Thanks Sam,
Here is the OTListIt2 Report:
OTListIt logfile created on: 2009-03-30 06:56:41 - Run 1
OTListIt2 by OldTimer - Version 2.0.7.2 Folder = C:\Documents and Settings\tnoftsger\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: yyyy-MM-dd
2.00 Gb Total Physical Memory | 1.38 Gb Available Physical Memory | 68.94% Memory free
3.85 Gb Paging File | 3.42 Gb Available in Paging File | 88.92% Paging File free
Paging file location(s): c:\pagefile.sys 2046 4092;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 34.18 Gb Total Space | 16.00 Gb Free Space | 46.82% Space Free | Partition Type: NTFS
Drive D: | 34.76 Gb Total Space | 12.94 Gb Free Space | 37.23% Space Free | Partition Type: NTFS
Drive E: | 0.88 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive M: | 221.61 Gb Total Space | 167.79 Gb Free Space | 75.71% Space Free | Partition Type: NTFS
Drive P: | 124.41 Gb Total Space | 75.32 Gb Free Space | 60.54% Space Free | Partition Type: NTFS
Drive Q: | 116.84 Gb Total Space | 17.72 Gb Free Space | 15.16% Space Free | Partition Type: NWFS
Drive U: | 124.41 Gb Total Space | 75.32 Gb Free Space | 60.54% Space Free | Partition Type: NTFS
Drive Z: | 116.84 Gb Total Space | 17.72 Gb Free Space | 15.16% Space Free | Partition Type: NWFS
Computer Name: TNOFTSGER
Current User Name: tnoftsger
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ========== PRC - [2007-10-24 02:47:40 | 00,070,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
PRC - [2008-12-15 07:27:32 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2001-02-23 11:07:30 | 00,270,336 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
PRC - [2009-02-27 07:02:14 | 00,115,560 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton AntiVirus\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe
PRC - [2007-12-05 02:41:00 | 00,155,716 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe
PRC - [2007-08-09 03:27:52 | 00,073,728 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe
PRC - [2000-07-17 08:10:00 | 00,555,520 | ---- | M] () -- d:\Program Files\Rainbow Technologies\SentinelLM 7.1.0 Server\English\lservnt.exe
PRC - [2009-02-27 07:02:14 | 00,115,560 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton AntiVirus\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe
PRC - [2009-03-09 11:49:18 | 00,037,888 | ---- | M] () -- D:\Program Files\Winamp\winampa.exe
PRC - [2002-03-12 12:37:28 | 00,028,672 | ---- | M] (Novell, Inc.) -- C:\WINDOWS\system32\NWTRAY.EXE
PRC - [2008-06-10 13:56:32 | 01,406,024 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft IntelliPoint\ipoint.exe
PRC - [2008-04-23 02:08:13 | 00,483,328 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
PRC - [2008-04-13 20:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msmsgs.exe
PRC - [2005-09-24 01:28:44 | 00,282,624 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
PRC - [2005-09-24 01:42:32 | 00,475,136 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
PRC - [2008-04-13 20:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.exe
PRC - [2004-08-04 00:56:52 | 00,093,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\iexplore.exe
PRC - [2009-02-27 07:02:15 | 00,442,224 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton AntiVirus\Norton AntiVirus\Engine\16.5.0.134\mcui32.exe
PRC - [2009-03-30 06:56:22 | 00,498,688 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\tnoftsger\Desktop\OTListIt2.exe
========== Win32 Services (SafeList) ========== SRV - [2009-03-11 14:12:24 | 00,072,704 | ---- | M] (Adobe Systems) -- C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe -- (Adobe LM Service [On_Demand | Stopped])
SRV - [2007-10-24 02:47:22 | 00,033,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2008-02-22 16:13:48 | 00,085,096 | ---- | M] (Autodesk) -- C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe -- (Autodesk Licensing Service [On_Demand | Stopped])
SRV - [2007-03-23 11:24:04 | 00,902,760 | ---- | M] (Autodesk, Inc.) -- C:\Program Files\Common Files\Autodesk Shared\Service\AdskNetSrv.exe -- (Autodesk Network Licensing Service [On_Demand | Stopped])
SRV - [2007-10-24 02:47:40 | 00,070,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [Auto | Running])
SRV - [2006-08-11 16:51:04 | 00,028,672 | ---- | M] (Novell, Inc.) -- C:\WINDOWS\system32\cusrvc.exe -- (cusrvc [On_Demand | Stopped])
SRV - [2007-10-09 13:58:12 | 00,036,864 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2009-03-23 20:02:30 | 00,183,280 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [Auto | Stopped])
SRV - [2008-04-13 20:12:02 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2005-05-20 11:37:12 | 00,081,920 | ---- | M] (Hewlett-Packard Company) -- C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE -- (HP Port Resolver [On_Demand | Stopped])
SRV - [2004-10-16 06:31:06 | 00,073,728 | ---- | M] (Hewlett-Packard Company) -- C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE -- (HP Status Server [On_Demand | Stopped])
SRV - [2007-10-11 10:55:10 | 00,864,256 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
SRV - [2008-12-15 07:27:32 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
SRV - [2001-02-23 11:07:30 | 00,270,336 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe -- (MDM [Auto | Running])
SRV - [2007-10-11 10:55:14 | 00,122,880 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
