Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

IE doesn't work 2


  • This topic is locked This topic is locked
14 replies to this topic

#1 wartburgtrack33

wartburgtrack33

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:06:47 PM

Posted 26 January 2009 - 07:38 PM

This wartburgtrack33 and I ave been working through rodg12 to fix my IE. This a new thread that I will post the next logs to.

BC AdBot (Login to Remove)

 


#2 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,304 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:05:47 PM

Posted 26 January 2009 - 07:57 PM

Hello :thumbup2:

Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#3 wartburgtrack33

wartburgtrack33
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:06:47 PM

Posted 26 January 2009 - 08:14 PM

Billy,

I ran OTMoveIt3 and here is the file you wanted.

========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iexplore.exe\\ deleted successfully.
Unable to delete registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4AF70395-A10B-3644-1705-89E9FC5BAE81}\\ .
Unable to delete registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{77F8D6E9-F0A7-8D50-B905-CAC75B2E221B}\\ .
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\Pamela\LOCALS~1\Temp\etilqs_0Wv1UzoQ6PJKJufFf5Ro scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pamela\LOCALS~1\Temp\~DF92D0.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pamela\LOCALS~1\Temp\~DF93B6.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pamela\LOCALS~1\Temp\~DFAC8E.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\Pamela\LOCALS~1\Temp\~DFAD59.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_770.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\Pamela\Local Settings\Application Data\Mozilla\Firefox\Profiles\3tlkszhq.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Pamela\Local Settings\Application Data\Mozilla\Firefox\Profiles\3tlkszhq.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Pamela\Local Settings\Application Data\Mozilla\Firefox\Profiles\3tlkszhq.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Pamela\Local Settings\Application Data\Mozilla\Firefox\Profiles\3tlkszhq.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Pamela\Local Settings\Application Data\Mozilla\Firefox\Profiles\3tlkszhq.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Pamela\Local Settings\Application Data\Mozilla\Firefox\Profiles\3tlkszhq.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.

OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 01262009_190107

Files moved on Reboot...

#4 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,304 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:05:47 PM

Posted 26 January 2009 - 08:42 PM

Does internet exploder work now?

Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#5 wartburgtrack33

wartburgtrack33
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:06:47 PM

Posted 26 January 2009 - 09:03 PM

Yes. Its opened for the first time in a month. Thank you so much for your help! :thumbup2:

#6 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,304 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:05:47 PM

Posted 26 January 2009 - 09:25 PM

You're welcome :D

If that's the case, you're still not clean yet. Please run the other instructions located back here :thumbup2:
http://www.bleepingcomputer.com/forums/ind...t&p=1108618

That is, HostsXPert, Update Java, ESET, and a fresh pair of OTVI logs :)

Billy3

Edited by Billy O'Neal, 26 January 2009 - 09:25 PM.

Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#7 wartburgtrack33

wartburgtrack33
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:06:47 PM

Posted 27 January 2009 - 12:04 AM

OK. I did all of your instructions from the other thread. I am posting the logs from the programs you listed. If there is anything elase I should do, please let me know and I will do it as quick as I can.

Thanks again!

ESET:
# version=4
# OnlineScanner.ocx=1.0.0.635
# OnlineScannerDLLA.dll=1, 0, 0, 79
# OnlineScannerDLLW.dll=1, 0, 0, 78
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=3802 (20090126)
# vers_arch_module=1.064 (20080214)
# vers_adv_heur_module=1.066 (20070917)
# EOSSerial=475ed52ce5bb5049919ded7d9386a96c
# end=finished
# remove_checked=true
# unwanted_checked=true
# utc_time=2009-01-27 04:55:39
# local_time=2009-01-26 10:55:39 (-0600, Central Standard Time)
# country="United States"
# osver=5.1.2600 NT Service Pack 3
# scanned=576092
# found=1
# scan_time=9322
C:\WINDOWS\SYSTEM32\svch?st.exe Win32/Agent.BHNZ trojan (unable to clean - deleted) 00000000000000000000000000000000


OTVIew It Main:
OTViewIt logfile created on: 1/26/2009 10:57:56 PM - Run 2
OTViewIt by OldTimer - Version 1.0.21.0 Folder = C:\Documents and Settings\Pamela\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18241)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

765.98 Mb Total Physical Memory | 385.14 Mb Available Physical Memory | 50.28% Memory free
1.83 Gb Paging File | 1.43 Gb Available in Paging File | 78.40% Paging File free
Paging file location(s): C:\pagefile.sys 1149 1349;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 33.52 Gb Total Space | 4.57 Gb Free Space | 13.64% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PAMANDTRISH
Current User Name: Pamela
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days

========== Processes ==========

[2008/12/17 08:32:06 | 00,419,448 | ---- | M] (Emsi Software GmbH) -- C:\Program Files\a-squared Free\a2service.exe
[2004/04/07 11:07:32 | 01,135,728 | ---- | M] (America Online, Inc.) -- C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
[2008/11/07 14:28:16 | 00,132,424 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
[2008/06/29 14:23:18 | 02,944,392 | ---- | M] () -- C:\Program Files\Bradford Networks\Persistent Agent\bndaemon.exe
[2008/08/29 09:18:44 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe
[2003/05/21 00:22:36 | 00,032,768 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
[2003/06/19 22:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
[2003/05/21 00:27:46 | 00,610,304 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
[2005/03/30 15:03:26 | 01,872,384 | ---- | M] (Webroot Software, Inc.) -- C:\Program Files\Webroot\Enterprise\CommAgent\CommAgent.exe
[2008/04/13 18:12:40 | 00,218,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SYSTEM32\WBEM\wmiprvse.exe
[2004/10/14 13:42:54 | 01,404,928 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\Core\smax4pnp.exe
[2003/09/03 19:12:44 | 00,221,184 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
[2005/03/15 07:58:08 | 00,135,168 | ---- | M] (Musicmatch, Inc.) -- C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
[2004/12/06 00:05:00 | 00,127,035 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\dla\tfswctrl.exe
[2005/03/15 07:58:08 | 00,053,248 | ---- | M] (Musicmatch Inc.) -- C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe
[2003/05/21 00:21:18 | 00,090,112 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\VPTray.exe
[2004/03/04 09:46:24 | 00,172,032 | ---- | M] (HP) -- C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\hpztsb10.exe
[2003/12/22 07:38:42 | 00,241,664 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
[2005/02/16 23:11:42 | 00,049,152 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe
[2005/09/20 09:32:24 | 00,077,824 | ---- | M] (Intel Corporation) -- C:\WINDOWS\SYSTEM32\hkcmd.exe
[2005/09/20 09:36:20 | 00,114,688 | ---- | M] (Intel Corporation) -- C:\WINDOWS\SYSTEM32\igfxpers.exe
[2005/06/06 22:46:24 | 00,057,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
[2005/10/21 09:40:26 | 00,430,080 | ---- | M] (Dell) -- C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
[2008/04/07 06:25:21 | 00,185,896 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[2008/06/29 14:23:18 | 02,612,616 | ---- | M] () -- C:\Program Files\Bradford Networks\Persistent Agent\bncsaui.exe
[2008/08/03 17:02:20 | 00,036,352 | ---- | M] () -- C:\Program Files\Winamp\winampa.exe
[2005/10/28 06:41:52 | 00,491,520 | ---- | M] ( ) -- C:\WINDOWS\SYSTEM32\dlcccoms.exe
[2008/11/20 13:20:54 | 00,290,088 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunesHelper.exe
[2007/03/15 10:09:36 | 00,460,784 | ---- | M] (Gteko Ltd.) -- C:\Program Files\DellSupport\DSAgnt.exe
[2007/10/18 10:34:02 | 05,724,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe
[2007/07/20 06:29:07 | 00,068,856 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[2006/09/11 03:40:32 | 00,218,032 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
[2008/06/10 16:18:10 | 00,785,520 | ---- | M] (The Weather Channel Interactive, Inc.) -- C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe
[2006/12/22 10:17:32 | 00,598,016 | ---- | M] () -- C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe
[2008/11/20 13:20:44 | 00,536,872 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe
[2007/10/18 10:31:54 | 00,098,328 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\usnsvc.exe
[2009/01/26 19:51:45 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
[2009/01/26 19:51:45 | 00,136,600 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
[2009/01/26 12:48:53 | 00,422,912 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Pamela\Desktop\OTViewIt.exe

========== (O23) Win32 Services ==========

[2008/12/17 08:32:06 | 00,419,448 | ---- | M] (Emsi Software GmbH) -- C:\Program Files\a-squared Free\a2service.exe -- (a2free [Auto | Running])
[2004/04/07 11:07:32 | 01,135,728 | ---- | M] (America Online, Inc.) -- C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe -- (AOL ACS [Auto | Running])
[2008/11/07 14:28:16 | 00,132,424 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running])
[2004/07/15 00:49:26 | 00,032,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
[2008/06/29 14:23:18 | 02,944,392 | ---- | M] () -- C:\Program Files\Bradford Networks\Persistent Agent\bndaemon.exe -- (BNPagent [Auto | Running])
[2008/08/29 09:18:44 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service [Auto | Running])
[2003/05/21 00:22:36 | 00,032,768 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe -- (DefWatch [Auto | Running])
[2005/10/28 06:41:52 | 00,491,520 | ---- | M] ( ) -- C:\WINDOWS\SYSTEM32\dlcccoms.exe -- (dlcc_device [On_Demand | Running])
File not found -- -- (DM1Service [Auto | Stopped])
[2007/03/07 14:47:46 | 00,076,848 | ---- | M] () -- C:\Program Files\DellSupport\brkrsvc.exe -- (DSBrokerService [On_Demand | Stopped])
[2007/01/24 08:10:32 | 00,138,168 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [On_Demand | Stopped])
[2005/11/14 00:06:04 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
[2008/11/20 13:20:44 | 00,536,872 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Running])
[2003/06/19 22:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE -- (MDM [Auto | Running])
File not found -- -- (navapsvc [Auto | Stopped])
[2003/12/17 12:59:48 | 00,143,360 | ---- | M] (Intel® Corporation) -- C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe -- (NetSvc [On_Demand | Stopped])
[2003/05/21 00:27:46 | 00,610,304 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe -- (Norton AntiVirus Server [Auto | Running])
[2003/07/28 11:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
[2007/10/18 10:31:54 | 00,098,328 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\usnsvc.exe -- (usnjsvc [On_Demand | Running])
[2005/03/30 15:03:26 | 01,872,384 | ---- | M] (Webroot Software, Inc.) -- C:\Program Files\Webroot\Enterprise\CommAgent\CommAgent.exe -- (WebrootCommAgentService [Auto | Running])
[2005/03/30 15:03:46 | 01,812,992 | ---- | M] (Webroot Software, Inc.) -- C:\Program Files\Webroot\Enterprise\Spy Sweeper\SpySweeper.exe -- (WebrootSpySweeperService [Auto | Stopped])
[2007/10/25 14:27:54 | 00,266,240 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\installer\WLSetupSvc.exe -- (WLSetupSvc [On_Demand | Stopped])
[2006/10/18 19:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])
[2009/01/26 19:51:45 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])

