Here's OTViewIt Logfile:
OTViewIt logfile created on: 11/4/2008 12:30:38 PM - Run
OTViewIt by OldTimer - Version 1.0.20.0 Folder = D:\Documents and Settings\decastro\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1015.23 Mb Total Physical Memory | 607.76 Mb Available Physical Memory | 59.86% Memory free
2.39 Gb Paging File | 2.00 Gb Available in Paging File | 83.79% Paging File free
Paging file location(s): D:\pagefile.sys 1524 3048;
%SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files
Drive C: | 39.06 Gb Total Space | 26.51 Gb Free Space | 67.86% Space Free | Partition Type: NTFS
Drive D: | 35.46 Gb Total Space | 22.64 Gb Free Space | 63.85% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DECASTRO-96A801
Current User Name: decastro
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days
========== Processes ==========
[2008/10/27 18:12:58 | 00,611,664 | ---- | M] (Lavasoft) -- D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
[2008/07/19 06:25:06 | 00,016,056 | ---- | M] (ALWIL Software) -- D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
[2008/07/19 06:38:28 | 00,147,640 | ---- | M] (ALWIL Software) -- D:\Program Files\Alwil Software\Avast4\ashServ.exe
[2008/07/19 06:38:34 | 00,078,008 | ---- | M] (ALWIL Software) -- D:\Program Files\Alwil Software\Avast4\ashDisp.exe
[2008/06/10 03:27:04 | 00,144,784 | ---- | M] (Sun Microsystems, Inc.) -- D:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
[2007/11/22 00:40:32 | 16,858,112 | R--- | M] (Realtek Semiconductor Corp.) -- D:\WINDOWS\RTHDCPL.exe
[2006/11/23 14:10:42 | 00,056,928 | ---- | M] (Cyberlink Corp.) -- C:\CyberLink\PowerDVD\PDVDServ.exe
[2007/01/12 17:46:36 | 00,135,168 | R--- | M] (Intel Corporation) -- D:\WINDOWS\system32\igfxpers.exe
[2008/09/10 16:40:06 | 00,289,576 | ---- | M] (Apple Inc.) -- D:\Program Files\iTunes\iTunesHelper.exe
[2007/01/12 17:47:04 | 00,163,840 | R--- | M] (Intel Corporation) -- D:\WINDOWS\system32\hkcmd.exe
[2008/01/11 21:16:38 | 00,039,792 | ---- | M] (Adobe Systems Incorporated) -- D:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
[2004/08/04 04:00:00 | 00,151,552 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\system32\wscript.exe
[2008/07/07 07:46:45 | 00,416,768 | ---- | M] (Stardock Corporation) -- D:\Program Files\Stardock\CursorFX\CursorFX.exe
[2008/09/10 15:50:26 | 00,116,040 | ---- | M] (Apple Inc.) -- D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
[2008/08/29 09:18:44 | 00,238,888 | ---- | M] (Apple Inc.) -- D:\Program Files\Bonjour\mDNSResponder.exe
[2007/11/27 14:38:04 | 00,695,136 | ---- | M] (National Instruments, Inc.) -- D:\WINDOWS\system32\lkcitdl.exe
[2007/11/27 12:56:48 | 00,040,488 | ---- | M] (National Instruments Corporation) -- D:\WINDOWS\system32\lkads.exe
[2007/11/27 12:57:20 | 00,050,736 | ---- | M] (National Instruments Corporation) -- D:\WINDOWS\system32\lktsrv.exe
[2007/11/27 12:57:52 | 00,213,552 | ---- | M] (National Instruments Corporation) -- D:\Program Files\National Instruments\Shared\Security\nidmsrv.exe
[2007/07/19 15:38:16 | 00,048,704 | ---- | M] (National Instruments Corp.) -- D:\WINDOWS\system32\nisvcloc.exe
[2005/08/07 05:54:00 | 00,167,936 | ---- | M] () -- D:\Program Files\CyberLink\Shared Files\RichVideo.exe
[2004/08/04 04:00:00 | 00,013,824 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\system32\wscntfy.exe
[2008/07/19 06:38:04 | 00,250,040 | ---- | M] (ALWIL Software) -- D:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
[2008/07/23 06:25:45 | 00,348,344 | ---- | M] (ALWIL Software) -- D:\Program Files\Alwil Software\Avast4\ashWebSv.exe
[2008/09/10 16:39:48 | 00,536,872 | ---- | M] (Apple Inc.) -- D:\Program Files\iPod\bin\iPodService.exe
[2008/08/03 15:04:00 | 01,345,376 | ---- | M] (Nullsoft) -- D:\Program Files\Winamp\winamp.exe
[2004/08/04 04:00:00 | 00,111,104 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\system32\wuauclt.exe
[2008/09/28 12:33:45 | 00,307,712 | ---- | M] (Mozilla Corporation) -- D:\Program Files\Mozilla Firefox\firefox.exe
[2008/11/04 12:29:28 | 00,422,400 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\decastro\Desktop\OTViewIt.exe
========== (O23) Win32 Services ==========
[2008/10/27 18:12:58 | 00,611,664 | ---- | M] (Lavasoft) -- D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe -- (aawservice [Auto | Running])
[2008/09/10 15:50:26 | 00,116,040 | ---- | M] (Apple Inc.) -- D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running])
[2005/09/23 06:28:32 | 00,029,896 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
[2008/07/19 06:25:06 | 00,016,056 | ---- | M] (ALWIL Software) -- D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv [Auto | Running])
[2008/07/19 06:38:28 | 00,147,640 | ---- | M] (ALWIL Software) -- D:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus [Auto | Running])
[2008/07/19 06:38:04 | 00,250,040 | ---- | M] (ALWIL Software) -- D:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner [On_Demand | Running])
[2008/07/23 06:25:45 | 00,348,344 | ---- | M] (ALWIL Software) -- D:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner [On_Demand | Running])
[2008/08/29 09:18:44 | 00,238,888 | ---- | M] (Apple Inc.) -- D:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service [Auto | Running])
[2005/09/23 06:28:56 | 00,066,240 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
[2008/09/10 16:39:48 | 00,536,872 | ---- | M] (Apple Inc.) -- D:\Program Files\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Running])
[2007/11/27 14:38:04 | 00,695,136 | ---- | M] (National Instruments, Inc.) -- D:\WINDOWS\system32\lkcitdl.exe -- (LkCitadelServer [Auto | Running])
