I'm posting the extra one as well...
OTL logfile created on: 4/27/2010 10:18:53 AM - Run 2
OTL by OldTimer - Version 3.2.3.0 Folder = C:\Documents and Settings\Eric is The Man\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
959.00 Mb Total Physical Memory | 417.00 Mb Available Physical Memory | 43.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): C:\pagefile.sys 1440 2880 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 63.94 Gb Total Space | 1.57 Gb Free Space | 2.46% Space Free | Partition Type: NTFS
Drive D: | 9.56 Gb Total Space | 1.42 Gb Free Space | 14.84% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: HAL9000
Current User Name: Eric is The Man
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ========== PRC - [2010/04/27 10:18:15 | 000,563,712 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Eric is The Man\Desktop\OTL.exe
PRC - [2010/04/02 12:44:46 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/03/30 23:31:18 | 011,957,424 | ---- | M] (Mozilla Messaging) -- C:\Program Files\Mozilla Thunderbird\thunderbird.exe
PRC - [2010/03/24 19:12:00 | 002,434,168 | ---- | M] (Check Point Software Technologies LTD) -- C:\WINDOWS\system32\ZoneLabs\vsmon.exe
PRC - [2010/03/24 19:10:32 | 001,038,728 | ---- | M] (Check Point Software Technologies LTD) -- C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
PRC - [2009/09/10 11:15:42 | 000,870,672 | ---- | M] (SonicWALL, Inc.) -- C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\mantispm.exe
PRC - [2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/01/29 17:38:31 | 000,583,048 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
PRC - [2005/12/24 00:44:26 | 000,491,606 | ---- | M] () -- C:\Program Files\HPQ\Shared\HpqToaster.exe
========== Modules (SafeList) ========== MOD - [2010/04/27 10:18:15 | 000,563,712 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Eric is The Man\Desktop\OTL.exe
MOD - [2009/09/10 11:15:48 | 000,013,072 | ---- | M] () -- C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\MlfHook.dll
========== Win32 Services (SafeList) ========== SRV - File not found [Disabled | Stopped] -- -- (ASKUpgrade)
SRV - File not found [Disabled | Stopped] -- -- (ASKService)
SRV - [2010/03/24 19:12:00 | 002,434,168 | ---- | M] (Check Point Software Technologies LTD) [Auto | Running] -- C:\WINDOWS\System32\ZoneLabs\vsmon.exe -- (vsmon)
SRV - [2009/01/16 16:31:58 | 000,161,064 | ---- | M] (Seagate Technology LLC) [Disabled | Stopped] -- C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe -- (FreeAgentGoNext Service)
SRV - [2008/12/08 07:40:00 | 000,128,280 | ---- | M] (EMC Corporation) [Disabled | Stopped] -- C:\Program Files\Retrospect\Retrospect 7.6\rthlpsvc.exe -- (Retrospect Helper)
SRV - [2008/12/08 07:40:00 | 000,115,992 | ---- | M] (EMC Corporation) [Disabled | Stopped] -- C:\Program Files\Retrospect\Retrospect 7.6\retrorun.exe -- (RetroLauncher)
SRV - [2008/01/29 17:38:31 | 000,583,048 | ---- | M] (Symantec Corporation) [Disabled | Stopped] -- C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe -- (LiveUpdate Notice Service)
========== Driver Services (SafeList) ========== DRV - [2010/04/20 13:50:50 | 000,015,944 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\hitmanpro35.sys -- (hitmanpro35)
DRV - [2010/04/10 17:10:49 | 000,050,176 | ---- | M] (eSage Lab) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\rk_remover.sys -- (rk_remover-boot)
DRV - [2010/03/24 10:36:50 | 000,528,008 | ---- | M] (Check Point Software Technologies LTD) [Kernel | System | Running] -- C:\WINDOWS\system32\vsdatant.sys -- (vsdatant)
DRV - [2010/02/17 11:25:50 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)
DRV - [2010/02/17 11:15:58 | 000,066,632 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010/02/17 11:15:58 | 000,012,872 | R--- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM)
DRV - [2009/10/12 18:15:30 | 000,317,072 | ---- | M] (Kaspersky Lab) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\klif.sys -- (KLIF)
DRV - [2009/10/12 18:15:26 | 000,128,016 | ---- | M] (Kaspersky Lab) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\kl1.sys -- (kl1)
DRV - [2009/08/27 04:00:00 | 000,371,248 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2009/06/22 07:48:44 | 000,091,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mqac.sys -- (MQAC)
