OTViewIt logfile created on: 14/10/2008 6:23:31 PM - Run
OTViewIt by OldTimer - Version 1.0.11.0 Folder = C:\Documents and Settings\Trollope\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
1.25 Gb Total Physical Memory | 0.79 Gb Available Physical Memory | 63.29% Memory free
1.48 Gb Paging File | 1.08 Gb Available in Paging File | 72.91% Paging File free
Paging file location(s): C:\pagefile.sys 384 768;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 10.60 Gb Free Space | 28.45% Space Free | Partition Type: FAT32
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: HOME
Current User Name:
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days
========== Processes ========== [2007/12/01 13:10:12 | 00,418,816 | ---- | M] (GRISOFT, s.r.o.) -- C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
[2007/12/01 12:46:58 | 00,049,664 | ---- | M] (GRISOFT, s.r.o.) -- C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
[2008/01/16 08:50:36 | 00,406,528 | ---- | M] (GRISOFT, s.r.o.) -- C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
[2002/09/27 15:38:00 | 00,065,536 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvsvc32.exe
[2002/10/30 17:40:34 | 00,028,672 | ---- | M] () -- C:\WINDOWS\htpatch.exe
[2002/02/25 01:59:00 | 00,204,800 | ---- | M] (Logitech Inc. ) -- C:\Program Files\Logitech\iTouch\iTouch.exe
[2002/02/08 05:01:24 | 00,040,960 | ---- | M] (Creative Technology Ltd) -- C:\WINDOWS\system32\CTHELPER.EXE
[2002/01/28 09:43:00 | 00,035,328 | ---- | M] (Logitech Inc. ) -- C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
[2004/08/04 17:56:56 | 00,033,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\RunDll32.exe
[2004/04/30 20:56:30 | 00,356,352 | ---- | M] (GlobespanVirata, Inc.) -- C:\Program Files\D-Link\DSL-200\dslstat.exe
[2004/04/30 20:56:30 | 00,016,384 | ---- | M] () -- C:\Program Files\D-Link\DSL-200\dslagent.exe
[2008/04/26 08:49:38 | 00,579,584 | ---- | M] (GRISOFT, s.r.o.) -- C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
[2008/07/07 09:42:06 | 02,156,368 | RHS- | M] (Safer Networking Limited) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[2008/09/03 14:07:12 | 01,576,176 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
[2008/07/18 22:10:42 | 00,053,448 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wuauclt.exe
[2008/06/23 19:20:52 | 00,625,664 | -HS- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\iexplore.exe
[2008/10/14 18:23:26 | 00,421,376 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Trollope\Desktop\OTViewIt.exe
========== (O23) Win32 Services ========== [2007/10/24 01:47:22 | 00,033,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
[2007/12/01 13:10:12 | 00,418,816 | ---- | M] (GRISOFT, s.r.o.) -- C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe -- (Avg7Alrt [Auto | Running])
[2007/12/01 12:46:58 | 00,049,664 | ---- | M] (GRISOFT, s.r.o.) -- C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe -- (Avg7UpdSvc [Auto | Running])
[2008/01/16 08:50:36 | 00,406,528 | ---- | M] (GRISOFT, s.r.o.) -- C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe -- (AVGEMS [Auto | Running])
[2007/10/24 01:47:40 | 00,070,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
[2007/10/09 12:58:12 | 00,036,864 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
[2007/10/11 09:55:10 | 00,864,256 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
[2006/11/10 19:18:02 | 00,774,144 | ---- | M] (Nero AG) -- C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe -- (NBService [On_Demand | Stopped])
[2007/10/11 09:55:14 | 00,122,880 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
[2002/09/27 15:38:00 | 00,065,536 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\nvsvc32.exe -- (NVSvc [Auto | Running])
[2003/07/28 12:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
[2007/10/18 11:31:54 | 00,098,328 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\usnsvc.exe -- (usnjsvc [On_Demand | Stopped])
