OTViewIt logfile created on: 10/18/2008 2:54:31 AM - Run 3
OTViewIt by OldTimer - Version 1.0.9.4 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
990.42 Mb Total Physical Memory | 503.58 Mb Available Physical Memory | 50.84% Memory free
1.21 Gb Paging File | 0.89 Gb Available in Paging File | 73.60% Paging File free
Paging file location(s): C:\pagefile.sys 336 672;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.88 Gb Total Space | 37.72 Gb Free Space | 67.49% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: MAIN
Current User Name: Owner
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days
========== Processes ========== [2008/07/09 09:05:18 | 00,075,304 | ---- | M] (Zone Labs, LLC) -- C:\WINDOWS\system32\ZoneLabs\vsmon.exe
[2008/10/01 13:06:14 | 00,116,040 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
[2007/10/24 17:35:37 | 00,418,816 | ---- | M] (GRISOFT, s.r.o.) -- C:\Program Files\Grisoft\AVG Free\avgamsvr.exe
[2007/01/25 21:20:40 | 00,049,664 | ---- | M] (GRISOFT, s.r.o.) -- C:\Program Files\Grisoft\AVG Free\avgupsvc.exe
[2007/12/22 20:25:21 | 00,406,528 | ---- | M] (GRISOFT, s.r.o.) -- C:\Program Files\Grisoft\AVG Free\avgemc.exe
[2008/04/13 16:12:14 | 00,005,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\cisvc.exe
[2007/02/20 17:35:02 | 00,073,728 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe
[2005/04/27 14:59:24 | 00,241,725 | ---- | M] (Microsoft Corporation) -- C:\Program Files\UPHClean\uphclean.exe
[2008/10/16 10:01:15 | 00,590,848 | ---- | M] (GRISOFT, s.r.o.) -- C:\Program Files\Grisoft\AVG Free\avgcc.exe
[2007/09/15 02:27:20 | 01,015,808 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
[2008/07/09 09:05:20 | 00,919,016 | ---- | M] (Zone Labs, LLC) -- C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
[2008/10/01 18:57:12 | 00,289,576 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunesHelper.exe
[2004/09/16 09:52:42 | 01,605,632 | ---- | M] (Webshots.com) -- C:\Program Files\Webshots\webshots.scr
[2008/10/01 18:57:00 | 00,536,872 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe
[2008/10/09 09:30:58 | 00,307,712 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
[2004/08/04 04:00:00 | 00,008,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\cidaemon.exe
[2008/04/13 16:12:29 | 00,069,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\notepad.exe
[2008/10/05 07:19:24 | 00,419,328 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTViewIt.exe
========== (O23) Win32 Services ========== [2008/10/01 13:06:14 | 00,116,040 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running])
File not found -- C:\Program Files\Aluria Software\ASE\ASEServ.exe -- (ASEService [Disabled | Stopped])
[2007/10/24 02:47:22 | 00,033,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
[2007/10/18 12:08:42 | 00,109,080 | ---- | M] (PCTEL) -- C:\Program Files\AT&T\Communication Manager\RcAppSvc.exe -- (ATTRcAppSvc [On_Demand | Stopped])
[2007/10/24 17:35:37 | 00,418,816 | ---- | M] (GRISOFT, s.r.o.) -- C:\Program Files\Grisoft\AVG Free\avgamsvr.exe -- (Avg7Alrt [Auto | Running])
[2007/01/25 21:20:40 | 00,049,664 | ---- | M] (GRISOFT, s.r.o.) -- C:\Program Files\Grisoft\AVG Free\avgupsvc.exe -- (Avg7UpdSvc [Auto | Running])
[2007/12/22 20:25:21 | 00,406,528 | ---- | M] (GRISOFT, s.r.o.) -- C:\Program Files\Grisoft\AVG Free\avgemc.exe -- (AVGEMS [Auto | Running])
[2007/10/18 12:08:32 | 00,118,784 | ---- | M] (Bytemobile, Inc.) -- C:\WINDOWS\system32\bmwebcfg.exe -- (bmwebcfg [Disabled | Stopped])
[2008/08/29 10:18:44 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service [Disabled | Stopped])
[2008/04/13 16:12:14 | 00,005,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\cisvc.exe -- (CiSvc [Auto | Running])
[2007/10/24 02:47:40 | 00,070,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
[2007/10/09 13:58:12 | 00,036,864 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
[2004/07/27 16:25:24 | 00,098,304 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files\HPQ\shared\hpqwmi.exe -- (hpqwmi [On_Demand | Stopped])
[2005/04/04 01:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
[2007/10/11 10:55:10 | 00,864,256 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
File not found -- C:\DOCUME~1\Owner\Desktop\InCD\InCDsrv.exe -- (InCDsrv [Disabled | Stopped])
[2008/10/01 18:57:00 | 00,536,872 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Running])
[2007/10/11 10:55:14 | 00,122,880 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
[2007/02/20 17:35:02 | 00,073,728 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12 [Auto | Running])
[2005/04/05 11:17:22 | 00,206,552 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe -- (SNDSrvc [Disabled | Stopped])
[2005/04/27 14:59:24 | 00,241,725 | ---- | M] (Microsoft Corporation) -- C:\Program Files\UPHClean\uphclean.exe -- (UPHClean [Auto | Running])
[2008/07/09 09:05:18 | 00,075,304 | ---- | M] (Zone Labs, LLC) -- C:\WINDOWS\system32\ZoneLabs\vsmon.exe -- (vsmon [Auto | Running])
[2006/10/18 20:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])
========== Driver Services ========== [2007/10/24 17:35:30 | 00,821,856 | ---- | M] (GRISOFT, s.r.o.) -- C:\WINDOWS\system32\drivers\avg7core.sys -- (Avg7Core [System | Running])
[2007/01/25 21:20:44 | 00,004,224 | ---- | M] (GRISOFT, s.r.o.) -- C:\WINDOWS\system32\drivers\avg7rsw.sys -- (Avg7RsW [System | Running])
[2007/02/27 19:11:46 | 00,027,776 | ---- | M] (GRISOFT, s.r.o.) -- C:\WINDOWS\system32\drivers\avg7rsxp.sys -- (Avg7RsXP [System | Running])
[2007/12/22 20:25:22 | 00,010,760 | ---- | M] (GRISOFT, s.r.o.) -- C:\WINDOWS\system32\drivers\avgclean.sys -- (AvgClean [System | Running])
[2007/01/25 21:21:05 | 00,004,960 | ---- | M] (GRISOFT, s.r.o.) -- C:\WINDOWS\system32\drivers\avgtdi.sys -- (AvgTdi [Auto | Running])
[2008/09/11 02:18:18 | 01,386,624 | ---- | M] (Broadcom Corporation) -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX [On_Demand | Running])
[2004/11/23 14:57:12 | 00,293,120 | ---- | M] (Conexant Systems Inc.) -- C:\WINDOWS\system32\drivers\camcaud.sys -- (CAMCAUD [On_Demand | Running])
[2004/11/23 14:57:56 | 00,280,192 | ---- | M] (Conexant Systems Inc.) -- C:\WINDOWS\system32\drivers\camchal.sys -- (CAMCHALA [On_Demand | Running])
[2004/04/14 09:36:50 | 00,007,432 | ---- | M] (Hewlett-Packard Company) -- C:\WINDOWS\system32\drivers\eabfiltr.sys -- (eabfiltr [System | Running])