DRV - [2009/01/23 10:49:08 | 000,037,664 | ---- | M] (RapidSolution Software AG) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tbhsd.sys -- (tbhsd)
DRV - [2008/05/08 10:02:52 | 000,203,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rmcast.sys -- (RMCAST)
DRV - [2008/04/13 14:45:12 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbaudio.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2008/04/13 14:36:39 | 000,043,008 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\amdagp.sys -- (amdagp)
DRV - [2008/04/13 14:36:39 | 000,040,960 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sisagp.sys -- (sisagp)
DRV - [2008/04/13 12:36:05 | 000,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2006/08/24 14:05:32 | 000,594,432 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\CHDAud.sys -- (HdAudAddService)
DRV - [2006/05/10 14:27:00 | 000,036,864 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2006/04/21 10:16:00 | 003,659,872 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2006/03/09 12:56:58 | 000,995,712 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV)
DRV - [2006/03/09 12:56:16 | 000,206,976 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys -- (HSFHWAZL)
DRV - [2006/03/09 12:56:10 | 000,726,400 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2006/03/06 10:49:36 | 000,011,136 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvsmu.sys -- (nvsmu)
DRV - [2006/03/04 01:31:48 | 000,192,736 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SynTP.sys -- (SynTP)
DRV - [2006/03/03 11:31:04 | 000,013,056 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2006/03/03 11:31:02 | 000,034,176 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2006/01/27 11:04:16 | 000,099,584 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\nvata.sys -- (nvata)
DRV - [2006/01/19 05:18:52 | 000,424,320 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2005/12/22 20:02:22 | 000,051,840 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2005/11/16 23:28:32 | 000,028,928 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2005/11/01 21:08:00 | 000,308,992 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2005/10/13 05:07:12 | 000,874,240 | ---- | M] (Intel Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\iaStor.sys -- (iaStor)
DRV - [2005/09/19 17:24:20 | 000,005,760 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\EabUsb.sys -- (eabusb)
DRV - [2005/09/19 17:24:10 | 000,009,344 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\CPQBttn.sys -- (HBtnKey)
DRV - [2005/09/19 17:23:52 | 000,007,808 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\eabfiltr.sys -- (eabfiltr)
DRV - [2005/05/16 02:30:00 | 000,016,000 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ctpdusb.sys -- (Jukebox3)
DRV - [2004/08/04 02:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2001/08/18 02:07:44 | 000,019,072 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sparrow.sys -- (Sparrow)
DRV - [2001/08/18 02:07:42 | 000,030,688 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys -- (sym_u3)
DRV - [2001/08/18 02:07:40 | 000,028,384 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys -- (sym_hi)
DRV - [2001/08/18 02:07:36 | 000,032,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys -- (symc8xx)
DRV - [2001/08/18 02:07:34 | 000,016,256 | ---- | M] (Symbios Logic Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\symc810.sys -- (symc810)
DRV - [2001/08/18 01:52:22 | 000,036,736 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ultra.sys -- (ultra)
DRV - [2001/08/18 01:52:20 | 000,045,312 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql12160.sys -- (ql12160)
DRV - [2001/08/18 01:52:20 | 000,040,320 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql1080.sys -- (ql1080)
DRV - [2001/08/18 01:52:18 | 000,049,024 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\ql1280.sys -- (ql1280)
DRV - [2001/08/18 01:52:16 | 000,179,584 | ---- | M] (Mylex Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys -- (dac2w2k)
DRV - [2001/08/18 01:52:12 | 000,017,280 | ---- | M] (American Megatrends Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys -- (mraid35x)
DRV - [2001/08/18 01:52:00 | 000,026,496 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\asc.sys -- (asc)