[2007/10/25 15:27:54 | 00,266,240 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\installer\WLSetupSvc.exe -- (WLSetupSvc [On_Demand | Stopped])
[2006/10/18 20:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])
========== Driver Services ========== [2007/12/01 13:09:54 | 00,821,856 | ---- | M] (GRISOFT, s.r.o.) -- C:\WINDOWS\System32\Drivers\avg7core.sys -- (Avg7Core [System | Running])
[2007/12/01 12:47:08 | 00,004,224 | ---- | M] (GRISOFT, s.r.o.) -- C:\WINDOWS\System32\Drivers\avg7rsw.sys -- (Avg7RsW [System | Running])
[2007/12/01 13:09:58 | 00,027,776 | ---- | M] (GRISOFT, s.r.o.) -- C:\WINDOWS\System32\Drivers\avg7rsxp.sys -- (Avg7RsXP [System | Running])
[2008/01/16 08:50:40 | 00,010,760 | ---- | M] (GRISOFT, s.r.o.) -- C:\WINDOWS\System32\Drivers\avgclean.sys -- (AvgClean [System | Running])
[2007/12/01 12:47:12 | 00,004,960 | ---- | M] (GRISOFT, s.r.o.) -- C:\WINDOWS\System32\Drivers\avgtdi.sys -- (AvgTdi [Auto | Running])
[2001/08/10 16:33:00 | 00,078,498 | ---- | M] (Conexant Systems) -- C:\WINDOWS\System32\DRIVERS\basic2.sys -- (basic2 [On_Demand | Running])
File not found -- C:\DOCUME~1\Trollope\LOCALS~1\Temp\catchme.sys -- (catchme [On_Demand | Running])
[2002/09/30 20:24:58 | 00,417,999 | ---- | M] (C-Media Inc) -- C:\WINDOWS\system32\drivers\cmuda.sys -- (cmuda [On_Demand | Running])
[2001/07/04 17:42:00 | 00,017,776 | ---- | M] (Conexant Systems) -- C:\WINDOWS\System32\DRIVERS\cnxtdiag.sys -- (Cnxtdiag [Auto | Running])
[2002/03/22 23:08:12 | 00,114,944 | ---- | M] (Creative Technology Ltd) -- C:\WINDOWS\System32\drivers\ctac32k.sys -- (ctac32k [On_Demand | Stopped])
[2002/03/22 23:09:40 | 00,835,636 | ---- | M] (Creative Technology Ltd) -- C:\WINDOWS\system32\drivers\ctaud2k.sys -- (ctaud2k [On_Demand | Stopped])
[2002/03/22 23:09:54 | 00,011,068 | ---- | M] (Creative Technology Ltd) -- C:\WINDOWS\System32\drivers\ctprxy2k.sys -- (ctprxy2k [On_Demand | Stopped])
[2002/03/22 23:10:10 | 00,211,724 | ---- | M] (Creative Technology Ltd) -- C:\WINDOWS\System32\drivers\ctsfm2k.sys -- (ctsfm2k [On_Demand | Stopped])
[2002/03/22 23:10:20 | 00,156,604 | ---- | M] (Creative Technology Ltd) -- C:\WINDOWS\System32\drivers\emupia2k.sys -- (emupia [On_Demand | Stopped])
[2001/07/13 13:52:00 | 00,310,739 | ---- | M] (Conexant Systems) -- C:\WINDOWS\System32\DRIVERS\fallback.sys -- (Fallback [Auto | Running])
[2001/06/15 18:37:00 | 00,127,405 | ---- | M] (Conexant Systems) -- C:\WINDOWS\System32\DRIVERS\fsksnt.sys -- (Fsks [Auto | Running])
[2004/08/04 16:08:22 | 00,010,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\DRIVERS\gameenum.sys -- (gameenum [On_Demand | Running])
[2002/03/22 23:10:58 | 00,991,656 | ---- | M] (Creative Technology Ltd) -- C:\WINDOWS\system32\drivers\ha10kx2k.sys -- (ha10kx2k [On_Demand | Stopped])
[2001/08/17 13:28:10 | 00,542,879 | ---- | M] (Conexant) -- C:\WINDOWS\System32\DRIVERS\HSF_MSFT.sys -- (hsf_msft [On_Demand | Stopped])
[2002/09/28 12:47:38 | 00,010,496 | ---- | M] (Logitech Inc. ) -- C:\WINDOWS\System32\DRIVERS\itchfltr.sys -- (itchfltr [On_Demand | Running])
[2001/07/23 18:41:00 | 00,427,167 | ---- | M] (Conexant Systems) -- C:\WINDOWS\System32\DRIVERS\k56nt.sys -- (K56 [Auto | Running])
[2002/09/28 12:47:36 | 00,050,994 | ---- | M] (Logitech) -- C:\WINDOWS\System32\DRIVERS\L8042Pr2.sys -- (l8042pr2 [On_Demand | Stopped])
[2002/09/28 12:47:36 | 00,022,210 | ---- | M] (Logitech) -- C:\WINDOWS\System32\DRIVERS\LHidFlt2.sys -- (LHidFlt2 [On_Demand | Running])
[2002/09/28 12:47:36 | 00,005,842 | ---- | M] (Logitech) -- C:\WINDOWS\System32\DRIVERS\LKbdFlt2.sys -- (LKbdFlt2 [On_Demand | Running])
[2002/09/28 12:47:36 | 00,067,698 | ---- | M] (Logitech) -- C:\WINDOWS\System32\DRIVERS\LMouFlt2.sys -- (LMouFlt2 [On_Demand | Running])
[2001/08/17 14:00:04 | 00,002,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\msmpu401.sys -- (ms_mpu401 [On_Demand | Running])
[2001/03/15 17:08:54 | 00,042,900 | ---- | M] () -- C:\WINDOWS\System32\drivers\Nbmkmd.sys -- (Nbmkmd [On_Demand | Stopped])
