Hi peku006,
Some additional info that i didn't mention but not sure if it's of importance. Whenever i load Spybot S&D using my computer, i always get a syntax error. i successfully logged into hotmail today however, logging out continues to produce a "page not found" error.
also, just starting last night, my second computer is having problems with connecting to websites. i get a message saying "DNS error. Server not found". My second computer uses Google Chrome. I also encountered some problems getting to this forum just now. What i tried doing was "ipconfig /flushdns" in cmd and i was able to go onto the forum immediately to post this reply.
I am using a router and never had problems with it.
OTViewIt logfile created on: 1/15/2009 6:50:38 PM - Run
OTViewIt by OldTimer - Version 1.0.21.0 Folder = C:\Documents and Settings\L\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.22 Gb Total Physical Memory | 0.85 Gb Available Physical Memory | 69.64% Memory free
1.41 Gb Paging File | 1.08 Gb Available in Paging File | 77.02% Paging File free
Paging file location(s): C:\pagefile.sys 336 672;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.78 Gb Total Space | 8.47 Gb Free Space | 7.58% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 232.88 Gb Total Space | 7.66 Gb Free Space | 3.29% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: L-3746562C4F964
Current User Name: L
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days
========== Processes ==========
[2008/07/09 09:05:18 | 00,075,304 | ---- | M] (Zone Labs, LLC) -- C:\WINDOWS\system32\ZoneLabs\vsmon.exe
[2007/12/03 14:53:58 | 00,139,264 | ---- | M] () -- C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe
[2007/09/06 12:28:18 | 00,110,592 | ---- | M] (Apple, Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
[1999/12/12 12:01:00 | 00,044,032 | ---- | M] (Creative Technology Ltd) -- C:\WINDOWS\system32\CTSVCCDA.EXE
[2009/01/07 19:25:51 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
[2005/01/28 15:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wdfmgr.exe
[2001/11/21 06:39:08 | 00,294,912 | ---- | M] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\system32\SISAUDUT.EXE
[2009/01/07 19:25:51 | 00,136,600 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
[2008/07/09 09:05:20 | 00,919,016 | ---- | M] (Zone Labs, LLC) -- C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
[2004/12/02 18:23:34 | 00,102,400 | ---- | M] (Creative Technology Ltd) -- C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
[2008/03/08 12:35:08 | 01,481,968 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
[2007/05/11 07:50:24 | 00,804,376 | ---- | M] ( ) -- C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\mantispm.exe
[2009/01/15 17:32:34 | 00,422,912 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\L\Desktop\OTViewIt.exe
========== (O23) Win32 Services ==========
[2007/09/06 12:28:18 | 00,110,592 | ---- | M] (Apple, Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running])
File not found -- -- (CLTNetCnService [Auto | Stopped])
[1999/12/12 12:01:00 | 00,044,032 | ---- | M] (Creative Technology Ltd) -- C:\WINDOWS\system32\CTSVCCDA.EXE -- (Creative Service for CDROM Access [Auto | Running])
[2007/09/14 08:59:56 | 00,503,608 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Stopped])
[2009/01/07 19:25:51 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
[2007/01/15 17:14:38 | 00,774,144 | ---- | M] (Nero AG) -- C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe -- (NBService [On_Demand | Stopped])
[2007/01/15 16:01:56 | 00,266,240 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe -- (NMIndexingService [On_Demand | Stopped])
[2005/08/11 01:17:28 | 00,118,272 | ---- | M] (TuneUp Software GmbH) -- C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe -- (TUWinStylerThemeSvc [On_Demand | Stopped])
[2005/01/28 15:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wdfmgr.exe -- (UMWdf [Auto | Running])
[2007/01/19 11:54:14 | 00,097,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\MSN Messenger\usnsvc.exe -- (usnjsvc [On_Demand | Stopped])
[2008/07/09 09:05:18 | 00,075,304 | ---- | M] (Zone Labs, LLC) -- C:\WINDOWS\system32\ZoneLabs\vsmon.exe -- (vsmon [Auto | Running])
========== Driver Services ==========
[2004/04/30 09:37:02 | 00,160,640 | ---- | M] ( ) -- C:\WINDOWS\system32\drivers\a347bus.sys -- (a347bus [Boot | Running])
[2004/04/30 09:33:00 | 00,005,248 | ---- | M] ( ) -- C:\WINDOWS\system32\drivers\a347scsi.sys -- (a347scsi [Boot | Running])
[2004/08/03 16:59:44 | 00,095,360 | ---- | M] () -- C:\WINDOWS\system32\drivers\atapi.sys -- (atapi [Boot | Running])
[2002/05/24 13:52:58 | 00,010,368 | ---- | M] (Digit@lway Co., Ltd.) -- C:\WINDOWS\system32\drivers\dwusbdnt.sys -- (dwusbdnt [On_Demand | Stopped])
[2007/02/15 20:22:16 | 00,094,080 | ---- | M] (VSO Software) -- C:\WINDOWS\system32\drivers\ezplay.sys -- (ezplay [On_Demand | Stopped])
[2004/08/03 18:08:22 | 00,010,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum [On_Demand | Running])
[2006/09/19 13:44:04 | 00,015,664 | ---- | M] (GEAR Software Inc.) -- C:\WINDOWS\system32\drivers\GEARAspiWDM.sys -- (GEARAspiWDM [On_Demand | Running])