[2003/06/06 13:46:16 | 00,005,220 | ---- | M] (Hewlett-Packard Company) -- C:\WINDOWS\system32\drivers\EabUsb.sys -- (eabusb [On_Demand | Stopped])
[2008/04/17 13:12:54 | 00,015,464 | ---- | M] (GEAR Software Inc.) -- C:\WINDOWS\system32\drivers\GEARAspiWDM.sys -- (GEARAspiWDM [On_Demand | Running])
[2004/12/14 08:07:44 | 00,051,120 | R--- | M] (HP) -- C:\WINDOWS\system32\drivers\HPZid412.sys -- (HPZid412 [On_Demand | Stopped])
[2004/12/14 08:07:44 | 00,016,496 | R--- | M] (HP) -- C:\WINDOWS\system32\drivers\HPZipr12.sys -- (HPZipr12 [On_Demand | Stopped])
[2004/12/14 08:07:44 | 00,021,744 | R--- | M] (HP) -- C:\WINDOWS\system32\drivers\HPZius12.sys -- (HPZius12 [On_Demand | Stopped])
[2004/12/15 15:18:34 | 00,207,232 | ---- | M] (Conexant Systems, Inc.) -- C:\WINDOWS\system32\drivers\HSFHWICH.sys -- (HSFHWICH [On_Demand | Running])
[2004/12/15 15:18:26 | 01,038,208 | ---- | M] (Conexant Systems, Inc.) -- C:\WINDOWS\system32\drivers\HSF_DP.sys -- (HSF_DP [On_Demand | Running])
[2003/11/07 02:45:46 | 00,094,075 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\drivers\ialmnt5.sys -- (ialm [On_Demand | Running])
[2006/03/23 17:15:58 | 00,102,016 | ---- | M] (Nero AG) -- C:\WINDOWS\System32\drivers\InCDfs.sys -- (InCDfs [Disabled | Running])
[2006/03/23 17:15:56 | 00,029,440 | ---- | M] (Nero AG) -- C:\WINDOWS\system32\drivers\InCDpass.sys -- (InCDPass [System | Running])
[2006/03/23 17:15:56 | 00,033,536 | ---- | M] (Nero AG) -- C:\WINDOWS\System32\drivers\InCDrm.sys -- (incdrm [System | Running])
[2008/04/13 10:31:32 | 00,036,352 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\intelppm.sys -- (intelppm [System | Running])
[2007/07/19 15:10:28 | 00,127,768 | ---- | M] (Kaspersky Lab) -- C:\WINDOWS\system32\drivers\klif.sys -- (KLIF [System | Running])
[2006/09/01 20:03:01 | 00,008,413 | ---- | M] (RealNetworks, Inc.) -- C:\WINDOWS\System32\drivers\mcstrm.sys -- (MCSTRM [Auto | Running])
[2004/03/17 11:04:14 | 00,013,059 | ---- | M] (Conexant) -- C:\WINDOWS\system32\drivers\mdmxsdk.sys -- (mdmxsdk [Auto | Running])
[2001/08/17 14:57:38 | 00,016,128 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\MODEMCSA.sys -- (MODEMCSA [On_Demand | Stopped])
[2007/10/08 14:04:20 | 00,450,560 | ---- | M] (ZyDAS Technology Corporation) -- C:\WINDOWS\system32\drivers\WlanUZXP.SYS -- (NB762_XP [On_Demand | Stopped])
[2004/03/23 18:12:34 | 00,017,280 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) -- C:\WINDOWS\system32\nsndis5.sys -- (NSNDIS5 [On_Demand | Stopped])
[2006/09/01 18:34:05 | 00,016,694 | ---- | M] (PalmSource, Inc.) -- C:\WINDOWS\system32\drivers\PalmUSBD.sys -- (PalmUSBD [On_Demand | Stopped])
[2001/08/17 14:51:52 | 00,003,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\pciide.sys -- (PCIIde [Boot | Running])
[2007/10/18 12:08:32 | 00,032,160 | ---- | M] (PCTEL Inc.) -- C:\WINDOWS\system32\PCTINDIS5.sys -- (PCTINDIS5 [On_Demand | Stopped])
[2004/08/04 04:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink [On_Demand | Running])
[2005/12/04 21:12:26 | 00,020,640 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\system32\drivers\pxhelp20.sys -- (PxHelp20 [Boot | Running])
[2007/10/18 12:08:16 | 00,026,368 | R--- | M] (Research in Motion Ltd) -- C:\WINDOWS\system32\drivers\RimSerial.sys -- (RimVSerPort [On_Demand | Running])
[2004/08/04 04:00:00 | 00,005,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\rootmdm.sys -- (ROOTMODEM [On_Demand | Running])
[2004/04/27 07:03:00 | 00,069,504 | ---- | M] (Realtek Semiconductor Corporation ) -- C:\WINDOWS\system32\drivers\Rtlnic51.sys -- (RTL8023 [On_Demand | Stopped])
[2008/02/25 12:54:56 | 00,105,088 | ---- | M] (Realtek Semiconductor Corporation ) -- C:\WINDOWS\system32\drivers\Rtnicxp.sys -- (RTL8023xp [On_Demand | Stopped])
[2004/08/03 14:31:34 | 00,020,992 | ---- | M] (Realtek Semiconductor Corporation) -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139 [On_Demand | Stopped])
[2007/11/13 02:25:53 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv [On_Demand | Stopped])
[2008/02/27 03:10:44 | 00,051,176 | ---- | M] (Zone Labs, LLC) -- C:\WINDOWS\system32\ZoneLabs\srescan.sys -- (srescan [Boot | Running])
[2007/10/18 12:08:48 | 00,025,736 | R--- | M] () -- C:\WINDOWS\system32\drivers\swmsflt.sys -- (swmsflt [On_Demand | Running])
[2005/04/05 11:16:52 | 00,011,512 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\symdns.sys -- (SYMDNS [On_Demand | Stopped])
File not found -- C:\Program Files\Symantec\SYMEVENT.SYS -- (SymEvent [On_Demand | Stopped])
[2005/04/05 11:16:54 | 00,173,208 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\symfw.sys -- (SYMFW [On_Demand | Stopped])
[2005/04/05 11:16:58 | 00,036,984 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\symids.sys -- (SYMIDS [On_Demand | Stopped])
[2005/04/05 11:16:56 | 00,047,192 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\symndis.sys -- (SYMNDIS [On_Demand | Stopped])
[2005/04/05 11:17:00 | 00,017,976 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\symredrv.sys -- (SYMREDRV [On_Demand | Stopped])
[2005/04/05 11:17:02 | 00,267,192 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\symtdi.sys -- (SYMTDI [System | Running])
[2007/09/15 02:09:44 | 00,213,696 | ---- | M] (Synaptics, Inc.) -- C:\WINDOWS\system32\drivers\SynTP.sys -- (SynTP [On_Demand | Running])
[2007/10/18 12:08:30 | 00,018,816 | ---- | M] (Bytemobile, Inc.) -- C:\WINDOWS\System32\drivers\tcpipBM.sys -- (tcpipBM [System | Running])
[2008/10/01 13:01:28 | 00,032,000 | ---- | M] (Apple, Inc.) -- C:\WINDOWS\system32\drivers\usbaapl.sys -- (USBAAPL [On_Demand | Stopped])
[2008/04/13 10:45:12 | 00,060,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio [On_Demand | Stopped])
[2008/04/13 10:45:35 | 00,030,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\usbehci.sys -- (usbehci [On_Demand | Running])
[2008/04/13 10:45:35 | 00,017,152 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\usbohci.sys -- (usbohci [On_Demand | Stopped])
[2008/04/13 10:45:36 | 00,026,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\usbser.sys -- (usbser [On_Demand | Stopped])
[2008/04/13 10:56:49 | 00,012,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\usb8023x.sys -- (usb_rndisx [On_Demand | Stopped])
[2008/07/09 09:05:22 | 00,394,952 | ---- | M] (Zone Labs, LLC) -- C:\WINDOWS\system32\vsdatant.sys -- (vsdatant [System | Running])
[2004/12/15 15:18:28 | 00,703,232 | ---- | M] (Conexant Systems, Inc.) -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf [On_Demand | Running])