[2004/08/04 15:59:50 | 00,040,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\NMnt.sys -- (nm [On_Demand | Stopped])
[2007/05/16 11:42:02 | 00,013,440 | ---- | M] (NoteBurn Software) -- C:\WINDOWS\system32\DRIVERS\ntcdrdrv.sys -- (ntcdrdrv [Boot | Running])
[2002/09/27 15:38:00 | 01,104,282 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\DRIVERS\nv4_mini.sys -- (nv [On_Demand | Running])
[2002/03/22 23:09:52 | 00,195,432 | ---- | M] (Creative Technology Ltd.) -- C:\WINDOWS\system32\drivers\ctoss2k.sys -- (ossrv [On_Demand | Stopped])
[2003/03/26 12:51:52 | 00,030,336 | ---- | M] (JDSoft Inc.) -- C:\WINDOWS\system32\DRIVERS\pcnat.sys -- (PCNat [On_Demand | Stopped])
[2007/10/01 11:42:06 | 00,035,904 | ---- | M] (VSO Software) -- C:\WINDOWS\System32\Drivers\Pcouffin.sys -- (Pcouffin [On_Demand | Running])
File not found -- C:\WINDOWS\system32\drivers\PfModNT.sys -- (PfModNT [Auto | Stopped])
[2002/08/29 12:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
[2005/04/25 19:03:00 | 00,020,640 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20 [Boot | Running])
[2001/08/10 16:33:00 | 00,068,006 | ---- | M] (Conexant Systems) -- C:\WINDOWS\System32\DRIVERS\rksample.sys -- (Rksample [On_Demand | Running])
[2002/08/29 12:00:00 | 00,005,888 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\Drivers\RootMdm.sys -- (ROOTMODEM [On_Demand | Stopped])
[2002/04/01 09:47:36 | 00,045,312 | ---- | M] (Realtek Semiconductor Corporation) -- C:\WINDOWS\System32\DRIVERS\R8139n51.SYS -- (rtl8139 [On_Demand | Stopped])
[2008/09/03 14:07:14 | 00,008,944 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS -- (SASDIFSV [System | Running])
[2008/09/03 14:07:16 | 00,007,408 | R--- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM [On_Demand | Running])
[2008/09/03 14:07:12 | 00,055,024 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys -- (SASKUTIL [System | Running])
[2007/11/13 21:25:54 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])
[2003/01/23 18:08:00 | 00,257,408 | ---- | M] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\DRIVERS\sisgrp.sys -- (SiS315 [On_Demand | Stopped])
[2002/10/31 11:58:42 | 00,030,848 | ---- | M] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\DRIVERS\SISAGPX.sys -- (sisagp [Boot | Running])
[2001/06/15 18:36:00 | 00,216,987 | ---- | M] (Conexant Systems) -- C:\WINDOWS\System32\DRIVERS\faxnt.sys -- (SoftFax [Auto | Running])
[2001/08/17 13:56:16 | 00,007,552 | ---- | M] (Sony Corporation) -- C:\WINDOWS\System32\DRIVERS\SONYPVU1.SYS -- (SONYPVU1 [On_Demand | Stopped])
[2001/06/15 18:35:00 | 00,056,639 | ---- | M] (Conexant Systems) -- C:\WINDOWS\System32\DRIVERS\tonesnt.sys -- (Tones [Auto | Running])
[2001/07/23 18:40:00 | 00,534,605 | ---- | M] (Conexant Systems) -- C:\WINDOWS\System32\DRIVERS\v124nt.sys -- (V124 [Auto | Running])
[2004/04/30 20:56:16 | 00,150,369 | ---- | M] (GlobespanVirata Inc.) -- C:\WINDOWS\System32\DRIVERS\gwausb.sys -- (wanusb [On_Demand | Running])
[2001/08/10 16:36:00 | 00,585,152 | ---- | M] (Conexant Systems) -- C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys -- (winachsf [On_Demand | Running])
========== (R ) Internet Explorer ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
"Default_Search_URL"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Default_Secondary_Page_URL"=
"Extensions Off Page"=about:NoAdd-ons
"Local Page"=C:\windows\system32\blank.htm
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Security Risk Page"=about:SecurityRisk
"Start Page"=http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search]
"CustomizeSearch"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
"Default_Search_URL"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"SearchAssistant"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\WINDOWS\system32\blank.htm
"Page_Transitions"=
"Search Page"=http://www.google.com
"Start Page"=http://www.google.com
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Search]
"SearchAssistant"=http://www.google.com
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main]