[2007/07/19 15:10:28 | 00,127,768 | ---- | M] (Kaspersky Lab) -- C:\WINDOWS\system32\drivers\klif.sys -- (KLIF [System | Running])
[2001/08/17 09:00:04 | 00,002,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\msmpu401.sys -- (ms_mpu401 [On_Demand | Stopped])
[2004/08/04 00:29:30 | 00,014,336 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\drivers\atinpdxx.sys -- (PCDCODEC [Auto | Running])
[2007/02/15 20:22:01 | 00,047,360 | ---- | M] (VSO Software) -- C:\WINDOWS\system32\drivers\pcouffin.sys -- (pcouffin [On_Demand | Stopped])
[2001/08/23 07:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink [On_Demand | Running])
[2007/03/07 18:51:00 | 00,043,528 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\system32\drivers\PxHelp20.sys -- (PxHelp20 [Boot | Running])
[2006/10/10 13:53:48 | 00,005,632 | ---- | M] () -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV [System | Running])
[2006/02/16 17:51:08 | 00,004,096 | R--- | M] (SuperAdBlocker, Inc.) -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM [On_Demand | Running])
[2008/03/08 12:35:08 | 00,051,440 | ---- | M] () -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL [System | Running])
[2004/07/17 05:36:38 | 00,027,440 | ---- | M] () -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv [On_Demand | Stopped])
[2001/12/13 13:52:48 | 00,163,200 | ---- | M] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\system32\drivers\sisgrp.sys -- (SiS315 [On_Demand | Running])
[2001/11/26 09:00:08 | 00,165,760 | R--- | M] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\system32\drivers\sis7012.sys -- (SiS7012 [On_Demand | Running])
[2001/12/26 15:52:58 | 00,027,136 | ---- | M] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\system32\drivers\SISAGP.SYS -- (sisagp [Boot | Running])
[2001/09/28 15:16:46 | 00,031,744 | R--- | M] (SiS Corporation) -- C:\WINDOWS\system32\drivers\sisnic.sys -- (SISNIC [On_Demand | Running])
[2004/08/09 00:44:40 | 00,051,040 | RH-- | M] (MCCI) -- C:\WINDOWS\system32\drivers\slabbus.sys -- (slabbus [On_Demand | Stopped])
[2004/08/09 00:44:40 | 00,082,768 | RH-- | M] (MCCI) -- C:\WINDOWS\system32\drivers\slabser.sys -- (slabser [On_Demand | Stopped])
[2001/08/17 15:56:16 | 00,007,552 | ---- | M] (Sony Corporation) -- C:\WINDOWS\system32\drivers\SONYPVU1.SYS -- (SONYPVU1 [On_Demand | Stopped])
[2008/02/27 03:10:44 | 00,051,176 | ---- | M] (Zone Labs, LLC) -- C:\WINDOWS\system32\ZoneLabs\srescan.sys -- (srescan [Boot | Running])
[2006/11/18 01:02:53 | 00,080,272 | R--- | M] (MCCI) -- C:\WINDOWS\system32\drivers\sscdbus.sys -- (sscdbus [On_Demand | Stopped])
[2006/11/18 01:02:53 | 00,010,864 | R--- | M] (MCCI) -- C:\WINDOWS\system32\drivers\sscdmdfl.sys -- (sscdmdfl [On_Demand | Stopped])
[2006/11/18 01:02:53 | 00,137,884 | R--- | M] (MCCI) -- C:\WINDOWS\system32\drivers\sscdmdm.sys -- (sscdmdm [On_Demand | Stopped])
[2006/11/18 01:02:54 | 00,108,003 | R--- | M] (MCCI) -- C:\WINDOWS\system32\drivers\sscdserd.sys -- (sscdserd [On_Demand | Stopped])
[2007/07/19 15:10:28 | 00,127,768 | ---- | M] (Kaspersky Lab) -- C:\WINDOWS\system32\drivers\klif.sys -- (TSP [On_Demand | Stopped])
[2004/08/04 00:29:32 | 00,013,824 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\drivers\atinttxx.sys -- (TTDec [Auto | Running])
[2008/07/09 09:05:22 | 00,394,952 | ---- | M] (Zone Labs, LLC) -- C:\WINDOWS\system32\vsdatant.sys -- (vsdatant [System | Running])
========== (R ) Internet Explorer ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=http://go.microsoft.com/fwlink/?LinkId=69157
"Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896
"Local Page"=%SystemRoot%\system32\blank.htm
"Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896
"Start Page"=http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search]
"CustomizeSearch"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
"SearchAssistant"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\WINDOWS\system32\blank.htm
"Page_Transitions"=
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.google.ca/
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURL]
"provider"=
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation)
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main]
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main]
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main]
"Start Page"=http://securityresponse.symantec.com/avcenter/fix_homepage/
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main]
"Start Page"=http://securityresponse.symantec.com/avcenter/fix_homepage/
[HKEY_USERS\S-1-5-21-1960408961-1417001333-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\WINDOWS\system32\blank.htm
"Page_Transitions"=
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.google.ca/
[HKEY_USERS\S-1-5-21-1960408961-1417001333-1801674531-1003\Software\Microsoft\Internet Explorer\SearchURL]
"provider"=
[HKEY_USERS\S-1-5-21-1960408961-1417001333-1801674531-1003\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-1960408961-1417001333-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
========== (O1) Hosts File ==========
HOSTS File = (291104 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
First 25 entries...