========== Driver Services ==========

[2007/07/02 21:06:02 | 00,021,035 | ---- | M] (Meetinghouse Data Communications) -- C:\WINDOWS\SYSTEM32\DRIVERS\AegisP.sys -- (AegisP [Auto | Running])
[2001/08/17 12:51:56 | 00,005,248 | ---- | M] (Acer Laboratories Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\ALIIDE.SYS -- (AliIde [Boot | Running])
[2008/04/13 12:36:39 | 00,043,008 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\amdagp.sys -- (amdagp [Boot | Running])
[2001/08/17 12:52:00 | 00,026,496 | ---- | M] (Advanced System Products, Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\ASC.SYS -- (asc [Boot | Running])
[2001/08/17 12:51:58 | 00,014,848 | ---- | M] (Advanced System Products, Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\ASC3550.SYS -- (asc3550 [Boot | Running])
[2001/08/17 12:51:54 | 00,006,656 | ---- | M] (CMD Technology, Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\CMDIDE.SYS -- (CmdIde [Boot | Running])
[2001/08/17 12:52:16 | 00,179,584 | ---- | M] (Mylex Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\DAC2W2K.SYS -- (dac2w2k [Boot | Running])
[2004/12/01 02:22:00 | 00,087,488 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\DRIVERS\drvmcdb.sys -- (drvmcdb [Boot | Running])
[2004/11/23 01:56:00 | 00,040,480 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\DRIVERS\drvnddm.sys -- (drvnddm [Auto | Running])
[2006/10/05 15:07:28 | 00,004,736 | ---- | M] (Gteko Ltd.) -- C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys -- (DSproct [On_Demand | Running])
[2007/02/25 11:10:48 | 00,005,376 | --S- | M] (Gteko Ltd.) -- C:\WINDOWS\SYSTEM32\DRIVERS\dsunidrv.sys -- (dsunidrv [Auto | Running])
[2004/02/10 14:49:14 | 00,154,112 | ---- | M] (Intel Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\e100b325.sys -- (E100B [On_Demand | Running])
[2008/04/17 12:12:54 | 00,015,464 | ---- | M] (GEAR Software Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys -- (GEARAspiWDM [On_Demand | Running])
[2009/01/26 12:55:00 | 00,085,969 | ---- | M] (GMER) -- C:\WINDOWS\SYSTEM32\DRIVERS\gmer.sys -- (gmer [On_Demand | Stopped])
[2005/09/20 10:00:54 | 01,302,332 | ---- | M] (Intel Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\ialmnt5.sys -- (ialm [On_Demand | Running])
[2004/03/05 21:14:42 | 01,233,525 | ---- | M] (Intel Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\IntelC51.sys -- (IntelC51 [On_Demand | Running])
[2004/03/05 21:15:34 | 00,647,929 | ---- | M] (Intel Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\IntelC52.sys -- (IntelC52 [On_Demand | Running])
[2004/06/15 21:52:40 | 00,061,157 | ---- | M] (Intel Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\IntelC53.sys -- (IntelC53 [On_Demand | Running])
[2008/04/13 12:39:48 | 00,014,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\kbdhid.sys -- (kbdhid [System | Stopped])
[2001/08/17 12:57:38 | 00,016,128 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\MODEMCSA.sys -- (MODEMCSA [On_Demand | Running])
[2004/03/05 21:13:38 | 00,037,048 | ---- | M] (Intel Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\mohfilt.sys -- (mohfilt [On_Demand | Running])
[2001/08/17 12:52:12 | 00,017,280 | ---- | M] (American Megatrends Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\MRAID35X.SYS -- (mraid35x [Boot | Running])
[2003/05/02 20:08:18 | 00,224,256 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Navap.sys -- (NAVAP [On_Demand | Running])
[2003/05/02 20:08:22 | 00,030,208 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Navapel.sys -- (NAVAPEL [Auto | Running])
[2009/01/23 03:00:00 | 00,089,104 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090123.003\NAVENG.SYS -- (NAVENG [On_Demand | Running])
[2009/01/23 03:00:00 | 00,876,112 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090123.003\NAVEX15.SYS -- (NAVEX15 [On_Demand | Running])
[2004/08/03 21:29:56 | 01,897,408 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\NV4_MINI.SYS -- (nv [On_Demand | Stopped])
[2004/08/04 04:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\PTILINK.SYS -- (Ptilink [On_Demand | Running])
[2007/03/07 17:51:00 | 00,043,528 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\DRIVERS\pxhelp20.sys -- (PxHelp20 [Boot | Running])
[2001/08/17 12:52:20 | 00,040,320 | ---- | M] (QLogic Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\QL1080.SYS -- (ql1080 [Boot | Running])
[2001/08/17 12:52:20 | 00,045,312 | ---- | M] (QLogic Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\QL12160.SYS -- (ql12160 [Boot | Running])
[2001/08/17 12:52:18 | 00,049,024 | ---- | M] (QLogic Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\QL1280.SYS -- (ql1280 [Boot | Running])
[2006/12/26 13:58:02 | 00,189,312 | ---- | M] (Realtek Semiconductor Corporation ) -- C:\WINDOWS\SYSTEM32\DRIVERS\RTL8187B.sys -- (RTL8187B [On_Demand | Stopped])
[2007/11/13 04:25:53 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\SYSTEM32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])
[2004/09/17 08:02:54 | 00,732,928 | ---- | M] (Creative Technology Ltd.) -- C:\WINDOWS\SYSTEM32\DRIVERS\senfilt.sys -- (senfilt [On_Demand | Running])
[2008/04/13 12:36:39 | 00,040,960 | ---- | M] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\sisagp.sys -- (sisagp [Boot | Running])
[2005/01/27 14:31:06 | 00,260,352 | ---- | M] (Analog Devices, Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\smwdm.sys -- (smwdm [On_Demand | Running])
[2001/08/17 13:07:44 | 00,019,072 | ---- | M] (Adaptec, Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\SPARROW.SYS -- (Sparrow [Boot | Running])
[2004/07/14 10:29:04 | 00,005,627 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\DRIVERS\sscdbhk5.sys -- (sscdbhk5 [System | Running])
[2008/07/16 10:15:34 | 00,020,336 | ---- | M] (Webroot Software Inc (www.webroot.com)) -- C:\WINDOWS\SYSTEM32\DRIVERS\ssfs0BB9.sys -- (SSFS0BB9 [Boot | Running])
[2008/07/16 10:15:34 | 00,021,872 | ---- | M] (Webroot Software Inc (www.webroot.com)) -- C:\WINDOWS\SYSTEM32\DRIVERS\SSHRMD.SYS -- (SSHRMD [Boot | Running])
[2008/07/16 10:15:36 | 00,163,696 | ---- | M] (Webroot Software Inc (www.webroot.com)) -- C:\WINDOWS\SYSTEM32\DRIVERS\SSIDRV.SYS -- (SSIDRV [Boot | Running])
[2004/07/14 10:28:50 | 00,023,545 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\DRIVERS\ssrtln.sys -- (ssrtln [System | Running])
[2001/08/17 13:07:34 | 00,016,256 | ---- | M] (Symbios Logic Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\SYMC810.SYS -- (symc810 [Boot | Running])
[2001/08/17 13:07:36 | 00,032,640 | ---- | M] (LSI Logic) -- C:\WINDOWS\SYSTEM32\DRIVERS\SYMC8XX.SYS -- (symc8xx [Boot | Running])
[2005/03/15 14:33:52 | 00,123,208 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\SYMEVENT.SYS -- (SymEvent [On_Demand | Running])
[2001/08/17 13:07:40 | 00,028,384 | ---- | M] (LSI Logic) -- C:\WINDOWS\SYSTEM32\DRIVERS\SYM_HI.SYS -- (sym_hi [Boot | Running])
[2001/08/17 13:07:42 | 00,030,688 | ---- | M] (LSI Logic) -- C:\WINDOWS\SYSTEM32\DRIVERS\SYM_U3.SYS -- (sym_u3 [Boot | Running])
[2004/12/06 00:05:00 | 00,025,883 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\dla\tfsnboio.sys -- (tfsnboio [Auto | Running])
[2004/12/06 00:05:00 | 00,034,843 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\dla\tfsncofs.sys -- (tfsncofs [Auto | Running])
[2004/12/06 00:05:00 | 00,004,123 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\dla\tfsndrct.sys -- (tfsndrct [Auto | Running])
[2004/12/06 00:05:00 | 00,002,239 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\dla\tfsndres.sys -- (tfsndres [Auto | Running])
[2004/12/06 00:05:00 | 00,086,586 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\dla\tfsnifs.sys -- (tfsnifs [Auto | Running])
[2004/12/06 00:05:00 | 00,015,227 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\dla\tfsnopio.sys -- (tfsnopio [Auto | Running])
[2004/12/06 00:05:00 | 00,006,363 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\dla\tfsnpool.sys -- (tfsnpool [Auto | Running])
[2004/12/06 00:05:00 | 00,098,714 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\dla\tfsnudf.sys -- (tfsnudf [Auto | Running])
[2004/12/06 00:05:00 | 00,100,603 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\dla\tfsnudfa.sys -- (tfsnudfa [Auto | Running])
[2004/02/04 09:27:56 | 00,049,536 | ---- | M] (Texas Instruments Incorporated) -- C:\WINDOWS\SYSTEM32\DRIVERS\tiehdusb.sys -- (TIEHDUSB [On_Demand | Stopped])
[2001/08/17 12:52:22 | 00,036,736 | ---- | M] (Promise Technology, Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\ULTRA.SYS -- (ultra [Boot | Running])
[2003/01/10 15:13:04 | 00,033,588 | ---- | M] (America Online, Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\wanatw4.sys -- (wanatw [On_Demand | Running])

========== (R ) Internet Explorer ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=http://go.microsoft.com/fwlink/?LinkId=69157
"Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896
"Default_Secondary_Page_URL"=
"Extensions Off Page"=about:NoAdd-ons
"Local Page"=C:\WINDOWS\system32\blank.htm
"Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896
"Security Risk Page"=about:SecurityRisk
"Start Page"=http://go.microsoft.com/fwlink/?LinkId=69157

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search]
"CustomizeSearch"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
"Default_Search_URL"=http://www.google.com/ie
"SearchAssistant"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\WINDOWS\system32\blank.htm
"Page_Transitions"=
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"SearchMigratedDefaultName"=Google
"SearchMigratedDefaultURL"=http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
"Start Page"=http://exchange.wartburg.edu/

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURL]
""=

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\SYSTEM32\ieframe.dll (Microsoft Corporation)

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=http://www.dell4me.com/myway
"First Home Page"=http://www.dell4me.com/myway
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=http://www.dell4me.com/myway
"First Home Page"=http://www.dell4me.com/myway
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome

[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main]

[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main]

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\WINDOWS\system32\blank.htm
"Page_Transitions"=
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"SearchMigratedDefaultName"=Google
"SearchMigratedDefaultURL"=http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
"Start Page"=http://exchange.wartburg.edu/

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\Software\Microsoft\Internet Explorer\SearchURL]
""=

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\SYSTEM32\ieframe.dll (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

========== (O1) Hosts File ==========

HOSTS File = (812 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
First 25 entries...
127.0.0.1 localhost
r3HQZ]'TA!HF& 7Zi2E 3'BM.˾2͘GY}!":}am5 # Webroot SpySweeper entry

========== (O2) BHO's ==========

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (HKLM) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
{3049C3E9-B461-4BC5-8870-4C09146192CA} (HKLM) -- C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
{53707962-6F74-2D53-2644-206D7942484F} (HKLM) -- C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
{5CA3D70E-1895-11CF-8E15-001234567890} (HKLM) -- C:\WINDOWS\SYSTEM32\dla\tfswshx.dll (Sonic Solutions)
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (HKLM) -- C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
{7E853D72-626A-48EC-A868-BA8D5E23E045} (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
{9030D464-4C02-4ABF-8ECC-5164760863C6} (HKLM) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
{AA1F9DDB-E605-4ba6-81D4-E427DEE012AD} (HKLM) -- C:\WINDOWS\SYSTEM32\TwcToolbarBho.dll ()
{AA58ED58-01DD-4d91-8333-CF10577473F7} (HKLM) -- c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (HKLM) -- C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll (Google Inc.)
{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} (HKLM) -- C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll (Microsoft Corporation)
{d2ce3e00-f94a-4740-988e-03dc2f38c34f} (HKLM) -- C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll (Microsoft Corp.)
{DBC80044-A445-435b-BC74-9C25C1C588A9} (HKLM) -- C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
{E7E6F031-17CE-4C07-BC86-EABFE594F69C} (HKLM) -- C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)

========== (O3) Toolbars ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414}" (HKLM) -- C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll (Microsoft Corp.)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" (HKLM) -- c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{2E5E800E-6AC0-411E-940A-369530A35E43}" (HKLM) -- C:\WINDOWS\SYSTEM32\TwcToolbarIe7.dll ()

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}" (HKLM) -- C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll (Microsoft Corporation)

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" (HKLM) -- c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" (HKLM) -- c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{604BC32A-9680-40D1-9AC6-E06B23A1BA4C}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}" (HKLM) -- C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll (Microsoft Corporation)

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" (HKLM) -- c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)

[HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{5BED3930-2E9E-76D8-BACC-80DF2188D455}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" (HKLM) -- c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)

[HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{5BED3930-2E9E-76D8-BACC-80DF2188D455}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" (HKLM) -- c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" (HKLM) -- c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{604BC32A-9680-40D1-9AC6-E06B23A1BA4C}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}" (HKLM) -- C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

========== (O4) Run Keys ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" (Adobe Systems Incorporated)
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
"AppleSyncNotifier"=C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
"bncsaui.exe"=%ProgramFiles%\Bradford Networks\Persistent Agent\bncsaui.exe ()
"dla"=C:\WINDOWS\system32\dla\tfswctrl.exe (Sonic Solutions)
"DLCCCATS"=rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16 ()
"dlccmon.exe"="C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe" (Dell)
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" (Hewlett-Packard Company)
"HP Software Update"=C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe (Hewlett-Packard Co.)
"HPDJ Taskbar Utility"=C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe (HP)
"igfxhkcmd"=C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
"igfxpers"=C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
"igfxtray"=C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
"IntelMeM"=C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe (Intel Corporation)
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
"mmtask"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe" (Musicmatch Inc.)
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" (Musicmatch, Inc.)
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r (Sonic Solutions)
"vptray"=C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe (Symantec Corporation)
"Webroot Spy Sweeper, Enterprise Edition"=C:\Program Files\Webroot\Enterprise\Spy Sweeper\SpySweeperTray.exe (Webroot Software, Inc.)
"WebrootClientUI"="C:\Program Files\Webroot\Client\SpySweeperUI.exe" (Webroot Software, Inc.)
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" ()

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" /startup (Gteko Ltd.)
"DW6"="C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe" (The Weather Channel Interactive, Inc.)
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler (Macrovision Corporation)
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (Microsoft Corporation)
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" /startup (Gteko Ltd.)
"DW6"="C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe" (The Weather Channel Interactive, Inc.)
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler (Macrovision Corporation)
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (Microsoft Corporation)
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)

========== (O4) Startup Folders ==========

[2004/09/01 10:56:34 | 00,156,784 | -H-- | M] (America Online, Inc.) -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
[2005/09/20 18:10:04 | 00,238,080 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearch.exe
[2006/12/22 10:17:32 | 00,598,016 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Wireless Configuration Utility HW.14.lnk = C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe

========== (O6 & O7) Current Version Policies ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"AllowLegacyWebView"=1
"AllowUnhashedWebView"=1
"NoCDBurning"=0
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"DisableRegistryTools"=0

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
"NoDriveAutoRun"=67108863

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
"NoDriveAutoRun"=67108863

[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

========== (O8) IE Context Menu Extensions ==========

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\]
&MSN Search: C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-us\msntb.dll [2005/06/15 20:02:08 | 00,577,232 | ---- | M] (Microsoft Corporation)
&Search: Reg Error: Value does not exist or could not be read. File not found
&Yahoo! Search: File not found
E&xport to Microsoft Excel: C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE [2008/10/13 11:29:28 | 10,351,944 | ---- | M] (Microsoft Corporation)
Open in new background tab: C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1110\en-us\msntabres.dll [2005/08/01 16:18:58 | 00,078,848 | ---- | M] (Microsoft Corporation)
Open in new foreground tab: C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1110\en-us\msntabres.dll [2005/08/01 16:18:58 | 00,078,848 | ---- | M] (Microsoft Corporation)
Yahoo! &Dictionary: File not found
Yahoo! &Maps: File not found
Yahoo! &SMS: File not found

[HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE [2008/10/13 11:29:28 | 10,351,944 | ---- | M] (Microsoft Corporation)

[HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE [2008/10/13 11:29:28 | 10,351,944 | ---- | M] (Microsoft Corporation)

[HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: Reg Error: Key does not exist or could not be opened. File not found

[HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: Reg Error: Key does not exist or could not be opened. File not found

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\Software\Microsoft\Internet Explorer\MenuExt\]
&MSN Search: C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-us\msntb.dll [2005/06/15 20:02:08 | 00,577,232 | ---- | M] (Microsoft Corporation)
&Search: Reg Error: Value does not exist or could not be read. File not found
&Yahoo! Search: File not found
E&xport to Microsoft Excel: C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE [2008/10/13 11:29:28 | 10,351,944 | ---- | M] (Microsoft Corporation)
Open in new background tab: C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1110\en-us\msntabres.dll [2005/08/01 16:18:58 | 00,078,848 | ---- | M] (Microsoft Corporation)
Open in new foreground tab: C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1110\en-us\msntabres.dll [2005/08/01 16:18:58 | 00,078,848 | ---- | M] (Microsoft Corporation)
Yahoo! &Dictionary: File not found
Yahoo! &Maps: File not found
Yahoo! &SMS: File not found

========== (O9) IE Extensions ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}: Menu: Sun Java Console -- %ProgramFiles%\Java\jre6\bin\npjpi160_11.dll [2009/01/26 19:51:46 | 00,132,504 | ---- | M] (Sun Microsystems, Inc.)
{2E5E800E-6AC0-411E-940A-369530A35E43}: Button: The Weather Channel -- Reg Error: Key does not exist or could not be opened. File not found
{2E5E800E-6AC0-411E-940A-369530A35E43}: Menu: The Weather Channel -- File not found
{92780B25-18CC-41C8-B9BE-3C9C571A8263}: Button: Research -- %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [2007/04/19 13:10:18 | 00,063,840 | ---- | M] (Microsoft Corporation)
{e2e2dd38-d088-4134-82b7-f2ba38496583}: Menu: @xpsp3res.dll,-20001 -- %SystemRoot%\network diagnostic\xpnetdiag.exe [2008/04/13 12:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Button: Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2008/04/13 18:12:28 | 01,695,232 | -HS- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Menu: Windows Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2008/04/13 18:12:28 | 01,695,232 | -HS- | M] (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %SystemRoot%\SYSTEM32\msjava.dll [Web Browser Applet Control] -> [2003/02/28 17:26:26 | 00,947,472 | ---- | M] (Microsoft Corporation)
CmdMapping\\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2007/04/19 13:10:18 | 00,063,840 | ---- | M] (Microsoft Corporation)
CmdMapping\\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} [HKLM] -> [Reg Error: Value MenuText does not exist or could not be read.] -> File not found
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 18:12:28 | 01,695,232 | -HS- | M] (Microsoft Corporation)

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %SystemRoot%\SYSTEM32\msjava.dll [Web Browser Applet Control] -> [2003/02/28 17:26:26 | 00,947,472 | ---- | M] (Microsoft Corporation)
CmdMapping\\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2007/04/19 13:10:18 | 00,063,840 | ---- | M] (Microsoft Corporation)
CmdMapping\\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} [HKLM] -> [Reg Error: Value MenuText does not exist or could not be read.] -> File not found
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 18:12:28 | 01,695,232 | -HS- | M] (Microsoft Corporation)

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %SystemRoot%\SYSTEM32\msjava.dll [Web Browser Applet Control] -> [2003/02/28 17:26:26 | 00,947,472 | ---- | M] (Microsoft Corporation)
CmdMapping\\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2007/04/19 13:10:18 | 00,063,840 | ---- | M] (Microsoft Corporation)
CmdMapping\\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} [HKLM] -> [Reg Error: Value MenuText does not exist or could not be read.] -> File not found
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 18:12:28 | 01,695,232 | -HS- | M] (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %SystemRoot%\SYSTEM32\msjava.dll [Web Browser Applet Control] -> [2003/02/28 17:26:26 | 00,947,472 | ---- | M] (Microsoft Corporation)
CmdMapping\\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2007/04/19 13:10:18 | 00,063,840 | ---- | M] (Microsoft Corporation)
CmdMapping\\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} [HKLM] -> [Reg Error: Value MenuText does not exist or could not be read.] -> File not found
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 18:12:28 | 01,695,232 | -HS- | M] (Microsoft Corporation)

========== (O12) Internet Explorer Plugins ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\]
PluginsPage: "" = http://activex.microsoft.com/controls/find...=%s&mime=%s
PluginsPageFriendlyName: "" = Microsoft ActiveX Gallery

========== (O13) Default Prefixes ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
""=http://

========== (O15) Trusted Sites ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
1 domain(s) and sub-domain(s) not assigned to a zone.

========== (O16) DPF ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\]
{14B87622-7E19-4EA8-93B3-97215F77A6BC}: http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab -- MessengerStatsClient Class
{17492023-C23A-453E-A040-C7C580BBF700}: http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409 -- Windows Genuine Advantage Validation Tool
{20A60F0D-9AFA-4515-A0FD-83BD84642501}: http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab -- Checkers Class
{33564D57-0000-0010-8000-00AA00389B71}: http://download.microsoft.com/download/F/6...922/wmv9VCM.CAB -- Reg Error: Key does not exist or could not be opened.
{3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}: http://office.microsoft.com/officeupdate/content/opuc2.cab -- Office Update Installation Engine
{4871A87A-BFDD-4106-8153-FFDE2BAC2967}: http://dlm.tools.akamai.com/dlmanager/vers...vex-2.2.4.1.cab -- DLM Control
{56762DEC-6B0D-4AB4-A8AD-989993B5D08B}: http://www.eset.eu/buxus/docs/OnlineScanner.cab -- OnlineScanner Control
{5F8469B4-B055-49DD-83F7-62B522420ECC}: http://upload.facebook.com/controls/Facebo...otoUploader.cab -- Facebook Photo Uploader Control
{74C861A1-D548-4916-BC8A-FDE92EDFF62C}: http://mediaplayer.walmart.com/installer/install.cab -- Reg Error: Key does not exist or could not be opened.
{8AD9C840-044E-11D1-B3E9-00805F499D93}: http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_11
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}: http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab -- Reg Error: Key does not exist or could not be opened.
{A8F2B9BD-A6A0-486A-9744-18920D898429}: http://www.sibelius.com/download/software/...tiveXPlugin.cab -- ScorchPlugin Class
{B8BE5E93-A60C-4D26-A2DC-220313175592}: http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab -- ZoneIntro Class
{C3F79A2B-B9B4-4A66-B012-3EE46475B072}: http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab -- MessengerStatsClient Class
{CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}: http://java.sun.com/products/plugin/autodl...indows-i586.cab -- Reg Error: Key does not exist or could not be opened.
{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA}: http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab -- Reg Error: Key does not exist or could not be opened.
{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}: http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab -- Reg Error: Key does not exist or could not be opened.
{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA}: http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab -- Reg Error: Key does not exist or could not be opened.
{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}: http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab -- Reg Error: Key does not exist or could not be opened.
{CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}: http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab -- Reg Error: Key does not exist or could not be opened.
{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}: http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab -- Reg Error: Key does not exist or could not be opened.
{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_11
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_11
{D27CDB6E-AE6D-11CF-96B8-444553540000}: http://download.macromedia.com/pub/shockwa...ash/swflash.cab -- Shockwave Flash Object
Microsoft XML Parser for Java: file://C:\WINDOWS\Java\classes\xmldso.cab -- Reg Error: Key does not exist or could not be opened.

========== (O17) DNS Name Servers ==========

{1B9DDFCC-CF74-4172-AA8F-5A9586A6AEF9} (Servers: | Description: Intel® PRO/100 VE Network Connection)
{44E86920-94C2-473A-BDE4-F3F35EB2E0AC} (Servers: | Description: TRENDnet TEW-424UB Wireless 802.11g 54Mbps USB 2.0 Network Adapter)

========== (O20) Winlogon Notify Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\]
igfxcui: "DllName" = igfxdev.dll -- C:\WINDOWS\SYSTEM32\igfxdev.dll (Intel Corporation)
NavLogon: "DllName" = C:\WINDOWS\system32\NavLogon.dll -- C:\WINDOWS\SYSTEM32\NavLogon.dll ()
WRNotifier: "DllName" = WRLogonNtf.DLL -- C:\WINDOWS\SYSTEM32\WRLogonNtf.DLL (Webroot Software, Inc.)

========== Safeboot Options ==========

"AlternateShell"=cmd.exe

========== CDRom AutoRun Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1

========== Autorun Files on Drives ==========

AUTOEXEC.BAT []
[2004/08/11 16:15:00 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT -- [ NTFS ]

========== MountPoints2 ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3ff550be-bbe5-11dc-9eff-0014d1362be8}\Shell]
""=AutoRun

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3ff550be-bbe5-11dc-9eff-0014d1362be8}\Shell\AutoRun]
""=Auto&Play


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3ff550be-bbe5-11dc-9eff-0014d1362be8}\Shell\AutoRun\command]
""=G:\LaunchU3.exe -- File not found

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3ff550c0-bbe5-11dc-9eff-0014d1362be8}\Shell]
""=AutoRun

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3ff550c0-bbe5-11dc-9eff-0014d1362be8}\Shell\AutoRun]
""=Auto&Play


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3ff550c0-bbe5-11dc-9eff-0014d1362be8}\Shell\AutoRun\command]
""=G:\LaunchU3.exe -- File not found

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b2a55fe8-7e81-11db-9d90-00038a000015}\Shell]
""=AutoRun

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b2a55fe8-7e81-11db-9d90-00038a000015}\Shell\AutoRun]
""=Auto&Play


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b2a55fe8-7e81-11db-9d90-00038a000015}\Shell\AutoRun\command]
""=G:\LaunchU3.exe -- File not found