[2008/04/13 10:36:38 | 00,008,832 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\wmiacpi.sys -- (WmiAcpi [System | Running])
[2004/08/04 04:00:00 | 00,012,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\ws2ifsl.sys -- (WS2IFSL [System | Running])
[2006/09/28 18:55:50 | 00,077,568 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\WudfPf.sys -- (WudfPf [On_Demand | Stopped])
[2006/09/28 19:00:34 | 00,082,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\WudfRd.sys -- (WudfRd [On_Demand | Stopped])
[2006/08/24 14:44:14 | 00,477,696 | ---- | M] (ZyDAS Technology Corporation) -- C:\WINDOWS\system32\drivers\ZD1211BU.sys -- (ZD1211BU(ZyDAS) [On_Demand | Stopped])
File not found -- C:\WINDOWS\system32\ZDCndis5.SYS -- (ZDCNDIS5 [On_Demand | Stopped])
[2003/11/07 02:46:52 | 00,120,798 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\drivers\ialmsbw.sys -- ({6080A529-897E-4629-A488-ABA0C29B635E} [On_Demand | Running])
[2003/11/07 02:46:44 | 00,098,938 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\drivers\ialmkchw.sys -- ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91} [On_Demand | Running])
========== (R ) Internet Explorer ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=http://go.microsoft.com/fwlink/?LinkId=69157
"Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896
"Default_Secondary_Page_URL"=
"Extensions Off Page"=about:NoAdd-ons
"Local Page"=%SystemRoot%\system32\blank.htm
"Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896
"Security Risk Page"=about:SecurityRisk
"Start Page"=http://go.microsoft.com/fwlink/?LinkId=69157
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=www.gci.net
"Default_Search_URL"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Local Page"=C:\WINDOWS\system32\blank.htm
"Page_Transitions"=
"Search Page"=http://www.msn.com/access/allinone.asp
"Start Page"=http://www.coasttocoastam.com/
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Search]
"SearchAssistant"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURL]
""=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
"ProxyOverride" = *.local
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main]
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main]
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main]
[HKEY_USERS\S-1-5-21-1390067357-1383384898-1060284298-1003\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=www.gci.net
"Default_Search_URL"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Local Page"=C:\WINDOWS\system32\blank.htm
"Page_Transitions"=
"Search Page"=http://www.msn.com/access/allinone.asp
"Start Page"=http://www.coasttocoastam.com/
[HKEY_USERS\S-1-5-21-1390067357-1383384898-1060284298-1003\SOFTWARE\Microsoft\Internet Explorer\Search]
"SearchAssistant"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
[HKEY_USERS\S-1-5-21-1390067357-1383384898-1060284298-1003\Software\Microsoft\Internet Explorer\SearchURL]
""=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
[HKEY_USERS\S-1-5-21-1390067357-1383384898-1060284298-1003\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-1390067357-1383384898-1060284298-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
"ProxyOverride" = *.local
========== (O1) Hosts File ========== HOSTS File = (267187 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
First 25 entries...
127.0.0.1 localhost
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 100sexlinks.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 www.10sek.com
127.0.0.1 10sek.com
127.0.0.1 www.123topsearch.com
127.0.0.1 123topsearch.com
127.0.0.1 www.132.com
127.0.0.1 132.com
127.0.0.1 136136.net
127.0.0.1 www.136136.net
127.0.0.1 www.163ns.com
127.0.0.1 163ns.com
9253 more lines...
========== (O2) BHO's ========== [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (HKLM) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
{3049C3E9-B461-4BC5-8870-4C09146192CA} (HKLM) -- C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
{53707962-6F74-2D53-2644-206D7942484F} (HKLM) -- C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
{5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (HKLM) -- C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} (HKLM) -- C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL (ZoneAlarm)
}A3EAA9BB06DF-DB68-E964-D8B2-F47DB7E4{ (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
========== (O3) Toolbars ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA}" (HKLM) -- C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL (ZoneAlarm)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"}A3EAA9BB06DF-DB68-E964-D8B2-F47DB7E4{" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}" (HKLM) -- C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL (ZoneAlarm)
[HKEY_USERS\S-1-5-21-1390067357-1383384898-1060284298-1003\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
[HKEY_USERS\S-1-5-21-1390067357-1383384898-1060284298-1003\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
[HKEY_USERS\S-1-5-21-1390067357-1383384898-1060284298-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
[HKEY_USERS\S-1-5-21-1390067357-1383384898-1060284298-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
[HKEY_USERS\S-1-5-21-1390067357-1383384898-1060284298-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
[HKEY_USERS\S-1-5-21-1390067357-1383384898-1060284298-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}" (HKLM) -- C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL (ZoneAlarm)
========== (O4) Run Keys ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AppleSyncNotifier"=C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
"AVG7_CC"=C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP (GRISOFT, s.r.o.)
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
"SynTPLpr"=C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" (Zone Labs, LLC)
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"=C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (GRISOFT, s.r.o.)
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"=C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (GRISOFT, s.r.o.)
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"=C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (GRISOFT, s.r.o.)
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"=C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (GRISOFT, s.r.o.)