[2007/11/27 12:56:48 | 00,040,488 | ---- | M] (National Instruments Corporation) -- D:\WINDOWS\system32\lkads.exe -- (lkClassAds [Auto | Running])
[2007/11/27 12:57:20 | 00,050,736 | ---- | M] (National Instruments Corporation) -- D:\WINDOWS\system32\lktsrv.exe -- (lkTimeSync [Auto | Running])
[2007/11/27 12:57:52 | 00,213,552 | ---- | M] (National Instruments Corporation) -- D:\Program Files\National Instruments\Shared\Security\nidmsrv.exe -- (NIDomainService [Auto | Running])
[2007/01/29 14:19:48 | 01,007,616 | ---- | M] (Macrovision Corporation) -- D:\Program Files\National Instruments\Shared\License Manager\Bin\lmgrd.exe -- (NILM License Manager [On_Demand | Stopped])
[2007/07/19 15:38:16 | 00,048,704 | ---- | M] (National Instruments Corp.) -- D:\WINDOWS\system32\nisvcloc.exe -- (niSvcLoc [Auto | Running])
[2004/03/31 16:55:24 | 00,172,544 | ---- | M] (INCA Internet Co., Ltd.) -- D:\WINDOWS\system32\npkcsvc.exe -- (npkcsvc [Auto | Stopped])
[2003/07/28 11:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
[2005/08/07 05:54:00 | 00,167,936 | ---- | M] () -- D:\Program Files\CyberLink\Shared Files\RichVideo.exe -- (RichVideo [Auto | Running])
[2006/10/18 20:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])
========== Driver Services ==========
[2008/07/19 06:32:15 | 00,026,944 | ---- | M] (ALWIL Software) -- D:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4 [System | Running])
[2008/09/17 21:22:04 | 00,021,035 | ---- | M] (Meetinghouse Data Communications) -- D:\WINDOWS\system32\drivers\AegisP.sys -- (AegisP [Auto | Running])
[2008/07/19 06:37:42 | 00,020,560 | ---- | M] (ALWIL Software) -- D:\WINDOWS\system32\drivers\aswFsBlk.sys -- (aswFsBlk [Auto | Running])
[2008/07/19 06:37:21 | 00,094,416 | ---- | M] (ALWIL Software) -- D:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2 [Auto | Running])
[2008/07/19 06:33:42 | 00,023,152 | ---- | M] (ALWIL Software) -- D:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr [On_Demand | Running])
[2008/07/19 06:35:18 | 00,078,416 | ---- | M] (ALWIL Software) -- D:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP [System | Running])
[2008/07/19 06:32:36 | 00,042,912 | ---- | M] (ALWIL Software) -- D:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi [System | Running])
[2007/10/23 09:00:00 | 00,004,096 | ---- | M] () -- D:\WINDOWS\System32\drivers\cvintdrv.sys -- (cvintdrv [Auto | Running])
[2008/04/17 12:12:54 | 00,015,464 | ---- | M] (GEAR Software Inc.) -- D:\WINDOWS\system32\drivers\GEARAspiWDM.sys -- (GEARAspiWDM [On_Demand | Running])
[2005/01/07 16:07:18 | 00,138,752 | ---- | M] (Windows ® Server 2003 DDK provider) -- D:\WINDOWS\system32\drivers\Hdaudbus.sys -- (HDAudBus [On_Demand | Running])
[2007/01/12 18:33:18 | 05,672,032 | R--- | M] (Intel Corporation) -- D:\WINDOWS\system32\drivers\igxpmp32.sys -- (ialm [On_Demand | Running])
[2007/11/27 04:06:42 | 04,630,016 | R--- | M] (Realtek Semiconductor Corp.) -- D:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService [On_Demand | Running])
[2001/08/17 05:51:32 | 00,018,688 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\system32\drivers\irsir.sys -- (irsir [On_Demand | Running])
[2004/12/27 13:16:58 | 00,021,442 | ---- | M] (INCA Internet Co., Ltd.) -- D:\WINDOWS\system32\npkcrypt.sys -- (npkcrypt [On_Demand | Stopped])
[2004/08/04 04:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- D:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink [On_Demand | Running])
[2007/03/07 15:51:00 | 00,043,528 | ---- | M] (Sonic Solutions) -- D:\WINDOWS\system32\drivers\PxHelp20.sys -- (PxHelp20 [Boot | Running])
[2007/10/23 02:51:04 | 00,103,296 | R--- | M] (Realtek Semiconductor Corporation ) -- D:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp [On_Demand | Running])
[2008/09/03 14:07:14 | 00,008,944 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) -- D:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV [System | Running])
[2008/09/03 14:07:16 | 00,007,408 | R--- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) -- D:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM [On_Demand | Running])
[2008/09/03 14:07:12 | 00,055,024 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) -- D:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL [System | Running])
[2004/08/04 04:00:00 | 00,027,440 | ---- | M] () -- D:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv [On_Demand | Stopped])
========== (R ) Internet Explorer ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
"Default_Search_URL"=http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
"Search Page"=http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
"Start Page"=http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search]
"CustomizeSearch"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
"CustomSearch"=http://us.rd.yahoo.com/customize/ie/defaults/cs/msgr8/*http://www.yahoo.com/ext/search/search.html
"SearchAssistant"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main]
"Page_Transitions"=
"Search Page"=http://www.redtube.com/
"Start Page"=http://www.redtube.com/
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURL]
""=http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
"provider"=yaho
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- D:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation)
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
"ProxyOverride" = *.local
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main]
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main]
