:40 | 000,028,384 | ---- | M] (LSI Logic)
(symc8xx) symc8xx [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\symc8xx.sys -> [2001/08/17 14:07:36 | 000,032,640 | ---- | M] (LSI Logic)
(symc810) symc810 [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\symc810.sys -> [2001/08/17 14:07:34 | 000,016,256 | ---- | M] (Symbios Logic Inc.)
(ultra) ultra [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\ultra.sys -> [2001/08/17 13:52:22 | 000,036,736 | ---- | M] (Promise Technology, Inc.)
(ql12160) ql12160 [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\ql12160.sys -> [2001/08/17 13:52:20 | 000,045,312 | ---- | M] (QLogic Corporation)
(ql1080) ql1080 [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\ql1080.sys -> [2001/08/17 13:52:20 | 000,040,320 | ---- | M] (QLogic Corporation)
(ql1280) ql1280 [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\ql1280.sys -> [2001/08/17 13:52:18 | 000,049,024 | ---- | M] (QLogic Corporation)
(dac2w2k) dac2w2k [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\dac2w2k.sys -> [2001/08/17 13:52:16 | 000,179,584 | ---- | M] (Mylex Corporation)
(mraid35x) mraid35x [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\mraid35x.sys -> [2001/08/17 13:52:12 | 000,017,280 | ---- | M] (American Megatrends Inc.)
(asc) asc [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\asc.sys -> [2001/08/17 13:52:00 | 000,026,496 | ---- | M] (Advanced System Products, Inc.)
(asc3550) asc3550 [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\asc3550.sys -> [2001/08/17 13:51:58 | 000,014,848 | ---- | M] (Advanced System Products, Inc.)
(AliIde) AliIde [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\aliide.sys -> [2001/08/17 13:51:56 | 000,005,248 | ---- | M] (Acer Laboratories Inc.)
(CmdIde) CmdIde [Kernel | Disabled | Stopped] -> C:\WINDOWS\system32\DRIVERS\cmdide.sys -> [2001/08/17 13:51:54 | 000,006,656 | ---- | M] (CMD Technology, Inc.)
[Registry - Safe List]
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> ->
< Internet Explorer Settings [HKEY_USERS\.DEFAULT\] > -> ->
HKEY_USERS\.DEFAULT\: "ProxyEnable" -> 0 ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-18\] > -> ->
HKEY_USERS\S-1-5-18\: "ProxyEnable" -> 0 ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-19\] > -> ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-20\] > -> ->
< Internet Explorer Settings [HKEY_USERS\S-1-5-21-540961431-1912937874-3570792479-1006\] > -> ->
HKEY_USERS\S-1-5-21-540961431-1912937874-3570792479-1006\: Main\\"SearchMigratedDefaultName" -> Google ->
HKEY_USERS\S-1-5-21-540961431-1912937874-3570792479-1006\: Main\\"SearchMigratedDefaultURL" -> http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 ->
HKEY_USERS\S-1-5-21-540961431-1912937874-3570792479-1006\: Main\\"Start Page" -> http://www.msn.com/ ->
HKEY_USERS\S-1-5-21-540961431-1912937874-3570792479-1006\: SearchURL\\"" -> http://www.google.com/keyword/%s ->
HKEY_USERS\S-1-5-21-540961431-1912937874-3570792479-1006\: "ProxyEnable" -> 0 ->
HKEY_USERS\S-1-5-21-540961431-1912937874-3570792479-1006\: "ProxyOverride" -> *.local ->
< FireFox Settings [Prefs.js] > -> C:\Documents and Settings\ron\Application Data\Mozilla\FireFox\Profiles\92zofaby.default\prefs.js ->
browser.search.defaultenginename -> "Google" ->
browser.search.defaulturl -> "http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=" ->
browser.startup.homepage -> "msn.com" ->
extensions.enabledItems -> {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.783 ->
extensions.enabledItems -> jqs@sun.com:1.0 ->
extensions.enabledItems -> moveplayer@movenetworks.com:1.0.0.%(version)s ->
< FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla
HKLM\software\mozilla\Firefox\extensions -> ->
HKLM\software\mozilla\Firefox\extensions\\{3f963a5b-e555-4543-90e2-c3908898db71} -> C:\Program Files\AVG\AVG9\Firefox [C:\PROGRAM FILES\AVG\AVG9\FIREFOX] -> [2010/03/21 10:38:26 | 000,000,000 | ---D | M]
HKLM\software\mozilla\Mozilla Firefox 3.6\extensions -> ->
HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Components -> C:\Program Files\Mozilla Firefox\components [C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS] -> [2010/03/17 06:52:14 | 000,000,000 | ---D | M]
HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Plugins -> C:\Program Files\Mozilla Firefox\plugins [C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS] -> [2010/03/17 06:52:12 | 000,000,000 | ---D | M]
< FireFox Extensions [User Folders] > ->
-> C:\Documents and Settings\ron\Application Data\Mozilla\Extensions -> [2008/12/31 10:19:41 | 000,000,000 | ---D | M]
-> C:\Documents and Settings\ron\Application Data\Mozilla\Firefox\Profiles\92zofaby.default\extensions -> [2010/03/22 11:58:40 | 000,000,000 | ---D | M]
Microsoft .NET Framework Assistant -> C:\Documents and Settings\ron\Application Data\Mozilla\Firefox\Profiles\92zofaby.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} -> [2009/09/04 15:19:22 | 000,000,000 | ---D | M]
< FireFox Extensions [Program Folders] > ->
-> C:\Program Files\Mozilla Firefox\extensions -> [2010/03/22 11:58:40 | 000,000,000 | ---D | M]
No name found -> C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}-trash -> [2007/01/02 23:54:03 | 000,000,000 | ---D | M]
< HOSTS File > ([2009/06/15 20:14:51 | 000,306,450 | R--- | M] - 10600 lines) -> C:\WINDOWS\system32\drivers\etc\hosts ->
First 25 entries...