========== (O4) Startup Folders ========== [2003/09/30 15:30:04 | 00,057,344 | ---- | M] (Hewlett-Packard) -- C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\AutoTBar.exe
[2004/09/16 09:46:18 | 00,045,056 | ---- | M] () -- C:\Documents and Settings\Bekky\Start Menu\Programs\Startup\Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
[2003/09/30 15:30:04 | 00,057,344 | ---- | M] (Hewlett-Packard) -- C:\Documents and Settings\Default User\Start Menu\Programs\Startup\AutoTBar.exe
[2004/09/16 09:46:18 | 00,045,056 | ---- | M] () -- C:\Documents and Settings\Owner\Start Menu\Programs\Startup\Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
========== (O6 & O7) Current Version Policies ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
[HKEY_USERS\S-1-5-21-1390067357-1383384898-1060284298-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
========== (O8) IE Context Menu Extensions ========== [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: C:\Program Files\Microsoft Office\Office10\EXCEL.EXE [2008/08/19 09:15:34 | 09,364,480 | R--- | M] (Microsoft Corporation)
[HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: C:\Program Files\Microsoft Office\Office10\EXCEL.EXE [2008/08/19 09:15:34 | 09,364,480 | R--- | M] (Microsoft Corporation)
[HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: C:\Program Files\Microsoft Office\Office10\EXCEL.EXE [2008/08/19 09:15:34 | 09,364,480 | R--- | M] (Microsoft Corporation)
[HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: Reg Error: Key does not exist or could not be opened. File not found
[HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: Reg Error: Key does not exist or could not be opened. File not found
[HKEY_USERS\S-1-5-21-1390067357-1383384898-1060284298-1003\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: C:\Program Files\Microsoft Office\Office10\EXCEL.EXE [2008/08/19 09:15:34 | 09,364,480 | R--- | M] (Microsoft Corporation)
========== (O9) IE Extensions ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}: Menu: Sun Java Console -- %ProgramFiles%\Java\jre1.6.0_07\bin\npjpi160_07.dll [2008/06/10 04:27:02 | 00,132,496 | ---- | M] (Sun Microsystems, Inc.)
{2EAF5BB1-070F-11D3-9307-00C04FAE2D4F}: Button: Create Mobile Favorite -- %ProgramFiles%\Microsoft ActiveSync\INetRepl.dll [2006/11/13 14:39:34 | 00,158,504 | ---- | M] (Microsoft Corporation)
{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F}: Menu: Create Mobile Favorite... -- %ProgramFiles%\Microsoft ActiveSync\INetRepl.dll [2006/11/13 14:39:34 | 00,158,504 | ---- | M] (Microsoft Corporation)
{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}: Menu: Spybot - Search & Destroy Configuration -- %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [2008/09/15 14:25:44 | 01,562,960 | RHS- | M] (Safer Networking Limited)
{e2e2dd38-d088-4134-82b7-f2ba38496583}: Menu: @xpsp3res.dll,-20001 -- %SystemRoot%\network diagnostic\xpnetdiag.exe [2008/04/13 10:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Button: Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2008/04/13 16:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Menu: Windows Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2008/04/13 16:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_07\bin\npjpi160_07.dll [Sun Java Console] -> [2008/06/10 04:27:02 | 00,132,496 | ---- | M] (Sun Microsystems, Inc.)
CmdMapping\\{2D663D1A-8670-49D9-A1A5-4C56B4E14E84} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 16:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_07\bin\npjpi160_07.dll [Sun Java Console] -> [2008/06/10 04:27:02 | 00,132,496 | ---- | M] (Sun Microsystems, Inc.)
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 16:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_07\bin\npjpi160_07.dll [Sun Java Console] -> [2008/06/10 04:27:02 | 00,132,496 | ---- | M] (Sun Microsystems, Inc.)
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 16:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-1390067357-1383384898-1060284298-1003\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_07\bin\npjpi160_07.dll [Sun Java Console] -> [2008/06/10 04:27:02 | 00,132,496 | ---- | M] (Sun Microsystems, Inc.)
CmdMapping\\{2D663D1A-8670-49D9-A1A5-4C56B4E14E84} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 16:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)
========== (O12) Internet Explorer Plugins ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\]
PluginsPage: "" =
http://activex.microsoft.com/controls/find...=%s&mime=%sPluginsPageFriendlyName: "" = Microsoft ActiveX Gallery
========== (O13) Default Prefixes ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
""=http://
"@"=http://
========== (O15) Trusted Sites ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
45 domain(s) and sub-domain(s) not assigned to a zone.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
microsoft.com\www.update: http in My Computer
1259 domain(s) and sub-domain(s) not assigned to a zone.
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
47 domain(s) and sub-domain(s) not assigned to a zone.
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
47 domain(s) and sub-domain(s) not assigned to a zone.
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
42 domain(s) and sub-domain(s) not assigned to a zone.
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
42 domain(s) and sub-domain(s) not assigned to a zone.
[HKEY_USERS\S-1-5-21-1390067357-1383384898-1060284298-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
microsoft.com\www.update: http in My Computer
1259 domain(s) and sub-domain(s) not assigned to a zone.
========== (O16) DPF ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\]
{05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8}:
http://download.microsoft.com/download/e/7.../OGAControl.cab -- Office Genuine Advantage Validation Tool
{14C1B87C-3342-445F-9B5E-365FF330A3AC}:
http://h50203.www5.hp.com/HPISWeb/Customer...DataManager.CAB -- Hewlett-Packard Online Support Services
{17492023-C23A-453E-A040-C7C580BBF700}:
http://go.microsoft.com/fwlink/?linkid=48835 -- Windows Genuine Advantage Validation Tool
{6B75345B-AA36-438A-BBE6-4078B4C6984D}:
http://h20270.www2.hp.com/ediags/gmn2/inst...ctDetection.cab -- HpProductDetection Class
{8AD9C840-044E-11D1-B3E9-00805F499D93}:
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_07
{A90A5822-F108-45AD-8482-9BC8B12DD539}:
http://www.crucial.com/controls/cpcScanner.cab -- Crucial cpcScan
{A93D84FD-641F-43AE-B963-E6FA84BE7FE7}:
http://www.linksysfix.com/netcheck/67/install/gtdownls.cab -- LinkSys Content Update
{C7DB51B4-BCF7-4923-8874-7F1A0DC92277}:
http://office.microsoft.com/officeupdate/content/opuc4.cab -- Office Update Installation Engine
{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_07
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}:
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_07
{DBA230D1-8467-4e69-987E-5FAE815A3B45}: -- Reg Error: Key does not exist or could not be opened.