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main]
[HKEY_USERS\S-1-5-21-1614895754-1343024091-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Main]
"Page_Transitions"=
"Search Page"=http://www.redtube.com/
"Start Page"=http://www.redtube.com/
[HKEY_USERS\S-1-5-21-1614895754-1343024091-839522115-1003\Software\Microsoft\Internet Explorer\SearchURL]
""=http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
"provider"=yaho
[HKEY_USERS\S-1-5-21-1614895754-1343024091-839522115-1003\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- D:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-1614895754-1343024091-839522115-1003\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
[HKEY_USERS\S-1-5-21-1614895754-1343024091-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
"ProxyOverride" = *.local
========== (O1) Hosts File ==========
HOSTS File = (801 bytes) - D:\WINDOWS\System32\drivers\etc\Hosts
First 25 entries...
127.0.0.1 localhost
66.98.148.65 auto.search.msn.com
66.98.148.65 auto.search.msn.es
========== (O2) BHO's ==========
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\]
{02478D38-C3F9-4efb-9B51-7695ECA05670} (HKLM) -- D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (HKLM) -- D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} (HKLM) -- D:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (HKLM) -- D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
========== (O3) Toolbars ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{D2F8F919-690B-4EA2-9FA7-A203D1E04F75}" (HKLM) -- D:\Program Files\Styler\TB\StylerTB.dll (StyleFantasist)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
[HKEY_USERS\S-1-5-21-1614895754-1343024091-839522115-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- D:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
========== (O4) Run Keys ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
"Alcmtr"=ALCMTR.EXE (Realtek Semiconductor Corp.)
"avast!"=D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
"HotKeysCmds"=D:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
"IgfxTray"=D:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
"iTunesHelper"="D:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
"LanguageShortcut"=C:\CyberLink\PowerDVD\Language\Language.exe ()
"NI Background Service"=D:\Program Files\National Instruments\Shared\Update Service\BackgroundService.exe (National Instruments)
"Persistence"=D:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
"QuickTime Task"="D:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
"RawOs"=wscript.exe "D:\WINDOWS\sowar.vbs" (Microsoft Corporation)
"RemoteControl"=C:\CyberLink\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
"RTHDCPL"=RTHDCPL.EXE (Realtek Semiconductor Corp.)
"SunJavaUpdateSched"="D:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" (Sun Microsystems, Inc.)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CursorFX"="D:\Program Files\Stardock\CursorFX\CursorFX.exe" (Stardock Corporation)
"SUPERAntiSpyware"=D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
"Yahoo! Pager"="D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (Yahoo! Inc.)
[HKEY_USERS\S-1-5-21-1614895754-1343024091-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CursorFX"="D:\Program Files\Stardock\CursorFX\CursorFX.exe" (Stardock Corporation)
"SUPERAntiSpyware"=D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
"Yahoo! Pager"="D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (Yahoo! Inc.)
========== (O4) Startup Folders ==========
[2007/12/14 16:39:22 | 00,978,944 | ---- | M] (AzureWave.com) -- D:\Documents and Settings\All Users\Start Menu\Programs\Startup\ASRock WiFi-802.11g.lnk = D:\Program Files\ASRock WiFi-802.11g\RtWLan.exe
[2007/11/08 10:28:54 | 01,224,704 | ---- | M] (ASRock Inc.) -- D:\Documents and Settings\All Users\Start Menu\Programs\Startup\ASRock WiFi-802.11n Utility.lnk = D:\Program Files\ASRock\WiFi-802.11n\WiFi-80211n.exe
[2008/01/21 15:41:28 | 00,393,216 | ---- | M] () -- D:\Documents and Settings\decastro\Start Menu\Programs\Startup\OpenOffice.org 2.4.lnk = D:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
========== (O6 & O7) Current Version Policies ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=128
"NoDriveAutoRun"=FF FF FF FF [binary data]
"NoFolderOptions"=1
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"DisableRegistryTools"=1
"DisableTaskMgr"=1
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=149
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=149
[HKEY_USERS\S-1-5-21-1614895754-1343024091-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=128
"NoDriveAutoRun"=FF FF FF FF [binary data]
"NoFolderOptions"=1
[HKEY_USERS\S-1-5-21-1614895754-1343024091-839522115-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"DisableRegistryTools"=1
"DisableTaskMgr"=1
========== (O8) IE Context Menu Extensions ==========
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: D:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE [2003/08/13 01:34:38 | 10,073,144 | ---- | M] (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-1614895754-1343024091-839522115-1003\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: D:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE [2003/08/13 01:34:38 | 10,073,144 | ---- | M] (Microsoft Corporation)
========== (O9) IE Extensions ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}: Menu: Sun Java Console -- %ProgramFiles%\Java\jre1.6.0_04\bin\npjpi160_04.dll [2007/12/14 02:42:37 | 00,132,496 | ---- | M] (Sun Microsystems, Inc.)