DRV - [2001/08/18 01:51:58 | 000,014,848 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\asc3550.sys -- (asc3550)
DRV - [2001/08/18 01:51:56 | 000,005,248 | ---- | M] (Acer Laboratories Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\aliide.sys -- (AliIde)
DRV - [2001/08/18 01:51:54 | 000,006,656 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\system32\DRIVERS\cmdide.sys -- (CmdIde)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.davidbowie.com/IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ========== FF - prefs.js..browser.search.selectedEngine: "YouTube Video Search"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "www.davidbowie.com"
FF - prefs.js..extensions.enabledItems: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:0.9.10.2
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: tunebite-firefox-surf-and-catch-extension@audials.com:1.4.7600.0
FF - prefs.js..network.proxy.http: "87.66.29.96"
FF - prefs.js..network.proxy.http_port: 80
FF - prefs.js..network.proxy.type: 4
FF - HKLM\software\mozilla\Firefox\extensions\\tunebite-firefox-surf-and-catch-extension@audials.com: C:\Program Files\RapidSolution\Tunebite\plugins\GeckoBased\tunebite-firefox-surf-and-catch-extension@audials.com\ [2009/08/28 23:03:01 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/02 12:44:59 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/10 10:55:17 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.0.4\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010/03/30 23:31:19 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.0.4\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
[2010/03/27 17:26:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eric is The Man\Application Data\Mozilla\Extensions
[2010/03/27 17:26:04 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Eric is The Man\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010/04/27 10:15:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eric is The Man\Application Data\Mozilla\Firefox\Profiles\akhs435d.default\extensions
[2010/02/07 11:47:38 | 000,000,000 | ---D | M] (Forecastfox) -- C:\Documents and Settings\Eric is The Man\Application Data\Mozilla\Firefox\Profiles\akhs435d.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2010/02/01 16:26:50 | 000,001,924 | ---- | M] () -- C:\Documents and Settings\Eric is The Man\Application Data\Mozilla\Firefox\Profiles\akhs435d.default\searchplugins\antsmarchingorg.xml
[2009/09/02 23:20:55 | 000,002,013 | ---- | M] () -- C:\Documents and Settings\Eric is The Man\Application Data\Mozilla\Firefox\Profiles\akhs435d.default\searchplugins\urban-dictionary.xml
[2009/12/16 01:01:01 | 000,002,452 | ---- | M] () -- C:\Documents and Settings\Eric is The Man\Application Data\Mozilla\Firefox\Profiles\akhs435d.default\searchplugins\wikiquote-en.xml
[2009/08/15 20:53:00 | 000,000,952 | ---- | M] () -- C:\Documents and Settings\Eric is The Man\Application Data\Mozilla\Firefox\Profiles\akhs435d.default\searchplugins\youtube-video-search.xml
[2010/04/27 10:15:15 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: ([2010/04/23 18:08:35 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Tunebite_WebRipPlugin Class) - {AA102584-3B97-47e7-B9BC-75D54C110A7D} - C:\Program Files\RapidSolution\Tunebite\plugins\IE\TB_WebRipIePlugin.dll (RapidSolution Software)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O4 - HKLM..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe ()
O4 - HKLM..\Run: [MsmqIntCert] C:\WINDOWS\System32\mqrt.dll (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [RecGuard] C:\WINDOWS\SMINST\RecGuard.exe ()
O4 - HKLM..\Run: [Symantec PIF AlertEng] C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: vzTCPConfig
http://www2.verizon.net/help/fios_settings...vzTCPConfig.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Documents and Settings\Eric is The Man\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Eric is The Man\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/07/27 22:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2004/04/30 14:01:14 | 000,000,053 | -HS- | M] () - D:\AUTORUN.FCB -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...exe [@ = exefile] -- Reg Error: Key error. File not found
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2009/08/14 03:49:46 | 000,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17183584330711040)