Reset Hosts
127.0.0.1 localhost
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1001namen.com
127.0.0.1 1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 100sexlinks.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 10sek.com
127.0.0.1 www.10sek.com
127.0.0.1 www.1-2005-search.com
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} [HKLM] -> C:\Program Files\AVG\AVG9\avgssie.dll [AVG Safe Search] -> [2010/03/13 09:59:16 | 001,598,744 | ---- | M] (AVG Technologies CZ, s.r.o.)
{53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [Spybot-S&D IE Protection] -> [2009/01/26 16:31:02 | 001,879,896 | ---- | M] (Safer Networking Limited)
{7C554162-8CB7-45A4-B8F4-8EA1C75885F9} [HKLM] -> C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll [AOL Toolbar Launcher] -> [2007/10/10 09:56:58 | 001,090,912 | ---- | M] (AOL LLC)
{7E853D72-626A-48EC-A868-BA8D5E23E045} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
{AA58ED58-01DD-4d91-8333-CF10577473F7} [HKLM] -> c:\Program Files\Google\GoogleToolbar3.dll [Google Toolbar Helper] -> [2007/01/20 00:55:32 | 002,403,392 | R--- | M] (Google Inc.)
{AE7CD045-E861-484f-8273-0445EE161910} [HKLM] -> C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll [AcroIEToolbarHelper Class] -> [2003/05/15 01:03:46 | 000,147,456 | ---- | M] ()
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} [HKLM] -> C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll [Google Toolbar Notifier BHO] -> [2008/10/12 11:10:48 | 000,737,776 | ---- | M] (Google Inc.)
{d2ce3e00-f94a-4740-988e-03dc2f38c34f} [HKLM] -> C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll [MSN Toolbar Helper] -> [2008/12/04 13:29:32 | 000,083,800 | ---- | M] (Microsoft Corp.)
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar ->
"{1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414}" [HKLM] -> C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll [MSN Toolbar] -> [2008/12/04 13:29:32 | 000,083,800 | ---- | M] (Microsoft Corp.)
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" [HKLM] -> c:\Program Files\Google\GoogleToolbar3.dll [&Google] -> [2007/01/20 00:55:32 | 002,403,392 | R--- | M] (Google Inc.)
"{47833539-D0C5-4125-9FA8-0819E2EAAC93}" [HKLM] -> C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll [Adobe PDF] -> [2003/05/15 01:03:46 | 000,147,456 | ---- | M] ()
"{DE9C389F-3316-41A7-809B-AA305ED9D922}" [HKLM] -> C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll [AIM Toolbar] -> [2007/10/10 09:56:58 | 001,090,912 | ---- | M] (AOL LLC)
< Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-540961431-1912937874-3570792479-1006\] > -> HKEY_USERS\S-1-5-21-540961431-1912937874-3570792479-1006\Software\Microsoft\Internet Explorer\Toolbar\ ->
WebBrowser\\"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" [HKLM] -> c:\Program Files\Google\GoogleToolbar3.dll [&Google] -> [2007/01/20 00:55:32 | 002,403,392 | R--- | M] (Google Inc.)
WebBrowser\\"{47833539-D0C5-4125-9FA8-0819E2EAAC93}" [HKLM] -> C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll [Adobe PDF] -> [2003/05/15 01:03:46 | 000,147,456 | ---- | M] ()
WebBrowser\\"{DE9C389F-3316-41A7-809B-AA305ED9D922}" [HKLM] -> C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll [AIM Toolbar] -> [2007/10/10 09:56:58 | 001,090,912 | ---- | M] (AOL LLC)
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"AppleSyncNotifier" -> C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe] -> [2009/08/13 15:51:42 | 000,177,440 | ---- | M] (Apple Inc.)
"AVG9_TRAY" -> C:\Program Files\AVG\AVG9\avgtray.exe [C:\PROGRA~1\AVG\AVG9\avgtray.exe] -> [2010/03/13 09:59:29 | 002,059,544 | ---- | M] (AVG Technologies CZ, s.r.o.)