{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}: Button: Yahoo! Services -- %ProgramFiles%\Yahoo!\Common\yiesrvc.dll [2007/12/12 14:09:42 | 00,222,448 | ---- | M] (Yahoo! Inc.)
{92780B25-18CC-41C8-B9BE-3C9C571A8263}: Button: Research -- %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [2003/07/14 21:57:08 | 00,040,512 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Button: Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2004/08/04 00:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Menu: Windows Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2004/08/04 00:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_04\bin\npjpi160_04.dll [Sun Java Console] -> [2007/12/14 02:42:37 | 00,132,496 | ---- | M] (Sun Microsystems, Inc.)
CmdMapping\\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} [HKLM] -> %ProgramFiles%\Yahoo!\Common\yiesrvc.dll [Yahoo! IE Services Button] -> [2007/12/12 14:09:42 | 00,222,448 | ---- | M] (Yahoo! Inc.)
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2003/07/14 21:57:08 | 00,040,512 | ---- | M] (Microsoft Corporation)
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/08/04 00:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation)
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/08/04 00:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation)
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/08/04 00:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-1614895754-1343024091-839522115-1003\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_04\bin\npjpi160_04.dll [Sun Java Console] -> [2007/12/14 02:42:37 | 00,132,496 | ---- | M] (Sun Microsystems, Inc.)
CmdMapping\\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} [HKLM] -> %ProgramFiles%\Yahoo!\Common\yiesrvc.dll [Yahoo! IE Services Button] -> [2007/12/12 14:09:42 | 00,222,448 | ---- | M] (Yahoo! Inc.)
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2003/07/14 21:57:08 | 00,040,512 | ---- | M] (Microsoft Corporation)
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2004/08/04 00:06:34 | 01,667,584 | ---- | M] (Microsoft Corporation)
========== (O12) Internet Explorer Plugins ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\]
PluginsPage: "" =
http://activex.microsoft.com/controls/find...=%s&mime=%s
PluginsPageFriendlyName: "" = Microsoft ActiveX Gallery
========== (O13) Default Prefixes ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
""=http://
========== (O15) Trusted Sites ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
1 domain(s) and sub-domain(s) not assigned to a zone.
========== (O16) DPF ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\]
{30528230-99f7-4bb4-88d8-fa1d4f56a2ab}: D:\Program Files\Yahoo!\Common\Yinsthelper.dll -- Installation Support
{8AD9C840-044E-11D1-B3E9-00805F499D93}:
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_07
{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}:
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_04
{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_07
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}:
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_07
{D6FCA8ED-4715-43DE-9BD2-2789778A5B09}:
https://my.levelupgames.ph/keycrypt/npkcx.cab -- NPKCX Control
========== (O17) DNS Name Servers ==========
{F6300C1A-8EBE-4B96-AED4-C0230E891A73} (Servers: | Description: Realtek RTL8139/810x Family Fast Ethernet NIC)
========== (O20) HKLM Winlogon Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"UIHost"=vistaui.exe
>[2007/04/15 00:30:58 | 06,181,376 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\system32\vistaui.exe
========== (O20) Winlogon Notify Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\]
!SASWinLogon: "DllName" = D:\Program Files\SUPERAntiSpyware\SASWINLO.dll -- D:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
igfxcui: "DllName" = igfxdev.dll -- D:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
========== Shell Execute Hooks ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}" (HKLM) -- D:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
========== Safeboot Options ==========
"AlternateShell"=cmd.exe
========== CDRom AutoRun Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1
========== Autorun Files on Drives ==========
AUTOEXEC.BAT []
[2008/09/13 12:11:05 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT -- [ NTFS ]
autorun.inf []
[2008/10/31 15:30:04 | 00,000,000 | ---D | M] -- C:\autorun.inf -- [ NTFS ]
autorun.inf []
[2008/10/30 01:05:57 | 00,000,000 | ---D | M] -- D:\autorun.inf -- [ NTFS ]
AutoRuns []
[2008/10/30 01:00:22 | 00,000,000 | ---D | M] -- D:\AutoRuns -- [ NTFS ]
========== MountPoints2 ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2b979450-8f76-11dd-864b-00196669f170}\Shell\AutoRun\command]
""=ms-dos\ntdlr.com
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2b979450-8f76-11dd-864b-00196669f170}\Shell\Explore\command]
""=ms-dos\ntdlr.com
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2b979450-8f76-11dd-864b-00196669f170}\Shell\Open\command]
""=ms-dos\ntdlr.com
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2b979451-8f76-11dd-864b-00196669f170}\Shell\AutoRun\command]