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://global.acer.com/
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main]
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://global.acer.com/
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main]
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main]
"Start Page"=http://global.acer.com/
[HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
[HKEY_USERS\S-1-5-21-782189750-2424629274-2587936551-1005\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\WINDOWS\system32\blank.htm
"Page_Transitions"=
"Search Page"=http://www.google.com
"Start Page"=http://www.google.com
[HKEY_USERS\S-1-5-21-782189750-2424629274-2587936551-1005\SOFTWARE\Microsoft\Internet Explorer\Search]
"SearchAssistant"=http://www.google.com
[HKEY_USERS\S-1-5-21-782189750-2424629274-2587936551-1005\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\system32\ieframe.dll (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-782189750-2424629274-2587936551-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
========== (O1) Hosts File ========== HOSTS File = (686 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
First 25 entries...
127.0.0.1 localhost
========== (O2) BHO's ========== [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\]
{003F7B66-8E81-4C69-A4C0-8B73609283C0} (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
{50887A3E-98E4-477F-A03A-B7CD6389BB1C} (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
{53707962-6F74-2D53-2644-206D7942484F} (HKLM) -- C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
{6277CEAA-996A-485E-8245-4A31528803C7} (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
{6BB4BBB4-9506-4E50-A9EE-89BA967121FD} (HKLM) -- C:\WINDOWS\system32\jkkICtqn.dll File not found
{7611D02D-AD35-46E4-B41E-438C569B3EFD} (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
{998DAE3E-7D4F-4952-A71F-467D8FE64407} (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
{9C7C1C81-E002-43F3-8182-E9B0B6C59F89} (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
{F849FE04-066B-406C-9B9A-5701BD1C8A39} (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
========== (O4) Run Keys ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"=C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP (GRISOFT, s.r.o.)
"Cmaudio"=RunDll32 cmicnfg.cpl,CMICtrlWnd File not found
"DSLAGENTEXE"=C:\Program Files\D-Link\DSL-200\dslagent.exe ()
"DSLSTATEXE"=C:\Program Files\D-Link\DSL-200\dslstat.exe icon (GlobespanVirata, Inc.)
"EM_EXEC"=C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE (Logitech Inc. )
"HTpatch"=C:\WINDOWS\htpatch.exe ()
"NvCplDaemon"=RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup (NVIDIA Corporation)
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
"SiS KHooker"=C:\WINDOWS\System32\khooker.exe (Silicon Integrated Systems Corporation)
"SiS Tray"=C:\WINDOWS\System32\sistray.EXE File not found
"UpdReg"=C:\WINDOWS\UpdReg.EXE (Creative Technology Ltd.)
"WINDVDPatch"=CTHELPER.EXE (Creative Technology Ltd)
"zBrowser Launcher"=C:\Program Files\Logitech\iTouch\iTouch.exe (Logitech Inc. )
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"=C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (GRISOFT, s.r.o.)
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" /background File not found
"Symantec Network Driver Update Warning"=C:\PROGRA~1\Symantec\LIVEUP~1\SNDWarn.EXE File not found
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"=C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (GRISOFT, s.r.o.)
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" /background File not found
"Symantec Network Driver Update Warning"=C:\PROGRA~1\Symantec\LIVEUP~1\SNDWarn.EXE File not found
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"=C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (GRISOFT, s.r.o.)
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"=C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (GRISOFT, s.r.o.)