SRV - [2009-02-27 07:02:14 | 00,115,560 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton AntiVirus\Norton AntiVirus\Engine\16.5.0.134\ccSvcHst.exe -- (Norton AntiVirus [Auto | Running])
SRV - [2007-12-05 02:41:00 | 00,155,716 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc [Auto | Running])
SRV - [2007-08-09 03:27:52 | 00,073,728 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12 [Auto | Running])
SRV - [2000-07-17 08:10:00 | 00,555,520 | ---- | M] () -- d:\Program Files\Rainbow Technologies\SentinelLM 7.1.0 Server\English\lservnt.exe -- (SentinelLM [Auto | Running])
SRV - [2008-07-25 08:12:12 | 01,245,064 | ---- | M] () -- C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe -- (Symantec Core LC [On_Demand | Stopped])
SRV - [2006-10-18 20:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])
========== Driver Services (SafeList) ========== DRV - [2009-02-27 07:02:23 | 00,258,608 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\Drivers\NAV\1005000.086\BHDrvx86.sys -- (BHDrvx86 [System | Running])
DRV - [2005-05-31 15:11:08 | 00,030,189 | ---- | M] (Broadcom Corporation.) -- C:\WINDOWS\system32\DRIVERS\btwmodem.sys -- (btwmodem [On_Demand | Stopped])
DRV - [2009-03-04 11:49:24 | 00,482,352 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\Drivers\NAV\1005000.086\ccHPx86.sys -- (ccHP [System | Running])
DRV - [1997-08-07 05:03:02 | 00,007,328 | ---- | M] () -- C:\WINDOWS\SYSTEM32\drivers\DS1410D.SYS -- (DS1410D [Auto | Running])
DRV - [2007-12-11 14:34:40 | 00,242,320 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\DRIVERS\e1e5132.sys -- (e1express [On_Demand | Running])
DRV - [2009-02-26 05:00:00 | 00,371,248 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl [System | Running])
DRV - [2001-08-17 13:11:06 | 00,066,591 | ---- | M] (3Com Corporation) -- C:\WINDOWS\system32\DRIVERS\el90xbc5.sys -- (EL90XBC [On_Demand | Running])
DRV - [2009-02-26 05:00:00 | 00,101,936 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv [On_Demand | Running])
DRV - [2008-04-13 12:36:05 | 00,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) -- C:\WINDOWS\system32\DRIVERS\HDAudBus.sys -- (HDAudBus [On_Demand | Running])
DRV - [2005-10-27 05:52:18 | 00,049,664 | ---- | M] (HP) -- C:\WINDOWS\system32\DRIVERS\HPZid412.sys -- (HPZid412 [On_Demand | Stopped])
DRV - [2005-10-21 20:58:58 | 00,016,496 | ---- | M] (HP) -- C:\WINDOWS\system32\DRIVERS\HPZipr12.sys -- (HPZipr12 [On_Demand | Stopped])
DRV - [2005-10-22 08:22:48 | 00,021,568 | ---- | M] (HP) -- C:\WINDOWS\system32\DRIVERS\HPZius12.sys -- (HPZius12 [On_Demand | Stopped])
DRV - [2005-10-12 08:07:12 | 00,874,240 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\drivers\iaStor.sys -- (iaStor [Boot | Running])
DRV - [2009-01-29 17:50:18 | 00,276,344 | ---- | M] (Symantec Corporation) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20090318.001\IDSxpx86.sys -- (IDSxpx86 [System | Running])
DRV - [2008-08-21 19:49:22 | 00,018,688 | ---- | M] (Motorola) -- C:\WINDOWS\system32\DRIVERS\motccgp.sys -- (motccgp [On_Demand | Stopped])
DRV - [2008-08-21 19:49:56 | 00,008,320 | ---- | M] (Motorola) -- C:\WINDOWS\system32\DRIVERS\motccgpfl.sys -- (motccgpfl [On_Demand | Stopped])
DRV - [2007-10-10 18:41:50 | 00,042,112 | ---- | M] (Motorola Inc) -- C:\WINDOWS\system32\DRIVERS\motodrv.sys -- (MotDev [On_Demand | Stopped])
DRV - [2007-06-18 15:18:26 | 00,023,680 | ---- | M] (Motorola) -- C:\WINDOWS\system32\DRIVERS\motmodem.sys -- (motmodem [On_Demand | Stopped])
DRV - [2007-08-15 08:27:18 | 00,009,600 | ---- | M] () -- C:\WINDOWS\System32\Drivers\n558.sys -- (n558 [On_Demand | Stopped])
DRV - [2009-02-26 05:00:00 | 00,089,104 | ---- | M] (Symantec Corporation) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090329.021\NAVENG.SYS -- (NAVENG [On_Demand | Running])
DRV - [2009-02-26 05:00:00 | 00,876,144 | ---- | M] (Symantec Corporation) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090329.021\NAVEX15.SYS -- (NAVEX15 [On_Demand | Running])
DRV - [2007-06-21 15:03:08 | 00,513,664 | ---- | M] (Novell, Inc.) -- C:\WINDOWS\system32\NetWare\nwfs.sys -- (NetwareWorkstation [Auto | Running])
DRV - [2006-03-02 16:13:08 | 00,091,520 | ---- | M] (NovAtel Inc.) -- C:\WINDOWS\system32\drivers\ngpsser.sys -- (NGPSSER [On_Demand | Stopped])
DRV - [2006-03-02 16:13:08 | 00,076,928 | ---- | M] (NovAtel Inc.) -- C:\WINDOWS\system32\drivers\ngpsusb.sys -- (NGPSUSB [On_Demand | Stopped])
DRV - [2006-03-03 18:50:48 | 00,038,416 | ---- | M] (Novell, Inc.) -- C:\WINDOWS\system32\drivers\nicm.sys -- (NICM [Boot | Running])
DRV - [2008-06-09 14:12:06 | 00,018,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\NuidFltr.sys -- (NuidFltr [On_Demand | Stopped])
DRV - [2007-12-05 02:41:00 | 07,435,392 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\nv4_mini.sys -- (nv [On_Demand | Running])
DRV - [2005-11-22 11:51:22 | 00,018,353 | ---- | M] (Novell, Inc.) -- C:\WINDOWS\system32\NetWare\nwdhcp.sys -- (NWDHCP [On_Demand | Running])
DRV - [2006-10-27 17:53:48 | 00,043,568 | ---- | M] (Novell, Inc.) -- C:\WINDOWS\system32\NetWare\nwdns.sys -- (NWDNS [On_Demand | Running])
DRV - [2005-05-26 19:14:00 | 00,015,891 | ---- | M] (Novell, Inc.) -- C:\WINDOWS\system32\NetWare\nwfilter.sys -- (NWFILTER [Boot | Running])
DRV - [2005-10-12 14:12:18 | 00,009,297 | ---- | M] (Novell, Inc.) -- C:\WINDOWS\system32\NetWare\NWHOST.sys -- (NWHOST [On_Demand | Running])
DRV - [2003-02-26 15:51:18 | 00,023,232 | ---- | M] () -- C:\WINDOWS\system32\NetWare\NWSAP.sys -- (NWSAP [On_Demand | Stopped])