========== Files/Folders - Created Within 90 Days ========== [2010/04/27 10:18:13 | 000,563,712 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Eric is The Man\Desktop\OTL.exe
[2010/04/26 07:42:41 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Eric is The Man\Recent
[2010/04/25 19:37:45 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2010/04/25 18:12:48 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/25 18:12:44 | 000,020,824 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/25 07:27:16 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010/04/23 18:16:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2010/04/20 14:04:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\AdobeUM
[2010/04/20 14:04:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/04/20 14:00:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Sun
[2010/04/12 22:13:17 | 000,000,000 | -H-D | C] -- C:\WINDOWS\PIF
[2010/04/12 17:50:47 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2010/04/11 13:15:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2010/04/11 13:15:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Eric is The Man\Application Data\SUPERAntiSpyware.com
[2010/04/11 13:15:44 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2010/04/11 13:15:16 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard
[2010/04/10 18:24:03 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010/04/10 17:18:38 | 000,128,016 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\kl1.sys
[2010/04/10 17:18:16 | 000,317,072 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\klif.sys
[2010/04/10 17:06:04 | 000,050,176 | ---- | C] (eSage Lab) -- C:\WINDOWS\System32\drivers\rk_remover.sys
[2010/04/10 15:32:50 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2010/04/10 15:32:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/04/10 10:47:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Eric is The Man\Application Data\Malwarebytes
[2010/04/10 10:46:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/04/10 10:46:50 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/04/10 09:23:26 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010/04/10 09:23:26 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010/04/10 09:23:26 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010/04/10 09:23:26 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010/04/10 09:23:17 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010/04/10 09:12:08 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/04/10 03:27:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Eric is The Man\My Documents\RegRun2
[2010/04/09 23:24:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/04/09 23:24:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/04/06 21:12:07 | 000,000,000 | ---D | C] -- C:\SisterFist FINALS
[2010/03/23 21:57:44 | 000,000,000 | ---D | C] -- C:\Colin Huggins
[2010/03/22 19:26:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AIM
[2010/03/22 19:25:58 | 000,000,000 | ---D | C] -- C:\Program Files\AIM
[2010/03/15 07:39:06 | 000,012,872 | ---- | C] (SurfRight B.V.) -- C:\WINDOWS\System32\bootdelete.exe
[2010/03/11 04:03:16 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\MpEngineStore
[2010/03/07 20:22:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Hitman Pro
[2010/03/07 20:22:44 | 000,000,000 | ---D | C] -- C:\Program Files\Hitman Pro 3.5
[2010/02/23 00:17:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Eric is The Man\Application Data\dvdcss
[2010/02/22 18:05:57 | 000,000,000 | ---D | C] -- C:\Program Files\Burrrn
[2010/02/15 00:12:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Eric is The Man\Application Data\Cycling '74
[2010/02/14 23:30:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Eric is The Man\Local Settings\Application Data\MediaMonkey
[2010/02/14 23:30:46 | 000,000,000 | ---D | C] -- C:\Program Files\MediaMonkey
[2010/02/02 11:31:59 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Eric is The Man\My Documents\My Dropbox
[2010/02/02 11:30:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Eric is The Man\Application Data\Dropbox
[2010/02/02 03:05:47 | 000,000,000 | ---D | C] -- C:\John Butler Trio
[2010/02/01 17:28:05 | 000,000,000 | ---D | C] -- C:\Program Files\Celebrity Toolbar