[HKEY_USERS\S-1-5-21-782189750-2424629274-2587936551-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
========== (O4) Startup Folders ========== [2001/02/13 01:01:04 | 00,083,360 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
========== (O6 & O7) Current Version Policies ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=149
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
[HKEY_USERS\S-1-5-21-782189750-2424629274-2587936551-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
========== (O8) IE Context Menu Extensions ========== [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE [2008/05/15 15:42:26 | 10,354,176 | ---- | M] (Microsoft Corporation)
[HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE [2008/05/15 15:42:26 | 10,354,176 | ---- | M] (Microsoft Corporation)
[HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE [2008/05/15 15:42:26 | 10,354,176 | ---- | M] (Microsoft Corporation)
[HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: Reg Error: Key does not exist or could not be opened. File not found
[HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: Reg Error: Key does not exist or could not be opened. File not found
[HKEY_USERS\S-1-5-21-782189750-2424629274-2587936551-1005\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE [2008/05/15 15:42:26 | 10,354,176 | ---- | M] (Microsoft Corporation)
========== (O9) IE Extensions ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}: Menu: Sun Java Console -- %ProgramFiles%\Java\jre1.5.0_04\bin\npjpi150_04.dll [2005/06/03 04:09:54 | 00,069,746 | ---- | M] (Sun Microsystems, Inc.)
{85d1f590-48f4-11d9-9669-0800200c9a66}: Menu: Uninstall BitDefender Online Scanner v8 -- %SystemRoot%\bdoscandel.exe [2006/05/25 01:22:06 | 00,053,248 | ---- | M] ()
{92780B25-18CC-41C8-B9BE-3C9C571A8263}: Button: Research -- %SystemDrive%\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL [2007/04/19 14:10:18 | 00,063,840 | ---- | M] (Microsoft Corporation)
{DFB852A3-47F8-48C4-A200-58CAB36FD2A2}: Menu: Spybot - Search && Destroy Configuration -- %ProgramFiles%\Spybot - Search & Destroy\SDHelper.dll [2008/07/07 09:41:58 | 01,562,448 | ---- | M] (Safer Networking Limited)
{e2e2dd38-d088-4134-82b7-f2ba38496583}: Menu: @xpsp3res.dll,-20001 -- %SystemRoot%\Network Diagnostic\xpnetdiag.exe [2006/10/10 23:44:50 | 00,557,568 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Button: Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2004/10/14 03:24:38 | 01,694,208 | -HS- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Menu: Windows Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2004/10/14 03:24:38 | 01,694,208 | -HS- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %SystemRoot%\System32\msjava.dll [Web Browser Applet Control] -> [2003/02/28 18:26:26 | 00,947,472 | ---- | M] (Microsoft Corporation)
CmdMapping\\{85d1f590-48f4-11d9-9669-0800200c9a66} [HKLM] -> %SystemRoot%\bdoscandel.exe [Uninstall BitDefender Online Scanner v8] -> [2006/05/25 01:22:06 | 00,053,248 | ---- | M] ()
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %SystemDrive%\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL [Research] -> [2007/04/19 14:10:18 | 00,063,840 | ---- | M] (Microsoft Corporation)
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/10/14 03:24:38 | 01,694,208 | -HS- | M] (Microsoft Corporation)
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/10/14 03:24:38 | 01,694,208 | -HS- | M] (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-782189750-2424629274-2587936551-1005\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %SystemRoot%\System32\msjava.dll [Web Browser Applet Control] -> [2003/02/28 18:26:26 | 00,947,472 | ---- | M] (Microsoft Corporation)
CmdMapping\\{85d1f590-48f4-11d9-9669-0800200c9a66} [HKLM] -> %SystemRoot%\bdoscandel.exe [Uninstall BitDefender Online Scanner v8] -> [2006/05/25 01:22:06 | 00,053,248 | ---- | M] ()
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %SystemDrive%\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL [Research] -> [2007/04/19 14:10:18 | 00,063,840 | ---- | M] (Microsoft Corporation)
========== (O12) Internet Explorer Plugins ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\]
PluginsPage: "" =
http://activex.microsoft.com/controls/find...=%s&mime=%sPluginsPageFriendlyName: "" = Microsoft ActiveX Gallery
Extension\.spop: -- C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll [2001/01/30 13:56:24 | 00,225,280 | ---- | M] (InterTrust Technologies Corporation, Inc.)
========== (O13) Default Prefixes ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
""=http://
========== (O15) Trusted Sites ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
1 domain(s) and sub-domain(s) not assigned to a zone.