DRV - [2005-10-27 17:15:14 | 00,039,731 | ---- | M] (Novell, Inc.) -- C:\WINDOWS\system32\NetWare\nwsipx32.sys -- (NWSIPX32 [Auto | Stopped])
DRV - [2005-01-03 15:51:38 | 00,020,332 | ---- | M] (Novell, Inc.) -- C:\WINDOWS\system32\NetWare\nwslp.sys -- (NWSLP [On_Demand | Running])
DRV - [2005-10-12 14:11:32 | 00,006,128 | ---- | M] (Novell, Inc.) -- C:\WINDOWS\system32\NetWare\NWSNS.sys -- (NWSNS [On_Demand | Running])
DRV - [2008-12-04 12:34:32 | 00,027,784 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\point32.sys -- (Point32 [On_Demand | Running])
DRV - [2001-08-23 08:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
DRV - [2007-03-07 19:51:00 | 00,043,528 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20 [Boot | Running])
DRV - [2004-06-01 19:19:34 | 00,027,249 | ---- | M] (Novell, Inc.) -- C:\WINDOWS\system32\NetWare\resmgr.sys -- (RESMGR [Auto | Running])
DRV - [2007-11-13 06:25:53 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])
DRV - [2007-03-16 15:59:40 | 00,054,272 | ---- | M] (Sonic Focus, Inc) -- C:\WINDOWS\system32\drivers\sfng32.sys -- (sfng32 [On_Demand | Running])
DRV - [2009-02-27 07:02:23 | 00,307,760 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\Drivers\NAV\1005000.086\SRTSP.SYS -- (SRTSP [System | Running])
DRV - [2009-02-27 07:02:23 | 00,043,696 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\NAV\1005000.086\SRTSPX.SYS -- (SRTSPX [System | Running])
DRV - [2006-09-25 10:54:54 | 00,160,209 | ---- | M] (Novell, Inc.) -- C:\WINDOWS\system32\NetWare\srvloc.sys -- (SRVLOC [Auto | Running])
DRV - [2006-07-24 17:05:00 | 00,005,632 | ---- | M] () -- C:\WINDOWS\System32\drivers\StarOpen.sys -- (StarOpen [System | Running])
DRV - [2008-05-06 17:17:22 | 01,271,032 | ---- | M] (IDT, Inc.) -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA [On_Demand | Running])
DRV - [2009-02-27 07:02:23 | 00,310,320 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\NAV\1005000.086\SYMEFA.SYS -- (SymEFA [Boot | Running])
DRV - [2009-03-04 11:49:37 | 00,124,464 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\Drivers\SYMEVENT.SYS -- (SymEvent [On_Demand | Running])
DRV - [2009-02-27 07:02:23 | 00,089,776 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\Drivers\NAV\1005000.086\SYMFW.SYS -- (SYMFW [On_Demand | Running])
DRV - [2009-02-27 07:02:23 | 00,034,736 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\Drivers\NAV\1005000.086\SYMIDS.SYS -- (SYMIDS [On_Demand | Running])
DRV - [2009-02-27 07:02:15 | 00,036,400 | R--- | M] (Symantec Corporation) -- C:\WINDOWS\system32\DRIVERS\SymIM.sys -- (SymIM [On_Demand | Stopped])
DRV - [2009-02-27 07:02:15 | 00,036,400 | R--- | M] (Symantec Corporation) -- C:\WINDOWS\system32\DRIVERS\SymIM.sys -- (SymIMMP [On_Demand | Running])
DRV - [2009-02-27 07:02:23 | 00,037,296 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\Drivers\NAV\1005000.086\SYMNDIS.SYS -- (SYMNDIS [On_Demand | Running])
DRV - [2009-02-27 07:02:23 | 00,217,392 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\Drivers\NAV\1005000.086\SYMTDI.SYS -- (SYMTDI [System | Running])
DRV - [2008-03-18 06:42:13 | 00,023,600 | ---- | M] (EnTech Taiwan) -- C:\WINDOWS\system32\DRIVERS\TVICHW32.SYS -- (TVICHW32 [On_Demand | Stopped])
DRV - [2008-03-13 16:08:54 | 00,022,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\DRIVERS\usbsermpt.sys -- (usbsermpt [On_Demand | Stopped])
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.microsoft.com/isapi/redir.dll?p...ER}&ar=homeIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htmIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ieIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearchIE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhomeIE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearchIE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhomeIE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-816959666-2918063317-318358597-1610\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\S-1-5-21-816959666-2918063317-318358597-1610\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKU\S-1-5-21-816959666-2918063317-318358597-1610\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearchIE - HKU\S-1-5-21-816959666-2918063317-318358597-1610\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/IE - HKU\S-1-5-21-816959666-2918063317-318358597-1610\S-1-5-21-816959666-2918063317-318358597-1610\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..extensions.enabledItems: {08D5008D-5AD0-4E2F-B2BE-A00EFBD6F6CD}:1.0
FF - prefs.js..extensions.enabledItems: {8545daff-ad1e-493f-a37e-eed1ac79682b}:1.0
FF - prefs.js..extensions.enabledItems: {9B4BEBCE-0CC2-4B05-9F43-BED9F0A317DF}:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.7
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009-03-27 08:40:49 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009-03-27 08:40:41 | 00,000,000 | ---D | M]
[2009-03-27 08:40:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\tnoftsger\Application Data\mozilla\Extensions
[2009-03-27 08:40:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\tnoftsger\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009-03-10 10:41:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\tnoftsger\Application Data\mozilla\Extensions\mozswing@mozswing.org
[2009-03-27 08:40:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\tnoftsger\Application Data\mozilla\Firefox\Profiles\qdxi2v8a.default\extensions
