OTL logfile created on: 10/22/2011 3:24:18 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Administrator\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.99 Gb Total Physical Memory | 1.69 Gb Available Physical Memory | 84.85% Memory free
3.84 Gb Paging File | 3.74 Gb Available in Paging File | 97.25% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 66.51 Gb Total Space | 16.65 Gb Free Space | 25.04% Space Free | Partition Type: NTFS
Drive D: | 8.01 Gb Total Space | 6.35 Gb Free Space | 79.27% Space Free | Partition Type: NTFS
Computer Name: HP52192360163 | User Name: Administrator | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Administrator\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\LP\010C\3A9.exe ()
PRC - C:\Program Files\59F61\lvvm.exe ()
PRC - C:\Documents and Settings\Administrator\Application Data\CDC59\88A01.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\LP\010C\3A9.exe ()
MOD - C:\Program Files\59F61\lvvm.exe ()
MOD - C:\Documents and Settings\Administrator\Application Data\CDC59\88A01.exe ()
MOD - \\?\globalroot\systemroot\system32\mswsock.dll ()
MOD - \\.\globalroot\systemroot\system32\mswsock.dll ()
========== Win32 Services (SafeList) ==========
SRV - (Symantec RemoteAssist) -- File not found
SRV - (IntuitUpdateService) -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (LVPrcSrv) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (CVPND) -- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
SRV - (AOL ACS) -- C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (AOL LLC)
========== Driver Services (SafeList) ==========
DRV - (MBAMSwissArmy) -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (FilterService) -- C:\WINDOWS\system32\drivers\lvuvcflt.sys (Logitech Inc.)
DRV - (LVUVC) Logitech QuickCam Pro 9000(UVC) -- C:\WINDOWS\system32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (LVUSBSta) -- C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (LVRS) -- C:\WINDOWS\system32\drivers\lvrs.sys (Logitech Inc.)
DRV - (LVPr2Mon) -- C:\WINDOWS\system32\drivers\LVPr2Mon.sys ()
DRV - (CVPNDRVA) -- C:\WINDOWS\system32\drivers\CVPNDRVA.sys (Cisco Systems, Inc.)
DRV - (DNE) -- C:\WINDOWS\system32\drivers\dne2000.sys (Deterministic Networks, Inc.)
DRV - (CVirtA) -- C:\WINDOWS\system32\drivers\CVirtA.sys (Cisco Systems, Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (b57w2k) -- C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (Blfp) -- C:\WINDOWS\system32\drivers\baspxp32.sys (Broadcom Corporation)
DRV - (vsdatant) -- C:\WINDOWS\system32\vsdatant.sys (Zone Labs LLC)
DRV - (HdAudAddService) -- C:\WINDOWS\system32\drivers\HdAudio.sys (Windows ® Server 2003 DDK provider)
DRV - (iAimFP4) -- C:\WINDOWS\system32\drivers\wVchNTxx.sys (Intel® Corporation)
DRV - (iAimFP3) -- C:\WINDOWS\system32\drivers\wSiINTxx.sys (Intel® Corporation)
DRV - (iAimTV5) -- C:\WINDOWS\system32\drivers\wATV10nt.sys (Intel® Corporation)
DRV - (iAimTV4) -- C:\WINDOWS\system32\drivers\wCh7xxNT.sys (Intel® Corporation)
DRV - (iAimTV6) -- C:\WINDOWS\system32\drivers\wATV06nt.sys (Intel® Corporation)
DRV - (iAimTV3) -- C:\WINDOWS\system32\drivers\wATV04nt.sys (Intel® Corporation)
DRV - (iAimTV1) -- C:\WINDOWS\system32\drivers\wATV02NT.sys (Intel® Corporation)