"COMODO Internet Security" -> C:\Program Files\COMODO\COMODO Internet Security\cfp.exe ["C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h] -> [2010/01/30 11:07:10 | 001,800,464 | ---- | M] (COMODO)
"HPDJ Taskbar Utility" -> C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe [C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe] -> [2003/07/25 09:14:02 | 000,188,416 | ---- | M] (HP)
"HPHmon05" -> C:\WINDOWS\system32\hphmon05.exe [C:\WINDOWS\system32\hphmon05.exe] -> [2003/08/20 16:15:48 | 000,483,328 | R--- | M] (Hewlett-Packard)
"HPHUPD05" -> C:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe [C:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe] -> [2003/08/20 16:23:08 | 000,049,152 | R--- | M] (Hewlett-Packard)
"QUICKCARE" -> C:\Program Files\Qwest\QuickCare\bin\sprtcmd.exe [C:\Program Files\Qwest\QuickCare\bin\sprtcmd.exe /P QUICKCARE] -> [2006/11/07 21:07:42 | 000,192,512 | ---- | M] (Qwest)
"SoundMAXPnP" -> C:\Program Files\Analog Devices\Core\smax4pnp.exe [C:\Program Files\Analog Devices\Core\smax4pnp.exe] -> [2004/10/14 12:42:54 | 001,404,928 | ---- | M] (Analog Devices, Inc.)
< Run [HKEY_USERS\S-1-5-21-540961431-1912937874-3570792479-1006\] > -> HKEY_USERS\S-1-5-21-540961431-1912937874-3570792479-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"EPSON Stylus CX7400 Series" -> C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDA.EXE [C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDA.EXE /FU "C:\WINDOWS\TEMP\E_S81D.tmp" /EF "HKCU"] -> [2007/02/15 06:00:00 | 000,179,200 | ---- | M] (SEIKO EPSON CORPORATION)
"SpybotSD TeaTimer" -> C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe] -> [2009/03/05 16:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.)
< Administrator Startup Folder > -> C:\Documents and Settings\Administrator\Start Menu\Programs\Startup ->
< All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup ->
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk -> C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe -> [2003/05/15 01:19:50 | 000,217,193 | ---- | M] (Adobe Systems Inc.)
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\McAfee Security Scan.lnk -> C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe -> [2009/07/27 19:19:10 | 000,199,184 | ---- | M] (McAfee, Inc.)
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\PictureMover.lnk -> C:\Program Files\PictureMover\Bin\PictureMover.exe -> [2008/08/13 09:11:00 | 000,413,696 | ---- | M] (Hewlett-Packard Company)
< Default User Startup Folder > -> C:\Documents and Settings\Default User\Start Menu\Programs\Startup ->
< ron Startup Folder > -> C:\Documents and Settings\ron\Start Menu\Programs\Startup ->
C:\Documents and Settings\ron\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk -> C:\Program Files\ERUNT\AUTOBACK.EXE -> [2005/10/20 13:04:08 | 000,038,912 | ---- | M] ()
< Software Policy Settings [HKEY_USERS\S-1-5-21-540961431-1912937874-3570792479-1006] > -> HKEY_USERS\S-1-5-21-540961431-1912937874-3570792479-1006\SOFTWARE\Policies\Microsoft\Internet Explorer ->
< CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveAutoRun" -> [67108863] -> File not found
\\"NoDriveTypeAutoRun" -> [323] -> File not found
\\"NoDrives" -> [0] -> File not found
\\"HonorAutoRunSetting" -> [1] -> File not found
\\"NoCDBurning" -> [0] -> File not found
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
< CurrentVersion Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [145] -> File not found
\\"NoDriveAutoRun" -> [67108863] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\.DEFAULT] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [145] -> File not found
\\"NoDriveAutoRun" -> [67108863] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-18] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-19] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [145] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-20] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [145] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-540961431-1912937874-3570792479-1006] > -> HKEY_USERS\S-1-5-21-540961431-1912937874-3570792479-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_USERS\S-1-5-21-540961431-1912937874-3570792479-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [323] -> File not found
\\"NoDriveAutoRun" -> [67108863] -> File not found
\\"NoDrives" -> [0] -> File not found
< CurrentVersion Policy Settings [HKEY_USERS\S-1-5-21-540961431-1912937874-3570792479-1006] > -> HKEY_USERS\S-1-5-21-540961431-1912937874-3570792479-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
HKEY_USERS\S-1-5-21-540961431-1912937874-3570792479-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
< Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\MenuExt\ ->
Add to Google Photos Screensa&ver -> C:\WINDOWS\System32\GPhotos.scr [res://C:\WINDOWS\system32\GPhotos.scr/200] -> [2009/01/05 17:33:03 | 003,751,995 | ---- | M] (Google Inc.)
< Internet Explorer Menu Extensions [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\MenuExt\ ->
Add to Google Photos Screensa&ver -> C:\WINDOWS\System32\GPhotos.scr [res://C:\WINDOWS\system32\GPhotos.scr/200] -> [2009/01/05 17:33:03 | 003,751,995 | ---- | M] (Google Inc.)