[2009-03-27 15:55:49 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009-03-11 07:17:05 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{08D5008D-5AD0-4E2F-B2BE-A00EFBD6F6CD}
[2009-03-27 08:40:41 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009-03-10 10:56:46 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{9B4BEBCE-0CC2-4B05-9F43-BED9F0A317DF}
[2009-02-19 21:43:33 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009-02-19 21:43:34 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009-02-19 15:33:08 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009-02-19 15:33:08 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009-02-19 15:33:08 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009-02-19 15:33:08 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009-02-19 15:33:08 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009-02-19 15:33:08 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009-02-19 15:33:08 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Norton AntiVirus\Engine\16.5.0.134\IPSBHO.DLL (Symantec Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-21-816959666-2918063317-318358597-1610\..\Toolbar\ShellBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-21-816959666-2918063317-318358597-1610\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - Reg Error: Key error. File not found
O3 - HKU\S-1-5-21-816959666-2918063317-318358597-1610\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O4 - HKLM..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe" (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NWTRAY] NWTRAY.EXE (Novell, Inc.)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [WinampAgent] "D:\Program Files\Winamp\winampa.exe" ()
O4 - HKU\S-1-5-21-816959666-2918063317-318358597-1610..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKLM..\RunOnce: [NSSInstallation] C:\WINDOWS\system32\Adobe\Shockwave 11\nssstub.exe /RunOnce (Symantec Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk = C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe (Autodesk, Inc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Development Company, L.P.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe (Hewlett-Packard Development Company, L.P.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\tnoftsger\Start Menu\Programs\Startup\Microsoft Outlook.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: CompatibleRUPSecurity = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKU\S-1-5-20_Classes\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-21-816959666-2918063317-318358597-1610\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKU\S-1-5-21-816959666-2918063317-318358597-1610\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-816959666-2918063317-318358597-1610\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-816959666-2918063317-318358597-1610\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-816959666-2918063317-318358597-1610_Classes\Software\Policies\Microsoft\Internet Explorer\control panel present
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra Button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [Bluetooth Namespace] - C:\WINDOWS\system32\wshbth.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [Novell Directory Services Name Provider] - C:\WINDOWS\system32\netware\NWWS2NDS.DLL (Novell, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [Novell IPX/SPX SAP Name Provider] - C:\WINDOWS\system32\netware\NWWS2SAP.DLL (Novell, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [Novell SLP Provider] - C:\WINDOWS\system32\netware\NWWS2SLP.DLL (Novell, Inc.)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089}
http://office.microsoft.com/templates/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://download.macromedia.com/pub/shockwa...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/download/5/b...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://www.update.microsoft.com/windowsupd...b?1207232951508 (WUWebControl Class)
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862}
https://webdl.symantec.com/activex/symdlmgr.cab (Symantec Download Manager)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/microsoftu...b?1207082870068 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flash...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A364AF35-0CDF-41E8-8F3B-E0E55E15EBA1}
http://www.programchecker.com/dll/nixon.cab (Zenturi Active Programs Control)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
https://fpdownload.macromedia.com/get/flash...ent/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = CMWRICHMOND.COM
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{A180D1CB-0884-45CF-ADF5-A26997FAACD5}\\NameServer = 204.152.114.181,204.152.114.182
O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\jpip {B92DD248-E3D5-4A92-B311-C9B841681455} - C:\Program Files\LizardTech\Express View\expressview.dll (Lizardtech Software)
O18 - Protocol\Handler\mctp {d7b95390-b1c5-11d0-b111-0080c712fe82} - C:\Program Files\Microsoft ActiveSync\aatp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\sidlet {B92DD248-E3D5-4A92-B311-C9B841681455} - C:\Program Files\LizardTech\Express View\expressview.dll (Lizardtech Software)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (NWGINA.DLL) - C:\WINDOWS\system32\NWGINA.DLL (Novell, Inc.)