========== Files/Folders - Created Within 30 Days ==========

[1 C:\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[2009/01/26 20:18:27 | 00,000,000 | ---D | C] -- C:\Program Files\EsetOnlineScanner
[2009/01/26 19:54:32 | 00,001,261 | ---- | C] () -- C:\Documents and Settings\Pamela\Desktop\1233021253772-integrated.jnlp
[2009/01/26 19:46:52 | 00,001,261 | ---- | C] () -- C:\Documents and Settings\Pamela\Desktop\1233020791728-integrated.jnlp
[2009/01/26 19:22:13 | 00,000,000 | ---- | C] () -- C:\jre-6u11-windows-i586-p.exe.bak4
[2009/01/26 19:22:13 | 00,000,000 | ---- | C] () -- C:\jre-6u11-windows-i586-p.exe.bak3
[2009/01/26 19:22:13 | 00,000,000 | ---- | C] () -- C:\jre-6u11-windows-i586-p.exe.bak2
[2009/01/26 19:22:13 | 00,000,000 | ---- | C] () -- C:\jre-6u11-windows-i586-p.exe.bak
[2009/01/26 19:22:13 | 00,000,000 | ---- | C] () -- C:\jre-6u11-windows-i586-p.exe
[2009/01/26 19:01:07 | 00,000,000 | ---D | C] -- C:\_OTMoveIt
[2009/01/26 19:00:27 | 00,348,160 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Pamela\Desktop\OTMoveIt3.exe
[2009/01/26 18:58:51 | 00,000,000 | ---D | C] -- C:\HostsXpert
[2009/01/26 18:58:25 | 00,353,485 | ---- | C] () -- C:\Documents and Settings\Pamela\Desktop\HostsXpert.zip
[2009/01/26 12:55:04 | 00,000,250 | ---- | C] () -- C:\WINDOWS\gmer.ini
[2009/01/26 12:55:00 | 00,884,736 | ---- | C] () -- C:\WINDOWS\gmer.dll
[2009/01/26 12:55:00 | 00,085,969 | ---- | C] (GMER) -- C:\WINDOWS\System32\drivers\gmer.sys
[2009/01/26 12:55:00 | 00,000,080 | ---- | C] () -- C:\WINDOWS\gmer_uninstall.cmd
[2009/01/26 12:54:59 | 00,811,008 | ---- | C] () -- C:\WINDOWS\gmer.exe
[2009/01/26 12:54:50 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pamela\Desktop\gmer
[2009/01/26 12:53:28 | 00,747,873 | ---- | C] () -- C:\Documents and Settings\Pamela\Desktop\gmer.zip
[2009/01/26 12:48:52 | 00,422,912 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Pamela\Desktop\OTViewIt.exe
[2009/01/24 23:02:38 | 00,000,121 | ---- | C] () -- C:\wallpaper_log.html
[2009/01/24 23:01:39 | 00,000,000 | ---D | C] -- C:\Program Files\Animated Screensaver Maker
[2009/01/22 23:08:59 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pamela\My Documents\Screensavers2
[2009/01/22 23:06:37 | 00,201,728 | ---- | C] (ScreenTime Media) -- C:\Documents and Settings\All Users\Documents\Harry Potter Order of the Phoenix.scr
[2009/01/22 23:06:37 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\Harry Potter Order of the Phoenix dir
[2009/01/22 23:04:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\HarryPotter_setup
[2009/01/22 23:03:09 | 00,471,040 | ---- | C] (ScreenTime Media) -- C:\WINDOWS\HarryPotter_screensaver_pc.scr
[2009/01/22 23:03:04 | 00,000,000 | ---D | C] -- C:\WINDOWS\HarryPotter_screensaver_pc dir
[2009/01/22 23:02:15 | 01,806,450 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\HarryPotter_setup.zip
[2009/01/22 19:57:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pamela\My Documents\Temps
[2009/01/21 08:29:33 | 00,261,366 | ---- | C] () -- C:\Documents and Settings\Pamela\Desktop\obamainauguration012009.pdf
[2009/01/19 22:46:00 | 00,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2009/01/19 16:16:57 | 00,000,765 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Calculator.lnk
[2009/01/19 16:16:56 | 00,000,000 | ---D | C] -- C:\Program Files\Moffsoft FreeCalc
[2009/01/19 16:16:13 | 00,782,433 | ---- | C] (Moffsoft ) -- C:\Documents and Settings\All Users\Documents\MoffFreeCalcSetup.exe
[2009/01/18 17:37:41 | 00,000,782 | ---- | C] () -- C:\Documents and Settings\Pamela\Desktop\Windows Media Player.lnk
[2009/01/18 17:30:34 | 00,000,000 | ---D | C] -- C:\Program Files\msn gaming zone
[2009/01/18 17:30:32 | 80,326,2464 | -HS- | C] () -- C:\hiberfil.sys
[2009/01/18 17:12:28 | 00,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2009/01/18 17:08:26 | 16,710,688 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\Pamela\Desktop\IE8-WindowsXP-x86-ENU.exe
[2009/01/13 09:04:38 | 00,001,754 | ---- | C] () -- C:\Documents and Settings\Pamela\Desktop\The Weather Channel Desktop.lnk
[2009/01/13 09:03:32 | 00,000,000 | ---D | C] -- C:\Program Files\The Weather Channel FW
[2009/01/10 16:53:23 | 00,000,000 | -HSD | C] -- C:\RECYCLER
[2009/01/10 13:11:11 | 00,000,000 | ---D | C] -- C:\32788R22FWJFW
[2009/01/09 10:36:53 | 00,000,000 | ---D | C] -- C:\49672c618e1a2f641b2c
[2009/01/08 19:16:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pamela\Local Settings\Application Data\Mozilla
[2009/01/08 19:15:05 | 07,518,240 | ---- | C] (Mozilla) -- C:\Documents and Settings\All Users\Documents\Firefox Setup 3.0.5.exe
[2009/01/08 12:56:35 | 15,452,536 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\Pamela\Desktop\IE7-WindowsXP-x86-enu-2.exe
[2009/01/08 09:07:24 | 00,000,776 | ---- | C] () -- C:\Documents and Settings\Pamela\Desktop\Shortcut to SPYSWEEPER.lnk
[2009/01/08 09:07:16 | 00,000,786 | ---- | C] () -- C:\Documents and Settings\Pamela\Desktop\Shortcut to SpySweeperUI.lnk
[2009/01/08 08:51:14 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pamela\Application Data\Malwarebytes
[2009/01/08 08:51:11 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/01/08 08:51:11 | 00,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/01/08 08:51:09 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/01/08 08:51:08 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/01/08 08:51:08 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/01/07 22:24:28 | 00,000,000 | ---D | C] -- C:\WINDOWS\temp
[2009/01/07 22:11:49 | 00,000,000 | ---D | C] -- C:\MyComboFix
[2009/01/07 21:59:36 | 00,000,211 | ---- | C] () -- C:\Boot.bak
[2009/01/07 21:59:32 | 00,260,272 | ---- | C] () -- C:\cmldr
[2009/01/07 21:59:26 | 00,000,000 | ---D | C] -- C:\cmdcons
[2009/01/07 21:57:18 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2009/01/07 21:57:18 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2009/01/07 21:57:18 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2009/01/07 21:57:18 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2009/01/07 21:57:18 | 00,089,504 | ---- | C] (Smallfrogs Studio) -- C:\WINDOWS\fdsv.exe
[2009/01/07 21:57:18 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2009/01/07 21:57:18 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2009/01/07 21:57:18 | 00,049,152 | ---- | C] () -- C:\WINDOWS\VFIND.exe
[2009/01/07 21:57:18 | 00,028,672 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2009/01/07 21:57:11 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/01/07 21:57:11 | 00,000,000 | ---D | C] -- C:\Qoobox
[2009/01/07 21:07:46 | 00,003,262 | ---- | C] () -- C:\Documents and Settings\Pamela\Application Data\61a44a292ee8cc98
[2009/01/07 21:07:27 | 00,003,262 | ---- | C] () -- C:\Documents and Settings\Pamela\Application Data\f80e9f63a882607b
[2009/01/07 12:12:50 | 00,000,648 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\a-squared Free.lnk
[2009/01/07 12:12:40 | 00,000,000 | ---D | C] -- C:\Program Files\a-squared Free
[2009/01/07 12:12:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pamela\My Documents\a-squared Free
[2009/01/07 11:54:53 | 00,005,120 | -HS- | C] () -- C:\Program Files\Thumbs.db
@Alternate Data Stream - 0 bytes -> C:\Program Files\Thumbs.db:encryptable
[2009/01/07 11:20:34 | 00,003,262 | ---- | C] () -- C:\Documents and Settings\Pamela\Application Data\bc51dcd3ae0b201
[2009/01/07 11:10:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\151917531
[2009/01/07 11:06:47 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pamela\Application Data\s_5849_OTl8fHx8OTl8fHwxMjQzOTc3Njk1fA_
[2009/01/07 11:01:22 | 00,003,262 | ---- | C] () -- C:\Documents and Settings\Pamela\Application Data\46da395f8f0ab0d
[2009/01/07 11:01:16 | 00,000,124 | -H-- | C] () -- C:\Documents and Settings\Pamela\Local Settings\Application Data\Thumbs.db
[2009/01/07 08:06:18 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pamela\Application Data\alot
[2009/01/05 23:24:27 | 00,000,000 | ---D | C] -- C:\Program Files\alot
[2009/01/05 23:24:08 | 00,575,504 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\movie.exe
[2009/01/05 22:36:17 | 00,000,000 | ---D | C] -- C:\Program Files\Twighlightthemoviescreens
[2009/01/05 22:35:00 | 06,044,845 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\Twighlightthemoviescreens1.0.exe
[2009/01/05 21:18:26 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pamela\My Documents\2009 Stuff
[2009/01/05 19:39:21 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pamela\My Documents\World Religions
[2009/01/03 23:06:10 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pamela\My Documents\Picture Motion Browser
[2009/01/03 22:40:25 | 00,081,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xinput1_3.dll
[2009/01/03 22:40:17 | 00,261,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_7.dll
[2009/01/03 22:40:08 | 01,123,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DCompiler_33.dll
[2009/01/03 22:40:08 | 00,443,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx10_33.dll
[2009/01/03 22:39:54 | 03,495,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_33.dll
[2009/01/03 22:39:53 | 00,255,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_6.dll
[2009/01/03 22:39:52 | 00,251,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_5.dll
[2009/01/03 22:39:51 | 03,426,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_32.dll
[2009/01/03 22:39:49 | 00,237,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_4.dll
[2009/01/03 22:39:49 | 00,015,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\x3daudio1_1.dll
[2009/01/03 22:39:48 | 02,414,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_31.dll
[2009/01/03 22:39:47 | 00,236,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_3.dll
[2009/01/03 22:39:46 | 00,230,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_2.dll
[2009/01/03 22:39:46 | 00,062,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xinput1_2.dll
[2009/01/03 22:39:45 | 00,062,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xinput1_1.dll
[2009/01/03 22:39:44 | 00,229,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_1.dll
[2009/01/03 22:39:28 | 02,388,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_30.dll
[2009/01/03 22:39:27 | 00,230,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_0.dll
[2009/01/03 22:39:27 | 00,014,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\x3daudio1_0.dll
[2009/01/03 22:39:26 | 02,332,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_29.dll
[2009/01/03 22:39:25 | 02,323,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_28.dll
[2009/01/03 22:39:24 | 00,061,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xinput9_1_0.dll
[2009/01/03 22:39:23 | 02,319,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_27.dll
[2009/01/03 22:39:21 | 02,297,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_26.dll
[2009/01/03 22:39:20 | 02,337,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_25.dll
[2009/01/03 22:39:17 | 02,222,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_24.dll
[2009/01/03 22:28:03 | 00,000,000 | ---D | C] -- C:\Program Files\Sony
[2009/01/03 19:23:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pamela\Application Data\Media Player Classic
[2009/01/03 19:17:16 | 00,000,000 | ---D | C] -- C:\Program Files\AviSynth 2.5
[2009/01/03 19:17:05 | 00,000,780 | ---- | C] () -- C:\Documents and Settings\Pamela\Desktop\DVD slideshow GUI.lnk
[2009/01/03 19:16:40 | 00,000,000 | ---D | C] -- C:\Program Files\DVD slideshow GUI

========== Files - Modified Within 30 Days ==========

[1 C:\*.tmp files]
[4 C:\WINDOWS\System32\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[2009/01/26 20:20:28 | 00,002,497 | ---- | M] () -- C:\Documents and Settings\Pamela\Desktop\Word 2003.lnk
[2009/01/26 19:54:33 | 00,001,261 | ---- | M] () -- C:\Documents and Settings\Pamela\Desktop\1233021253772-integrated.jnlp
[2009/01/26 19:53:17 | 00,000,000 | ---- | M] () -- C:\jre-6u11-windows-i586-p.exe
[2009/01/26 19:47:31 | 00,000,000 | ---- | M] () -- C:\jre-6u11-windows-i586-p.exe.bak4
[2009/01/26 19:46:52 | 00,001,261 | ---- | M] () -- C:\Documents and Settings\Pamela\Desktop\1233020791728-integrated.jnlp
[2009/01/26 19:41:16 | 00,000,000 | ---- | M] () -- C:\jre-6u11-windows-i586-p.exe.bak3
[2009/01/26 19:32:47 | 00,000,000 | ---- | M] () -- C:\jre-6u11-windows-i586-p.exe.bak2
[2009/01/26 19:22:13 | 00,000,000 | ---- | M] () -- C:\jre-6u11-windows-i586-p.exe.bak
[2009/01/26 19:12:42 | 00,000,584 | ---- | M] () -- C:\Documents and Settings\Pamela\My Documents\My Sharing Folders.lnk
[2009/01/26 19:06:06 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\WPA.DBL
[2009/01/26 19:05:42 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/01/26 19:05:39 | 00,002,048 | --S- | M] () -- C:\WINDOWS\BOOTSTAT.DAT
[2009/01/26 19:05:38 | 80,326,2464 | -HS- | M] () -- C:\hiberfil.sys
[2009/01/26 19:00:28 | 00,348,160 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Pamela\Desktop\OTMoveIt3.exe
[2009/01/26 18:58:25 | 00,353,485 | ---- | M] () -- C:\Documents and Settings\Pamela\Desktop\HostsXpert.zip
[2009/01/26 12:55:04 | 00,000,250 | ---- | M] () -- C:\WINDOWS\gmer.ini
[2009/01/26 12:55:00 | 00,884,736 | ---- | M] () -- C:\WINDOWS\gmer.dll
[2009/01/26 12:55:00 | 00,085,969 | ---- | M] (GMER) -- C:\WINDOWS\System32\drivers\gmer.sys
[2009/01/26 12:55:00 | 00,000,080 | ---- | M] () -- C:\WINDOWS\gmer_uninstall.cmd
[2009/01/26 12:54:50 | 00,811,008 | ---- | M] () -- C:\WINDOWS\gmer.exe
[2009/01/26 12:53:30 | 00,747,873 | ---- | M] () -- C:\Documents and Settings\Pamela\Desktop\gmer.zip
[2009/01/26 12:48:53 | 00,422,912 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Pamela\Desktop\OTViewIt.exe
[2009/01/24 23:02:45 | 00,000,121 | ---- | M] () -- C:\wallpaper_log.html
[2009/01/22 23:23:07 | 00,000,874 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/01/22 23:10:52 | 00,012,288 | ---- | M] () -- C:\WINDOWS\impborl.dll
[2009/01/22 23:10:22 | 00,471,040 | ---- | M] (ScreenTime Media) -- C:\WINDOWS\HarryPotter_screensaver_pc.scr
[2009/01/22 23:02:30 | 01,806,450 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\HarryPotter_setup.zip
[2009/01/22 09:45:01 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/01/21 08:29:36 | 00,261,366 | ---- | M] () -- C:\Documents and Settings\Pamela\Desktop\obamainauguration012009.pdf
[2009/01/19 16:16:57 | 00,000,765 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Calculator.lnk
[2009/01/19 16:16:17 | 00,782,433 | ---- | M] (Moffsoft ) -- C:\Documents and Settings\All Users\Documents\MoffFreeCalcSetup.exe
[2009/01/18 21:23:52 | 00,000,281 | RHS- | M] () -- C:\BOOT.INI
[2009/01/18 21:23:51 | 00,000,728 | ---- | M] () -- C:\WINDOWS\WIN.INI
[2009/01/18 17:37:42 | 00,000,782 | ---- | M] () -- C:\Documents and Settings\Pamela\Desktop\Windows Media Player.lnk
[2009/01/18 17:29:47 | 00,004,566 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009/01/18 17:29:35 | 00,445,156 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/01/18 17:29:35 | 00,384,596 | ---- | M] () -- C:\WINDOWS\System32\PERFH009.DAT
[2009/01/18 17:29:35 | 00,054,280 | ---- | M] () -- C:\WINDOWS\System32\PERFC009.DAT
[2009/01/18 17:28:58 | 00,000,057 | ---- | M] () -- C:\WINDOWS\System32\MAPISVC.INF
[2009/01/18 17:17:34 | 00,000,077 | -HS- | M] () -- C:\Documents and Settings\Pamela\My Documents\DESKTOP.INI
[2009/01/18 17:08:46 | 16,710,688 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Pamela\Desktop\IE8-WindowsXP-x86-ENU.exe
[2009/01/13 09:04:38 | 00,001,754 | ---- | M] () -- C:\Documents and Settings\Pamela\Desktop\The Weather Channel Desktop.lnk
[2009/01/12 23:06:18 | 00,026,624 | -HS- | M] () -- C:\Documents and Settings\Pamela\My Documents\Thumbs.db
@Alternate Data Stream - 0 bytes -> C:\Documents and Settings\Pamela\My Documents\Thumbs.db:encryptable
[2009/01/09 19:35:28 | 20,853,704 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009/01/08 19:16:34 | 00,001,602 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/01/08 19:15:37 | 07,518,240 | ---- | M] (Mozilla) -- C:\Documents and Settings\All Users\Documents\Firefox Setup 3.0.5.exe
[2009/01/08 12:56:34 | 15,452,536 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Pamela\Desktop\IE7-WindowsXP-x86-enu-2.exe
[2009/01/08 09:07:24 | 00,000,776 | ---- | M] () -- C:\Documents and Settings\Pamela\Desktop\Shortcut to SPYSWEEPER.lnk
[2009/01/08 09:07:16 | 00,000,786 | ---- | M] () -- C:\Documents and Settings\Pamela\Desktop\Shortcut to SpySweeperUI.lnk
[2009/01/08 08:51:11 | 00,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/01/07 21:08:27 | 04,278,026 | -H-- | M] () -- C:\Documents and Settings\Pamela\Local Settings\Application Data\IconCache.db
[2009/01/07 21:07:46 | 00,003,262 | ---- | M] () -- C:\Documents and Settings\Pamela\Application Data\61a44a292ee8cc98
[2009/01/07 21:07:27 | 00,003,262 | ---- | M] () -- C:\Documents and Settings\Pamela\Application Data\f80e9f63a882607b
[2009/01/07 14:45:00 | 00,000,124 | -H-- | M] () -- C:\Documents and Settings\Pamela\Local Settings\Application Data\Thumbs.db
[2009/01/07 12:12:51 | 00,000,648 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\a-squared Free.lnk
[2009/01/07 11:20:34 | 00,003,262 | ---- | M] () -- C:\Documents and Settings\Pamela\Application Data\bc51dcd3ae0b201
[2009/01/07 11:10:51 | 00,108,424 | ---- | M] () -- C:\Documents and Settings\Pamela\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/01/07 11:01:22 | 00,003,262 | ---- | M] () -- C:\Documents and Settings\Pamela\Application Data\46da395f8f0ab0d
[2009/01/05 23:24:22 | 00,575,504 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\movie.exe
[2009/01/05 22:35:22 | 06,044,845 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\Twighlightthemoviescreens1.0.exe
[2009/01/04 18:39:00 | 00,038,496 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/01/04 18:38:56 | 00,015,504 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/01/04 11:30:30 | 00,015,360 | ---- | M] () -- C:\Documents and Settings\Pamela\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/01/03 23:32:50 | 00,002,341 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/01/03 22:43:01 | 00,376,056 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/01/03 19:17:05 | 00,000,780 | ---- | M] () -- C:\Documents and Settings\Pamela\Desktop\DVD slideshow GUI.lnk
< End of report >