127.0.0.1 localhost
127.0.0.1 007guard.com
127.0.0.1
www.007guard.com
127.0.0.1 008i.com
127.0.0.1 008k.com
127.0.0.1
www.008k.com
127.0.0.1 00hq.com
127.0.0.1
www.00hq.com
127.0.0.1 010402.com
127.0.0.1 032439.com
127.0.0.1
www.032439.com
127.0.0.1 100888290cs.com
127.0.0.1
www.100888290cs.com
127.0.0.1 100sexlinks.com
127.0.0.1
www.100sexlinks.com
127.0.0.1 10sek.com
127.0.0.1
www.10sek.com
127.0.0.1 123topsearch.com
127.0.0.1
www.123topsearch.com
127.0.0.1 132.com
127.0.0.1
www.132.com
127.0.0.1 136136.net
127.0.0.1
www.136136.net
127.0.0.1 163ns.com
127.0.0.1
www.163ns.com
10048 more lines...
========== (O2) BHO's ==========
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (HKLM) -- C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
{2F364306-AA45-47B5-9F9D-39A8B94E7EF7} (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (HKLM) -- C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
{7E853D72-626A-48EC-A868-BA8D5E23E045} (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
{DBC80044-A445-435b-BC74-9C25C1C588A9} (HKLM) -- C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
{E7E6F031-17CE-4C07-BC86-EABFE594F69C} (HKLM) -- C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
{F156768E-81EF-470C-9057-481BA8380DBA} (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
========== (O3) Toolbars ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{E0E899AB-F487-11D5-8D29-0050BA6940E3}" (HKLM) -- C:\Program Files\FlashGet\fgiebar.dll (Amaze Soft)
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
[HKEY_USERS\S-1-5-21-1960408961-1417001333-1801674531-1003\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
[HKEY_USERS\S-1-5-21-1960408961-1417001333-1801674531-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
========== (O4) Run Keys ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
"SiS7012Utility"=C:\WINDOWS\system32\SiSAudUt.exe -wdm (Silicon Integrated Systems Corporation)
"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" (Zone Labs, LLC)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R (Creative Technology Ltd)
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
[HKEY_USERS\S-1-5-21-1960408961-1417001333-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R (Creative Technology Ltd)
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
========== (O4) RunOnce Keys ==========
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"=Narrator.exe (Microsoft Corporation)
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"=Narrator.exe (Microsoft Corporation)
========== (O4) Startup Folders ==========
[1999/11/04 15:06:48 | 00,113,664 | ---- | M] (Adobe Systems, Inc.) -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
[2005/09/24 00:05:26 | 00,029,696 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
[1999/02/17 23:05:56 | 00,065,588 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
========== (O6 & O7) Current Version Policies ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"DisableRegistryTools"=0
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
"NoDriveAutoRun"=67108863
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
"NoDriveAutoRun"=67108863
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
[HKEY_USERS\S-1-5-21-1960408961-1417001333-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
========== (O8) IE Context Menu Extensions ==========
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\]
Download All by FlashGet: C:\Program Files\FlashGet\jc_all.htm [2000/02/06 13:06:06 | 00,000,575 | ---- | M] ()
Download using FlashGet: C:\Program Files\FlashGet\jc_link.htm [2000/02/06 13:06:34 | 00,001,898 | ---- | M] ()
[HKEY_USERS\S-1-5-21-1960408961-1417001333-1801674531-1003\Software\Microsoft\Internet Explorer\MenuExt\]
Download All by FlashGet: C:\Program Files\FlashGet\jc_all.htm [2000/02/06 13:06:06 | 00,000,575 | ---- | M] ()
Download using FlashGet: C:\Program Files\FlashGet\jc_link.htm [2000/02/06 13:06:34 | 00,001,898 | ---- | M] ()
========== (O9) IE Extensions ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
{44226DFF-747E-4edc-B30C-78752E50CD0C}: Button: ATI TV -- %ProgramFiles%\ATI Multimedia\TV\EXPLBAR.DLL [2001/01/15 15:07:54 | 00,131,072 | ---- | M] (ATI Technologies Inc.)