[2010/01/27 15:10:37 | 000,000,000 | ---D | C] -- C:\Jamie Lidell
[2010/01/27 15:10:17 | 000,000,000 | ---D | C] -- C:\Nicole Atkins
[2010/01/27 15:10:02 | 000,000,000 | ---D | C] -- C:\Jackie Greene
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 90 Days ========== [2010/04/27 10:25:29 | 000,001,018 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-4214705666-3317862147-3515745651-1005UA.job
[2010/04/27 10:18:15 | 000,563,712 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Eric is The Man\Desktop\OTL.exe
[2010/04/27 10:18:13 | 004,456,448 | -H-- | M] () -- C:\Documents and Settings\Eric is The Man\NTUSER.DAT
[2010/04/27 09:25:18 | 000,004,212 | -H-- | M] () -- C:\WINDOWS\System32\zllictbl.dat
[2010/04/27 09:07:29 | 000,001,447 | ---- | M] () -- C:\hpqp.ini
[2010/04/27 09:07:23 | 000,000,039 | ---- | M] () -- C:\XP_TV.ini
[2010/04/27 09:07:22 | 000,050,868 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2010/04/27 09:07:06 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/04/27 09:06:33 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/04/27 09:06:21 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/04/27 09:06:18 | 1005,170,688 | -HS- | M] () -- C:\hiberfil.sys
[2010/04/26 22:57:12 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Eric is The Man\ntuser.ini
[2010/04/26 00:24:05 | 000,000,966 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-4214705666-3317862147-3515745651-1005Core.job
[2010/04/23 18:10:49 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010/04/23 18:08:35 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010/04/22 22:35:01 | 000,016,494 | ---- | M] () -- C:\Documents and Settings\Eric is The Man\My Documents\Artists ideas.odt
[2010/04/22 16:52:32 | 003,923,062 | R--- | M] () -- C:\Documents and Settings\Eric is The Man\Desktop\schrauber.exe
[2010/04/21 00:18:26 | 000,000,644 | ---- | M] () -- C:\Documents and Settings\Eric is The Man\My Documents\cc_20100421_001819.reg
[2010/04/20 14:00:54 | 000,525,824 | ---- | M] () -- C:\Documents and Settings\Eric is The Man\Desktop\dds.scr
[2010/04/20 13:59:55 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/04/20 13:59:38 | 000,293,376 | ---- | M] () -- C:\Documents and Settings\Eric is The Man\Desktop\hh01p02y.exe
[2010/04/20 13:50:50 | 000,015,944 | ---- | M] () -- C:\WINDOWS\System32\drivers\hitmanpro35.sys
[2010/04/15 02:54:20 | 000,001,022 | ---- | M] () -- C:\Documents and Settings\Eric is The Man\My Documents\cc_20100415_025416.reg
[2010/04/12 17:50:48 | 000,001,744 | ---- | M] () -- C:\Documents and Settings\Eric is The Man\Desktop\HijackThis.lnk
[2010/04/10 18:49:02 | 000,005,574 | ---- | M] () -- C:\Documents and Settings\Eric is The Man\My Documents\cc_20100410_184900.reg
[2010/04/10 18:24:20 | 000,000,293 | RHS- | M] () -- C:\boot.ini
[2010/04/10 17:18:05 | 000,421,484 | ---- | M] () -- C:\WINDOWS\System32\vsconfig.xml
[2010/04/10 17:10:49 | 000,050,176 | ---- | M] (eSage Lab) -- C:\WINDOWS\System32\drivers\rk_remover.sys
[2010/04/10 15:19:01 | 000,011,812 | ---- | M] () -- C:\Documents and Settings\Eric is The Man\My Documents\cc_20100410_151858.reg
[2010/04/10 13:55:14 | 000,000,000 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\N8NHc
[2010/04/10 10:18:37 | 000,000,796 | ---- | M] () -- C:\Documents and Settings\Eric is The Man\My Documents\cc_20100410_101817.reg
[2010/04/10 09:21:00 | 000,000,223 | ---- | M] () -- C:\Boot.bak
[2010/04/10 09:20:59 | 000,000,461 | ---- | M] () -- C:\WINDOWS\win.ini
[2010/04/10 04:15:03 | 000,870,128 | ---- | M] () -- C:\Documents and Settings\Eric is The Man\Application Data\mcs.rma
[2010/04/10 04:15:03 | 000,000,004 | ---- | M] () -- C:\Documents and Settings\Eric is The Man\Application Data\F97BF5
[2010/04/10 03:27:20 | 000,002,577 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2010/04/10 03:27:20 | 000,001,688 | ---- | M] () -- C:\WINDOWS\System32\AUTOEXEC.NT
[2010/04/10 03:27:20 | 000,000,002 | RHS- | M] () -- C:\WINDOWS\winstart.bat
[2010/04/09 23:28:06 | 000,001,666 | ---- | M] () -- C:\Documents and Settings\Eric is The Man\My Documents\cc_20100409_232802.reg
[2010/04/04 10:30:51 | 000,012,872 | ---- | M] (SurfRight B.V.) -- C:\WINDOWS\System32\bootdelete.exe
[2010/04/01 00:55:54 | 000,012,404 | -HS- | M] () -- C:\Documents and Settings\Eric is The Man\Local Settings\Application Data\4NXd80