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->
{3369AF0D-62E9-4bda-8103-B4C75499B578}:{DE9C389F-3316-41A7-809B-AA305ED9D922} [HKLM] -> C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll [Button: AIM Toolbar] -> [2007/10/10 09:56:58 | 001,090,912 | ---- | M] (AOL LLC)
{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}:{53707962-6F74-2D53-2644-206D7942484F} [HKLM] -> C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [Menu: Spybot - Search && Destroy Configuration] -> [2009/01/26 16:31:02 | 001,879,896 | ---- | M] (Safer Networking Limited)
< Internet Explorer Extensions [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\ ->
CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> [Reg Error: Value error.] -> File not found
< Internet Explorer Extensions [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Extensions\ ->
CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> [Reg Error: Value error.] -> File not found
< Internet Explorer Extensions [HKEY_USERS\S-1-5-21-540961431-1912937874-3570792479-1006\] > -> HKEY_USERS\S-1-5-21-540961431-1912937874-3570792479-1006\Software\Microsoft\Internet Explorer\Extensions\ ->
CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> [Reg Error: Value error.] -> File not found
CmdMapping\\"{3369AF0D-62E9-4bda-8103-B4C75499B578}" [HKLM] -> C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll [AIM Toolbar] -> [2007/10/10 09:56:58 | 001,090,912 | ---- | M] (AOL LLC)
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ ->
< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 5511 domain(s) found. ->
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 36 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 5523 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\.DEFAULT\] > -> HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 58 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 5523 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-18\] > -> HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 58 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1394 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-19\] > -> HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 40 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1394 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-20\] > -> HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 40 range(s) found. ->
< Trusted Sites Domains [HKEY_USERS\S-1-5-21-540961431-1912937874-3570792479-1006\] > -> HKEY_USERS\S-1-5-21-540961431-1912937874-3570792479-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_USERS\S-1-5-21-540961431-1912937874-3570792479-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 5511 domain(s) found. ->
< Trusted Sites Ranges [HKEY_USERS\S-1-5-21-540961431-1912937874-3570792479-1006\] > -> HKEY_USERS\S-1-5-21-540961431-1912937874-3570792479-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_USERS\S-1-5-21-540961431-1912937874-3570792479-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 36 range(s) found. ->
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} [HKLM] -> http://www.apple.com/qtactivex/qtplugin.cab [QuickTime Object] ->
{0CCA191D-13A6-4E29-B746-314DEE697D83} [HKLM] -> http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab [Facebook Photo Uploader 5 Control] ->
{166B1BCA-3F9C-11CF-8075-444553540000} [HKLM] -> http://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab [Shockwave ActiveX Control] ->
{33564D57-0000-0010-8000-00AA00389B71} [HKLM] -> http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB [Reg Error: Key error.] ->
{406B5949-7190-4245-91A9-30A17DE16AD0} [HKLM] -> http://www2.snapfish.com/SnapfishActivia.cab [Snapfish Activia] ->
{49232000-16E4-426C-A231-62846947304B} [HKLM] -> http://ipgweb.cce.hp.com/rdqna/downloads/sysinfo.cab [SysData Class] ->
{4F1E5B1A-2A80-42CA-8532-2D05CB959537} [HKLM] -> http://gfx2.mail.live.com/mail/w1/resources/MSNPUpld.cab [MSN Photo Upload Tool] ->
{596AF4AC-40A0-474A-9F86-33F0A90F0FD6} [HKLM] -> http://photos.msn.com/resources/neutral/controls/DigWebX2.cab [PictureItLauncher Class] ->
{5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} [HKLM] -> http://upload.facebook.com/controls/FacebookPhotoUploader3.cab [Facebook Photo Uploader 4 Control] ->
{5F8469B4-B055-49DD-83F7-62B522420ECC} [HKLM] -> http://upload.facebook.com/controls/FacebookPhotoUploader.cab [Facebook Photo Uploader Control] ->
{6414512B-B978-451D-A0D8-FCFDF33E833C} [HKLM] -> http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1150132468906 [WUWebControl Class] ->
{6B75345B-AA36-438A-BBE6-4078B4C6984D} [HKLM] -> http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab [Reg Error: Key error.] ->
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} [HKLM] -> http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1150132521938 [MUWebControl Class] ->
{6F750202-1362-4815-A476-88533DE61D0C} [HKLM] -> http://targetphoto.kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab [Kodak Gallery Easy Upload Manager Class] ->
{7530BFB8-7293-4D34-9923-61A11451AFC5} [HKLM] -> http://download.eset.com/special/eos/OnlineScanner.cab [Reg Error: Key error.] ->
{8AD9C840-044E-11D1-B3E9-00805F499D93} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab [Java Plug-in 1.6.0_18] ->
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C} [HKLM] -> http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab [Reg Error: Key error.] ->
{9600F64D-755F-11D4-A47F-0001023E6D5A} [HKLM] -> http://web1.shutterfly.com/downloads/Uploader.cab [Shutterfly Picture Upload Plugin] ->
{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab [Java Plug-in 1.6.0_18] ->
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} [HKLM] -> http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab [Java Plug-in 1.6.0_18] ->
{D27CDB6E-AE6D-11CF-96B8-444553540000} [HKLM] -> http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab [Shockwave Flash Object] ->
{E2883E8F-472F-4FB0-9522-AC9BF37916A7} [HKLM] -> http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab [Reg Error: Key error.] ->
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\ ->
DhcpNameServer -> 192.168.0.1 205.171.3.25 ->
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->
{37A0395D-CE3C-43B4-904B-C3ED107A7DCF}\\DhcpNameServer -> 192.168.0.1 205.171.3.25 (Broadcom NetXtreme 57xx Gigabit Controller) ->
< AppInit_DLLs [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs ->
*AppInit_DLLs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls ->
C:\WINDOWS\system32\guard32.dll -> C:\WINDOWS\system32\guard32.dll -> [2010/02/02 07:46:25 | 000,171,552 | ---- | M] (COMODO)
*MultiFile Done* -> ->
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell ->
Explorer.exe -> C:\WINDOWS\explorer.exe -> [2008/04/13 19:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ ->
avgrsstarter -> C:\WINDOWS\System32\avgrsstx.dll -> [2010/03/13 09:59:20 | 000,012,464 | ---- | M] (AVG Technologies CZ, s.r.o.)