{D6E814A0-E0C5-11d4-8D29-0050BA6940E3}: Button: FlashGet -- %ProgramFiles%\FlashGet\flashget.exe [2006/09/11 19:01:40 | 01,400,832 | ---- | M] (FlashGet.com)
{D6E814A0-E0C5-11d4-8D29-0050BA6940E3}: Menu: &FlashGet -- %ProgramFiles%\FlashGet\flashget.exe [2006/09/11 19:01:40 | 01,400,832 | ---- | M] (FlashGet.com)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Button: Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2004/08/04 03:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Menu: Windows Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2004/08/04 03:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{44226DFF-747E-4edc-B30C-78752E50CD0C} [HKLM] -> %ProgramFiles%\ATI Multimedia\TV\EXPLBAR.DLL [&ATI TV] -> [2001/01/15 15:07:54 | 00,131,072 | ---- | M] (ATI Technologies Inc.)
CmdMapping\\{D6E814A0-E0C5-11d4-8D29-0050BA6940E3} [HKLM] -> %ProgramFiles%\FlashGet\flashget.exe [FlashGet] -> [2006/09/11 19:01:40 | 01,400,832 | ---- | M] (FlashGet.com)
CmdMapping\\{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/08/04 03:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation)
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{44226DFF-747E-4edc-B30C-78752E50CD0C} [HKLM] -> %ProgramFiles%\ATI Multimedia\TV\EXPLBAR.DLL [&ATI TV] -> [2001/01/15 15:07:54 | 00,131,072 | ---- | M] (ATI Technologies Inc.)
CmdMapping\\{D6E814A0-E0C5-11d4-8D29-0050BA6940E3} [HKLM] -> %ProgramFiles%\FlashGet\flashget.exe [FlashGet] -> [2006/09/11 19:01:40 | 01,400,832 | ---- | M] (FlashGet.com)
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/08/04 03:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation)
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{44226DFF-747E-4edc-B30C-78752E50CD0C} [HKLM] -> %ProgramFiles%\ATI Multimedia\TV\EXPLBAR.DLL [&ATI TV] -> [2001/01/15 15:07:54 | 00,131,072 | ---- | M] (ATI Technologies Inc.)
CmdMapping\\{D6E814A0-E0C5-11d4-8D29-0050BA6940E3} [HKLM] -> %ProgramFiles%\FlashGet\flashget.exe [FlashGet] -> [2006/09/11 19:01:40 | 01,400,832 | ---- | M] (FlashGet.com)
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/08/04 03:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-1960408961-1417001333-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{44226DFF-747E-4edc-B30C-78752E50CD0C} [HKLM] -> %ProgramFiles%\ATI Multimedia\TV\EXPLBAR.DLL [&ATI TV] -> [2001/01/15 15:07:54 | 00,131,072 | ---- | M] (ATI Technologies Inc.)
CmdMapping\\{D6E814A0-E0C5-11d4-8D29-0050BA6940E3} [HKLM] -> %ProgramFiles%\FlashGet\flashget.exe [FlashGet] -> [2006/09/11 19:01:40 | 01,400,832 | ---- | M] (FlashGet.com)
CmdMapping\\{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/08/04 03:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation)
========== (O12) Internet Explorer Plugins ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\]
PluginsPage: "" =
http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s
PluginsPageFriendlyName: "" = Microsoft ActiveX Gallery
========== (O13) Default Prefixes ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
""=http://
========== (O15) Trusted Sites ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
50 domain(s) and sub-domain(s) not assigned to a zone.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
56 domain(s) and sub-domain(s) not assigned to a zone.
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
49 domain(s) and sub-domain(s) not assigned to a zone.
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
49 domain(s) and sub-domain(s) not assigned to a zone.
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
32 domain(s) and sub-domain(s) not assigned to a zone.
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
32 domain(s) and sub-domain(s) not assigned to a zone.
[HKEY_USERS\S-1-5-21-1960408961-1417001333-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
56 domain(s) and sub-domain(s) not assigned to a zone.