[2010/04/01 00:55:54 | 000,012,404 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\4NXd80
[2010/03/30 11:50:51 | 000,002,964 | ---- | M] () -- C:\Documents and Settings\Eric is The Man\My Documents\cc_20100330_115046.reg
[2010/03/30 00:46:30 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/03/30 00:45:52 | 000,020,824 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/03/22 19:26:31 | 000,000,920 | -H-- | M] () -- C:\IPH.PH
[2010/03/22 19:21:45 | 000,006,332 | ---- | M] () -- C:\Documents and Settings\Eric is The Man\My Documents\Awaymessage.reg
[2010/03/21 15:18:11 | 000,453,442 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/03/21 15:18:11 | 000,391,638 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/03/21 15:18:11 | 000,056,124 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/03/14 16:25:22 | 000,017,408 | ---- | M] () -- C:\Documents and Settings\Eric is The Man\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/12 18:02:38 | 000,261,632 | ---- | M] () -- C:\WINDOWS\PEV.exe
[2010/03/11 04:03:16 | 000,000,127 | ---- | M] () -- C:\WINDOWS\System32\MRT.INI
[2010/03/07 22:37:47 | 000,065,770 | ---- | M] () -- C:\Documents and Settings\Eric is The Man\My Documents\cc_20100307_213742.reg
[2010/03/07 20:27:30 | 000,000,788 | ---- | M] () -- C:\WINDOWS\System32\.crusader
[2010/03/02 00:02:32 | 000,001,047 | ---- | M] () -- C:\WINDOWS\cdplayer.ini
[2010/02/27 00:50:51 | 000,473,552 | ---- | M] () -- C:\Documents and Settings\Eric is The Man\My Documents\bad night.html
[2010/02/17 20:30:10 | 000,015,483 | ---- | M] () -- C:\Documents and Settings\Eric is The Man\My Documents\Two Headed Boy.odt
[2010/02/14 23:27:46 | 000,001,798 | ---- | M] () -- C:\Documents and Settings\Eric is The Man\My Documents\cc_20100214_222743.reg
[2010/02/14 20:11:02 | 000,018,191 | ---- | M] () -- C:\Documents and Settings\Eric is The Man\My Documents\up on cripple creek.odt
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ========== [2010/04/22 22:25:21 | 000,016,494 | ---- | C] () -- C:\Documents and Settings\Eric is The Man\My Documents\Artists ideas.odt
[2010/04/22 16:52:32 | 003,923,062 | R--- | C] () -- C:\Documents and Settings\Eric is The Man\Desktop\schrauber.exe
[2010/04/21 00:18:21 | 000,000,644 | ---- | C] () -- C:\Documents and Settings\Eric is The Man\My Documents\cc_20100421_001819.reg
[2010/04/20 14:00:37 | 000,525,824 | ---- | C] () -- C:\Documents and Settings\Eric is The Man\Desktop\dds.scr
[2010/04/20 13:59:19 | 000,293,376 | ---- | C] () -- C:\Documents and Settings\Eric is The Man\Desktop\hh01p02y.exe
[2010/04/15 02:54:18 | 000,001,022 | ---- | C] () -- C:\Documents and Settings\Eric is The Man\My Documents\cc_20100415_025416.reg
[2010/04/12 17:50:48 | 000,001,744 | ---- | C] () -- C:\Documents and Settings\Eric is The Man\Desktop\HijackThis.lnk
[2010/04/10 18:49:01 | 000,005,574 | ---- | C] () -- C:\Documents and Settings\Eric is The Man\My Documents\cc_20100410_184900.reg
[2010/04/10 18:24:18 | 000,000,223 | ---- | C] () -- C:\Boot.bak
[2010/04/10 18:24:09 | 000,260,272 | ---- | C] () -- C:\cmldr
[2010/04/10 15:19:00 | 000,011,812 | ---- | C] () -- C:\Documents and Settings\Eric is The Man\My Documents\cc_20100410_151858.reg
[2010/04/10 13:55:14 | 000,000,000 | -HS- | C] () -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\N8NHc
[2010/04/10 13:55:14 | 000,000,000 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\N8NHc
[2010/04/10 10:18:28 | 000,000,796 | ---- | C] () -- C:\Documents and Settings\Eric is The Man\My Documents\cc_20100410_101817.reg
[2010/04/10 09:23:26 | 000,261,632 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/04/10 09:23:26 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/04/10 09:23:26 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/04/10 09:23:26 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/04/10 09:23:26 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/04/10 03:27:20 | 000,000,002 | RHS- | C] () -- C:\WINDOWS\winstart.bat
[2010/04/09 23:28:04 | 000,001,666 | ---- | C] () -- C:\Documents and Settings\Eric is The Man\My Documents\cc_20100409_232802.reg
[2010/04/01 00:53:44 | 000,012,404 | -HS- | C] () -- C:\Documents and Settings\Eric is The Man\Local Settings\Application Data\4NXd80
[2010/04/01 00:53:44 | 000,012,404 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\4NXd80