O21 - SSODL: Icovacon - {D9666B03-BD81-4C2D-8584-2DF38A11132B} - C:\WINDOWS\system32\ceribbas.dll File not found
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O30 - LSA: Authentication Packages - (nwv1_0) - C:\WINDOWS\System32\nwv1_0.dll (Novell, Inc.)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008-02-21 09:58:15 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2008-07-22 08:48:39 | 00,001,429 | ---- | M] () - C:\autosave.fil -- [ NTFS ]
O32 - AutoRun File - File not found - -- [ NTFS ]
O32 - AutoRun File - [2007-12-18 13:40:34 | 17,161,728 | ---- | M] () - Z:\autocad_architecture_2008sp1.msp -- [ NWFS ]
O32 - AutoRun File - File not found - -- [ NWFS ]
O32 - AutoRun File - File not found - -- [ NWFS ]
O32 - AutoRun File - [1999-06-02 18:13:26 | 00,000,000 | ---D | M] - Z:\AutoCAD2000 -- [ NWFS ]
O32 - AutoRun File - [2007-08-13 13:15:44 | 00,000,000 | ---D | M] - Z:\AutoCAD2008 -- [ NWFS ]
O33 - MountPoints2\{7aa7bdba-75c3-11dd-b768-000a5e40fe71}\Shell\AutoRun\command - "" = G:\Autorun.exe -- File not found
O33 - MountPoints2\{7aa7bdba-75c3-11dd-b768-000a5e40fe71}\Shell\Shell00\Command - "" = G:\Autorun.exe -- File not found
O33 - MountPoints2\{7aa7bdba-75c3-11dd-b768-000a5e40fe71}\Shell\Shell01\Command - "" = G:\Autorun.exe -- File not found
O33 - MountPoints2\{7aa7bdba-75c3-11dd-b768-000a5e40fe71}\Shell\Shell02\Command - "" = G:\Autorun.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
========== Files/Folders - Created Within 30 Days ========== [2 C:\WINDOWS\System32\*.tmp files]
File not found -- C:\WINDOWS\System32\uixiai.dll
File not found -- C:\WINDOWS\System32\sapovdoc.dll
File not found -- C:\WINDOWS\System32\maxocreg.exe
File not found -- C:\WINDOWS\System32\favipvox32.dll
File not found -- C:\WINDOWS\System32\exemodll.dll
File not found -- C:\WINDOWS\System32\ceribbas.dll
[2009-03-30 06:56:15 | 00,498,688 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\tnoftsger\Desktop\OTListIt2.exe
[2009-03-27 16:10:50 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\tmpPrst.dll
[2009-03-27 16:10:50 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\lsprst7.dll
[2009-03-27 15:57:44 | 00,000,000 | -HSD | C] -- C:\RECYCLER
[2009-03-27 15:50:42 | 00,000,000 | ---D | C] -- C:\ComboFix
[2009-03-27 15:44:47 | 00,090,660 | ---- | C] () -- C:\Documents and Settings\tnoftsger\My Documents\cc_20090327_154445.reg
[2009-03-27 15:36:47 | 01,137,360 | ---- | C] (F-Secure Corporation) -- C:\Documents and Settings\tnoftsger\Desktop\fsbl.exe
[2009-03-27 15:16:44 | 00,360,002 | ---- | C] () -- C:\Documents and Settings\tnoftsger\Desktop\dds.scr
[2009-03-27 15:04:41 | 00,001,025 | ---- | C] () -- C:\WINDOWS\System32\serauth2.dll
[2009-03-27 15:04:41 | 00,001,025 | ---- | C] () -- C:\WINDOWS\System32\serauth1.dll
[2009-03-27 15:04:41 | 00,000,087 | ---- | C] () -- C:\WINDOWS\System32\nsprs.tgz
[2009-03-27 15:03:36 | 00,002,335 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
[2009-03-27 15:03:36 | 00,001,947 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoCAD Startup Accelerator.lnk
[2009-03-27 15:03:36 | 00,001,808 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2009-03-27 15:03:36 | 00,001,730 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
[2009-03-27 15:03:36 | 00,000,798 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Photosmart Premier Fast Start.lnk
[2009-03-27 15:03:36 | 00,000,104 | ---- | C] () -- C:\Documents and Settings\tnoftsger\Start Menu\Programs\Startup\Microsoft Outlook.lnk
[2009-03-27 13:47:24 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2009-03-27 13:47:24 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2009-03-27 13:47:24 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2009-03-27 13:47:24 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2009-03-27 13:47:24 | 00,089,504 | ---- | C] (Smallfrogs Studio) -- C:\WINDOWS\fdsv.exe
[2009-03-27 13:47:24 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2009-03-27 13:47:24 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2009-03-27 13:47:24 | 00,049,152 | ---- | C] () -- C:\WINDOWS\VFIND.exe
[2009-03-27 13:47:24 | 00,029,696 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2009-03-27 13:47:11 | 00,000,000 | ---D | C] -- C:\Qoobox
[2009-03-27 13:46:46 | 02,936,485 | R--- | C] () -- C:\Documents and Settings\tnoftsger\Desktop\ComboFix.exe
[2009-03-27 13:07:37 | 00,000,000 | ---D | C] -- C:\rsit
[2009-03-27 13:07:21 | 00,781,909 | ---- | C] () -- C:\Documents and Settings\tnoftsger\Desktop\RSIT.exe