========== (O17) DNS Name Servers ========== {3FA5E792-8C83-4756-9514-93E70CDF3891} (Servers: | Description: (ZD1211B)IEEE 802.11 b+g USB Adapter)
{43C1702B-DFB5-47A2-999C-574943A1A4FB} (Servers: | Description: (ZD1211B)IEEE 802.11 b+g USB Adapter)
{9CA103EA-70CC-43D6-AFB7-6DCC26715E71} (Servers: | Description: (ZD1211B)IEEE 802.11 b+g USB Adapter)
{AB9C8C67-FF18-4EC2-93F8-34711EE8656D} (Servers: | Description: Realtek RTL8139/810x Family Fast Ethernet NIC)
{ABB37615-BB89-485E-A397-D09A69C86795} (Servers: | Description: Broadcom 802.11b/g WLAN)
{CC02BD2C-14DE-40A2-9886-54DB1089E350} (Servers: | Description: (ZD1211B)IEEE 802.11 b+g USB Adapter)
{F5C8FC02-AFCE-448C-9C16-93B62C0BFD7E} (Servers: | Description: Windows Mobile-based Device)
========== (O20) Winlogon Notify Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\]
igfxcui: "DllName" = igfxsrvc.dll -- C:\WINDOWS\system32\igfxsrvc.dll (Intel Corporation)
WgaLogon: "DllName" = WgaLogon.dll -- C:\WINDOWS\system32\WgaLogon.dll (Microsoft Corporation)
========== (O21) SSODL Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"WPDShServiceObj"={AAA288BA-9A4C-45B0-95D7-94D524869DB5} (HKLM) -- C:\WINDOWS\system32\WPDShServiceObj.dll (Microsoft Corporation)
========== Safeboot Options ========== "AlternateShell"=cmd.exe
========== CDRom AutoRun Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1
========== Autorun Files on Drives ========== AUTOEXEC.BAK []
[2005/03/12 20:30:24 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAK -- [ NTFS ]
AUTOEXEC.BAT [ | C:\DAZZLE\DAZTSR.EXE /AHQE | ]
[2005/10/01 03:11:44 | 00,000,030 | ---- | M] () -- C:\AUTOEXEC.BAT -- [ NTFS ]
========== MountPoints2 ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{af967710-0062-11dd-8d97-0060b3a0fd36}\Shell]
""=AutoRun
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{af967710-0062-11dd-8d97-0060b3a0fd36}\Shell\AutoRun]
""=Auto&Play
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{af967710-0062-11dd-8d97-0060b3a0fd36}\Shell\AutoRun\command]
""=E:\LaunchU3.exe -- File not found
========== Files/Folders - Created Within 30 Days ========== [9 C:\WINDOWS\System32\*.tmp files]
[2008/10/17 05:48:06 | 00,037,775 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\for jason.jpg
[2008/10/15 20:16:19 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\OLEVIA
[2008/10/15 07:16:43 | 00,110,190 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\photo.jpg
[2008/10/15 07:09:04 | 00,110,190 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\chipmunk.aspx
[2008/10/14 14:12:46 | 01,846,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\win32k.sys
[2008/10/14 14:11:37 | 02,145,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrnlmp.exe
[2008/10/14 14:10:57 | 02,023,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrpamp.exe
[2008/10/11 09:04:12 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\1st timers
[2008/10/11 01:31:28 | 00,000,676 | ---- | C] () -- C:\Documents and Settings\Owner\Start Menu\Programs\Startup\Webshots.lnk
[2008/10/10 05:03:50 | 00,002,618 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Kaspersky scan.html
[2008/10/08 09:52:45 | 00,000,366 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\cc_20081008_095238.reg
[2008/10/08 09:36:26 | 00,000,304 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\cc_20081008_093622.reg
[2008/10/08 09:18:35 | 00,000,304 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\cc_20081008_091833.reg
[2008/10/08 09:18:05 | 00,002,396 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\cc_20081008_091802.reg
[2008/10/08 09:16:27 | 00,204,834 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\cc_20081008_091622.reg
[2008/10/07 17:52:44 | 00,002,137 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2008/10/07 17:48:26 | 00,000,000 | ---D | C] -- C:\Program Files\iPod
[2008/10/07 17:45:23 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2008/10/07 17:45:21 | 00,000,000 | ---D | C] -- C:\Program Files\iTunes
[2008/10/07 16:16:20 | 07,257,632 | -HS- | C] () -- C:\WINDOWS\System32\drivers\fidbox.dat
[2008/10/07 16:16:20 | 00,099,224 | -HS- | C] () -- C:\WINDOWS\System32\drivers\fidbox.idx
[2008/10/07 16:12:38 | 00,000,000 | ---D | C] -- C:\Program Files\ZoneAlarmSB
[2008/10/07 16:09:07 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\MailFrontier
[2008/10/07 16:07:52 | 00,075,248 | ---- | C] (Zone Labs, LLC) -- C:\WINDOWS\zllsputility.exe
[2008/10/07 16:06:31 | 00,127,768 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\klif.sys
[2008/10/07 16:05:34 | 00,796,048 | ---- | C] () -- C:\WINDOWS\System32\libeay32_0.9.6l.dll
[2008/10/07 16:05:33 | 00,071,144 | ---- | C] (Zone Labs, LLC) -- C:\WINDOWS\System32\vsregexp.dll
[2008/10/07 16:05:25 | 00,083,432 | ---- | C] (Zone Labs, LLC) -- C:\WINDOWS\System32\zlcomm.dll
[2008/10/07 16:05:25 | 00,071,144 | ---- | C] (Zone Labs, LLC) -- C:\WINDOWS\System32\zlcommdb.dll
[2008/10/07 16:05:06 | 00,046,568 | ---- | C] (Zone Labs, LLC) -- C:\WINDOWS\System32\vswmi.dll
[2008/10/07 16:04:59 | 01,086,952 | ---- | C] (Python Software Foundation) -- C:\WINDOWS\System32\zpeng24.dll
[2008/10/07 16:04:59 | 00,099,816 | ---- | C] (Zone Labs, LLC) -- C:\WINDOWS\System32\vsxml.dll
[2008/10/07 16:04:55 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\ZoneLabs
[2008/10/07 16:04:54 | 00,275,944 | ---- | C] (Zone Labs, LLC) -- C:\WINDOWS\System32\vspubapi.dll
[2008/10/07 16:04:54 | 00,000,000 | ---D | C] -- C:\Program Files\Zone Labs
[2008/10/07 16:04:53 | 00,103,912 | ---- | C] (Zone Labs, LLC) -- C:\WINDOWS\System32\vsmonapi.dll
[2008/10/07 16:04:49 | 00,394,952 | ---- | C] (Zone Labs, LLC) -- C:\WINDOWS\System32\vsdatant.sys
[2008/10/07 16:04:49 | 00,352,918 | ---- | C] () -- C:\WINDOWS\System32\vsconfig.xml
[2008/10/07 16:01:43 | 00,472,552 | ---- | C] (Zone Labs, LLC) -- C:\WINDOWS\System32\vsutil.dll
[2008/10/07 16:01:43 | 00,157,160 | ---- | C] (Zone Labs, LLC) -- C:\WINDOWS\System32\vsinit.dll
[2008/10/07 16:01:43 | 00,083,432 | ---- | C] (Zone Labs, LLC) -- C:\WINDOWS\System32\vsdata.dll
[2008/10/07 06:26:27 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\pagedefrag
[2008/10/07 05:40:03 | 00,873,398 | ---- | C] () -- C:\WINDOWS\System32\oem164.inf
[2008/10/06 13:37:19 | 00,003,406 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\cc_20081006_133716.reg
[2008/10/06 00:11:39 | 01,665,550 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\data mad.gif
[2008/10/05 07:41:02 | 02,482,695 | ---- | C] (McAfee Inc.) -- C:\Documents and Settings\Owner\Desktop\stinger.exe