igfxcui -> C:\WINDOWS\System32\igfxdev.dll -> [2005/10/14 14:45:38 | 000,135,168 | ---- | M] (Intel Corporation)
< Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List ->
"C:\Program Files\MSN Messenger\livecall.exe" -> C:\Program Files\MSN Messenger\livecall.exe [C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)] -> [2007/01/04 16:10:02 | 000,297,752 | ---- | M] (Microsoft Corporation)
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List ->
"C:\Program Files\AVG\AVG9\avgnsx.exe" -> C:\Program Files\AVG\AVG9\avgnsx.exe [C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe] -> [2010/03/13 09:59:18 | 000,617,752 | ---- | M] (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgupd.exe" -> C:\Program Files\AVG\AVG9\avgupd.exe [C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe] -> [2010/03/13 09:56:08 | 001,035,032 | ---- | M] (AVG Technologies CZ, s.r.o.)
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" -> C:\Program Files\Common Files\AOL\Loader\aolload.exe [C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader] -> [2006/11/03 02:17:27 | 000,010,800 | ---- | M] (AOL LLC)
"C:\Program Files\iTunes\iTunes.exe" -> C:\Program Files\iTunes\iTunes.exe [C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes] -> [2010/01/22 20:16:38 | 010,358,056 | ---- | M] (Apple Inc.)
"C:\Program Files\MSN Messenger\livecall.exe" -> C:\Program Files\MSN Messenger\livecall.exe [C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)] -> [2007/01/04 16:10:02 | 000,297,752 | ---- | M] (Microsoft Corporation)
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot ->
< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom ->
"AutoRun" -> 1 ->
"DisplayName" -> CD-ROM Driver ->
"ImagePath" -> [system32\DRIVERS\cdrom.sys] -> File not found
< Drives with AutoRun files > -> ->
C:\AUTOEXEC.BAT [] -> C:\AUTOEXEC.BAT [ NTFS ] -> [2004/08/11 17:15:00 | 000,000,000 | ---- | M] ()
G:\autorun [] -> G:\autorun [ FAT32 ] -> [2008/08/21 08:14:52 | 000,000,000 | ---D | M]
G:\autorun.in_2.org [] -> G:\autorun.in_2.org [ FAT32 ] -> [2008/05/30 09:31:56 | 000,000,054 | -H-- | M] ()
G:\autorun.inf [Ú3 | ] -> G:\autorun.inf [ FAT32 ] -> [2007/12/23 21:31:06 | 000,000,053 | ---- | M] ()
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 ->
\G
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G\Shell\AutoRun\command
\G\Shell\AutoRun\command\\"" -> [wdsync.exe] -> File not found
\{b9b1cdd7-28f3-11dc-a253-00137286ba87}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b9b1cdd7-28f3-11dc-a253-00137286ba87}\Shell
\{b9b1cdd7-28f3-11dc-a253-00137286ba87}\Shell\\"" -> [AutoRun] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b9b1cdd7-28f3-11dc-a253-00137286ba87}\Shell\AutoRun
\{b9b1cdd7-28f3-11dc-a253-00137286ba87}\Shell\AutoRun\\"" -> [Auto&Play] -> File not found
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b9b1cdd7-28f3-11dc-a253-00137286ba87}\Shell\AutoRun\command
\{b9b1cdd7-28f3-11dc-a253-00137286ba87}\Shell\AutoRun\command\\"" -> E:\LaunchU3.exe [E:\LaunchU3.exe -a] -> File not found
\{c94c79a0-fba9-11dd-a291-00137286ba87}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c94c79a0-fba9-11dd-a291-00137286ba87}\Shell\AutoRun\command
\{c94c79a0-fba9-11dd-a291-00137286ba87}\Shell\AutoRun\command\\"" -> [wdsync.exe] -> File not found
< Registry Shell Spawning - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command ->
comfile [open] -> "%1" %* ->
exefile [open] -> "%1" %* ->
< File Associations - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>\ ->
.com [@ = ComFile] -> "%1" %* ->
.exe [@ = exefile] -> "%1" %* ->
[Files/Folders - Created Within 30 Days]
Sun -> C:\Documents and Settings\All Users\Application Data\Sun -> [2010/03/15 17:32:40 | 000,000,000 | ---D | C]
Java -> C:\Program Files\Common Files\Java -> [2010/03/15 17:31:34 | 000,000,000 | ---D | C]
javacpl.cpl -> C:\WINDOWS\System32\javacpl.cpl -> [2010/03/15 06:59:36 | 000,073,728 | ---- | C] (Sun Microsystems, Inc.)