========== (O16) DPF ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\]
{072039AB-2117-4ED5-A85F-9B9EB903E021}:
http://www.clubbox.co.kr/neo.fld/NowStarter.cab -- NowStarter Control
{8AD9C840-044E-11D1-B3E9-00805F499D93}:
http://javadl.sun.com/webapps/download/AutoDL?BundleId=26688 -- Java Plug-in 1.6.0_11
{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:
http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab -- Java Plug-in 1.6.0_11
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}:
http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab -- Java Plug-in 1.6.0_11
{D27CDB6E-AE6D-11CF-96B8-444553540000}:
http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab -- Shockwave Flash Object
========== (O17) DNS Name Servers ==========
{A2BE0C7D-2E77-498A-B8C3-782620438865} (Servers: | Description: SiS 900 PCI Fast Ethernet Adapter)
========== (O19) User Style Sheets ==========
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Styles]
========== (O20) Winlogon Notify Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\]
!SASWinLogon: "DllName" = C:\Program Files\SUPERAntiSpyware\SASWINLO.dll -- C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
========== Shell Execute Hooks ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}" (HKLM) -- C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
========== Safeboot Options ==========
"AlternateShell"=cmd.exe
========== CDRom AutoRun Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1
========== Autorun Files on Drives ==========
AUTOEXEC.BAT []
[2006/09/17 19:48:43 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT -- [ NTFS ]
========== Files/Folders - Created Within 30 Days ==========
[3 C:\WINDOWS\*.tmp files]
[2009/01/15 18:49:55 | 02,216,820 | ---- | C] () -- C:\Documents and Settings\L\Desktop\ClubboxSetup.exe
[2009/01/15 18:08:21 | 52,423,056 | ---- | C] () -- C:\Documents and Settings\L\Desktop\zaSuiteSetup_80_059_000_en.exe
[2009/01/15 17:49:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\L\Application Data\MailFrontier
[2009/01/15 17:43:17 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\MailFrontier
[2009/01/15 17:42:54 | 00,127,768 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\klif.sys
[2009/01/15 17:32:30 | 00,422,912 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\L\Desktop\OTViewIt.exe
[2009/01/14 17:57:12 | 00,000,000 | -HSD | C] -- C:\RECYCLER
[2009/01/14 17:46:26 | 00,000,211 | ---- | C] () -- C:\Boot.bak
[2009/01/14 17:46:24 | 00,260,272 | ---- | C] () -- C:\cmldr
[2009/01/14 17:46:21 | 00,000,000 | RHSD | C] -- C:\cmdcons
[2009/01/14 17:43:59 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2009/01/14 17:43:59 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2009/01/14 17:43:59 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2009/01/14 17:43:59 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2009/01/14 17:43:59 | 00,089,504 | ---- | C] (Smallfrogs Studio) -- C:\WINDOWS\fdsv.exe
[2009/01/14 17:43:59 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2009/01/14 17:43:59 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2009/01/14 17:43:59 | 00,049,152 | ---- | C] () -- C:\WINDOWS\VFIND.exe
[2009/01/14 17:43:59 | 00,029,696 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2009/01/14 17:38:02 | 03,039,899 | R--- | C] () -- C:\Documents and Settings\L\Desktop\ComboFix.exe
[2009/01/13 17:51:34 | 00,000,000 | ---D | C] -- C:\Documents and Settings\L\Desktop\OTScanIt2
[2009/01/13 14:52:26 | 00,000,000 | ---D | C] -- C:\rsit
[2009/01/13 14:52:01 | 00,781,851 | ---- | C] () -- C:\Documents and Settings\L\Desktop\RSIT.exe
[2009/01/13 12:55:11 | 01,889,864 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\L\Desktop\mbam-rules.exe
[2009/01/13 09:18:16 | 00,000,000 | ---D | C] -- C:\Documents and Settings\L\Application Data\Malwarebytes
[2009/01/13 09:18:01 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/01/13 09:18:01 | 00,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/01/13 09:17:59 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/01/13 09:17:57 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/01/13 09:17:57 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/01/13 09:15:45 | 02,697,168 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\L\Desktop\mbam-setup.exe
[2009/01/11 16:28:43 | 00,021,547 | ---- | C] () -- C:\Documents and Settings\L\Desktop\dead-links.jpg
[2009/01/07 19:26:30 | 00,000,000 | ---D | C] -- C:\WINDOWS\Sun
[2009/01/07 19:25:46 | 00,000,000 | ---D | C] -- C:\Program Files\Java
[2009/01/07 19:24:09 | 00,000,000 | ---D | C] -- C:\Documents and Settings\L\Application Data\Sun
[2009/01/07 19:10:19 | 00,054,156 | -H-- | C] () -- C:\WINDOWS\QTFont.qfn
[2009/01/07 19:10:19 | 00,001,409 | ---- | C] () -- C:\WINDOWS\QTFont.for
========== Files - Modified Within 30 Days ==========
[3 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009/01/15 18:51:50 | 00,621,856 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox.dat
[2009/01/15 18:49:55 | 02,216,820 | ---- | M] () -- C:\Documents and Settings\L\Desktop\ClubboxSetup.exe
[2009/01/15 18:08:23 | 52,423,056 | ---- | M] () -- C:\Documents and Settings\L\Desktop\zaSuiteSetup_80_059_000_en.exe
[2009/01/15 18:07:12 | 00,003,954 | ---- | M] () -- C:\rollback.ini
[2009/01/15 17:48:05 | 00,004,212 | -H-- | M] () -- C:\WINDOWS\System32\zllictbl.dat
[2009/01/15 17:47:39 | 00,355,091 | ---- | M] () -- C:\WINDOWS\System32\vsconfig.xml
[2009/01/15 17:46:48 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/01/15 17:46:31 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/01/15 17:46:31 | 00,000,032 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox.idx
[2009/01/15 17:32:34 | 00,422,912 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\L\Desktop\OTViewIt.exe
[2009/01/14 22:07:49 | 00,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/01/14 22:07:47 | 00,202,240 | ---- | M] () -- C:\Documents and Settings\L\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/01/14 21:39:57 | 00,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2009/01/14 17:49:31 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/01/14 17:46:27 | 00,000,281 | RHS- | M] () -- C:\boot.ini