""=ms-dos\ntdlr.com
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2b979451-8f76-11dd-864b-00196669f170}\Shell\Explore\command]
""=ms-dos\ntdlr.com
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2b979451-8f76-11dd-864b-00196669f170}\Shell\Open\command]
""=ms-dos\ntdlr.com
========== Files/Folders - Created Within 30 Days ==========
[2008/11/04 12:29:14 | 00,422,400 | ---- | C] (OldTimer Tools) -- D:\Documents and Settings\decastro\Desktop\OTViewIt.exe
[2008/11/03 18:37:44 | 00,021,504 | ---- | C] () -- D:\Documents and Settings\decastro\My Documents\a href2.doc
[2008/11/03 15:15:00 | 00,019,968 | ---- | C] () -- D:\Documents and Settings\decastro\My Documents\012.doc
[2008/11/03 15:12:11 | 00,019,968 | ---- | C] () -- D:\Documents and Settings\decastro\My Documents\Ñ.doc
[2008/11/03 10:16:23 | 00,020,480 | ---- | C] () -- D:\Documents and Settings\decastro\My Documents\a href1.doc
[2008/10/30 00:58:29 | 00,000,000 | ---D | C] -- D:\AutoRuns
[2008/10/29 06:08:58 | 00,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2008/10/29 06:08:52 | 00,000,780 | ---- | C] () -- D:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2008/10/29 06:08:51 | 00,000,000 | ---D | C] -- D:\Program Files\SUPERAntiSpyware
[2008/10/29 06:08:51 | 00,000,000 | ---D | C] -- D:\Documents and Settings\decastro\Application Data\SUPERAntiSpyware.com
[2008/10/28 06:46:23 | 03,863,808 | ---- | C] (ESET) -- D:\Documents and Settings\decastro\Desktop\SysInspector.exe
[2008/10/27 18:11:54 | 00,000,793 | ---- | C] () -- D:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2008/10/27 18:11:48 | 00,000,000 | ---D | C] -- D:\Program Files\Lavasoft
[2008/10/27 18:11:46 | 00,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\Lavasoft
[2008/10/27 18:10:43 | 00,000,000 | ---D | C] -- D:\Program Files\Common Files\Wise Installation Wizard
[2008/10/27 17:25:41 | 00,000,000 | ---D | C] -- D:\autorun.inf
[2008/10/27 15:21:08 | 00,132,597 | ---- | C] () -- D:\Documents and Settings\decastro\Desktop\Flash_Disinfector.exe
[2008/10/27 14:34:09 | 00,001,734 | ---- | C] () -- D:\Documents and Settings\decastro\Desktop\HijackThis.lnk
[2008/10/27 14:34:09 | 00,000,000 | ---D | C] -- D:\Program Files\Trend Micro
[2008/10/27 14:33:34 | 00,000,000 | ---D | C] -- D:\Documents and Settings\decastro\Application Data\Malwarebytes
[2008/10/27 14:33:32 | 00,000,696 | ---- | C] () -- D:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2008/10/27 14:33:31 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- D:\WINDOWS\System32\drivers\mbam.sys
[2008/10/27 14:33:29 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- D:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2008/10/27 14:33:28 | 00,000,000 | ---D | C] -- D:\Program Files\Malwarebytes' Anti-Malware
[2008/10/27 14:33:28 | 00,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\Malwarebytes
[2008/10/27 12:30:50 | 00,002,959 | RHS- | C] () -- D:\WINDOWS\sowar.vbs
[2008/10/26 17:41:44 | 00,000,000 | ---D | C] -- D:\Program Files\GameHouse
[2008/10/26 10:02:47 | 00,000,000 | ---D | C] -- D:\Documents and Settings\decastro\Local Settings\Application Data\Identities
[2008/10/23 08:54:47 | 00,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\n7-89-o9-3r-4t-r9
[2008/10/23 08:54:23 | 00,000,000 | ---D | C] -- D:\Documents and Settings\decastro\Application Data\GameHouse
[2008/10/21 21:47:06 | 00,000,016 | ---- | C] () -- D:\WINDOWS\popcinfot.dat
========== Files - Modified Within 30 Days ==========
[6 D:\WINDOWS\System32\*.tmp files]
[3 D:\WINDOWS\*.tmp files]
[2008/11/04 12:29:28 | 00,422,400 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\decastro\Desktop\OTViewIt.exe
[2008/11/04 12:26:35 | 00,000,388 | ---- | M] () -- D:\WINDOWS\tasks\RegCure Program Check.job
[2008/11/04 12:26:27 | 00,000,006 | -H-- | M] () -- D:\WINDOWS\tasks\SA.DAT
[2008/11/04 12:26:18 | 00,002,048 | --S- | M] () -- D:\WINDOWS\bootstat.dat
[2008/11/04 10:00:02 | 00,002,497 | ---- | M] () -- D:\Documents and Settings\decastro\Desktop\Microsoft Office Word 2003.lnk
[2008/11/03 18:38:15 | 04,843,954 | -H-- | M] () -- D:\Documents and Settings\decastro\Local Settings\Application Data\IconCache.db
[2008/11/03 18:37:45 | 00,021,504 | ---- | M] () -- D:\Documents and Settings\decastro\My Documents\a href2.doc
[2008/11/03 15:15:01 | 00,019,968 | ---- | M] () -- D:\Documents and Settings\decastro\My Documents\012.doc
[2008/11/03 15:12:12 | 00,019,968 | ---- | M] () -- D:\Documents and Settings\decastro\My Documents\Ñ.doc
[2008/11/03 10:16:23 | 00,020,480 | ---- | M] () -- D:\Documents and Settings\decastro\My Documents\a href1.doc
[2008/11/02 13:54:34 | 00,002,228 | ---- | M] () -- D:\WINDOWS\System32\wpa.dbl
[2008/10/29 22:55:22 | 00,002,495 | ---- | M] () -- D:\Documents and Settings\decastro\Desktop\Microsoft Office Excel 2003.lnk
[2008/10/29 06:08:53 | 00,000,780 | ---- | M] () -- D:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2008/10/28 06:49:04 | 03,863,808 | ---- | M] (ESET) -- D:\Documents and Settings\decastro\Desktop\SysInspector.exe
[2008/10/27 18:11:54 | 00,000,793 | ---- | M] () -- D:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2008/10/27 15:21:09 | 00,132,597 | ---- | M] () -- D:\Documents and Settings\decastro\Desktop\Flash_Disinfector.exe