OTVIew It Extras:
OTViewIt Extras logfile created on: 1/26/2009 10:57:56 PM - Run 2
OTViewIt by OldTimer - Version 1.0.21.0 Folder = C:\Documents and Settings\Pamela\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18241)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

765.98 Mb Total Physical Memory | 385.14 Mb Available Physical Memory | 50.28% Memory free
1.83 Gb Paging File | 1.43 Gb Available in Paging File | 78.40% Paging File free
Paging file location(s): C:\pagefile.sys 1149 1349;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 33.52 Gb Total Space | 4.57 Gb Free Space | 13.64% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PAMANDTRISH
Current User Name: Pamela
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled"=1
"AntiVirusDisableNotify"=0
"FirewallDisableNotify"=0
"UpdatesDisableNotify"=0
"AntiVirusOverride"=1
"FirewallOverride"=0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall"=1
"DoNotAllowExceptions"=0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\IcmpSettings]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[2008/04/13 18:12:34 | 00,141,312 | ---- | M] (Microsoft Corporation) -- %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
[2004/04/07 11:07:32 | 01,135,728 | ---- | M] (America Online, Inc.) -- C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL
[2004/04/07 11:07:34 | 00,496,752 | ---- | M] (America Online, Inc) -- C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL
[2004/09/01 10:56:56 | 00,259,184 | ---- | M] (America Online, Inc.) -- C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0
[2008/04/13 12:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[2007/10/18 10:34:02 | 05,724,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
[2007/10/02 16:18:24 | 00,304,488 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[2008/04/13 18:12:34 | 00,141,312 | ---- | M] (Microsoft Corporation) -- %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
[2004/04/07 11:07:32 | 01,135,728 | ---- | M] (America Online, Inc.) -- C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL
[2004/04/07 11:07:34 | 00,496,752 | ---- | M] (America Online, Inc) -- C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL
[2004/09/01 10:56:56 | 00,259,184 | ---- | M] (America Online, Inc.) -- C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0
[2006/01/21 12:16:30 | 00,036,864 | ---- | M] () -- C:\Program Files\Maple 10\jre\bin\maple.exe:*:Enabled:maple
[2006/01/21 12:15:20 | 00,024,681 | ---- | M] () -- C:\Program Files\Maple 10\jre\bin\java.exe:*:Enabled:java
[2008/04/07 06:25:30 | 00,214,560 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer
[2005/02/15 10:36:40 | 00,565,248 | ---- | M] (Hewlett-Packard) -- C:\Program Files\Hewlett-Packard\HP Software Update\HPWUCli.exe:*:Disabled:HP Software Update Client
[2006/12/15 01:31:06 | 00,053,346 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre1.5.0_11\bin\javaw.exe:*:Enabled:Java™ 2 Platform Standard Edition binary
File not found -- C:\Program Files\Java\jre1.6.0_01\bin\javaw.exe:*:Enabled:Java™ Platform SE binary
[2008/04/13 12:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[2008/06/29 14:23:18 | 02,944,392 | ---- | M] () -- C:\Program Files\Bradford Networks\Persistent Agent\bndaemon.exe:*:Enabled:Bradford Persistent Agent
[2008/08/29 09:18:44 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour
[2007/10/18 10:34:02 | 05,724,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
[2007/10/02 16:18:24 | 00,304,488 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)
[2008/11/20 13:20:48 | 14,294,824 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes

========== (O10) Winsock2 Catalogs ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\]
NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] -- C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)

========== (O18) Protocol Handlers ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2003/12/22 07:38:40 | 00,081,920 | ---- | M] (Hewlett-Packard Company) C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (cetihpz:{CF184AD3-CDCB-4168-A3F7-8E447D129300} (HKLM) [CZipHandler Object])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
ipp: [HKLM - No CLSID value]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2005/09/20 11:33:58 | 00,843,984 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL ipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2007/10/18 10:31:54 | 00,066,072 | ---- | M] (Microsoft Corporation) C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (livecall:{828030A1-22C1-4009-854F-8E305202313F} (HKLM) [Reg Error: Value does not exist or could not be read.])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
msdaipp: [HKLM - No CLSID value]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2005/09/20 11:33:58 | 00,843,984 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2005/09/20 11:33:58 | 00,843,984 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\oledb:{E1D2BF40-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAIPP.BINDER]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2000/04/19 17:47:36 | 00,520,117 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (ms-itss:{0A9007C0-4076-11D3-8789-0000F8105754} (HKLM) [Microsoft Infotech Storage Protocol for IE 4.0])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2007/10/18 10:31:54 | 00,066,072 | ---- | M] (Microsoft Corporation) C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (msnim:{828030A1-22C1-4009-854F-8E305202313F} (HKLM) [Reg Error: Value does not exist or could not be read.])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2007/03/14 12:10:22 | 07,255,384 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (mso-offdap:{3D9F03FA-7A94-11D3-BE81-0050048385D1} (HKLM) [Data Page Pluggable Protocol mso-offdap Handler])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2007/05/10 12:45:34 | 08,069,464 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (mso-offdap11:{32505114-5902-49B2-880A-1F7738E5A384} (HKLM) [Data Page Plugable Protocal mso-offdap11 Handler])

========== (O18) Protocol Filters ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\] - Protocol Filters
[2007/04/19 12:57:40 | 00,046,432 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL text/xml:{807553E5-5146-11D5-A672-00B0D022E945} (HKLM) [Reg Error: Value does not exist or could not be read.]

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0456ebd7-5f67-4ab6-852e-63781e3f389c}"=Macromedia Flash Player
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}"=Sonic Update Manager
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}"=Microsoft Plus! Photo Story 2 LE
"{0EFC6259-3AD8-4CD2-BC57-D4937AF5CC0E}"=Symantec AntiVirus Client
"{10C69612-017B-45F5-B986-7D113D5A2EA3}"=MSN Toolbar
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}"=Sonic DLA
"{15EE79F4-4ED1-4267-9B0F-351009325D7D}"=HP Software Update
"{17334AAF-C9E7-483B-9F45-E3FCAF07FFA7}"=Intel® PROSet for Wired Connections
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}"=Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}"=Java™ 6 Update 11
"{318AB667-3230-41B5-A617-CB3BF748D371}"=iTunes
"{3248F0A8-6813-11D6-A77B-00B0D0150040}"=J2SE Runtime Environment 5.0 Update 4
"{3248F0A8-6813-11D6-A77B-00B0D0150060}"=J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0150080}"=J2SE Runtime Environment 5.0 Update 8
"{3248F0A8-6813-11D6-A77B-00B0D0150090}"=J2SE Runtime Environment 5.0 Update 9
"{3248F0A8-6813-11D6-A77B-00B0D0150100}"=J2SE Runtime Environment 5.0 Update 10
"{3248F0A8-6813-11D6-A77B-00B0D0150110}"=J2SE Runtime Environment 5.0 Update 11
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}"=Windows Media Player 10
"{3414C7E8-F883-445E-9994-E410D7E5B1F4}"=Bradford Persistent Agent
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}"=WebFldrs XP
"{35BDEFF1-A610-4956-A00D-15453C116395}"=Internet Explorer Default Page
"{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}"=Google Earth
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}"=Modem On Hold
"{4192EAC0-6B36-4723-B216-D0E86E7757AC}"=Jasc Paint Shop Photo Album 5
"{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}"=Adobe Photoshop Album Starter Edition 3.0
"{508CE775-4BA4-4748-82DF-FE28DA9F03B0}"=Windows Live Messenger
"{582D2A53-F426-4C5E-A2E6-43C1AB36B907}"=Safari
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}"=Dell Driver Reset Tool
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}"=Apple Software Update
"{697836DE-03BB-4C4C-9B06-CAFC93D0A506}"=Webroot Spy Sweeper Enterprise Client
"{6DA9102E-199F-43A0-A36B-6EF48081A658}"=MobileMe Control Panel
"{6E179C77-7335-458D-9537-4F4EAC0181ED}"=Photo Click
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}"=Microsoft Plus! Digital Media Edition Installer
"{7148F0A8-6813-11D6-A77B-00B0D0142030}"=Java 2 Runtime Environment, SE v1.4.2_03
"{728278A1-0BB7-45E4-AC5E-91D7C0FD1EDE}"=EarthLink setup files
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}"=Dell System Restore
"{75E71ADD-042C-4F30-BFAC-A9EC42351313}"=Python 2.4.3
"{78C496B9-5A6B-4692-8C2E-AFFFC34E4961}"=Jasc Paint Shop Pro Studio, Dell Editon
"{7A0EFAFB-AC4B-4B88-8C6B-6731BE88DB68}"=Modem Event Monitor
"{7B478ACE-8512-4A46-ACB2-69D83DF2F6C7}"=Digital Voice Recorder
"{7D1DCBBA-F6F5-42B4-B90B-F04ACE4DFD6C}"=MSN Search Toolbar
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}"=DellSupport
"{7F142D56-3326-11D5-B229-002078017FBF}"=Modem Helper
"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}"=Bonjour
"{8A708DD8-A5E6-11D4-A706-000629E95E20}"=Intel® Extreme Graphics 2 Driver
"{8EF1122E-E90C-4EE9-AB0C-7FDE2BA42C26}"=Musicmatch Jukebox
"{90110409-6000-11D3-8CFE-0150048383C9}"=Microsoft Office Professional Edition 2003
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}"=Sonic RecordNow!
"{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}"=Windows Live installer
"{A8B94669-8654-4126-BD28-D0D2412CDED6}"=TI Connect 1.6
"{AC0EE5B0-A8FB-4D0A-AF03-2EDC518F841B}"=Dell Media Experience
"{AC76BA86-7AD7-1033-7B44-A81300000003}"=Adobe Reader 8.1.3
"{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}"=ABBYY FineReader 6.0 Sprint
"{AF06CAE4-C134-44B1-B699-14FBDB63BD37}"=Dell Picture Studio v3.0
"{AF19F291-F22F-4798-9662-525305AE9E48}"=WordPerfect Office 12
"{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}"=Windows Live Sign-in Assistant
"{B8A432E2-D541-4F48-B9E8-243BEEC3D158}"=Wal-Mart Music Downloads Store
"{C43421C0-0DCB-4F26-8A3B-BF16155F9879}"=TRENDnet TEW-424UB
"{C9618743-1A5C-461E-91C4-E013A3D70F3C}"=Adobe Photoshop Album Starter Edition 3.0.1
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}"=Microsoft .NET Framework 1.1
"{EC4455AB-F155-4CC1-A4C5-88F3777F9886}"=Apple Mobile Device Support
"{F901CA6D-A074-42D3-A11D-33AAE6FFD0C1}"=HP Deskjet 3740
"{F958CA02-BB40-4007-894B-258729456EE4}"=QuickTime
"{FE7D7E78-B9FD-4CAE-B223-10C6E5B307E7}"=Webroot Client
"7-Zip"=7-Zip 4.62
"AC3Filter"=AC3Filter (remove only)
"Ad-Aware SE Personal"=Ad-Aware SE Personal
"Adobe Flash Player ActiveX"=Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin"=Adobe Flash Player 10 Plugin
"alotToolbar"=ALOT Toolbar
"America Online us"=America Online (Choose which version to remove)
"AOL Connectivity Services"=AOL Connectivity Services
"AOLCoach"=AOL Coach Version 1.0(Build:20040229.1 en)
"a-squared Free_is1"=a-squared Free 4.0
"AviSynth"=AviSynth 2.5
"BE37E547-62DF-43C8-AE6A-D03E82BC67A2_is1"=DVD slideshow GUI 0.9.0.9
"Bubblet!"=Bubblet!
"Coupon Printer for Windows4.0"=Coupon Printer for Windows
"Dell Digital Jukebox Driver"=Dell Digital Jukebox Driver
"Dell Photo AIO Printer 924"=Dell Photo AIO Printer 924
"EsetOnlineScanner"=ESET Online Scanner
"HarryPotter_screensaver_pc"=HarryPotter_screensaver_pc Screen Saver
"IDNMitigationAPIs"=Microsoft Internationalized Domain Names Mitigation APIs
"ie7"=Windows Internet Explorer 7
"ie8"=Windows Internet Explorer 8 Beta 2
"InstallShield_{C43421C0-0DCB-4F26-8A3B-BF16155F9879}"=TRENDnet TEW-424UB
"Intel® 537EP V9x DF PCI Modem"=Intel® 537EP V9x DF PCI Modem
"Jasc Paint Shop Pro Studio.01 , Dell Edition 1.0.1.1 Patch"=Jasc Paint Shop Pro Studio.01 , Dell Edition 1.0.1.1 Patch
"LiveUpdate"=LiveUpdate 1.80 (Symantec Corporation)
"Mah Jong Medley"=Mah Jong Medley
"Malwarebytes' Anti-Malware_is1"=Malwarebytes' Anti-Malware
"Maple 10"=Maple 10
"Microsoft .NET Framework 1.1 (1033)"=Microsoft .NET Framework 1.1
"MoffFreeCalc_is1"=Moffsoft FreeCalc
"Mozilla Firefox (3.0.5)"=Mozilla Firefox (3.0.5)
"MSCompPackV1"=Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST"=MSN
"MyEmo"=MyEmoticons
"NLSDownlevelMapping"=Microsoft National Language Support Downlevel APIs
"Pirates of the Caribbean"=Pirates of the Caribbean Screen Saver
"PROSet"=Intel® PRO Network Adapters and Drivers
"RealPlayer 6.0"=RealPlayer
"Shockwave"=Shockwave
"Spybot - Search & Destroy_is1"=Spybot - Search & Destroy 1.3
"StreetPlugin"=Learn2 Player (Uninstall Only)
"The Oregon Trail"=The Oregon Trail
"The Weather Channel Desktop 6"=The Weather Channel Desktop 6
"The Weather Channel Toolbar"=The Weather Channel Toolbar
"TheSky"=Software Bisque TheSky (Remove only)
"TightVNC_is1"=TightVNC 1.2.9
"Twighlightthemoviescreens 1.0_is1"=Twighlightthemoviescreens 1.0
"ViewpointMediaPlayer"=Viewpoint Media Player
"Winamp"=Winamp
"Windows Media Format Runtime"=Windows Media Format 11 runtime
"Windows Media Player"=Windows Media Player 11
"Windows XP Service Pack"=Windows XP Service Pack 3
"WMFDist11"=Windows Media Format 11 runtime
"wmp11"=Windows Media Player 11
"Wudf01000"=Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xena Season One"=Xena Season One Screen Saver
"Xvid_is1"=Xvid 1.1.3 final uninstall