[2009/01/14 17:38:02 | 03,039,899 | R--- | M] () -- C:\Documents and Settings\L\Desktop\ComboFix.exe
[2009/01/14 15:27:56 | 00,055,849 | ---- | M] () -- C:\WINDOWS\System32\fscflist.ini
[2009/01/14 08:08:18 | 00,000,079 | ---- | M] () -- C:\WINDOWS\System32\fscagent.ini
[2009/01/14 08:08:01 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\PDBOXGame.html
[2009/01/13 17:30:46 | 00,087,608 | ---- | M] () -- C:\Documents and Settings\L\Application Data\ezpinst.exe
[2009/01/13 17:30:46 | 00,007,812 | ---- | M] () -- C:\Documents and Settings\L\Application Data\ezplay.cat
[2009/01/13 17:30:45 | 00,094,080 | ---- | M] (VSO Software) -- C:\Documents and Settings\L\Application Data\ezplay.sys
[2009/01/13 17:30:45 | 00,001,104 | ---- | M] () -- C:\Documents and Settings\L\Application Data\LZAAYMNK.inf
[2009/01/13 17:30:44 | 00,047,360 | ---- | M] (VSO Software) -- C:\Documents and Settings\L\Application Data\pcouffin.sys
[2009/01/13 17:30:44 | 00,007,824 | ---- | M] () -- C:\Documents and Settings\L\Application Data\pcouffin.cat
[2009/01/13 17:30:44 | 00,001,144 | ---- | M] () -- C:\Documents and Settings\L\Application Data\pcouffin.inf
[2009/01/13 16:59:03 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt06.sqm
[2009/01/13 16:59:03 | 00,000,232 | -H-- | M] () -- C:\sqmdata06.sqm
[2009/01/13 14:52:06 | 00,781,851 | ---- | M] () -- C:\Documents and Settings\L\Desktop\RSIT.exe
[2009/01/13 12:55:20 | 01,889,864 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\L\Desktop\mbam-rules.exe
[2009/01/13 12:52:30 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt05.sqm
[2009/01/13 12:52:30 | 00,000,232 | -H-- | M] () -- C:\sqmdata05.sqm
[2009/01/13 10:54:22 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt04.sqm
[2009/01/13 10:54:22 | 00,000,232 | -H-- | M] () -- C:\sqmdata04.sqm
[2009/01/13 09:18:01 | 00,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/01/13 09:15:53 | 02,697,168 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\L\Desktop\mbam-setup.exe
[2009/01/12 10:15:21 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt03.sqm
[2009/01/12 10:15:21 | 00,000,232 | -H-- | M] () -- C:\sqmdata03.sqm
[2009/01/11 21:52:55 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt02.sqm
[2009/01/11 21:52:55 | 00,000,232 | -H-- | M] () -- C:\sqmdata02.sqm
[2009/01/11 17:25:25 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt01.sqm
[2009/01/11 17:25:25 | 00,000,232 | -H-- | M] () -- C:\sqmdata01.sqm
[2009/01/11 16:28:43 | 00,021,547 | ---- | M] () -- C:\Documents and Settings\L\Desktop\dead-links.jpg
[2009/01/10 11:36:40 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/01/09 17:15:00 | 00,000,382 | ---- | M] () -- C:\WINDOWS\tasks\1-Click Maintenance.job
[2009/01/07 19:10:19 | 00,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
[2009/01/07 19:10:19 | 00,001,409 | ---- | M] () -- C:\WINDOWS\QTFont.for
[2009/01/05 21:26:57 | 00,291,104 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2009/01/04 18:38:22 | 00,038,496 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/01/04 18:38:18 | 00,015,504 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/01/03 13:13:47 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt00.sqm
[2009/01/03 13:13:47 | 00,000,232 | -H-- | M] () -- C:\sqmdata00.sqm
[2008/12/24 23:16:54 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt19.sqm
[2008/12/24 23:16:54 | 00,000,232 | -H-- | M] () -- C:\sqmdata19.sqm
[2008/12/23 18:48:22 | 00,000,232 | -H-- | M] () -- C:\sqmdata18.sqm
[2008/12/23 18:48:21 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt18.sqm
[2008/12/20 13:50:40 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt17.sqm
[2008/12/20 13:50:40 | 00,000,232 | -H-- | M] () -- C:\sqmdata17.sqm
[2008/12/20 13:42:21 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt16.sqm
[2008/12/20 13:42:21 | 00,000,232 | -H-- | M] () -- C:\sqmdata16.sqm
[2008/12/20 13:39:24 | 00,000,232 | -H-- | M] () -- C:\sqmdata15.sqm
[2008/12/20 13:39:23 | 00,000,244 | -H-- | M] () -- C:\sqmnoopt15.sqm
< End of report >
OTViewIt Extras logfile created on: 1/15/2009 6:50:38 PM - Run
OTViewIt by OldTimer - Version 1.0.21.0 Folder = C:\Documents and Settings\L\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.22 Gb Total Physical Memory | 0.85 Gb Available Physical Memory | 69.64% Memory free
1.41 Gb Paging File | 1.08 Gb Available in Paging File | 77.02% Paging File free
Paging file location(s): C:\pagefile.sys 336 672;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.78 Gb Total Space | 8.47 Gb Free Space | 7.58% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 232.88 Gb Total Space | 7.66 Gb Free Space | 3.29% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: L-3746562C4F964
Current User Name: L
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days
"Use My Stylesheet"=
"User Stylesheet"=
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled"=1
"AntiVirusDisableNotify"=1
"FirewallDisableNotify"=0
"UpdatesDisableNotify"=1
"AntiVirusOverride"=0
"FirewallOverride"=0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring"=1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring"=1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall"=0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== (O18) Protocol Handlers ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
ipp: [HKLM - No CLSID value]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2002/05/24 14:22:16 | 00,532,480 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL ipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - Microsoft OLE DB Moniker Binder for Internet Publishing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2007/01/19 11:53:24 | 00,063,344 | ---- | M] (Microsoft Corporation) C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (livecall:{828030A1-22C1-4009-854F-8E305202313F} (HKLM) [Reg Error: Value does not exist or could not be read.])