DRV - (iAimTV0) -- C:\WINDOWS\system32\drivers\wATV01nt.sys (Intel® Corporation)
DRV - (iAimFP7) -- C:\WINDOWS\system32\drivers\wADV09NT.sys (Intel® Corporation)
DRV - (iAimFP5) -- C:\WINDOWS\system32\drivers\wADV07nt.sys (Intel® Corporation)
DRV - (iAimFP6) -- C:\WINDOWS\system32\drivers\wADV08NT.sys (Intel® Corporation)
DRV - (i81x) -- C:\WINDOWS\system32\drivers\i81xnt5.sys (Intel® Corporation)
DRV - (iAimFP0) -- C:\WINDOWS\system32\drivers\wADV01nt.sys (Intel® Corporation)
DRV - (iAimFP1) -- C:\WINDOWS\system32\drivers\wADV02NT.sys (Intel® Corporation)
DRV - (iAimFP2) -- C:\WINDOWS\system32\drivers\wADV05NT.sys (Intel® Corporation)
DRV - (wanatw) WAN Miniport (ATW) -- C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (Symmpi) -- C:\WINDOWS\system32\DRIVERS\symmpi.sys (LSI Logic)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\URLSearchHook: {f0e98552-8e47-4c6c-9b3a-11ab0549f94d} - No CLSID value found
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = AOL search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://search.aol.com/aolcom/search?query={searchTerms}&invocationType=msie70a
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
https://lhchurch.onthecity.org/session/new
IE - HKCU\..\URLSearchHook: {f0e98552-8e47-4c6c-9b3a-11ab0549f94d} - No CLSID value found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:61111
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\discoversoan@orbiscom: C:\Program Files\Discover\SOAN [2010/12/09 19:51:24 | 000,000,000 | ---D | M]
[2010/09/21 15:48:32 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2010/09/21 15:48:32 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions\guardianfr2008@touchwoodcreative.com
========== Chrome ==========
CHR - default_search_provider: Google ()
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}
O1 HOSTS File: ([2011/10/22 01:51:45 | 000,000,884 | RH-- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 94.63.240.133 www.google.com
O1 - Hosts: 94.63.240.134 www.bing.com
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll File not found
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (no name) - {3ef64538-8b54-4573-b48f-4d34b0238ab2} - No CLSID value found.
O2 - BHO: (Secure Online Account Numbers Helper) - {435EAA86-D32B-484F-869C-53745FCB1642} - C:\Program Files\Discover\SOAN\DiscoverSOANHelper.dll (Orbiscom Ltd. All rights reserved.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Secure Online Account Numbers) - {A8C7C2CA-6DFD-4E16-8458-592361564D38} - C:\Program Files\Discover\SOAN\DiscoverSOANToolbar.dll (Orbiscom Ltd. All rights reserved.)
O3 - HKLM\..\Toolbar: (no name) - {ba00b7b1-0351-477a-b948-23e3ee5a73d4} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)
O4 - HKLM..\Run: [3A9.exe] C:\Program Files\LP\010C\3A9.exe ()
O4 - HKLM..\Run: [ERCmYTJhduBEH.exe] C:\Documents and Settings\All Users\Application Data\ERCmYTJhduBEH.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\aol\1198957229\ee\aolsoftware.exe (AOL Inc.)
O4 - HKLM..\Run: [rzPNyxA1uDoFpHs] C:\WINDOWS\system32\svhostu.exe ()
O4 - HKLM..\Run: [Secure Online Account Numbers] C:\Program Files\Discover\SOAN\DiscoverSOAN.exe (Orbiscom Ltd. All rights reserved.)