[2010/03/30 11:50:50 | 000,002,964 | ---- | C] () -- C:\Documents and Settings\Eric is The Man\My Documents\cc_20100330_115046.reg
[2010/03/22 19:21:45 | 000,006,332 | ---- | C] () -- C:\Documents and Settings\Eric is The Man\My Documents\Awaymessage.reg
[2010/03/11 04:03:16 | 000,000,127 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2010/03/07 22:37:44 | 000,065,770 | ---- | C] () -- C:\Documents and Settings\Eric is The Man\My Documents\cc_20100307_213742.reg
[2010/03/07 20:27:30 | 000,000,788 | ---- | C] () -- C:\WINDOWS\System32\.crusader
[2010/03/07 20:22:56 | 000,015,944 | ---- | C] () -- C:\WINDOWS\System32\drivers\hitmanpro35.sys
[2010/02/27 00:50:51 | 000,473,552 | ---- | C] () -- C:\Documents and Settings\Eric is The Man\My Documents\bad night.html
[2010/02/17 20:13:37 | 000,015,483 | ---- | C] () -- C:\Documents and Settings\Eric is The Man\My Documents\Two Headed Boy.odt
[2010/02/14 23:27:44 | 000,001,798 | ---- | C] () -- C:\Documents and Settings\Eric is The Man\My Documents\cc_20100214_222743.reg
[2010/02/14 20:11:00 | 000,018,191 | ---- | C] () -- C:\Documents and Settings\Eric is The Man\My Documents\up on cripple creek.odt
[2009/12/08 22:44:38 | 000,000,038 | ---- | C] () -- C:\WINDOWS\entpack.ini
[2009/11/14 12:06:11 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\PdeSrvps.dll
[2009/09/06 11:51:34 | 000,796,048 | ---- | C] () -- C:\WINDOWS\System32\libeay32_0.9.6l.dll
[2009/08/18 20:22:24 | 000,001,047 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2008/06/18 14:59:56 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2006/08/06 04:56:01 | 000,000,174 | ---- | C] () -- C:\WINDOWS\QUICKEN.INI
[2006/08/06 04:53:16 | 000,000,698 | ---- | C] () -- C:\WINDOWS\NSSetDefaultBrowser.ini
[2006/08/06 04:25:19 | 000,028,836 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2006/08/06 04:11:47 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/08/06 01:50:29 | 000,016,480 | ---- | C] () -- C:\WINDOWS\System32\rixdicon.dll
[2006/08/06 01:50:17 | 001,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2006/08/06 01:50:17 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2006/08/06 01:50:16 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2006/08/06 01:50:15 | 001,466,368 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2006/08/06 01:50:15 | 000,098,304 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2006/03/27 12:54:36 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/03/27 12:18:52 | 000,000,059 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2006/03/27 12:15:14 | 000,000,791 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2006/01/30 10:00:00 | 000,106,496 | ---- | C] () -- C:\WINDOWS\System32\VSHP1018.DLL
[2005/12/02 14:09:10 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
========== LOP Check ========== [2009/08/14 02:37:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\acccore
[2010/03/22 19:26:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AIM
[2009/08/15 23:42:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Azureus
[2010/03/07 20:27:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Hitman Pro
[2009/11/11 11:46:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Kaspersky SDK
[2009/09/06 12:24:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MailFrontier
[2009/11/09 23:09:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RapidSolution
[2010/03/25 02:56:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Retrospect
[2009/08/14 01:34:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Seagate
[2010/04/10 10:52:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/09/09 18:27:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/08/14 02:47:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/08/14 02:39:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eric is The Man\Application Data\acccore
[2010/04/10 10:16:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eric is The Man\Application Data\Azureus
[2010/02/15 00:12:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eric is The Man\Application Data\Cycling '74
[2010/04/21 00:13:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eric is The Man\Application Data\Dropbox
[2009/09/06 11:59:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eric is The Man\Application Data\MailFrontier