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
msdaipp: [HKLM - No CLSID value]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2002/05/24 14:22:16 | 00,532,480 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - Microsoft OLE DB Moniker Binder for Internet Publishing]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2002/05/24 14:22:16 | 00,532,480 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\oledb:{E1D2BF40-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAIPP.BINDER]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2007/01/19 11:53:24 | 00,063,344 | ---- | M] (Microsoft Corporation) C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (msnim:{828030A1-22C1-4009-854F-8E305202313F} (HKLM) [Reg Error: Value does not exist or could not be read.])
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00000409-78E1-11D2-B60F-006097C998E7}"=Microsoft Office 2000 Premium
"{1485ABFA-12D7-4107-9148-54EE30CDBA67}"=Samsung USB Driver (MCCI 4.16)
"{224F7A6E-1D66-46B6-888A-D115E5AC20F6}"=MPIO Manager 2
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}"=Java(TM) 6 Update 11
"{2E0C1913-886B-4C5C-8DAF-D1E649CE5FCC}"=Creative MediaSource
"{31228E31-2BFF-11D2-8866-00805F0D9D40}"=QPST
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}"=WebFldrs XP
"{3EBD3749-304E-4A4C-9575-C00E5F015217}"=Apple Mobile Device Support
"{571700F0-DB9D-4B3A-B03D-35A14BB5939F}"=Windows Live Messenger
"{58BAA8D0-404E-4585-9FD3-ED1BB72AC2EE}"=Adobe Flash Player 9 ActiveX
"{75B307FF-E529-4D62-B184-3DF41665B1AF}"=ATI Multimedia Center
"{7B63B2922B174135AFC0E1377DD81EC2}"=DivX
"{7FF9CD9C-6E0C-4462-9670-F424DCB32DAF}"=iTunes
"{868D7896-99D4-4513-BC62-2B3AD3E24926}"=TuneUp Utilities 2006
"{8ADFC4160D694100B5B8A22DE9DCABD9}"=DivX Player
"{95A890AA-B3B1-44B6-9C18-A8F7AB3EE7FC}"=QuickTime
"{99D34763-7E45-4FE5-8424-28DBC3A5F0BF}"=GUIDE PLUS+(TM) for Windows® System
"{AC76BA86-7AD7-1033-7B44-A70500000002}"=Adobe Reader 7.0.5
"{AC76BA86-7AD7-5760-0000-705000000001}"=Adobe Reader Japanese Fonts
"{B13A7C41581B411290FBC0395694E2A9}"=DivX Converter
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1"=Spybot - Search & Destroy
"{B7050CBDB2504B34BC2A9CA0A692CC29}"=DivX Web Player
"{B74F042E-E1B9-4A5B-8D46-387BB172F0A4}"=Apple Software Update
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}"=SUPERAntiSpyware Free Edition
"{DC3065BF-95B4-42C5-B47D-0B713CDA75D0}"=Creative Zen Vision M
"{FA61D601-A0FC-48BD-AE7A-54946BCD7FB6}_is1"=BitPim 0.7.22
"{FC98FBE9-E931-494C-8717-497185371033}"=Nero 7
"Ad-Aware SE Personal"=Ad-Aware SE Personal
"Adobe Flash Player Plugin"=Adobe Flash Player Plugin
"Adobe Photoshop 7.0"=Adobe Photoshop 7.0
"Adobe Shockwave Player"=Adobe Shockwave Player
"Audacity_is1"=Audacity 1.2.6
"Creative Removable Disk Manager"=Creative Removable Disk Manager
"ffdshow_is1"=ffdshow [rev 1099] [2007-04-14]
"HijackThis"=HijackThis 2.0.2
"InstallShield_{1485ABFA-12D7-4107-9148-54EE30CDBA67}"=Samsung USB Driver (MCCI 4.16)
"Kaspersky Online Scanner"=Kaspersky Online Scanner
"KLiteCodecPack_is1"=K-Lite Codec Pack 2.46 Full
"Malwarebytes' Anti-Malware_is1"=Malwarebytes' Anti-Malware
"Mozilla Firefox (2.0.0.16)"=Mozilla Firefox (2.0.0.16)
"NeoAudio"=NeoAudio extraction audio
"RealPlayer 6.0"=RealPlayer
"ShockwaveFlash"=Adobe Flash Player 9 ActiveX
"SiS 650"=SiS 650
"SiS7012"=SiS Audio Driver
"SiSLan"=SiS 900 PCI Fast Ethernet Adapter Driver
"Spybot - Search & Destroy_is1"=Spybot - Search & Destroy 1.5.2.20
"SpywareBlaster_is1"=SpywareBlaster 4.1
"SUPER ©"=SUPER © Version 2008.bld.25 (Feb 5, 2008)
"SysInfo"=Creative System Information
"USBCOMM&10AB&10C5"=USB Data Cable
"VobSub"=VobSub v2.23 (Remove Only)
"Winamp"=Winamp
"WinAVIVideoConverter_is1"=WinAVIVideoConverter
"Windows Media Format Runtime"=Windows Media Format Runtime
"WinRAR archiver"=WinRAR archiver
"WinZip"=WinZip
"XPayMPI"=XPayMPI 2.0.1.2