[2008/10/05 07:19:09 | 00,419,328 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTViewIt.exe
[2008/10/03 15:54:05 | 00,000,665 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Teamspeak 2 RC2.lnk
[2008/10/03 15:46:19 | 00,060,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\USBAUDIO.sys
[2008/10/03 15:46:19 | 00,060,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbaudio.sys
[2008/10/03 01:19:20 | 00,166,230 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\cc_20081003_011917.reg
[2008/10/03 00:31:15 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Application Data\teamspeak2
[2008/10/03 00:30:25 | 00,034,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\lhacm.acm
[2008/10/03 00:30:03 | 00,000,000 | ---D | C] -- C:\Program Files\Teamspeak2_RC2
[2008/09/22 01:13:45 | 00,000,000 | ---D | C] -- C:\Program Files\piPOol
[2008/09/22 01:11:01 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner\My Documents\Bass
[2008/09/20 20:59:07 | 00,000,460 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\cc_20080920_205904.reg
[2008/09/20 20:43:26 | 00,000,906 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Shortcut to MP4ConverterSuite.lnk
[2008/09/18 14:40:22 | 00,000,540 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\cc_20080918_144019.reg
[2008/09/18 14:39:49 | 00,496,382 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\cc_20080918_143947.reg
[2008/09/18 14:39:03 | 01,007,418 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\cc_20080918_143857.reg
========== Files - Modified Within 30 Days ========== [9 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[2008/10/18 02:45:00 | 07,257,632 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox.dat
[2008/10/18 02:34:30 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2008/10/18 02:34:09 | 00,352,918 | ---- | M] () -- C:\WINDOWS\System32\vsconfig.xml
[2008/10/18 02:33:58 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2008/10/18 02:33:45 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2008/10/17 11:49:17 | 00,099,224 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox.idx
[2008/10/17 05:48:09 | 00,037,775 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\for jason.jpg
[2008/10/16 09:35:50 | 00,000,628 | ---- | M] () -- C:\WINDOWS\win.ini
[2008/10/16 09:35:50 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2008/10/16 09:35:50 | 00,000,210 | -HS- | M] () -- C:\boot.ini
[2008/10/16 09:11:50 | 00,267,187 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2008/10/16 09:11:12 | 00,267,187 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20081016-091150.backup
[2008/10/15 20:03:20 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2008/10/15 07:16:54 | 00,110,190 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\photo.jpg
[2008/10/15 07:09:25 | 00,110,190 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\chipmunk.aspx
[2008/10/15 03:58:57 | 00,002,137 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2008/10/15 03:07:16 | 00,339,440 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2008/10/10 11:53:30 | 00,000,000 | ---- | M] () -- C:\WINDOWS\NoTrace.cfl
[2008/10/10 05:03:50 | 00,002,618 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Kaspersky scan.html
[2008/10/08 19:46:42 | 00,526,710 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2008/10/08 19:46:42 | 00,444,766 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2008/10/08 19:46:42 | 00,072,350 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2008/10/08 09:52:54 | 00,000,366 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\cc_20081008_095238.reg
[2008/10/08 09:36:29 | 00,000,304 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\cc_20081008_093622.reg
[2008/10/08 09:18:43 | 00,000,304 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\cc_20081008_091833.reg
[2008/10/08 09:18:09 | 00,002,396 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\cc_20081008_091802.reg
[2008/10/08 09:16:35 | 00,204,834 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\cc_20081008_091622.reg
[2008/10/08 09:00:47 | 00,870,128 | ---- | M] () -- C:\WINDOWS\System32\mcs.rma
[2008/10/08 09:00:47 | 00,000,004 | ---- | M] () -- C:\WINDOWS\System32\53E50F
[2008/10/08 08:39:04 | 00,000,894 | ---- | M] () -- C:\WINDOWS\QUICKEN.INI
[2008/10/07 16:13:22 | 00,004,212 | -H-- | M] () -- C:\WINDOWS\System32\zllictbl.dat
[2008/10/07 11:19:40 | 16,721,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2008/10/07 05:50:02 | 00,265,912 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20081016-091112.backup
[2008/10/06 13:37:25 | 00,003,406 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\cc_20081006_133716.reg
[2008/10/06 00:11:43 | 01,665,550 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\data mad.gif
[2008/10/05 15:24:19 | 00,000,676 | ---- | M] () -- C:\Documents and Settings\Owner\Start Menu\Programs\Startup\Webshots.lnk
[2008/10/05 07:41:17 | 02,482,695 | ---- | M] (McAfee Inc.) -- C:\Documents and Settings\Owner\Desktop\stinger.exe
[2008/10/05 07:19:24 | 00,419,328 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTViewIt.exe
[2008/10/05 01:04:37 | 00,265,912 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20081007-055002.backup
[2008/10/05 01:04:06 | 00,265,912 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20081005-010437.backup
[2008/10/03 15:54:05 | 00,000,665 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Teamspeak 2 RC2.lnk
[2008/10/03 09:41:15 | 06,066,176 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\ieframe.dll
[2008/10/03 09:41:15 | 06,066,176 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieframe.dll
[2008/10/03 01:19:25 | 00,166,230 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\cc_20081003_011917.reg
[2008/10/03 00:30:25 | 00,034,064 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\lhacm.acm
[2008/09/28 07:39:26 | 00,265,486 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20081005-010406.backup
[2008/09/28 07:38:51 | 00,265,486 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20080928-073926.backup
[2008/09/22 18:37:48 | 00,873,398 | ---- | M] () -- C:\WINDOWS\System32\oem164.inf
[2008/09/21 23:46:54 | 00,000,433 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.ics
[2008/09/21 06:44:41 | 00,265,422 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20080928-073850.backup
[2008/09/20 20:59:09 | 00,000,460 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\cc_20080920_205904.reg
[2008/09/20 20:43:27 | 00,000,906 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Shortcut to MP4ConverterSuite.lnk