O4 - HKLM..\Run: [TK8gRZ9hYwUe8234A] C:\WINDOWS\system32\oxA0uvS2oFpGsJ.exe ()
O4 - HKLM..\Run: [volmgr] %APPDATA%\volmgr.exe File not found
O4 - HKCU..\Run: [0W1V5D3W3AWB1WXDCFNXHDYNFEXA] C:\Skype\3D7E786034B.exe ()
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: ezdata.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: ez-data.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: glic.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: glic.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: glic.com ([www6] https in Trusted sites)
O15 - HKCU\..Trusted Domains: gliconline.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: guardianinvestor.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: guardianlife.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O15 - HKCU\..Trusted Domains: pasmystreetscape.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: smartofficeonline.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: streetscape.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: turbotax.com ([]https in Trusted sites)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8}
http://download.microsoft.com/download/e/4/9/e494c802-dd90-4c6b-a074-469358f075a6/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {1FA44E01-A60B-4449-BF97-66CDAA200433}
https://www5.glic.com/so/java/downloads/SOConfig6.cab (SOConfig6 Class)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71}
http://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325}
https://www6.glic.com/srvlw3/iNotes6W.cab (iNotes6 Class)
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345}
https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab (Symantec Script Runner Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1198973371796 (MUWebControl Class)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203}
http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab (GMNRev Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968}
http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277}
http://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {D22621D3-E219-4B03-AF3E-5E8AEF7CC70B}
https://www5.glic.com/so/java/downloads/SmartOfficeLink6.cab (SmartBridge6 Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C}
https://guardianim.webex.com/client/T27LB/webex/ieatgpc.cab (GpcContainer Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2ED2ECEA-4FFA-4CB3-925E-74FAF454656A}: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (C:\Documents and Settings\Administrator\Application Data\CDC59\88A01.exe) -C:\Documents and Settings\Administrator\Application Data\CDC59\88A01.exe ()
O24 - Desktop WallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/04/30 19:01:00 | 000,000,053 | -HS- | M] () - D:\Autorun.inf -- [ NTFS ]
O33 - MountPoints2\{41e5e641-bfe0-11dc-93fb-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{41e5e641-bfe0-11dc-93fb-00038a000015}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{41e5e641-bfe0-11dc-93fb-00038a000015}\Shell\AutoRun\command - "" = F:\LaunchU3.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/10/22 15:22:43 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2011/10/22 10:27:40 | 000,000,000 | --SD | C] -- C:\32788R22FWJFW
[2011/10/22 09:26:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\tD2nF4amHsJfLgZ
[2011/10/22 09:26:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\W2ibD3pnG
[2011/10/22 09:24:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011/10/22 09:24:22 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/10/22 09:23:58 | 004,269,227 | R--- | C] (Swearware) -- C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
[2011/10/22 09:19:04 | 000,187,464 | ---- | C] (Webroot) -- C:\Documents and Settings\Administrator\Desktop\antizeroaccess.exe
[2011/10/22 09:15:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\QZqjYCwkIrOtAuS
[2011/10/22 09:15:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\oA1ivD2on4m5W7E
[2011/10/22 09:09:06 | 000,000,000 | ---D | C] -- C:\WINDOWS\3203397148
[2011/10/22 09:08:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Desktop\DummyCreator
[2011/10/22 09:07:03 | 000,000,000 | ---D | C] -- C:\Program Files\LP
[2011/10/15 17:18:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Desktop\gmer
[2011/10/15 17:14:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\LvS2ibF3pGaJdK
[2011/10/15 17:14:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\c8gTZqjYCkVzNx0
[2011/10/15 17:12:29 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Administrator\Start Menu\Programs\Administrative Tools
[2011/10/15 17:12:10 | 000,607,260 | R--- | C] (Swearware) -- C:\Documents and Settings\Administrator\Desktop\dds.scr
[2011/10/15 16:56:52 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Administrator\Recent
[2011/10/15 16:56:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\YbF4pmH5sJ
[2011/10/15 16:56:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\NdEL8gRZqYwUrOt
[2011/10/15 10:41:12 | 000,000,000 | ---D | C] -- C:\backup
[2011/10/15 08:33:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\OekBzNx1v2b4m5Q
[2011/10/15 08:33:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\bHs7fL9gTqY
[2011/10/15 07:54:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\K9TwjUVelBPyA
[2011/10/15 07:54:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\SwkIVrltAuipaJd
[2011/10/15 07:52:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Start Menu\Programs\Cloud Protection
[2011/10/15 07:52:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\qF4pmH5sQ7E8RqY
[2011/10/15 07:52:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\ZKfLgXjCkBzNxuD
[2011/10/14 03:55:35 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\mCwkIVrlOtAu2b3