========== (O16) DPF ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\]
{0246ECA8-996F-11D1-BE2F-00A0C9037DFE}:
http://www.kvali.com/wfplayer/tdserver.cab -- TDServer Control
{04E214E5-63AF-4236-83C6-A7ADCBF9BD02}:
http://housecall60.trendmicro.com/housecall/xscan60.cab -- HouseCall Control
{0CCA191D-13A6-4E29-B746-314DEE697D83}:
http://upload.facebook.com/controls/Facebo...toUploader5.cab -- Facebook Photo Uploader 5
{1239CC52-59EF-4DFA-8C61-90FFA846DF7E}:
http://www.musicnotes.com/download/mnviewer.cab -- Musicnotes Viewer
{166B1BCA-3F9C-11CF-8075-444553540000}:
http://fpdownload.macromedia.com/get/shock...director/sw.cab -- Shockwave ActiveX Control
{17492023-C23A-453E-A040-C7C580BBF700}:
http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409 -- Windows Genuine Advantage Validation Tool
{2646205B-878C-11D1-B07C-0000C040BCDB}: file://D:\HD\nskey.dll -- NSIEMisc Class
{41F17733-B041-4099-A042-B518BB6A408C}:
http://a1540.g.akamai.net/7/1540/52/200305...meInstaller.exe -- Reg Error: Key does not exist or could not be opened.
{556DDE35-E955-11D0-A707-000000521957}:
http://www.xblock.com/download/xclean_micro.exe -- Reg Error: Key does not exist or could not be opened.
{5D86DDB5-BDF9-441B-9E9E-D4730F4EE499}:
http://download.bitdefender.com/resources/scan8/oscan8.cab -- BDSCANONLINE Control
{6414512B-B978-451D-A0D8-FCFDF33E833C}:
http://v5.windowsupdate.microsoft.com/v5co...b?1098516934953 -- WUWebControl Class
{6E32070A-766D-4EE6-879C-DC1FA91D2FC3}:
http://www.update.microsoft.com/microsoftu...b?1201510920343 -- MUWebControl Class
{74D05D43-3236-11D4-BDCD-00C04F9A3B61}:
http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab -- HouseCall Control
{8AD9C840-044E-11D1-B3E9-00805F499D93}:
http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab -- Java Plug-in 1.5.0_04
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}:
http://fpdownload.macromedia.com/get/shock...h/ultrashim.cab -- Reg Error: Value does not exist or could not be read.
{A8F2B9BD-A6A0-486A-9744-18920D898429}:
http://www.sibelius.com/download/software/...tiveXPlugin.cab -- ScorchPlugin Class
{A90A5822-F108-45AD-8482-9BC8B12DD539}:
http://www.crucial.com/controls/cpcScanner.cab -- Crucial cpcScan
{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA}:
http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab -- Java Plug-in 1.5.0_04
{D27CDB6E-AE6D-11CF-96B8-444553540000}:
http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab -- Shockwave Flash Object
{EF791A6B-FC12-4C68-99EF-FB9E207A39E6}:
http://download.mcafee.com/molbin/iss-loc/...324/mcfscan.cab -- McFreeScan Class
DirectAnimation Java Classes: file://C:\WINDOWS\Java\classes\dajava.cab -- Reg Error: Key does not exist or could not be opened.
Microsoft XML Parser for Java: file://C:\WINDOWS\Java\classes\xmldso.cab -- Reg Error: Key does not exist or could not be opened.