[2009-03-27 12:38:32 | 00,000,196 | ---- | C] () -- C:\Documents and Settings\tnoftsger\Desktop\DrWeb.csv
[2009-03-27 09:58:00 | 00,446,464 | ---- | C] ( ) -- C:\Documents and Settings\tnoftsger\Desktop\RootRepeal.exe
[2009-03-27 09:56:05 | 13,369,216 | ---- | C] (Doctor Web, Ltd.) -- C:\Documents and Settings\tnoftsger\Desktop\launch.exe
[2009-03-27 08:40:42 | 00,001,602 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009-03-27 08:34:24 | 00,004,566 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2009-03-26 16:46:48 | 00,229,376 | ---- | C] () -- C:\WINDOWS\System32\deluwwin.dll
[2009-03-25 09:17:56 | 00,000,000 | ---D | C] -- C:\Program Files\Coupons
[2009-03-25 08:53:05 | 00,004,436 | ---- | C] () -- C:\Documents and Settings\tnoftsger\My Documents\cc_20090325_085302.reg
[2009-03-23 20:02:30 | 00,000,868 | ---- | C] () -- C:\WINDOWS\tasks\Google Software Updater.job
[2009-03-23 14:13:19 | 00,000,423 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\UDC Output Files.lnk
[2009-03-23 14:13:15 | 00,005,632 | ---- | C] (fCoder Group, Inc.) -- C:\WINDOWS\System32\udcpm.dll
[2009-03-23 14:13:09 | 00,000,000 | R--D | C] -- C:\UDC Output Files
[2009-03-23 14:13:09 | 00,000,000 | ---D | C] -- C:\Program Files\Universal Document Converter
[2009-03-23 13:49:14 | 00,000,000 | ---D | C] -- C:\Program Files\LizardTech
[2009-03-20 13:40:46 | 00,000,392 | ---- | C] () -- C:\WINDOWS\tasks\NSSstub.job
[2009-03-20 13:40:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Adobe
[2009-03-20 11:15:49 | 00,000,802 | ---- | C] () -- C:\Documents and Settings\tnoftsger\My Documents\cc_20090320_111548.reg
[2009-03-20 11:15:26 | 00,005,370 | ---- | C] () -- C:\Documents and Settings\tnoftsger\My Documents\cc_20090320_111525.reg
[2009-03-19 14:14:59 | 00,080,290 | ---- | C] () -- C:\Documents and Settings\tnoftsger\My Documents\cc_20090319_141458.reg
[2009-03-19 13:54:29 | 00,326,492 | ---- | C] () -- C:\Documents and Settings\tnoftsger\My Documents\cc_20090319_135426.reg
[2009-03-16 11:32:05 | 00,013,824 | ---- | C] () -- C:\Documents and Settings\tnoftsger\My Documents\Madison County Park.xls
[2009-03-13 12:59:00 | 00,000,000 | ---D | C] -- C:\Program Files\AvantGo Connect
[2009-03-13 12:58:59 | 00,002,464 | ---- | C] () -- C:\WINDOWS\$_hpcst$.hpc
[2009-03-13 12:58:16 | 00,114,688 | ---- | C] (AvantGo, Inc.) -- C:\WINDOWS\System32\malslib.dll
[2009-03-13 12:58:16 | 00,077,899 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rapi.dll
[2009-03-13 12:58:16 | 00,069,632 | ---- | C] (AvantGo, Inc.) -- C:\WINDOWS\System32\mbllnk.cpl
[2009-03-13 12:58:16 | 00,065,615 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\pmailext.dll
[2009-03-13 12:58:16 | 00,065,613 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ppvexp.dll
[2009-03-13 12:58:16 | 00,057,423 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MsgStRPC.dll
[2009-03-13 12:58:16 | 00,036,942 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ppcload.dll
[2009-03-13 12:58:16 | 00,024,653 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ceutil.dll
[2009-03-13 12:58:16 | 00,024,652 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\uicom.dll
[2009-03-13 12:40:00 | 00,057,422 | ---- | C] () -- C:\WINDOWS\System32\mobileV.acm
[2009-03-13 12:37:16 | 00,002,510 | ---- | C] () -- C:\WINDOWS\Microsoft.MIF
[2009-03-12 08:37:30 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe AIR
[2009-03-11 14:11:12 | 00,000,000 | ---D | C] -- C:\adobe fix
[2009-03-11 13:13:37 | 00,000,328 | ---- | C] () -- C:\Documents and Settings\tnoftsger\My Documents\3-11-09.reg
[2009-03-11 12:59:53 | 00,009,675 | ---- | C] () -- C:\Documents and Settings\tnoftsger\My Documents\infection.htm
[2009-03-11 10:19:03 | 00,000,000 | ---D | C] -- C:\UBCD4Win
[2009-03-11 07:08:57 | 00,000,000 | R--D | C] -- C:\Program Files\Norton Support
[2009-03-11 07:08:49 | 00,000,000 | ---D | C] -- C:\Documents and Settings\tnoftsger\Local Settings\Application Data\Symantec
[2009-03-09 10:59:00 | 00,000,000 | ---D | C] -- C:\Documents and Settings\tnoftsger\Application Data\Apple Computer
[2009-03-09 08:57:50 | 00,050,245 | ---- | C] () -- C:\Documents and Settings\tnoftsger\My Documents\KENTUCKY811.jpg
[2009-03-06 16:06:17 | 00,913,385 | ---- | C] () -- C:\Documents and Settings\tnoftsger\My Documents\Revised Stockyards.pdf
[2009-03-05 08:50:25 | 00,000,000 | ---D | C] -- C:\Documents and Settings\tnoftsger\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009-03-04 14:33:39 | 01,243,370 | ---- | C] () -- C:\Documents and Settings\tnoftsger\My Documents\ESMT PLAT - SHEET 3.pdf