[2011/10/14 03:55:35 | 000,000,000 | ---D | C] -- C:\DonF4pmH5W7E8Tq
[2011/10/14 03:55:30 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\U6sWK7fRLgXjCkB
[2011/10/14 03:55:29 | 000,000,000 | ---D | C] -- C:\S7fEL9gTZjCkVzN
[2011/10/14 03:35:13 | 000,470,528 | ---- | C] (Sun Microsystems, Inc.) -- C:\Documents and Settings\All Users\Application Data\ERCmYTJhduBEH.exe
[2011/10/14 03:04:23 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2011/10/11 18:49:20 | 000,000,000 | ---D | C] -- C:\Program Files\59F61
[2011/10/10 23:02:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\AdobeUM
[2011/10/10 23:02:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Adobe
[2011/10/10 19:22:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\CDC59
[2011/10/10 08:46:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Macromedia
[2011/10/10 08:46:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Adobe
[2011/10/09 19:19:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\AdobeUM
[2011/10/09 09:11:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Sun
[2011/10/09 09:11:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2011/10/09 09:08:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/10/09 09:08:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2011/09/26 11:41:20 | 000,220,160 | -H-- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\oleacc.dll
[2011/09/26 11:41:14 | 000,020,480 | -H-- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\oleaccrc.dll
[2011/09/22 16:33:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\My Documents\Pops
[2010/02/20 10:11:07 | 000,011,384 | ---- | C] (Symantec Corporation) -- C:\Program Files\SymantecRootInstallerRes.dll
[7 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/10/22 15:22:54 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\OTL.exe
[2011/10/22 15:20:06 | 000,001,158 | -H-- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/10/22 15:19:42 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/10/22 10:40:36 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/10/22 09:26:32 | 000,001,750 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Cloud Protection.lnk
[2011/10/22 09:26:11 | 000,000,882 | -H-- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/10/22 09:23:58 | 004,269,227 | R--- | M] (Swearware) -- C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
[2011/10/22 09:19:05 | 000,187,464 | ---- | M] (Webroot) -- C:\Documents and Settings\Administrator\Desktop\antizeroaccess.exe
[2011/10/22 09:08:07 | 000,455,503 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\DummyCreator.zip
[2011/10/15 17:37:13 | 000,294,216 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\gmer.zip
[2011/10/15 17:12:17 | 000,607,260 | R--- | M] (Swearware) -- C:\Documents and Settings\Administrator\Desktop\dds.scr
[2011/10/15 17:10:13 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Administrator\defogger_reenable
[2011/10/15 17:09:54 | 000,050,477 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Defogger.exe
[2011/10/15 17:00:01 | 000,037,276 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\cbSetup.exe
[2011/10/15 16:56:26 | 000,001,213 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\ldr.ini
[2011/10/14 03:55:30 | 000,103,936 | ---- | M] () -- C:\WINDOWS\System32\svhostu.exe
[2011/10/14 03:55:29 | 001,702,400 | ---- | M] () -- C:\WINDOWS\System32\oxA0uvS2oFpGsJ.exe
[2011/10/14 03:34:37 | 000,470,528 | ---- | M] (Sun Microsystems, Inc.) -- C:\Documents and Settings\All Users\Application Data\ERCmYTJhduBEH.exe
[2011/10/14 03:22:11 | 000,160,344 | -H-- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2011/10/14 03:05:36 | 000,444,794 | -H-- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/10/14 03:05:36 | 000,072,544 | -H-- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/10/14 03:02:56 | 048,324,552 | -H-- | M] () -- C:\WINDOWS\System32\MRT.exe
[2011/10/14 02:22:00 | 000,000,886 | -H-- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/10/11 18:48:59 | 000,005,375 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\9F61.DC5
[2011/10/10 20:38:58 | 000,000,130 | -H-- | M] () -- C:\WINDOWS\wininit.ini
[2011/10/08 15:16:41 | 003,646,384 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Courageous_FullPageFlyer.pdf
[2011/10/03 19:01:25 | 000,037,782 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\COM15-3755964-4145106-3029239-09302011.pdf
[2011/10/03 03:35:11 | 005,971,456 | -H-- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtml.dll
[2011/09/28 19:04:42 | 000,172,777 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\STD-3029239-09272011.pdf
[2011/09/26 11:41:20 | 000,611,328 | -H-- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\uiautomationcore.dll
[2011/09/26 11:41:20 | 000,220,160 | -H-- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\oleacc.dll
[2011/09/26 11:41:14 | 000,020,480 | -H-- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\oleaccrc.dll
[2011/09/26 11:41:14 | 000,020,480 | -H-- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\oleaccrc.dll
[2011/09/25 09:55:16 | 000,117,760 | ---- | M] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/09/24 09:51:54 | 000,071,015 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\DAD2011.jpg
[2011/09/23 14:32:08 | 000,002,473 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Microsoft Office Excel 2007.lnk
[2011/09/22 16:36:08 | 000,189,231 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\COM01-3735360-4145106-3029239-09222011.pdf
[2011/09/22 16:33:24 | 000,580,125 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Pops.zip
[7 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]