========== (O17) DNS Name Servers ========== {050C417B-206B-40B0-9B30-40A4595A0415} (Servers: | Description: 1394 Net Adapter)
{7232C297-3E10-48A6-807C-78FF19F4F8A1} (Servers: | Description: 1394 Net Adapter)
{F14F44A7-7D56-4E33-9F13-0F6710BDFCCC} (Servers: | Description: Realtek RTL8139/810x Family Fast Ethernet NIC)
========== (O20) AppInit_DLLs ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_Dlls"=notdtc.dll lvmrwe.dll
>[2008/10/11 10:02:36 | 00,107,520 | ---- | M] () -- C:\WINDOWS\system32\notdtc.dll
>File not found --
========== (O20) Winlogon Notify Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\]
!SASWinLogon: "DllName" = C:\Program Files\SUPERAntiSpyware\SASWINLO.dll -- C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
mlJBQHAP: "DllName" = Reg Error: Value DLLName does not exist or could not be read. -- File not found
========== Shell Execute Hooks ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}" (HKLM) -- C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
========== Safeboot Options ========== "AlternateShell"=cmd.exe
========== CDRom AutoRun Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1
========== Autorun Files on Drives ========== AUTOEXEC.BAT [PATH=%PATH%;C:\PROGRA~1\COMMON~1\MUVEET~1\030625 | ]
[2006/10/21 18:44:26 | 00,000,050 | ---- | M] () -- C:\AUTOEXEC.BAT -- [ FAT32 ]
========== MountPoints2 ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{cb2a09be-63c1-11da-9072-000f3d300101}\Shell\Auto\command]
""=infrom.exe
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{cb2a09be-63c1-11da-9072-000f3d300101}\Shell\AutoRun]
""=Auto&Play
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{cb2a09be-63c1-11da-9072-000f3d300101}\Shell\AutoRun\command]
""=C:\WINDOWS\system32\Shell32.DLL -- [2007/10/26 14:34:02 | 08,460,288 | ---- | M] (Microsoft Corporation)
========== Files/Folders - Created Within 30 Days ========== [2 C:\WINDOWS\System32\*.tmp files]
[2 C:\WINDOWS\*.tmp files]
[2008/10/14 18:23:15 | 00,421,376 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Trollope\Desktop\OTViewIt.exe
[2008/10/14 15:39:19 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERUNT
[2008/10/14 15:34:34 | 00,000,000 | ---D | C] -- C:\SDFix
[2008/10/14 15:33:58 | 01,431,710 | ---- | C] () -- C:\Documents and Settings\Trollope\Desktop\SDFix.exe
[2008/10/14 09:40:26 | 00,000,584 | ---- | C] () -- C:\Documents and Settings\Trollope\Desktop\DrWeb.csv
[2008/10/13 18:38:00 | 11,579,912 | ---- | C] (Doctor Web, Ltd.) -- C:\Documents and Settings\Trollope\Desktop\drweb-cureit.exe
[2008/10/13 16:13:38 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2008/10/13 16:13:01 | 00,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2008/10/13 16:13:01 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Trollope\Application Data\SUPERAntiSpyware.com
[2008/10/13 16:12:17 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard
[2008/10/13 16:12:11 | 06,637,592 | ---- | C] () -- C:\Documents and Settings\Trollope\Desktop\SUPERAntiSpyware.exe
[2008/10/13 09:52:13 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2008/10/12 22:46:05 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2008/10/12 16:43:13 | 00,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2008/10/12 16:32:47 | 00,002,548 | ---- | C] () -- C:\WINDOWS\System32\tmp.reg
[2008/10/12 14:39:22 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Trollope\Desktop\SmitfraudFix
[2008/10/12 13:06:32 | 00,054,156 | -H-- | C] () -- C:\WINDOWS\QTFont.qfn
[2008/10/12 13:06:32 | 00,001,409 | ---- | C] () -- C:\WINDOWS\QTFont.for
[2008/10/12 10:11:14 | 00,000,000 | ---D | C] -- C:\Program Files\MSBuild
[2008/10/12 10:10:53 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\XPSViewer
[2008/10/12 10:10:38 | 00,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies
[2008/10/12 10:09:01 | 00,014,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spmsg2.dll
[2008/10/12 10:06:26 | 00,000,000 | ---D | C] -- C:\Program Files\MSXML 6.0
[2008/10/11 16:50:22 | 00,000,095 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2008/10/11 16:13:26 | 00,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2008/10/11 16:13:26 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2008/10/11 12:22:11 | 00,000,124 | ---- | C] () -- C:\WINDOWS\netdet.ini
[2008/10/11 12:20:54 | 00,000,000 | -H-D | C] -- C:\WINDOWS\System32\CyberInstallerUninstallerSystem