javaws.exe -> C:\WINDOWS\System32\javaws.exe -> [2010/03/15 06:59:34 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.)
javaw.exe -> C:\WINDOWS\System32\javaw.exe -> [2010/03/15 06:59:34 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.)
java.exe -> C:\WINDOWS\System32\java.exe -> [2010/03/15 06:59:34 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.)
avgrsstx.dll -> C:\WINDOWS\System32\avgrsstx.dll -> [2010/03/13 09:59:20 | 000,012,464 | ---- | C] (AVG Technologies CZ, s.r.o.)
rsit -> C:\rsit -> [2010/03/09 20:36:02 | 000,000,000 | ---D | C]
moviemk.exe -> C:\WINDOWS\System32\dllcache\moviemk.exe -> [2010/03/09 20:22:26 | 003,558,912 | ---- | C] (Microsoft Corporation)
Malwarebytes -> C:\Documents and Settings\ron\Application Data\Malwarebytes -> [2010/03/09 08:06:04 | 000,000,000 | ---D | C]
mbamswissarmy.sys -> C:\WINDOWS\System32\drivers\mbamswissarmy.sys -> [2010/03/09 08:05:56 | 000,038,224 | ---- | C] (Malwarebytes Corporation)
Malwarebytes -> C:\Documents and Settings\All Users\Application Data\Malwarebytes -> [2010/03/09 08:05:54 | 000,000,000 | ---D | C]
mbam.sys -> C:\WINDOWS\System32\drivers\mbam.sys -> [2010/03/09 08:05:52 | 000,019,160 | ---- | C] (Malwarebytes Corporation)
Malwarebytes' Anti-Malware -> C:\Program Files\Malwarebytes' Anti-Malware -> [2010/03/09 08:05:52 | 000,000,000 | ---D | C]
Microsoft -> C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft -> [2009/12/02 18:50:32 | 000,000,000 | ---D | M]
Microsoft -> C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft -> [2009/12/02 18:50:32 | 000,000,000 | ---D | M]
Microsoft -> C:\Documents and Settings\NetworkService\Application Data\Microsoft -> [2009/12/02 18:50:31 | 000,000,000 | --SD | M]
Microsoft -> C:\Documents and Settings\LocalService\Application Data\Microsoft -> [2009/12/02 18:50:31 | 000,000,000 | --SD | M]
Google -> C:\Documents and Settings\LocalService\Local Settings\Application Data\Google -> [2009/02/15 19:42:12 | 000,000,000 | ---D | M]
Apple -> C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple -> [2007/07/30 13:06:01 | 000,000,000 | ---D | M]
[Files/Folders - Modified Within 30 Days]
HP Usg Daily.job -> C:\WINDOWS\tasks\HP Usg Daily.job -> [2010/03/22 15:22:00 | 000,000,312 | ---- | M] ()
incavi.avm -> C:\WINDOWS\System32\drivers\Avg\incavi.avm -> [2010/03/22 09:36:52 | 057,504,857 | ---- | M] ()
sqmnoopt18.sqm -> C:\sqmnoopt18.sqm -> [2010/03/21 19:26:53 | 000,000,244 | -H-- | M] ()
sqmdata18.sqm -> C:\sqmdata18.sqm -> [2010/03/21 19:26:53 | 000,000,232 | -H-- | M] ()
perfh009.dat -> C:\WINDOWS\System32\perfh009.dat -> [2010/03/21 10:41:51 | 000,445,370 | ---- | M] ()
perfc009.dat -> C:\WINDOWS\System32\perfc009.dat -> [2010/03/21 10:41:51 | 000,072,576 | ---- | M] ()
PerfStringBackup.INI -> C:\WINDOWS\System32\PerfStringBackup.INI -> [2010/03/21 10:41:50 | 000,528,020 | ---- | M] ()
wpa.dbl -> C:\WINDOWS\System32\wpa.dbl -> [2010/03/21 10:40:32 | 000,002,206 | ---- | M] ()
OGALogon.job -> C:\WINDOWS\tasks\OGALogon.job -> [2010/03/21 10:38:57 | 000,000,236 | ---- | M] ()
SA.DAT -> C:\WINDOWS\tasks\SA.DAT -> [2010/03/21 10:38:46 | 000,000,006 | -H-- | M] ()
bootstat.dat -> C:\WINDOWS\bootstat.dat -> [2010/03/21 10:38:44 | 000,002,048 | --S- | M] ()
hiberfil.sys -> C:\hiberfil.sys -> [2010/03/21 10:38:43 | 1063,399,424 | -HS- | M] ()
NTUSER.DAT -> C:\Documents and Settings\ron\NTUSER.DAT -> [2010/03/21 10:37:18 | 008,912,896 | -H-- | M] ()
ntuser.ini -> C:\Documents and Settings\ron\ntuser.ini -> [2010/03/21 10:37:18 | 000,000,278 | -HS- | M] ()
Adobe Reader 9.lnk -> C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk -> [2010/03/20 13:12:12 | 000,001,729 | ---- | M] ()
sqmnoopt17.sqm -> C:\sqmnoopt17.sqm -> [2010/03/17 22:37:36 | 000,000,244 | -H-- | M] ()
sqmdata17.sqm -> C:\sqmdata17.sqm -> [2010/03/17 22:37:36 | 000,000,232 | -H-- | M] ()
Mozilla Firefox.lnk -> C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk -> [2010/03/17 06:52:16 | 000,001,602 | ---- | M] ()
AppleSoftwareUpdate.job -> C:\WINDOWS\tasks\AppleSoftwareUpdate.job -> [2010/03/15 21:54:04 | 000,000,284 | ---- | M] ()
deploytk.dll -> C:\WINDOWS\System32\deploytk.dll -> [2010/03/15 06:58:55 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.)