[2009-03-04 14:31:27 | 01,188,917 | ---- | C] () -- C:\Documents and Settings\tnoftsger\My Documents\ESMT PLAT - SHEET 2.pdf
[2009-03-04 14:27:11 | 03,184,942 | ---- | C] () -- C:\Documents and Settings\tnoftsger\My Documents\ESMT PLAT - SHEET 1.pdf
[2009-03-04 13:49:46 | 00,000,011 | ---- | C] () -- C:\WINDOWS\NetWare.INI
[2009-03-03 11:56:51 | 00,021,051 | ---- | C] () -- C:\Documents and Settings\tnoftsger\My Documents\Richmond Centre Outparcel 9 Staking.pdf
[2009-03-03 07:54:12 | 00,067,072 | ---- | C] () -- C:\Documents and Settings\tnoftsger\My Documents\Richmond Centre Outparcel 9 Staking.doc
[2009-03-02 14:30:56 | 00,000,000 | ---D | C] -- C:\Documents and Settings\tnoftsger\My Documents\AdobeStockPhotos
[2009-03-02 11:54:09 | 00,023,081 | ---- | C] () -- C:\Documents and Settings\tnoftsger\My Documents\Foundation Contractors EKU Science Building.pdf
[2009-03-02 11:46:11 | 00,068,608 | ---- | C] () -- C:\Documents and Settings\tnoftsger\My Documents\Foundation Contractors EKU Science Building.doc
========== Files - Modified Within 30 Days ========== [1 C:\WINDOWS\System32\drivers\*.tmp files]
[2 C:\WINDOWS\System32\*.tmp files]
[13 C:\WINDOWS\*.tmp files]
File not found -- C:\WINDOWS\System32\uixiai.dll
File not found -- C:\WINDOWS\System32\sapovdoc.dll
File not found -- C:\WINDOWS\System32\maxocreg.exe
File not found -- C:\WINDOWS\System32\favipvox32.dll
File not found -- C:\WINDOWS\System32\exemodll.dll
File not found -- C:\WINDOWS\System32\ceribbas.dll
[2009-03-30 06:56:22 | 00,498,688 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\tnoftsger\Desktop\OTListIt2.exe
[2009-03-30 03:09:20 | 00,000,868 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
[2009-03-27 16:10:50 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\tmpPrst.dll
[2009-03-27 16:10:50 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\lsprst7.dll
[2009-03-27 16:01:07 | 00,000,392 | ---- | M] () -- C:\WINDOWS\tasks\NSSstub.job
[2009-03-27 15:56:28 | 00,000,246 | ---- | M] () -- C:\WINDOWS\system.ini
[2009-03-27 15:56:22 | 00,002,335 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
[2009-03-27 15:56:18 | 00,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2009-03-27 15:56:15 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009-03-27 15:55:39 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009-03-27 15:55:38 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009-03-27 15:51:28 | 00,642,508 | ---- | M] () -- C:\WINDOWS\System32\drivers\NAV\1005000.086\Cat.DB
[2009-03-27 15:44:50 | 00,090,660 | ---- | M] () -- C:\Documents and Settings\tnoftsger\My Documents\cc_20090327_154445.reg
[2009-03-27 15:36:53 | 01,137,360 | ---- | M] (F-Secure Corporation) -- C:\Documents and Settings\tnoftsger\Desktop\fsbl.exe
[2009-03-27 15:16:50 | 00,360,002 | ---- | M] () -- C:\Documents and Settings\tnoftsger\Desktop\dds.scr
[2009-03-27 15:04:41 | 00,001,025 | ---- | M] () -- C:\WINDOWS\System32\serauth2.dll
[2009-03-27 15:04:41 | 00,001,025 | ---- | M] () -- C:\WINDOWS\System32\serauth1.dll
[2009-03-27 15:04:41 | 00,000,087 | ---- | M] () -- C:\WINDOWS\System32\nsprs.tgz
[2009-03-27 15:03:36 | 00,001,169 | ---- | M] () -- C:\WINDOWS\win.ini
[2009-03-27 15:03:36 | 00,000,282 | -HS- | M] () -- C:\boot.ini
[2009-03-27 13:47:00 | 02,936,485 | R--- | M] () -- C:\Documents and Settings\tnoftsger\Desktop\ComboFix.exe
[2009-03-27 13:07:33 | 00,781,909 | ---- | M] () -- C:\Documents and Settings\tnoftsger\Desktop\RSIT.exe
[2009-03-27 12:38:32 | 00,000,196 | ---- | M] () -- C:\Documents and Settings\tnoftsger\Desktop\DrWeb.csv
[2009-03-27 09:56:36 | 13,369,216 | ---- | M] (Doctor Web, Ltd.) -- C:\Documents and Settings\tnoftsger\Desktop\launch.exe
[2009-03-27 09:07:54 | 00,521,724 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009-03-27 09:07:54 | 00,441,514 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009-03-27 09:07:54 | 00,071,454 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009-03-27 08:40:42 | 00,001,602 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009-03-27 08:35:13 | 00,004,566 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009-03-26 16:49:56 | 00,038,496 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009-03-26 16:49:50 | 00,015,504 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009-03-26 16:46:48 | 00,229,376 | ---- | M] () -- C:\WINDOWS\System32\deluwwin.dll
[2009-03-25 11:58:00 | 00,057,384 | ---- | M] () -- C:\Documents and Settings\tnoftsger\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009-03-25 11:51:35 | 00,212,880 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009-03-25 08:53:08 | 00,004,436 | ---- | M] () -- C:\Documents and Settings\tnoftsger\My Documents\cc_20090325_085302.reg