[2008/09/18 14:40:26 | 00,000,540 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\cc_20080918_144019.reg
[2008/09/18 14:39:56 | 00,496,382 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\cc_20080918_143947.reg
[2008/09/18 14:39:17 | 01,007,418 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\cc_20080918_143857.reg
< End of report >
OTViewIt Extras logfile created on: 10/18/2008 2:54:31 AM - Run 3
OTViewIt by OldTimer - Version 1.0.9.4 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
990.42 Mb Total Physical Memory | 503.58 Mb Available Physical Memory | 50.84% Memory free
1.21 Gb Paging File | 0.89 Gb Available in Paging File | 73.60% Paging File free
Paging file location(s): C:\pagefile.sys 336 672;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.88 Gb Total Space | 37.72 Gb Free Space | 67.49% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: MAIN
Current User Name: Owner
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days
========== File Associations ==========[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.url [@ = InternetShortcut] -- C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
========== Security Center Settings ==========[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled"=1
"AntiVirusDisableNotify"=0
"FirewallDisableNotify"=0
"UpdatesDisableNotify"=0
"AntiVirusOverride"=0
"FirewallOverride"=0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=1
========== Authorized Applications List ==========[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[2008/04/13 16:12:34 | 00,141,312 | ---- | M] (Microsoft Corporation) -- %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[2008/04/13 16:12:34 | 00,141,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019
========== (O10) Winsock2 Catalogs ==========[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\]
NameSpace_Catalog5\Catalog_Entries\000000000004 [NWLink IPX/SPX/NetBIOS Compatible Transport Protocol] -- C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
NameSpace_Catalog5\Catalog_Entries\000000000005 [mdnsNSP] -- C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
========== (O18) Protocol Handlers ==========[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
ipp: [HKLM - No CLSID value]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2007/08/29 00:55:14 | 01,014,128 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL ipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
msdaipp: [HKLM - No CLSID value]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2007/08/29 00:55:14 | 01,014,128 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2007/08/29 00:55:14 | 01,014,128 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\oledb:{E1D2BF40-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAIPP.BINDER]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2008/01/24 15:22:56 | 07,255,384 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (mso-offdap:{3D9F03FA-7A94-11D3-BE81-0050048385D1} (HKLM) [Data Page Pluggable Protocol mso-offdap Handler])
========== HKEY_LOCAL_MACHINE Uninstall List ==========[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{007C0BB9-C5E2-4C73-B96B-2BBD5CEA9BF9}"=2350
"{0390854C-42B9-4BC2-B0CF-87DDA0F62EC8}"=2350_Help
"{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}"=WD Diagnostics
"{0DC86BEC-5CE3-413A-BB61-C40A3D186B24}"=Scan
"{14BEB6DF-A499-4A38-8E06-E173BCD5C087}"=ScannerCopy
"{17293791-C82E-476C-9997-9A0FF234A19B}"=HP Product Assistant
"{181821B7-82AA-44DA-9DAF-EF254CCB670A}"=Fax
"{1AD5F465-8282-4DAD-B957-E09C0B783D18}"=InstantShare
"{1B680FBA-E317-4E93-AF43-3B59798A4BE0}"=Copy
"{20FBC0A0-3160-4F14-83ED-3A74BB6B8C31}"=TrayApp
"{22DE1881-9D24-4981-B5CC-EC7E9F2F4D52}"=Rhapsody Player Engine
"{25F6C900-C138-4888-A56C-91D3D063023A}"=HP Update
"{2604C0F9-BFD3-4BA0-9EB5-22537C648F03}"=MobileMe Control Panel
"{272EC8BA-5A08-4ea1-A189-684466A06B02}"=cp_dwShrek2Albums1
"{2BA00471-0328-3743-93BD-FA813353A783}"=Microsoft .NET Framework 3.0 Service Pack 1
"{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}"=Rhapsody Player Engine
"{2E8428AD-6CD2-4031-916A-3CF9BBF2DEC9}"=Unload
"{3248F0A8-6813-11D6-A77B-00B0D0160070}"=Java 6 Update 7
"{342C7C88-D335-4bc2-8CF1-281857629CE2}"=HP PSC & OfficeJet 4.7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}"=WebFldrs XP
"{3762DB2D-71BD-421F-9E55-C74DA7DF4D07}"=CueTour
"{391E18CE-7D3B-45E9-A8F0-34E77F14F47A}"=ProductContext
"{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}"=Google Earth
"{442BE28B-782B-4DC0-B490-E70A403B1C69}"=Readme
"{45BA7145-64B0-4B5D-BDC2-40E20FCDC6DC}"=palmOne
"{57C7C46A-D35D-492d-A328-4F8C9B5B4B52}"=PrintScreen
"{5E8D588F-307C-4250-B622-26969027319A}"=PanoStandAlone
"{600CF34A-89F8-4A30-9039-BF5C20C5E84E}"=MP4-based Video Downloader
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}"=Windows Genuine Advantage v1.3.0254.0
"{644D04A2-C682-4FD5-977D-03B804C4B9C5}"=CreativeProjects
"{646A65DD-23FC-418E-B9F0-E0500FB42CB1}"=PhotoGallery
"{655CB07D-C944-40BE-B93F-55957CAC7625}"=AiO_Scan
"{68963635-14A4-48D9-B431-DF3A74D1AAE1}"=Destinations
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}"=Apple Software Update
"{700A6597-3CE6-49C1-AA75-846B24CDA66D}"=BufferChm
"{724517BD-1DE1-4986-BFCA-C1DFD379E3BC}"=cp_dwShrek2Cards1
"{753D852A-D86D-42C9-9978-40AE66FB8985}"=Driver Installer
"{76EFFC7C-17A6-479D-9E47-8E658C1695AE}"=Windows Backup Utility
"{7AD25C9F-9957-4D1C-95EF-9BCD09F6D31B}"=HPSystemDiagnostics
"{7AEBFFF0-15A1-48A9-88F3-06604486C7C9}"=WMPTagSupportExtender
"{84CDF5A8-1D57-4B69-BAB6-1F11D8923375}"=SkinsHP1
"{85CFD253-38AE-4DB1-ACB7-F0F4C791990D}"=AiOSoftware
"{8777AC6D-89F9-4793-8266-DE406F343E89}"=QFolder
"{882F2BCD-C6A3-4D91-8A09-B2B34CB7E481}"=muvee autoProducer DVD Edition - HPH
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}"=Microsoft Silverlight
"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}"=Bonjour
"{8A708DD8-A5E6-11D4-A706-000629E95E20}"=Intel® Extreme Graphics 2 Driver
"{8BC3B99B-A6BE-4A0B-8535-B1B94BA4B1B1}"=DocProc
"{8DC42D05-680B-41B0-8878-6C14D24602DB}"=QuickTime
"{90300409-6000-11D3-8CFE-0050048383C9}"=Microsoft Office XP Media Content
"{91130409-6000-11D3-8CFE-0050048383C9}"=Microsoft Office XP Small Business
"{94FB906A-CF42-4128-A509-D353026A607E}"=REALTEK Gigabit and Fast Ethernet NIC Driver
"{95120000-00AF-0409-0000-0000000FF1CE}"=Microsoft Office PowerPoint Viewer 2007 (English)
"{976C2B2A-CE59-4AB3-83FB-BF895E28F2E6}"=Apple Mobile Device Support
"{98E8A2EF-4EAE-43B8-A172-74842B764777}"=InterVideo WinDVD