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"ESPN Java Check"=ESPN Java Check
"Move Networks Player - IE"=Move Networks Media Player for Internet Explorer

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"ESPN Java Check"=ESPN Java Check
"Move Networks Player - IE"=Move Networks Media Player for Internet Explorer

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/23/2009 10:15:33 PM | Computer Name = PAMANDTRISH | Source = Norton AntiVirus | ID = 16711685
Description = Virus Found!Virus name: Downloader in File: C:\Documents and Settings\Patricia\Local
Settings\Temporary Internet Files\Content.IE5\6PGZI9I5\2_z[1].htm by: Defwatch
scan. Action: Leave Alone succeeded :

Error - 1/23/2009 10:15:33 PM | Computer Name = PAMANDTRISH | Source = Norton AntiVirus | ID = 16711685
Description = Virus Found!Virus name: Downloader in File: C:\windows\ctfmon.exe
by: Defwatch scan. Action: Leave Alone succeeded :

Error - 1/23/2009 10:15:33 PM | Computer Name = PAMANDTRISH | Source = Norton AntiVirus | ID = 16711685
Description = Virus Found!Virus name: Downloader in File: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP647\A0066595.exe
by: Defwatch scan. Action: Leave Alone succeeded :

Error - 1/24/2009 7:02:50 AM | Computer Name = PAMANDTRISH | Source = WebrootSpySweeperService | ID = 0
Description =

Error - 1/24/2009 10:44:40 PM | Computer Name = PAMANDTRISH | Source = WebrootSpySweeperService | ID = 0
Description =

Error - 1/25/2009 11:21:28 AM | Computer Name = PAMANDTRISH | Source = WebrootSpySweeperService | ID = 0
Description =

Error - 1/26/2009 10:06:45 AM | Computer Name = PAMANDTRISH | Source = WebrootSpySweeperService | ID = 0
Description =

Error - 1/26/2009 2:50:00 PM | Computer Name = PAMANDTRISH | Source = Norton AntiVirus | ID = 16711685
Description = Virus Found!Virus name: Trojan Horse in File: C:\Program Files\Common
Files\Ndm399a2rL.exe by: Realtime Protection scan. Action: Quarantine succeeded
: Access denied

Error - 1/26/2009 9:05:46 PM | Computer Name = PAMANDTRISH | Source = WebrootSpySweeperService | ID = 0
Description =

Error - 1/27/2009 12:26:46 AM | Computer Name = PAMANDTRISH | Source = Norton AntiVirus | ID = 16711685
Description = Virus Found!Virus name: Downloader.MisleadApp in File: C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\msiconf.exe.vir
by: Realtime Protection scan. Action: Quarantine succeeded : Access denied

[ System Events ]
Error - 1/27/2009 12:06:13 AM | Computer Name = PAMANDTRISH | Source = DCOM | ID = 10010
Description = The server {0BDEAA4D-0722-406F-BD43-10935AC25E0E} did not register
with DCOM within the required timeout.

Error - 1/27/2009 12:08:14 AM | Computer Name = PAMANDTRISH | Source = DCOM | ID = 10010
Description = The server {0BDEAA4D-0722-406F-BD43-10935AC25E0E} did not register
with DCOM within the required timeout.

Error - 1/27/2009 12:10:15 AM | Computer Name = PAMANDTRISH | Source = DCOM | ID = 10010
Description = The server {0BDEAA4D-0722-406F-BD43-10935AC25E0E} did not register
with DCOM within the required timeout.

Error - 1/27/2009 12:12:15 AM | Computer Name = PAMANDTRISH | Source = DCOM | ID = 10010
Description = The server {0BDEAA4D-0722-406F-BD43-10935AC25E0E} did not register
with DCOM within the required timeout.

Error - 1/27/2009 12:14:16 AM | Computer Name = PAMANDTRISH | Source = DCOM | ID = 10010
Description = The server {0BDEAA4D-0722-406F-BD43-10935AC25E0E} did not register
with DCOM within the required timeout.

Error - 1/27/2009 12:16:17 AM | Computer Name = PAMANDTRISH | Source = DCOM | ID = 10010
Description = The server {0BDEAA4D-0722-406F-BD43-10935AC25E0E} did not register
with DCOM within the required timeout.

Error - 1/27/2009 12:18:18 AM | Computer Name = PAMANDTRISH | Source = DCOM | ID = 10010
Description = The server {0BDEAA4D-0722-406F-BD43-10935AC25E0E} did not register
with DCOM within the required timeout.

Error - 1/27/2009 12:20:18 AM | Computer Name = PAMANDTRISH | Source = DCOM | ID = 10010
Description = The server {0BDEAA4D-0722-406F-BD43-10935AC25E0E} did not register
with DCOM within the required timeout.

Error - 1/27/2009 12:22:19 AM | Computer Name = PAMANDTRISH | Source = DCOM | ID = 10010
Description = The server {0BDEAA4D-0722-406F-BD43-10935AC25E0E} did not register
with DCOM within the required timeout.

Error - 1/27/2009 12:24:20 AM | Computer Name = PAMANDTRISH | Source = DCOM | ID = 10010
Description = The server {0BDEAA4D-0722-406F-BD43-10935AC25E0E} did not register
with DCOM within the required timeout.


< End of report >

#8 wartburgtrack33

wartburgtrack33
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:06:47 PM

Posted 27 January 2009 - 09:38 AM

I have Symantec Anti Virus software and when I turned on the computer this morning, this message popped up.

Scan type: Realtime Protection Scan
Event: Virus Found!
Virus name: Trojan Horse
File: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP8\A0000416.exe
Location: Quarantine
Computer: PAMANDTRISH
User: SYSTEM
Action taken: Quarantine succeeded : Access denied
Date found: Tuesday, January 27, 2009 7:04:20 AM

what does it mean?

#9 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,304 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:05:47 PM

Posted 27 January 2009 - 07:41 PM

System Volume Information\_restore

The identified file is inside of system restore. It has already been removed.

How are things running? Do you have any more problems?

"{7148F0A8-6813-11D6-A77B-00B0D0142030}"=Java 2 Runtime Environment, SE v1.4.2_03
"{3248F0A8-6813-11D6-A77B-00B0D0150040}"=J2SE Runtime Environment 5.0 Update 4
"{3248F0A8-6813-11D6-A77B-00B0D0150060}"=J2SE Runtime Environment 5.0 Update 6
"{3248F0A8-6813-11D6-A77B-00B0D0150080}"=J2SE Runtime Environment 5.0 Update 8
"{3248F0A8-6813-11D6-A77B-00B0D0150090}"=J2SE Runtime Environment 5.0 Update 9
"{3248F0A8-6813-11D6-A77B-00B0D0150100}"=J2SE Runtime Environment 5.0 Update 10
"{3248F0A8-6813-11D6-A77B-00B0D0150110}"=J2SE Runtime Environment 5.0 Update 11

You appear to have missed several Javas from the Add/Remove programs area. Please go back and remove these old versions. The current version will be listed as

Java 6 Update 11


After that, please post another OTVI log :thumbup2:

Billy3
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#10 wartburgtrack33

wartburgtrack33
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:06:47 PM

Posted 27 January 2009 - 08:15 PM

Billy,
I removed the rest of the Java programs and ran OTVI again. I am including the text.

Everything is running really well today. I haven't had any problems. :thumbup2:

Main:
OTViewIt logfile created on: 1/27/2009 7:10:01 PM - Run 3
OTViewIt by OldTimer - Version 1.0.21.0 Folder = C:\Documents and Settings\Pamela\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18241)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

765.98 Mb Total Physical Memory | 293.34 Mb Available Physical Memory | 38.30% Memory free
1.83 Gb Paging File | 1.36 Gb Available in Paging File | 74.67% Paging File free
Paging file location(s): C:\pagefile.sys 1149 1349;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 33.52 Gb Total Space | 4.63 Gb Free Space | 13.82% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PAMANDTRISH
Current User Name: Pamela
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days