[2009-03-24 15:13:01 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009-03-23 14:13:19 | 00,000,423 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\UDC Output Files.lnk
[2009-03-20 12:17:31 | 07,430,876 | -H-- | M] () -- C:\Documents and Settings\tnoftsger\Local Settings\Application Data\IconCache.db
[2009-03-20 11:15:50 | 00,000,802 | ---- | M] () -- C:\Documents and Settings\tnoftsger\My Documents\cc_20090320_111548.reg
[2009-03-20 11:15:29 | 00,005,370 | ---- | M] () -- C:\Documents and Settings\tnoftsger\My Documents\cc_20090320_111525.reg
[2009-03-19 14:15:06 | 00,080,290 | ---- | M] () -- C:\Documents and Settings\tnoftsger\My Documents\cc_20090319_141458.reg
[2009-03-19 13:55:39 | 00,000,654 | ---- | M] () -- C:\Documents and Settings\tnoftsger\Desktop\CCleaner.lnk
[2009-03-19 13:54:42 | 00,326,492 | ---- | M] () -- C:\Documents and Settings\tnoftsger\My Documents\cc_20090319_135426.reg
[2009-03-19 13:11:59 | 00,000,011 | ---- | M] () -- C:\WINDOWS\NetWare.INI
[2009-03-16 11:48:42 | 00,013,824 | ---- | M] () -- C:\Documents and Settings\tnoftsger\My Documents\Madison County Park.xls
[2009-03-13 12:59:03 | 00,002,510 | ---- | M] () -- C:\WINDOWS\Microsoft.MIF
[2009-03-13 12:58:59 | 00,002,464 | ---- | M] () -- C:\WINDOWS\$_hpcst$.hpc
[2009-03-12 07:53:23 | 00,000,235 | ---- | M] () -- C:\WINDOWS\retainpro.ini
[2009-03-11 13:13:37 | 00,000,328 | ---- | M] () -- C:\Documents and Settings\tnoftsger\My Documents\3-11-09.reg
[2009-03-11 12:59:53 | 00,009,675 | ---- | M] () -- C:\Documents and Settings\tnoftsger\My Documents\infection.htm
[2009-03-10 22:18:20 | 01,482,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\LegitCheckControl.dll
[2009-03-10 22:18:14 | 00,934,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\WgaTray.exe
[2009-03-10 22:18:14 | 00,934,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\WgaTray.exe
[2009-03-10 22:18:00 | 00,239,496 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\WgaLogon.dll
[2009-03-10 22:18:00 | 00,239,496 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wgaLogon.dll
[2009-03-09 12:05:35 | 00,007,168 | ---- | M] () -- C:\Documents and Settings\tnoftsger\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009-03-09 11:17:29 | 00,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2009-03-06 16:06:17 | 00,913,385 | ---- | M] () -- C:\Documents and Settings\tnoftsger\My Documents\Revised Stockyards.pdf
[2009-03-04 14:33:39 | 01,243,370 | ---- | M] () -- C:\Documents and Settings\tnoftsger\My Documents\ESMT PLAT - SHEET 3.pdf
[2009-03-04 14:31:27 | 01,188,917 | ---- | M] () -- C:\Documents and Settings\tnoftsger\My Documents\ESMT PLAT - SHEET 2.pdf
[2009-03-04 14:27:11 | 03,184,942 | ---- | M] () -- C:\Documents and Settings\tnoftsger\My Documents\ESMT PLAT - SHEET 1.pdf
[2009-03-04 11:49:37 | 00,124,464 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2009-03-04 11:49:37 | 00,060,808 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\S32EVNT1.DLL
[2009-03-04 11:49:37 | 00,007,386 | ---- | M] () -- C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2009-03-04 11:49:37 | 00,000,805 | ---- | M] () -- C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2009-03-04 11:49:24 | 00,482,352 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1005000.086\cchpx86.sys
[2009-03-04 11:49:23 | 00,000,172 | ---- | M] () -- C:\WINDOWS\System32\drivers\NAV\1005000.086\isolate.ini
[2009-03-03 11:57:02 | 00,021,051 | ---- | M] () -- C:\Documents and Settings\tnoftsger\My Documents\Richmond Centre Outparcel 9 Staking.pdf
[2009-03-03 11:56:49 | 00,067,072 | ---- | M] () -- C:\Documents and Settings\tnoftsger\My Documents\Richmond Centre Outparcel 9 Staking.doc
[2009-03-02 16:53:04 | 00,057,448 | ---- | M] () -- C:\Documents and Settings\tnoftsger\Application Data\GDIPFONTCACHEV1.DAT
[2009-03-02 11:54:21 | 00,023,081 | ---- | M] () -- C:\Documents and Settings\tnoftsger\My Documents\Foundation Contractors EKU Science Building.pdf
[2009-03-02 11:54:01 | 00,068,608 | ---- | M] () -- C:\Documents and Settings\tnoftsger\My Documents\Foundation Contractors EKU Science Building.doc
========== Alternate Data Streams ========== @Alternate Data Stream - 183 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 127 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1CA73D29
< End of report >
and the Gmer is taking awhile, i will post when complete...