[2008/10/27 14:34:09 | 00,001,734 | ---- | M] () -- D:\Documents and Settings\decastro\Desktop\HijackThis.lnk
[2008/10/27 14:33:32 | 00,000,696 | ---- | M] () -- D:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2008/10/26 06:42:35 | 00,462,344 | ---- | M] () -- D:\WINDOWS\System32\PerfStringBackup.INI
[2008/10/26 06:42:35 | 00,395,200 | ---- | M] () -- D:\WINDOWS\System32\perfh009.dat
[2008/10/26 06:42:35 | 00,059,440 | ---- | M] () -- D:\WINDOWS\System32\perfc009.dat
[2008/10/25 10:36:01 | 00,002,137 | ---- | M] () -- D:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2008/10/25 09:28:45 | 00,000,017 | ---- | M] () -- D:\WINDOWS\popcinfo.dat
[2008/10/22 16:10:38 | 00,038,496 | ---- | M] (Malwarebytes Corporation) -- D:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2008/10/22 16:10:22 | 00,015,504 | ---- | M] (Malwarebytes Corporation) -- D:\WINDOWS\System32\drivers\mbam.sys
[2008/10/21 21:48:20 | 00,000,016 | ---- | M] () -- D:\WINDOWS\popcinfot.dat
[2008/10/18 19:17:53 | 00,000,813 | ---- | M] () -- D:\WINDOWS\win.ini
[2008/10/16 18:35:19 | 00,006,656 | ---- | M] () -- D:\Documents and Settings\decastro\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/10/14 22:12:30 | 00,000,620 | ---- | M] () -- D:\Documents and Settings\decastro\Desktop\Shortcut to Heavy Weapon Deluxe.lnk
< End of report >
Then Extras Logfile:
OTViewIt Extras logfile created on: 11/4/2008 12:30:38 PM - Run
OTViewIt by OldTimer - Version 1.0.20.0 Folder = D:\Documents and Settings\decastro\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1015.23 Mb Total Physical Memory | 607.76 Mb Available Physical Memory | 59.86% Memory free
2.39 Gb Paging File | 2.00 Gb Available in Paging File | 83.79% Paging File free
Paging file location(s): D:\pagefile.sys 1524 3048;
%SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files
Drive C: | 39.06 Gb Total Space | 26.51 Gb Free Space | 67.86% Space Free | Partition Type: NTFS
Drive D: | 35.46 Gb Total Space | 22.64 Gb Free Space | 63.85% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DECASTRO-96A801
Current User Name: decastro
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled"=1
"AntiVirusDisableNotify"=0
"FirewallDisableNotify"=0
"UpdatesDisableNotify"=0
"AntiVirusOverride"=0
"FirewallOverride"=0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[2004/08/04 04:00:00 | 00,140,800 | ---- | M] (Microsoft Corporation) -- %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[2004/08/04 04:00:00 | 00,140,800 | ---- | M] (Microsoft Corporation) -- %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
[2007/08/30 16:43:18 | 04,670,704 | ---- | M] (Yahoo! Inc.) -- D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger
[2007/08/30 16:43:18 | 00,091,376 | ---- | M] (Yahoo! Inc.) -- D:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server
[2008/09/18 10:50:21 | 00,147,456 | ---- | M] (Lime Wire, LLC) -- D:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire
[2008/08/29 09:18:44 | 00,238,888 | ---- | M] (Apple Inc.) -- D:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour
[2008/09/10 16:39:54 | 14,228,264 | ---- | M] (Apple Inc.) -- D:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes
========== (O10) Winsock2 Catalogs ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\]
NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] -- D:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
========== (O18) Protocol Handlers ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
ipp: [HKLM - No CLSID value]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2003/07/11 01:25:22 | 00,842,816 | ---- | M] (Microsoft Corporation) D:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL ipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
msdaipp: [HKLM - No CLSID value]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2003/07/11 01:25:22 | 00,842,816 | ---- | M] (Microsoft Corporation) D:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2003/07/11 01:25:22 | 00,842,816 | ---- | M] (Microsoft Corporation) D:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\oledb:{E1D2BF40-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAIPP.BINDER]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2003/08/04 12:19:34 | 07,330,360 | ---- | M] (Microsoft Corporation) D:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (mso-offdap:{3D9F03FA-7A94-11D3-BE81-0050048385D1} (HKLM) [Data Page Pluggable Protocol mso-offdap Handler])
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2003/08/01 14:09:04 | 08,086,072 | ---- | M] (Microsoft Corporation) D:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (mso-offdap11:{32505114-5902-49B2-880A-1F7738E5A384} (HKLM) [Data Page Plugable Protocal mso-offdap11 Handler])
========== (O18) Protocol Filters ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\] - Protocol Filters
[2003/07/14 21:45:12 | 00,039,488 | ---- | M] (Microsoft Corporation) D:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL text/xml:{807553E5-5146-11D5-A672-00B0D022E945} (HKLM) [Reg Error: Value does not exist or could not be read.]