"Yahoo! Photos Drag-Drop Uploader 1v7"=Yahoo! Photos Easy Upload Tool 1v7
"ZoneAlarm Security Suite"=ZoneAlarm Security Suite
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 1/3/2009 6:44:54 PM | Computer Name = L-3746562C4F964 | Source = Application Hang | ID = 1002
Description = Hanging application BitComet.exe, version 0.57.3.5, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 1/3/2009 8:06:10 PM | Computer Name = L-3746562C4F964 | Source = Application Hang | ID = 1002
Description = Hanging application BitComet.exe, version 0.57.3.5, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 1/3/2009 8:07:30 PM | Computer Name = L-3746562C4F964 | Source = Application Hang | ID = 1002
Description = Hanging application BitComet.exe, version 0.57.3.5, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 1/12/2009 4:40:50 PM | Computer Name = L-3746562C4F964 | Source = Application Hang | ID = 1002
Description = Hanging application BitComet.exe, version 0.57.3.5, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 1/12/2009 4:43:47 PM | Computer Name = L-3746562C4F964 | Source = Application Hang | ID = 1002
Description = Hanging application BitComet.exe, version 0.57.3.5, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 1/12/2009 4:43:53 PM | Computer Name = L-3746562C4F964 | Source = Application Hang | ID = 1002
Description = Hanging application BitComet.exe, version 0.57.3.5, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 1/12/2009 4:50:26 PM | Computer Name = L-3746562C4F964 | Source = Application Hang | ID = 1002
Description = Hanging application BitComet.exe, version 0.57.3.5, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 1/12/2009 5:37:58 PM | Computer Name = L-3746562C4F964 | Source = Application Hang | ID = 1002
Description = Hanging application BitComet.exe, version 0.57.3.5, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 1/12/2009 9:02:19 PM | Computer Name = L-3746562C4F964 | Source = Application Hang | ID = 1002
Description = Hanging application BitComet.exe, version 0.57.3.5, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 1/14/2009 7:39:51 PM | Computer Name = L-3746562C4F964 | Source = Application Error | ID = 1000
Description = Faulting application zlclient.exe, version 7.0.302.0, faulting module
, version 0.0.0.0, fault address 0x00000000.
[ System Events ]
Error - 1/13/2009 3:54:48 PM | Computer Name = L-3746562C4F964 | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 30 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)
Error - 1/13/2009 3:54:48 PM | Computer Name = L-3746562C4F964 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 29 minutes. NtpClient has no source of accurate
time.
Error - 1/13/2009 6:35:54 PM | Computer Name = L-3746562C4F964 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
kl1 SABKUTIL
Error - 1/14/2009 8:31:58 AM | Computer Name = L-3746562C4F964 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
kl1 SABKUTIL
Error - 1/14/2009 6:20:47 PM | Computer Name = L-3746562C4F964 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
kl1 SABKUTIL
Error - 1/14/2009 8:26:50 PM | Computer Name = L-3746562C4F964 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
kl1 SABKUTIL
Error - 1/14/2009 8:49:23 PM | Computer Name = L-3746562C4F964 | Source = BROWSER | ID = 8032
Description = The browser service has failed to retrieve the backup list too many
times on transport \Device\NetBT_Tcpip_{A2BE0C7D-2E77-498A-B8C3-782620438865}. The
backup browser is stopping.
Error - 1/15/2009 9:15:10 AM | Computer Name = L-3746562C4F964 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
kl1 SABKUTIL
Error - 1/15/2009 6:04:59 PM | Computer Name = L-3746562C4F964 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
kl1 SABKUTIL
Error - 1/15/2009 6:47:34 PM | Computer Name = L-3746562C4F964 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
SABKUTIL
< End of report >