[2009/09/05 22:57:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eric is The Man\Application Data\OpenOffice.org
[2010/03/27 17:26:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eric is The Man\Application Data\Thunderbird
[2009/10/05 00:26:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eric is The Man\Application Data\X-Chat 2
========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.exe > < MD5 for: AGP440.SYS >[2004/08/04 09:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\I386\sp2.cab:AGP440.sys
[2004/08/04 17:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2009/09/08 22:12:43 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2009/09/08 22:12:43 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 14:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2004/08/04 11:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
[2004/08/04 11:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\ERDNT\cache\agp440.sys
[2004/08/04 11:07:42 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS\system32\drivers\agp440.sys
< MD5 for: ATAPI.SYS >[2004/08/04 09:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\I386\sp2.cab:atapi.sys
[2004/08/04 17:00:00 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2009/09/08 22:12:43 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2009/09/08 22:12:43 | 023,852,652 | ---- | M] () .cab file -- C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/04 10:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2004/08/04 10:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\ReinstallBackups\0009\DriverFiles\i386\atapi.sys
< MD5 for: EVENTLOG.DLL >[2008/04/13 20:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008/04/13 20:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 20:11:53 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll
[2004/08/04 17:00:00 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: IASTOR.SYS >[2005/10/13 05:07:12 | 000,874,240 | ---- | M] (Intel Corporation) MD5=309C4D86D989FB1FCF64BD30DC81C51B -- C:\SwSetup\HDD\iastor.sys
[2005/10/13 05:07:12 | 000,874,240 | ---- | M] (Intel Corporation) MD5=309C4D86D989FB1FCF64BD30DC81C51B -- C:\WINDOWS\system32\drivers\iaStor.sys
< MD5 for: NETLOGON.DLL >[2008/04/13 20:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008/04/13 20:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 20:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll
[2009/02/06 14:46:09 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[2004/08/04 17:00:00 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\$NtUninstallKB968389_0$\netlogon.dll
< MD5 for: NVATA.SYS >[2006/01/27 11:04:16 | 000,099,584 | ---- | M] (NVIDIA Corporation) MD5=3AC5EEDD35B7437D53960F3998BFA462 -- C:\SwSetup\chipset\IDE\Win2K\sata_ide\nvata.sys
[2006/01/27 11:04:16 | 000,099,584 | ---- | M] (NVIDIA Corporation) MD5=3AC5EEDD35B7437D53960F3998BFA462 -- C:\SwSetup\chipset\IDE\WinXP\sata_ide\nvata.sys
[2006/01/27 11:04:16 | 000,099,584 | ---- | M] (NVIDIA Corporation) MD5=3AC5EEDD35B7437D53960F3998BFA462 -- C:\SwSetup\chipset\nvata.sys
[2006/01/27 11:04:16 | 000,099,584 | ---- | M] (NVIDIA Corporation) MD5=3AC5EEDD35B7437D53960F3998BFA462 -- C:\WINDOWS\system32\drivers\nvata.sys
< MD5 for: NVATABUS.SYS >[2006/01/27 11:04:16 | 000,099,584 | ---- | M] (NVIDIA Corporation) MD5=3AC5EEDD35B7437D53960F3998BFA462 -- C:\SwSetup\chipset\IDE\Win2K\sataraid\nvatabus.sys
[2006/01/27 11:04:16 | 000,099,584 | ---- | M] (NVIDIA Corporation) MD5=3AC5EEDD35B7437D53960F3998BFA462 -- C:\SwSetup\chipset\IDE\WinXP\sataraid\nvatabus.sys
[2006/01/27 11:04:16 | 000,099,584 | ---- | M] (NVIDIA Corporation) MD5=3AC5EEDD35B7437D53960F3998BFA462 -- C:\SwSetup\chipset\nvatabus.sys
< MD5 for: SCECLI.DLL >[2004/08/04 17:00:00 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll
< %systemroot%\*. /mp /s > < %systemroot%\system32\*.dll /lockedfiles >[2008/04/13 20:12:00 | 001,384,479 | ---- | M] (Microsoft Corporation)
Unable to obtain MD5 -- C:\WINDOWS\system32\msvbvm60.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles > < %systemroot%\system32\drivers\*.sys /lockedfiles > < %systemroot%\System32\config\*.sav >[2006/03/27 03:47:52 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2006/03/27 03:47:52 | 000,659,456 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
< End of report >