"{99052DB7-9592-4522-A558-5417BBAD48EE}"=Microsoft ActiveSync
"{A5B9D22C-755A-4AC6-9904-875E80838BB6}"=CP_AtenaShokunin1Config
"{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C}"=Windows Defender Signatures
"{A81BFA08-5D4C-4D4C-ACEF-BF558C70D99D}"=AT&T Communication Manager
"{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}"=HP Help and Support
"{AC76BA86-7AD7-1033-7B44-A81200000003}"=Adobe Reader 8.1.2
"{AC76BA86-7AD7-5464-3428-800000000003}"=Spelling Dictionaries Support For Adobe Reader 8
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1"=Spybot - Search & Destroy
"{B508B3F1-A24A-32C0-B310-85786919EF28}"=Microsoft .NET Framework 2.0 Service Pack 1
"{B911B811-BA3E-46D4-90F8-6F3338359651}"=Director
"{BAF78226-3200-4DB4-BE33-4D922A799840}"=Windows Presentation Foundation
"{BC4CA8FA-41D2-4B81-8680-E9B7573D6500}"=PLAYSTATION®Network Downloader
"{C0E7118C-CF3D-46EC-B431-F744C035A571}"=2350Trb
"{C9D96682-5A4D-45FA-BA3E-DDCB2B0CB868}"=Safari
"{CA0A1E54-CE0F-4366-B09C-A87B61DC5633}"=Symantec Network Drivers Update
"{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}"=HP Product Detection
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}"=Microsoft .NET Framework 1.1
"{CCD09A07-C045-412C-B287-472489ED0F02}"=Wi-Fire Connection Manager
"{CDFCF124-115F-4976-8BF4-08C89187A146}"=WebReg
"{CE0C8CC5-E396-442B-A50E-D1D374A9E820}"=DocumentViewer
"{CEB326EC-8F40-47B2-BA22-BB092565D66F}"=Quick Launch Buttons 5.00 B3
"{D3161124-2B4D-478F-901A-D21BCAD72C7E}"=Addit
"{D937DD80-3928-4617-876F-538A25AECB17}"=LocationFree Player
"{DDDE0BE3-0CBE-4BF6-B75A-E3F69C947843}"=iTunes
"{E434580A-2D4A-4433-A81E-4BCAE86AD148}"=palmOne
"{EB3526D4-4C7C-4F45-8303-340A23E4F950}"=HPIZFix3
"{EB807EB6-5179-48B7-98D4-7B4934A57A81}"=Documents To Go
"{EC3B598C-1151-4191-B5B4-A9072ADE6259}_is1"=ZipGenius 6 (6.0.2.1030A)
"{FC22D020-3005-4715-8DF9-F3EDE81DEB3D}"=CreativeProjectsTemplates
"{FF77941A-2BFA-4A18-BE2E-69B9498E4D55}"=User Profile Hive Cleanup Service
"Ad-Aware SE Personal"=Ad-Aware SE Personal
"Adobe Flash Player ActiveX"=Adobe Flash Player ActiveX
"Adobe Flash Player Plugin"=Adobe Flash Player Plugin
"AVG7Uninstall"=AVG Free Edition
"Broadcom 802.11b Network Adapter"=Broadcom 802.11 Driver
"CCleaner"=CCleaner (remove only)
"Chart Navigator"=Chart Navigator
"CNXT_MODEM_PCI_VEN_8086&DEV_24C6&SUBSYS_3080103C"=SoftV90 Data Fax Modem with SmartCP
"Conexant PCI Audio"=Conexant AC-Link Audio
"Cucusoft Ultimate DVD + Video Converter Suite_is1"=Cucusoft Ultimate DVD + Video Converter Suite 7.13.7.7
"HijackThis"=HijackThis 2.0.2
"HP Photo & Imaging"=HP Image Zone 4.7
"IDNMitigationAPIs"=Microsoft Internationalized Domain Names Mitigation APIs
"ie7"=Windows Internet Explorer 7
"InCD!UninstallKey"=InCD
"KB909520"=Microsoft Base Smart Card Cryptographic Service Provider Package
"LimeWire"=LimeWire PRO 4.9.30
"Malwarebytes' Anti-Malware_is1"=Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)"=Microsoft .NET Framework 1.1
"Mozilla Firefox (3.0.3)"=Mozilla Firefox (3.0.3)
"MSCompPackV1"=Microsoft Compression Client Pack 1.0 for Windows XP
"MSN Music Assistant"=MSN Music Assistant
"MSNINST"=MSN
"Nero - Burning Rom!UninstallKey"=Nero 6 Ultra Edition
"NeroVision!UninstallKey"=Nero Digital
"Network Stumbler"=Network Stumbler 0.4.0 (remove only)
"NLSDownlevelMapping"=Microsoft National Language Support Downlevel APIs
"NMIX!UninstallKey"=NeroMIX
"Picasa2"=Picasa 2
"Pocket Tunes"=Pocket Tunes 3.1.8
"Rhapsody"=Rhapsody
"SynTPDeinstKey"=Synaptics Pointing Device Driver
"Teamspeak 2 RC2_is1"=TeamSpeak 2 RC2
"Webshots Desktop"=Webshots Desktop
"WIC"=Windows Imaging Component
"Windows Media Format Runtime"=Windows Media Format 11 runtime
"Windows Media Player"=Windows Media Player 11
"Windows Mobile Device Handbook"=Windows Mobile® Device Handbook
"Windows XP Service Pack"=Windows XP Service Pack 3
"WMFDist11"=Windows Media Format 11 runtime
"wmp11"=Windows Media Player 11
"Wudf01000"=Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC"=XML Paper Specification Shared Components Pack 1.0
"ZoneAlarm"=ZoneAlarm
"ZoneAlarmSB Uninstall"=ZoneAlarm Spy Blocker
========== Last 10 Event Log Errors ==========[ Application Events ]
Error - 9/15/2008 6:50:45 PM | Computer Name = MAIN | Source = Windows Search Service | ID = 3024
Description =
Error - 9/15/2008 10:37:38 PM | Computer Name = MAIN | Source = Automatic LiveUpdate Scheduler | ID = 101
Description =
Error - 9/16/2008 2:53:13 AM | Computer Name = MAIN | Source = Application Error | ID = 1000
Description = Faulting application applesyncuihandler.exe, version 8.0.13.0, faulting
module corefoundation.dll, version 8.0.441.2, fault address 0x000aced3.
Error - 9/16/2008 2:54:10 AM | Computer Name = MAIN | Source = Application Error | ID = 1001
Description = Fault bucket 921536476.
Error - 9/17/2008 1:20:54 AM | Computer Name = MAIN | Source = Automatic LiveUpdate Scheduler | ID = 101
Description =
Error - 9/17/2008 1:25:54 AM | Computer Name = MAIN | Source = Automatic LiveUpdate Scheduler | ID = 101
Description =
Error - 9/17/2008 1:30:54 AM | Computer Name = MAIN | Source = Automatic LiveUpdate Scheduler | ID = 101
Description =
Error - 9/17/2008 1:35:54 AM | Computer Name = MAIN | Source = Automatic LiveUpdate Scheduler | ID = 101
Description =
Error - 9/22/2008 3:33:39 AM | Computer Name = MAIN | Source = Automatic LiveUpdate Scheduler | ID = 101
Description =
Error - 9/22/2008 3:38:39 AM | Computer Name = MAIN | Source = Automatic LiveUpdate Scheduler | ID = 101
Description =
[ System Events ]
Error - 10/8/2008 12:27:24 PM | Computer Name = MAIN | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 10/8/2008 12:27:24 PM | Computer Name = MAIN | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 10/8/2008 12:27:24 PM | Computer Name = MAIN | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 10/8/2008 12:27:24 PM | Computer Name = MAIN | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 10/8/2008 12:27:24 PM | Computer Name = MAIN | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 10/8/2008 12:27:24 PM | Computer Name = MAIN | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 10/8/2008 12:27:24 PM | Computer Name = MAIN | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 10/8/2008 12:27:24 PM | Computer Name = MAIN | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 10/8/2008 12:27:25 PM | Computer Name = MAIN | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 10/8/2008 12:27:25 PM | Computer Name = MAIN | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
< End of report >
running kasperspy now, a week ago it found zero...