javaws.exe -> C:\WINDOWS\System32\javaws.exe -> [2010/03/15 06:58:55 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.)
javaw.exe -> C:\WINDOWS\System32\javaw.exe -> [2010/03/15 06:58:55 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.)
java.exe -> C:\WINDOWS\System32\java.exe -> [2010/03/15 06:58:55 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.)
javacpl.cpl -> C:\WINDOWS\System32\javacpl.cpl -> [2010/03/15 06:58:55 | 000,073,728 | ---- | M] (Sun Microsystems, Inc.)
avgtdix.sys -> C:\WINDOWS\System32\drivers\avgtdix.sys -> [2010/03/13 09:59:26 | 000,242,696 | ---- | M] (AVG Technologies CZ, s.r.o.)
avgrsstx.dll -> C:\WINDOWS\System32\avgrsstx.dll -> [2010/03/13 09:59:20 | 000,012,464 | ---- | M] (AVG Technologies CZ, s.r.o.)
avgmfx86.sys -> C:\WINDOWS\System32\drivers\avgmfx86.sys -> [2010/03/13 09:59:19 | 000,029,512 | ---- | M] (AVG Technologies CZ, s.r.o.)
avgldx86.sys -> C:\WINDOWS\System32\drivers\avgldx86.sys -> [2010/03/13 09:57:58 | 000,216,200 | ---- | M] (AVG Technologies CZ, s.r.o.)
HP DArC Task #Hewlett-Packard#7700#MY3A8212F6K5.job -> C:\WINDOWS\tasks\HP DArC Task #Hewlett-Packard#7700#MY3A8212F6K5.job -> [2010/03/11 18:40:19 | 000,000,316 | ---- | M] ()
win.ini -> C:\WINDOWS\win.ini -> [2010/03/10 04:09:52 | 000,000,573 | ---- | M] ()
All-in-One Wedding Planner.xls -> C:\Documents and Settings\ron\Desktop\All-in-One Wedding Planner.xls -> [2010/03/09 08:04:33 | 000,124,928 | ---- | M] ()
Dolphin Wedding List.xls -> C:\Documents and Settings\ron\Desktop\Dolphin Wedding List.xls -> [2010/03/09 08:04:19 | 000,019,968 | ---- | M] ()
sqmnoopt16.sqm -> C:\sqmnoopt16.sqm -> [2010/03/03 23:14:58 | 000,000,244 | -H-- | M] ()
sqmdata16.sqm -> C:\sqmdata16.sqm -> [2010/03/03 23:14:58 | 000,000,232 | -H-- | M] ()
sqmnoopt15.sqm -> C:\sqmnoopt15.sqm -> [2010/02/28 11:06:17 | 000,000,244 | -H-- | M] ()
sqmdata15.sqm -> C:\sqmdata15.sqm -> [2010/02/28 11:06:17 | 000,000,232 | -H-- | M] ()
imsins.BAK -> C:\WINDOWS\imsins.BAK -> [2010/02/24 04:01:48 | 000,001,374 | ---- | M] ()
sqmnoopt14.sqm -> C:\sqmnoopt14.sqm -> [2010/02/22 19:43:02 | 000,000,244 | -H-- | M] ()
sqmdata14.sqm -> C:\sqmdata14.sqm -> [2010/02/22 19:43:02 | 000,000,232 | -H-- | M] ()
sqmnoopt13.sqm -> C:\sqmnoopt13.sqm -> [2010/02/21 22:07:49 | 000,000,244 | -H-- | M] ()
sqmdata13.sqm -> C:\sqmdata13.sqm -> [2010/02/21 22:07:49 | 000,000,232 | -H-- | M] ()
sqmnoopt12.sqm -> C:\sqmnoopt12.sqm -> [2010/02/21 19:04:22 | 000,000,244 | -H-- | M] ()
sqmdata12.sqm -> C:\sqmdata12.sqm -> [2010/02/21 19:04:22 | 000,000,232 | -H-- | M] ()
6 C:\Documents and Settings\ron\Local Settings\temp\*.tmp files -> C:\Documents and Settings\ron\Local Settings\temp\*.tmp ->
[Files - No Company Name]
Mozilla Firefox.lnk -> C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk -> [2010/03/17 06:52:16 | 000,001,602 | ---- | C] ()
All-in-One Wedding Planner.xls -> C:\Documents and Settings\ron\Desktop\All-in-One Wedding Planner.xls -> [2010/03/09 08:04:32 | 000,124,928 | ---- | C] ()
Dolphin Wedding List.xls -> C:\Documents and Settings\ron\Desktop\Dolphin Wedding List.xls -> [2010/03/09 08:04:18 | 000,019,968 | ---- | C] ()