[2008/10/11 12:20:39 | 00,000,000 | ---D | C] -- C:\Program Files\Guitar Freak Workstation With SightReader
[2008/10/11 12:20:00 | 00,787,696 | ---- | C] (MoonLight Software Inc. 1999-2007) -- C:\WINDOWS\System32\VBOLock.ocx
[2008/10/11 12:19:11 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Trollope\Application Data\CyberInstaller Studio 2008
[2008/10/11 11:55:11 | 00,107,520 | ---- | C] () -- C:\WINDOWS\System32\yzepzo.dll
[2008/10/11 11:55:02 | 01,088,753 | -HS- | C] () -- C:\WINDOWS\System32\pxpqnoip.ini
[2008/10/11 11:55:02 | 00,107,520 | ---- | C] () -- C:\WINDOWS\System32\gvqrxcph.dll
[2008/10/11 10:34:47 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Trollope\Application Data\Malwarebytes
[2008/10/11 10:34:13 | 00,017,200 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2008/10/11 10:34:12 | 00,038,528 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2008/10/11 10:34:11 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2008/10/11 10:34:10 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2008/10/11 10:33:28 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Trollope\Application Data\0000005377
[2008/10/11 10:02:35 | 00,107,520 | ---- | C] () -- C:\WINDOWS\System32\notdtc.dll
[2008/10/11 10:02:28 | 00,107,520 | ---- | C] () -- C:\WINDOWS\System32\rllcmujo.dll
[2008/10/11 09:51:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\obqbwrih
[2008/10/11 09:25:54 | 00,000,000 | ---D | C] -- C:\Program Files\SightReader Master
[2008/10/06 09:06:10 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Trollope\My Documents\oct 08
[2008/09/19 23:56:06 | 00,000,000 | ---D | C] -- C:\Program Files\7-Zip
========== Files - Modified Within 30 Days ========== [2 C:\WINDOWS\System32\*.tmp files]
[2 C:\WINDOWS\*.tmp files]
[2008/10/14 18:23:26 | 00,421,376 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Trollope\Desktop\OTViewIt.exe
[2008/10/14 18:21:02 | 00,000,366 | ---- | M] () -- C:\WINDOWS\tasks\Symantec NetDetect.job
[2008/10/14 15:57:06 | 00,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2008/10/14 15:56:52 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2008/10/14 15:56:48 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2008/10/14 15:34:10 | 01,431,710 | ---- | M] () -- C:\Documents and Settings\Trollope\Desktop\SDFix.exe
[2008/10/14 14:32:16 | 00,002,548 | ---- | M] () -- C:\WINDOWS\System32\tmp.reg
[2008/10/14 08:20:14 | 00,000,584 | ---- | M] () -- C:\Documents and Settings\Trollope\Desktop\DrWeb.csv
[2008/10/13 18:36:56 | 11,579,912 | ---- | M] (Doctor Web, Ltd.) -- C:\Documents and Settings\Trollope\Desktop\drweb-cureit.exe
[2008/10/13 16:10:50 | 06,637,592 | ---- | M] () -- C:\Documents and Settings\Trollope\Desktop\SUPERAntiSpyware.exe
[2008/10/12 22:47:42 | 00,528,784 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2008/10/12 22:47:42 | 00,445,870 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2008/10/12 22:47:42 | 00,072,824 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2008/10/12 22:04:22 | 00,000,124 | ---- | M] () -- C:\WINDOWS\netdet.ini
[2008/10/12 13:06:34 | 00,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
[2008/10/12 13:06:34 | 00,001,409 | ---- | M] () -- C:\WINDOWS\QTFont.for
[2008/10/12 12:40:18 | 00,341,832 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2008/10/12 10:18:36 | 00,104,248 | ---- | M] () -- C:\Documents and Settings\Trollope\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2008/10/11 16:50:24 | 00,000,095 | ---- | M] () -- C:\WINDOWS\wininit.ini
[2008/10/11 13:07:24 | 06,435,398 | -H-- | M] () -- C:\Documents and Settings\Trollope\Local Settings\Application Data\IconCache.db
[2008/10/11 12:33:20 | 00,001,023 | ---- | M] () -- C:\WINDOWS\win.ini
[2008/10/11 11:55:20 | 01,088,753 | -HS- | M] () -- C:\WINDOWS\System32\pxpqnoip.ini
[2008/10/11 11:55:12 | 00,107,520 | ---- | M] () -- C:\WINDOWS\System32\yzepzo.dll
[2008/10/11 11:55:12 | 00,107,520 | ---- | M] () -- C:\WINDOWS\System32\gvqrxcph.dll
[2008/10/11 10:02:36 | 00,107,520 | ---- | M] () -- C:\WINDOWS\System32\rllcmujo.dll
[2008/10/11 10:02:36 | 00,107,520 | ---- | M] () -- C:\WINDOWS\System32\notdtc.dll
[2008/10/03 06:40:54 | 00,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2008/10/02 10:58:28 | 00,151,040 | -HS- | M] () -- C:\Documents and Settings\Trollope\Desktop\Thumbs.db
< End of report >