========== Processes ==========

[2008/12/17 08:32:06 | 00,419,448 | ---- | M] (Emsi Software GmbH) -- C:\Program Files\a-squared Free\a2service.exe
[2004/04/07 11:07:32 | 01,135,728 | ---- | M] (America Online, Inc.) -- C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
[2008/11/07 14:28:16 | 00,132,424 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
[2008/06/29 14:23:18 | 02,944,392 | ---- | M] () -- C:\Program Files\Bradford Networks\Persistent Agent\bndaemon.exe
[2008/08/29 09:18:44 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe
[2003/05/21 00:22:36 | 00,032,768 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
[2009/01/27 12:37:47 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
[2003/06/19 22:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
[2003/05/21 00:27:46 | 00,610,304 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
[2005/03/30 15:03:26 | 01,872,384 | ---- | M] (Webroot Software, Inc.) -- C:\Program Files\Webroot\Enterprise\CommAgent\CommAgent.exe
[2008/04/13 18:12:40 | 00,218,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SYSTEM32\WBEM\wmiprvse.exe
[2004/10/14 13:42:54 | 01,404,928 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\Core\smax4pnp.exe
[2003/09/03 19:12:44 | 00,221,184 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
[2005/03/15 07:58:08 | 00,135,168 | ---- | M] (Musicmatch, Inc.) -- C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
[2004/12/06 00:05:00 | 00,127,035 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\dla\tfswctrl.exe
[2005/03/15 07:58:08 | 00,053,248 | ---- | M] (Musicmatch Inc.) -- C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe
[2003/05/21 00:21:18 | 00,090,112 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\VPTray.exe
[2004/03/04 09:46:24 | 00,172,032 | ---- | M] (HP) -- C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\hpztsb10.exe
[2003/12/22 07:38:42 | 00,241,664 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
[2005/02/16 23:11:42 | 00,049,152 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe
[2005/09/20 09:32:24 | 00,077,824 | ---- | M] (Intel Corporation) -- C:\WINDOWS\SYSTEM32\hkcmd.exe
[2005/09/20 09:36:20 | 00,114,688 | ---- | M] (Intel Corporation) -- C:\WINDOWS\SYSTEM32\igfxpers.exe
[2005/06/06 22:46:24 | 00,057,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
[2005/10/21 09:40:26 | 00,430,080 | ---- | M] (Dell) -- C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
[2008/04/07 06:25:21 | 00,185,896 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[2008/07/16 10:19:00 | 00,435,616 | ---- | M] (Webroot Software, Inc.) -- C:\Program Files\Webroot\Client\SpySweeperUI.exe
[2008/06/29 14:23:18 | 02,612,616 | ---- | M] () -- C:\Program Files\Bradford Networks\Persistent Agent\bncsaui.exe
[2008/08/03 17:02:20 | 00,036,352 | ---- | M] () -- C:\Program Files\Winamp\winampa.exe
[2008/11/20 13:20:54 | 00,290,088 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunesHelper.exe
[2005/10/28 06:41:52 | 00,491,520 | ---- | M] ( ) -- C:\WINDOWS\SYSTEM32\dlcccoms.exe
[2005/03/30 15:03:44 | 00,212,992 | ---- | M] (Webroot Software, Inc.) -- C:\Program Files\Webroot\Enterprise\Spy Sweeper\SpySweeperTray.exe
[2009/01/27 12:37:47 | 00,136,600 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
[2007/03/15 10:09:36 | 00,460,784 | ---- | M] (Gteko Ltd.) -- C:\Program Files\DellSupport\DSAgnt.exe
[2007/10/18 10:34:02 | 05,724,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe
[2007/07/20 06:29:07 | 00,068,856 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[2006/09/11 03:40:32 | 00,218,032 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
[2008/06/10 16:18:10 | 00,785,520 | ---- | M] (The Weather Channel Interactive, Inc.) -- C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe
[2008/11/20 13:20:44 | 00,536,872 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe
[2006/12/22 10:17:32 | 00,598,016 | ---- | M] () -- C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe
[2007/10/18 10:31:54 | 00,098,328 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\usnsvc.exe
[2008/08/22 03:16:40 | 00,637,984 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\iexplore.exe
[2008/08/22 03:16:40 | 00,637,984 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\iexplore.exe
[2007/09/20 09:35:36 | 00,118,336 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
[2008/08/22 03:16:40 | 00,637,984 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\iexplore.exe
[2009/01/26 12:48:53 | 00,422,912 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Pamela\Desktop\OTViewIt.exe

========== (O23) Win32 Services ==========

[2008/12/17 08:32:06 | 00,419,448 | ---- | M] (Emsi Software GmbH) -- C:\Program Files\a-squared Free\a2service.exe -- (a2free [Auto | Running])
[2004/04/07 11:07:32 | 01,135,728 | ---- | M] (America Online, Inc.) -- C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe -- (AOL ACS [Auto | Running])
[2008/11/07 14:28:16 | 00,132,424 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running])
[2004/07/15 00:49:26 | 00,032,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
[2008/06/29 14:23:18 | 02,944,392 | ---- | M] () -- C:\Program Files\Bradford Networks\Persistent Agent\bndaemon.exe -- (BNPagent [Auto | Running])
[2008/08/29 09:18:44 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service [Auto | Running])
[2003/05/21 00:22:36 | 00,032,768 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe -- (DefWatch [Auto | Running])
[2005/10/28 06:41:52 | 00,491,520 | ---- | M] ( ) -- C:\WINDOWS\SYSTEM32\dlcccoms.exe -- (dlcc_device [On_Demand | Running])
File not found -- -- (DM1Service [Auto | Stopped])
[2007/03/07 14:47:46 | 00,076,848 | ---- | M] () -- C:\Program Files\DellSupport\brkrsvc.exe -- (DSBrokerService [On_Demand | Stopped])
[2007/01/24 08:10:32 | 00,138,168 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [On_Demand | Stopped])
[2005/11/14 00:06:04 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
[2008/11/20 13:20:44 | 00,536,872 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Running])
[2009/01/27 12:37:47 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
[2003/06/19 22:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE -- (MDM [Auto | Running])
File not found -- -- (navapsvc [Auto | Stopped])
[2003/12/17 12:59:48 | 00,143,360 | ---- | M] (Intel® Corporation) -- C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe -- (NetSvc [On_Demand | Stopped])
[2003/05/21 00:27:46 | 00,610,304 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe -- (Norton AntiVirus Server [Auto | Running])
[2003/07/28 11:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
[2007/10/18 10:31:54 | 00,098,328 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\usnsvc.exe -- (usnjsvc [On_Demand | Running])
[2005/03/30 15:03:26 | 01,872,384 | ---- | M] (Webroot Software, Inc.) -- C:\Program Files\Webroot\Enterprise\CommAgent\CommAgent.exe -- (WebrootCommAgentService [Auto | Running])
[2005/03/30 15:03:46 | 01,812,992 | ---- | M] (Webroot Software, Inc.) -- C:\Program Files\Webroot\Enterprise\Spy Sweeper\SpySweeper.exe -- (WebrootSpySweeperService [Auto | Stopped])
[2007/10/25 14:27:54 | 00,266,240 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\installer\WLSetupSvc.exe -- (WLSetupSvc [On_Demand | Stopped])
[2006/10/18 19:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])

========== Driver Services ==========

[2007/07/02 21:06:02 | 00,021,035 | ---- | M] (Meetinghouse Data Communications) -- C:\WINDOWS\SYSTEM32\DRIVERS\AegisP.sys -- (AegisP [Auto | Running])
[2001/08/17 12:51:56 | 00,005,248 | ---- | M] (Acer Laboratories Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\ALIIDE.SYS -- (AliIde [Boot | Running])
[2008/04/13 12:36:39 | 00,043,008 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\amdagp.sys -- (amdagp [Boot | Running])
[2001/08/17 12:52:00 | 00,026,496 | ---- | M] (Advanced System Products, Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\ASC.SYS -- (asc [Boot | Running])
[2001/08/17 12:51:58 | 00,014,848 | ---- | M] (Advanced System Products, Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\ASC3550.SYS -- (asc3550 [Boot | Running])
[2001/08/17 12:51:54 | 00,006,656 | ---- | M] (CMD Technology, Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\CMDIDE.SYS -- (CmdIde [Boot | Running])
[2001/08/17 12:52:16 | 00,179,584 | ---- | M] (Mylex Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\DAC2W2K.SYS -- (dac2w2k [Boot | Running])
[2004/12/01 02:22:00 | 00,087,488 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\DRIVERS\drvmcdb.sys -- (drvmcdb [Boot | Running])
[2004/11/23 01:56:00 | 00,040,480 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\DRIVERS\drvnddm.sys -- (drvnddm [Auto | Running])
[2006/10/05 15:07:28 | 00,004,736 | ---- | M] (Gteko Ltd.) -- C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys -- (DSproct [On_Demand | Running])
[2007/02/25 11:10:48 | 00,005,376 | --S- | M] (Gteko Ltd.) -- C:\WINDOWS\SYSTEM32\DRIVERS\dsunidrv.sys -- (dsunidrv [Auto | Running])
[2004/02/10 14:49:14 | 00,154,112 | ---- | M] (Intel Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\e100b325.sys -- (E100B [On_Demand | Running])
[2008/04/17 12:12:54 | 00,015,464 | ---- | M] (GEAR Software Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys -- (GEARAspiWDM [On_Demand | Running])
[2009/01/26 12:55:00 | 00,085,969 | ---- | M] (GMER) -- C:\WINDOWS\SYSTEM32\DRIVERS\gmer.sys -- (gmer [On_Demand | Stopped])
[2005/09/20 10:00:54 | 01,302,332 | ---- | M] (Intel Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\ialmnt5.sys -- (ialm [On_Demand | Running])
[2004/03/05 21:14:42 | 01,233,525 | ---- | M] (Intel Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\IntelC51.sys -- (IntelC51 [On_Demand | Running])
[2004/03/05 21:15:34 | 00,647,929 | ---- | M] (Intel Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\IntelC52.sys -- (IntelC52 [On_Demand | Running])
[2004/06/15 21:52:40 | 00,061,157 | ---- | M] (Intel Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\IntelC53.sys -- (IntelC53 [On_Demand | Running])
[2008/04/13 12:39:48 | 00,014,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\kbdhid.sys -- (kbdhid [System | Stopped])
[2001/08/17 12:57:38 | 00,016,128 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\MODEMCSA.sys -- (MODEMCSA [On_Demand | Running])
[2004/03/05 21:13:38 | 00,037,048 | ---- | M] (Intel Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\mohfilt.sys -- (mohfilt [On_Demand | Running])
[2001/08/17 12:52:12 | 00,017,280 | ---- | M] (American Megatrends Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\MRAID35X.SYS -- (mraid35x [Boot | Running])
[2003/05/02 20:08:18 | 00,224,256 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Navap.sys -- (NAVAP [On_Demand | Running])
[2003/05/02 20:08:22 | 00,030,208 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Navapel.sys -- (NAVAPEL [Auto | Running])
[2009/01/23 03:00:00 | 00,089,104 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090123.003\NAVENG.SYS -- (NAVENG [On_Demand | Running])
[2009/01/23 03:00:00 | 00,876,112 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090123.003\NAVEX15.SYS -- (NAVEX15 [On_Demand | Running])
[2004/08/03 21:29:56 | 01,897,408 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\NV4_MINI.SYS -- (nv [On_Demand | Stopped])
[2004/08/04 04:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\PTILINK.SYS -- (Ptilink [On_Demand | Running])
[2007/03/07 17:51:00 | 00,043,528 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\DRIVERS\pxhelp20.sys -- (PxHelp20 [Boot | Running])
[2001/08/17 12:52:20 | 00,040,320 | ---- | M] (QLogic Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\QL1080.SYS -- (ql1080 [Boot | Running])
[2001/08/17 12:52:20 | 00,045,312 | ---- | M] (QLogic Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\QL12160.SYS -- (ql12160 [Boot | Running])
[2001/08/17 12:52:18 | 00,049,024 | ---- | M] (QLogic Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\QL1280.SYS -- (ql1280 [Boot | Running])
[2006/12/26 13:58:02 | 00,189,312 | ---- | M] (Realtek Semiconductor Corporation ) -- C:\WINDOWS\SYSTEM32\DRIVERS\RTL8187B.sys -- (RTL8187B [On_Demand | Stopped])
[2007/11/13 04:25:53 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\SYSTEM32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])
[2004/09/17 08:02:54 | 00,732,928 | ---- | M] (Creative Technology Ltd.) -- C:\WINDOWS\SYSTEM32\DRIVERS\senfilt.sys -- (senfilt [On_Demand | Running])
[2008/04/13 12:36:39 | 00,040,960 | ---- | M] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\sisagp.sys -- (sisagp [Boot | Running])
[2005/01/27 14:31:06 | 00,260,352 | ---- | M] (Analog Devices, Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\smwdm.sys -- (smwdm [On_Demand | Running])
[2001/08/17 13:07:44 | 00,019,072 | ---- | M] (Adaptec, Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\SPARROW.SYS -- (Sparrow [Boot | Running])
[2004/07/14 10:29:04 | 00,005,627 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\DRIVERS\sscdbhk5.sys -- (sscdbhk5 [System | Running])
[2008/07/16 10:15:34 | 00,020,336 | ---- | M] (Webroot Software Inc (www.webroot.com)) -- C:\WINDOWS\SYSTEM32\DRIVERS\ssfs0BB9.sys -- (SSFS0BB9 [Boot | Running])
[2008/07/16 10:15:34 | 00,021,872 | ---- | M] (Webroot Software Inc (www.webroot.com)) -- C:\WINDOWS\SYSTEM32\DRIVERS\SSHRMD.SYS -- (SSHRMD [Boot | Running])
[2008/07/16 10:15:36 | 00,163,696 | ---- | M] (Webroot Software Inc (www.webroot.com)) -- C:\WINDOWS\SYSTEM32\DRIVERS\SSIDRV.SYS -- (SSIDRV [Boot | Running])
[2004/07/14 10:28:50 | 00,023,545 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\DRIVERS\ssrtln.sys -- (ssrtln [System | Running])
[2001/08/17 13:07:34 | 00,016,256 | ---- | M] (Symbios Logic Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\SYMC810.SYS -- (symc810 [Boot | Running])
[2001/08/17 13:07:36 | 00,032,640 | ---- | M] (LSI Logic) -- C:\WINDOWS\SYSTEM32\DRIVERS\SYMC8XX.SYS -- (symc8xx [Boot | Running])
[2005/03/15 14:33:52 | 00,123,208 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\SYMEVENT.SYS -- (SymEvent [On_Demand | Running])
[2001/08/17 13:07:40 | 00,028,384 | ---- | M] (LSI Logic) -- C:\WINDOWS\SYSTEM32\DRIVERS\SYM_HI.SYS -- (sym_hi [Boot | Running])
[2001/08/17 13:07:42 | 00,030,688 | ---- | M] (LSI Logic) -- C:\WINDOWS\SYSTEM32\DRIVERS\SYM_U3.SYS -- (sym_u3 [Boot | Running])
[2004/12/06 00:05:00 | 00,025,883 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\dla\tfsnboio.sys -- (tfsnboio [Auto | Running])
[2004/12/06 00:05:00 | 00,034,843 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\dla\tfsncofs.sys -- (tfsncofs [Auto | Running])
[2004/12/06 00:05:00 | 00,004,123 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\dla\tfsndrct.sys -- (tfsndrct [Auto | Running])
[2004/12/06 00:05:00 | 00,002,239 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\dla\tfsndres.sys -- (tfsndres [Auto | Running])
[2004/12/06 00:05:00 | 00,086,586 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\dla\tfsnifs.sys -- (tfsnifs [Auto | Running])
[2004/12/06 00:05:00 | 00,015,227 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\dla\tfsnopio.sys -- (tfsnopio [Auto | Running])
[2004/12/06 00:05:00 | 00,006,363 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\dla\tfsnpool.sys -- (tfsnpool [Auto | Running])
[2004/12/06 00:05:00 | 00,098,714 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\dla\tfsnudf.sys -- (tfsnudf [Auto | Running])
[2004/12/06 00:05:00 | 00,100,603 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\dla\tfsnudfa.sys -- (tfsnudfa [Auto | Running])
[2004/02/04 09:27:56 | 00,049,536 | ---- | M] (Texas Instruments Incorporated) -- C:\WINDOWS\SYSTEM32\DRIVERS\tiehdusb.sys -- (TIEHDUSB [On_Demand | Stopped])
[2001/08/17 12:52:22 | 00,036,736 | ---- | M] (Promise Technology, Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\ULTRA.SYS -- (ultra [Boot | Running])
[2003/01/10 15:13:04 | 00,033,588 | ---- | M] (America Online, Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\wanatw4.sys -- (wanatw [On_Demand | Running])