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{065F29A4-D4D9-4BB9-85AF-8A878907BBD6}"=NI LabVIEW Run-Time Engine 8.5.1
"{0699C67B-F5B5-4CA3-A3A9-B976406FA4DA}"=NI Service Locator
"{17F4ADCB-387E-43A5-8292-A4A37704D670}"=NI MDF Support
"{297BDF30-471F-4E8C-9C05-09C3882300CD}"=NI LabWindows/CVI 8.1.1 Run-Time Engine
"{2CD2C0DB-81C3-416B-9FA6-589B9235359B}"=OpenOffice.org 2.4
"{2D8A240A-B593-4A7A-8FE5-ED056D1112BA}"=NI Circuit Design Suite 10.1 Pro Licenses
"{3116A1B1-4E07-46ED-89F9-57409D88588A}"=NI MetaSuite Installer
"{3248F0A8-6813-11D6-A77B-00B0D0160040}"=Java 6 Update 4
"{3248F0A8-6813-11D6-A77B-00B0D0160070}"=Java 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}"=WebFldrs XP
"{38A4AD83-3492-4A4E-A502-48106D88DD3E}"=NI USI 1.5.0
"{3B99111A-D004-4D15-9B8F-7D6571FCCF60}"=ASRock WiFi-802.11n
"{41B9E2CF-0B3F-442A-B5B3-592A4A355634}"=iTunes
"{45FA54F6-8574-49D2-9E2D-0BDDE6237822}"=NI LabVIEW Run-Time Engine 8.2.1
"{4E0DE929-EB66-4A28-A351-645B22369078}"=NI Update Service 1.0
"{5474BF08-A9D0-49A2-9FCA-4D081B3797B5}"=NI Logos XT Support
"{57700DD3-0C10-4CE6-95BA-630284EE2CB1}"=NI License Manager
"{6600970A-BAE7-412A-BFFC-91AD793B3A41}"=ASRock WiFi-802.11n
"{671A5B67-1A00-424A-A902-49BC020FB3D1}"=NI VC2005MSMs x86
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}"=PowerDVD
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}"=Apple Software Update
"{6E605604-E2CE-4331-AA19-5FEF273F3CFD}"=NI LabVIEW Real-Time FIFO for Runtime
"{6F7D11DC-DE87-45C8-A37E-A35B724FC771}"=NI Help Assistant
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}"=Microsoft .NET Framework 2.0
"{7469D3E1-2470-4539-81CB-A95036683D9B}"=NI Update Service Extras 1.0
"{74712ACB-DD68-4A05-8D2B-8ABD5B29087C}"=NI Circuit Design Suite 10.1 Core
"{77F73F6E-139D-4B38-AB0D-6D2F0E860478}"=NI Logos 4.9.1
"{7C0B9FD1-5181-4446-AD62-299873B5508B}"=NI Uninstaller
"{7E3668CB-1228-416E-B721-C2FA3247B985}"=NI LabVIEW Real-Time FIFO for Runtime
"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}"=Bonjour
"{8B3F4499-32E6-470D-8586-E6C03420F889}"=ASRock WiFi-802.11g
"{8DC42D05-680B-41B0-8878-6C14D24602DB}"=QuickTime
"{90110409-6000-11D3-8CFE-0150048383C9}"=Microsoft Office Professional Edition 2003
"{AA9768AA-FF0B-4C66-A085-31E934F77841}"=Apple Mobile Device Support
"{AC76BA86-7AD7-1033-7B44-A81200000003}"=Adobe Reader 8.1.2
"{BA3602F6-F307-43B8-9879-F8F354C3382F}"=NI Circuit Design Suite 10.1 Pro
"{C1080852-065E-4991-9260-F3756E3CC182}"=CursorFX
"{C9BED750-1211-4480-B1A5-718A3BE15525}"=REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}"=SUPERAntiSpyware Free Edition
"{D105D090-E9E5-4572-A61C-01EDE7568A17}"=NI TDMS
"{DB2C5648-700D-4AEF-83E1-70C72F0C34FA}"=NI Math Kernel Libraries
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}"=Ad-Aware
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}"=Realtek High Definition Audio Driver
"{F28D6E4E-EA52-49F5-B5E8-EDA4F380F83A}"=NI DN 2.0 installer
"{F7D0E9F5-6025-49FA-B13C-CFA27E062062}"=NI EULA Depot
"Adobe Flash Player ActiveX"=Adobe Flash Player ActiveX
"Adobe Flash Player Plugin"=Adobe Flash Player 10 Plugin
"avast!"=avast! Antivirus
"CrazyKart"=CrazyKart
"CursorFX"=CursorFX
"HC51 9.60PL0"=HI-TECH C51-lite V9.60PL0
"HDMI"=Intel® Graphics Media Accelerator Driver
"HijackThis"=HijackThis 2.0.2
"LimeWire"=LimeWire 4.18.8
"Malwarebytes' Anti-Malware_is1"=Malwarebytes' Anti-Malware
"MatlabR2007b"=MATLAB R2007b
"Microsoft .NET Framework 2.0"=Microsoft .NET Framework 2.0
"Mozilla Firefox (3.0.3)"=Mozilla Firefox (3.0.3)
"MSCompPackV1"=Microsoft Compression Client Pack 1.0 for Windows XP
"NI Uninstaller"=National Instruments Software
"npkcxp"=nProtect KeyCrypt
"PICC 9.60PL0"=HI-TECH PICC lite V9.60PL0
"Vista Transformation Pack"=Vista Visual Pack 7.0
"Winamp"=Winamp