Adobe Reader 9.lnk -> C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk -> [2010/02/27 10:58:05 | 000,001,729 | ---- | C] ()
OGACheckControl.dll -> C:\WINDOWS\System32\OGACheckControl.dll -> [2009/08/03 15:07:42 | 000,403,816 | ---- | C] ()
wininit.ini -> C:\WINDOWS\wininit.ini -> [2009/02/22 22:24:27 | 000,000,091 | ---- | C] ()
xvidcore.dll -> C:\WINDOWS\System32\xvidcore.dll -> [2009/01/21 16:35:10 | 000,765,952 | ---- | C] ()
xvidvfw.dll -> C:\WINDOWS\System32\xvidvfw.dll -> [2009/01/21 16:35:10 | 000,180,224 | ---- | C] ()
PICSDK.ini -> C:\WINDOWS\System32\PICSDK.ini -> [2008/07/14 19:39:21 | 000,000,097 | ---- | C] ()
EPSCX7400.ini -> C:\WINDOWS\EPSCX7400.ini -> [2008/07/14 19:38:13 | 000,000,079 | ---- | C] ()
HP_CounterReport_Update_HPSU.ini -> C:\WINDOWS\HP_CounterReport_Update_HPSU.ini -> [2007/02/28 13:14:38 | 000,000,227 | ---- | C] ()
PrnHlpLogConfig.ini -> C:\WINDOWS\PrnHlpLogConfig.ini -> [2007/02/28 13:13:37 | 000,000,234 | ---- | C] ()
HP_InstantSHareJPG.ini -> C:\WINDOWS\HP_InstantSHareJPG.ini -> [2007/02/28 13:13:25 | 000,000,214 | ---- | C] ()
FreeImage.dll -> C:\WINDOWS\System32\FreeImage.dll -> [2007/01/02 23:11:00 | 000,667,648 | ---- | C] ()
unrar.dll -> C:\WINDOWS\System32\unrar.dll -> [2007/01/02 23:11:00 | 000,159,744 | ---- | C] ()
UNACE.DLL -> C:\WINDOWS\System32\UNACE.DLL -> [2007/01/02 23:11:00 | 000,040,448 | ---- | C] ()
cdplayer.ini -> C:\WINDOWS\cdplayer.ini -> [2006/10/30 19:59:58 | 000,000,092 | ---- | C] ()
HP_IZClosingDiscErrorPatch.ini -> C:\WINDOWS\HP_IZClosingDiscErrorPatch.ini -> [2006/09/20 23:09:12 | 000,000,217 | ---- | C] ()
HPGdiPlus.ini -> C:\WINDOWS\HPGdiPlus.ini -> [2006/09/20 19:08:47 | 000,000,206 | ---- | C] ()
HP_RedboxHprblog_HPSU.ini -> C:\WINDOWS\HP_RedboxHprblog_HPSU.ini -> [2006/09/20 19:06:45 | 000,000,221 | ---- | C] ()
hpzids01.dll -> C:\WINDOWS\System32\hpzids01.dll -> [2006/07/13 07:57:54 | 000,077,824 | R--- | C] ()
GlobalUserInterface.CompositeFont -> C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont -> [2006/06/29 14:58:52 | 000,030,808 | ---- | C] ()
GlobalSansSerif.CompositeFont -> C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont -> [2006/06/29 14:53:56 | 000,026,489 | ---- | C] ()
smscfg.ini -> C:\WINDOWS\smscfg.ini -> [2006/06/08 00:09:22 | 000,000,061 | ---- | C] ()
ODBC.INI -> C:\WINDOWS\ODBC.INI -> [2006/06/08 00:06:58 | 000,000,376 | ---- | C] ()
OEMINFO.INI -> C:\WINDOWS\System32\OEMINFO.INI -> [2006/06/07 23:44:52 | 000,000,391 | ---- | C] ()
GlobalSerif.CompositeFont -> C:\WINDOWS\Fonts\GlobalSerif.CompositeFont -> [2006/04/18 15:39:28 | 000,029,779 | ---- | C] ()
GlobalMonospace.CompositeFont -> C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont -> [2006/04/18 15:39:28 | 000,026,040 | ---- | C] ()
orun32.ini -> C:\WINDOWS\orun32.ini -> [2004/08/11 17:24:19 | 000,000,791 | ---- | C] ()
fxsperf.ini -> C:\WINDOWS\System32\fxsperf.ini -> [2004/08/11 17:11:31 | 000,001,793 | ---- | C] ()
OUTLPERF.INI -> C:\WINDOWS\System32\OUTLPERF.INI -> [2003/01/07 15:05:08 | 000,002,695 | ---- | C] ()
< End of report >