"Windows Media Format Runtime"=Windows Media Format 11 runtime
"Windows Media Player"=Windows Media Player 11
"WinRAR archiver"=WinRAR archiver
"WMFDist11"=Windows Media Format 11 runtime
"wmp11"=Windows Media Player 11
"Wudf01000"=Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xvid_is1"=Xvid 1.1.3 final uninstall
"Yahoo! Companion"=Yahoo! Toolbar
"Yahoo! Extras"=Yahoo! Browser Services
"Yahoo! Mail"=Yahoo! Internet Mail
"Yahoo! Messenger"=Yahoo! Messenger
"YInstHelper"=Yahoo! Install Manager
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 10/26/2008 2:47:32 PM | Computer Name = DECASTRO-96A801 | Source = Application Error | ID = 1000
Description = Faulting application yahoomessenger.exe, version 8.1.0.421, faulting
module ntdll.dll, version 5.1.2600.2180, fault address 0x00010f29.
Error - 10/27/2008 6:20:00 PM | Computer Name = DECASTRO-96A801 | Source = Application Hang | ID = 1002
Description = Hanging application IEXPLORE.EXE, version 6.0.2900.2180, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
[ System Events ]
Error - 10/2/2008 12:51:05 PM | Computer Name = DECASTRO-96A801 | Source = SideBySide | ID = 16842784
Description = Dependent Assembly Microsoft.VC80.MFCLOC could not be found and Last
Error was The referenced assembly is not installed on your system.
Error - 10/2/2008 12:51:05 PM | Computer Name = DECASTRO-96A801 | Source = SideBySide | ID = 16842811
Description = Resolve Partial Assembly failed for Microsoft.VC80.MFCLOC. Reference
error message: The referenced assembly is not installed on your system. .
Error - 10/2/2008 12:51:05 PM | Computer Name = DECASTRO-96A801 | Source = SideBySide | ID = 16842811
Description = Generate Activation Context failed for D:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\MFC80.DLL.
Reference
error message: The operation completed successfully. .
Error - 10/2/2008 11:03:26 PM | Computer Name = DECASTRO-96A801 | Source = SideBySide | ID = 16842784
Description = Dependent Assembly Microsoft.VC80.MFCLOC could not be found and Last
Error was The referenced assembly is not installed on your system.
Error - 10/2/2008 11:03:26 PM | Computer Name = DECASTRO-96A801 | Source = SideBySide | ID = 16842811
Description = Resolve Partial Assembly failed for Microsoft.VC80.MFCLOC. Reference
error message: The referenced assembly is not installed on your system. .
Error - 10/2/2008 11:03:26 PM | Computer Name = DECASTRO-96A801 | Source = SideBySide | ID = 16842811
Description = Generate Activation Context failed for D:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\MFC80U.DLL.
Reference
error message: The operation completed successfully. .
Error - 10/2/2008 11:03:26 PM | Computer Name = DECASTRO-96A801 | Source = SideBySide | ID = 16842784
Description = Dependent Assembly Microsoft.VC80.MFCLOC could not be found and Last
Error was The referenced assembly is not installed on your system.
Error - 10/2/2008 11:03:26 PM | Computer Name = DECASTRO-96A801 | Source = SideBySide | ID = 16842811
Description = Resolve Partial Assembly failed for Microsoft.VC80.MFCLOC. Reference
error message: The referenced assembly is not installed on your system. .
Error - 10/2/2008 11:03:26 PM | Computer Name = DECASTRO-96A801 | Source = SideBySide | ID = 16842811
Description = Generate Activation Context failed for D:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\MFC80U.DLL.
Reference
error message: The operation completed successfully. .
Error - 10/17/2008 7:48:51 PM | Computer Name = DECASTRO-96A801 | Source = Dhcp | ID = 1002
Description = The IP address lease 10.0.21.113 for the Network Card with network
address 00196669F170 has been denied by the DHCP server 0.0.0.0 (The DHCP Server
sent a DHCPNACK message).
< End of report >