========== (R ) Internet Explorer ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=http://go.microsoft.com/fwlink/?LinkId=69157
"Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896
"Default_Secondary_Page_URL"=
"Extensions Off Page"=about:NoAdd-ons
"Local Page"=C:\WINDOWS\system32\blank.htm
"Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896
"Security Risk Page"=about:SecurityRisk
"Start Page"=http://go.microsoft.com/fwlink/?LinkId=69157

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search]
"CustomizeSearch"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
"Default_Search_URL"=http://www.google.com/ie
"SearchAssistant"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\WINDOWS\system32\blank.htm
"Page_Transitions"=
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"SearchMigratedDefaultName"=Google
"SearchMigratedDefaultURL"=http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
"Start Page"=http://exchange.wartburg.edu/

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURL]
""=

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\SYSTEM32\ieframe.dll (Microsoft Corporation)

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=http://www.dell4me.com/myway
"First Home Page"=http://www.dell4me.com/myway
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=http://www.dell4me.com/myway
"First Home Page"=http://www.dell4me.com/myway
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome

[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main]

[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main]

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\WINDOWS\system32\blank.htm
"Page_Transitions"=
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"SearchMigratedDefaultName"=Google
"SearchMigratedDefaultURL"=http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
"Start Page"=http://exchange.wartburg.edu/

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\Software\Microsoft\Internet Explorer\SearchURL]
""=

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\SYSTEM32\ieframe.dll (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

========== (O1) Hosts File ==========

HOSTS File = (812 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
First 25 entries...
127.0.0.1 localhost
r3HQZ]'TA!HF& 7Zi2E 3'BM.˾2͘GY}!":}am5 # Webroot SpySweeper entry

========== (O2) BHO's ==========

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (HKLM) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
{3049C3E9-B461-4BC5-8870-4C09146192CA} (HKLM) -- C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
{53707962-6F74-2D53-2644-206D7942484F} (HKLM) -- C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
{5CA3D70E-1895-11CF-8E15-001234567890} (HKLM) -- C:\WINDOWS\SYSTEM32\dla\tfswshx.dll (Sonic Solutions)
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (HKLM) -- C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
{7E853D72-626A-48EC-A868-BA8D5E23E045} (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
{9030D464-4C02-4ABF-8ECC-5164760863C6} (HKLM) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
{AA1F9DDB-E605-4ba6-81D4-E427DEE012AD} (HKLM) -- C:\WINDOWS\SYSTEM32\TwcToolbarBho.dll ()
{AA58ED58-01DD-4d91-8333-CF10577473F7} (HKLM) -- c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (HKLM) -- C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll (Google Inc.)
{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} (HKLM) -- C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll (Microsoft Corporation)
{d2ce3e00-f94a-4740-988e-03dc2f38c34f} (HKLM) -- C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll (Microsoft Corp.)
{DBC80044-A445-435b-BC74-9C25C1C588A9} (HKLM) -- C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
{E7E6F031-17CE-4C07-BC86-EABFE594F69C} (HKLM) -- C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)

========== (O3) Toolbars ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414}" (HKLM) -- C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll (Microsoft Corp.)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" (HKLM) -- c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{2E5E800E-6AC0-411E-940A-369530A35E43}" (HKLM) -- C:\WINDOWS\SYSTEM32\TwcToolbarIe7.dll ()

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}" (HKLM) -- C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll (Microsoft Corporation)

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" (HKLM) -- c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" (HKLM) -- c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{604BC32A-9680-40D1-9AC6-E06B23A1BA4C}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}" (HKLM) -- C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll (Microsoft Corporation)

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" (HKLM) -- c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)

[HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{5BED3930-2E9E-76D8-BACC-80DF2188D455}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" (HKLM) -- c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)

[HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{5BED3930-2E9E-76D8-BACC-80DF2188D455}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" (HKLM) -- c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" (HKLM) -- c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{604BC32A-9680-40D1-9AC6-E06B23A1BA4C}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}" (HKLM) -- C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

========== (O4) Run Keys ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" (Adobe Systems Incorporated)
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
"AppleSyncNotifier"=C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
"bncsaui.exe"=%ProgramFiles%\Bradford Networks\Persistent Agent\bncsaui.exe ()
"dla"=C:\WINDOWS\system32\dla\tfswctrl.exe (Sonic Solutions)
"DLCCCATS"=rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16 ()
"dlccmon.exe"="C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe" (Dell)
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" (Hewlett-Packard Company)
"HP Software Update"=C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe (Hewlett-Packard Co.)
"HPDJ Taskbar Utility"=C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe (HP)
"igfxhkcmd"=C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
"igfxpers"=C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
"igfxtray"=C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
"IntelMeM"=C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe (Intel Corporation)
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
"mmtask"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe" (Musicmatch Inc.)
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" (Musicmatch, Inc.)
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r (Sonic Solutions)
"vptray"=C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe (Symantec Corporation)
"Webroot Spy Sweeper, Enterprise Edition"=C:\Program Files\Webroot\Enterprise\Spy Sweeper\SpySweeperTray.exe (Webroot Software, Inc.)
"WebrootClientUI"="C:\Program Files\Webroot\Client\SpySweeperUI.exe" (Webroot Software, Inc.)
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" ()

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" /startup (Gteko Ltd.)
"DW6"="C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe" (The Weather Channel Interactive, Inc.)
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler (Macrovision Corporation)
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (Microsoft Corporation)
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" /startup (Gteko Ltd.)
"DW6"="C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe" (The Weather Channel Interactive, Inc.)
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler (Macrovision Corporation)
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (Microsoft Corporation)
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)

========== (O4) Startup Folders ==========

[2004/09/01 10:56:34 | 00,156,784 | -H-- | M] (America Online, Inc.) -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
[2005/09/20 18:10:04 | 00,238,080 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearch.exe
[2006/12/22 10:17:32 | 00,598,016 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Wireless Configuration Utility HW.14.lnk = C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe

========== (O6 & O7) Current Version Policies ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"AllowLegacyWebView"=1
"AllowUnhashedWebView"=1
"NoCDBurning"=0
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"DisableRegistryTools"=0

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
"NoDriveAutoRun"=67108863

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
"NoDriveAutoRun"=67108863

[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

========== (O8) IE Context Menu Extensions ==========

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\]
&MSN Search: C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-us\msntb.dll [2005/06/15 20:02:08 | 00,577,232 | ---- | M] (Microsoft Corporation)
&Search: Reg Error: Value does not exist or could not be read. File not found
&Yahoo! Search: File not found
E&xport to Microsoft Excel: C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE [2008/10/13 11:29:28 | 10,351,944 | ---- | M] (Microsoft Corporation)
Open in new background tab: C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1110\en-us\msntabres.dll [2005/08/01 16:18:58 | 00,078,848 | ---- | M] (Microsoft Corporation)
Open in new foreground tab: C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1110\en-us\msntabres.dll [2005/08/01 16:18:58 | 00,078,848 | ---- | M] (Microsoft Corporation)
Yahoo! &Dictionary: File not found
Yahoo! &Maps: File not found
Yahoo! &SMS: File not found

[HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE [2008/10/13 11:29:28 | 10,351,944 | ---- | M] (Microsoft Corporation)

[HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE [2008/10/13 11:29:28 | 10,351,944 | ---- | M] (Microsoft Corporation)

[HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: Reg Error: Key does not exist or could not be opened. File not found

[HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: Reg Error: Key does not exist or could not be opened. File not found

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\Software\Microsoft\Internet Explorer\MenuExt\]
&MSN Search: C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-us\msntb.dll [2005/06/15 20:02:08 | 00,577,232 | ---- | M] (Microsoft Corporation)
&Search: Reg Error: Value does not exist or could not be read. File not found
&Yahoo! Search: File not found
E&xport to Microsoft Excel: C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE [2008/10/13 11:29:28 | 10,351,944 | ---- | M] (Microsoft Corporation)
Open in new background tab: C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1110\en-us\msntabres.dll [2005/08/01 16:18:58 | 00,078,848 | ---- | M] (Microsoft Corporation)
Open in new foreground tab: C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1110\en-us\msntabres.dll [2005/08/01 16:18:58 | 00,078,848 | ---- | M] (Microsoft Corporation)
Yahoo! &Dictionary: File not found
Yahoo! &Maps: File not found
Yahoo! &SMS: File not found

========== (O9) IE Extensions ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}: Menu: Sun Java Console -- %SystemRoot%\SYSTEM32\msjava.dll [2003/02/28 17:26:26 | 00,947,472 | ---- | M] (Microsoft Corporation)
{2E5E800E-6AC0-411E-940A-369530A35E43}: Button: The Weather Channel -- Reg Error: Key does not exist or could not be opened. File not found
{2E5E800E-6AC0-411E-940A-369530A35E43}: Menu: The Weather Channel -- File not found
{92780B25-18CC-41C8-B9BE-3C9C571A8263}: Button: Research -- %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [2007/04/19 13:10:18 | 00,063,840 | ---- | M] (Microsoft Corporation)
{e2e2dd38-d088-4134-82b7-f2ba38496583}: Menu: @xpsp3res.dll,-20001 -- %SystemRoot%\network diagnostic\xpnetdiag.exe [2008/04/13 12:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Button: Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2008/04/13 18:12:28 | 01,695,232 | -HS- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Menu: Windows Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2008/04/13 18:12:28 | 01,695,232 | -HS- | M] (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %SystemRoot%\SYSTEM32\msjava.dll [Web Browser Applet Control] -> [2003/02/28 17:26:26 | 00,947,472 | ---- | M] (Microsoft Corporation)
CmdMapping\\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2007/04/19 13:10:18 | 00,063,840 | ---- | M] (Microsoft Corporation)
CmdMapping\\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} [HKLM] -> [Reg Error: Value MenuText does not exist or could not be read.] -> File not found
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 18:12:28 | 01,695,232 | -HS- | M] (Microsoft Corporation)

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %SystemRoot%\SYSTEM32\msjava.dll [Web Browser Applet Control] -> [2003/02/28 17:26:26 | 00,947,472 | ---- | M] (Microsoft Corporation)
CmdMapping\\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2007/04/19 13:10:18 | 00,063,840 | ---- | M] (Microsoft Corporation)
CmdMapping\\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} [HKLM] -> [Reg Error: Value MenuText does not exist or could not be read.] -> File not found
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 18:12:28 | 01,695,232 | -HS- | M] (Microsoft Corporation)

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %SystemRoot%\SYSTEM32\msjava.dll [Web Browser Applet Control] -> [2003/02/28 17:26:26 | 00,947,472 | ---- | M] (Microsoft Corporation)
CmdMapping\\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2007/04/19 13:10:18 | 00,063,840 | ---- | M] (Microsoft Corporation)
CmdMapping\\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} [HKLM] -> [Reg Error: Value MenuText does not exist or could not be read.] -> File not found
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 18:12:28 | 01,695,232 | -HS- | M] (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %SystemRoot%\SYSTEM32\msjava.dll [Web Browser Applet Control] -> [2003/02/28 17:26:26 | 00,947,472 | ---- | M] (Microsoft Corporation)
CmdMapping\\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2007/04/19 13:10:18 | 00,063,840 | ---- | M] (Microsoft Corporation)
CmdMapping\\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} [HKLM] -> [Reg Error: Value MenuText does not exist or could not be read.] -> File not found
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 18:12:28 | 01,695,232 | -HS- | M] (Microsoft Corporation)

========== (O12) Internet Explorer Plugins ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\]
PluginsPage: "" = http://activex.microsoft.com/controls/find...=%s&mime=%s
PluginsPageFriendlyName: "" = Microsoft ActiveX Gallery

========== (O13) Default Prefixes ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
""=http://

========== (O15) Trusted Sites ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
1 domain(s) and sub-domain(s) not assigned to a zone.

========== (O16) DPF ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\]
{14B87622-7E19-4EA8-93B3-97215F77A6BC}: http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab -- MessengerStatsClient Class
{17492023-C23A-453E-A040-C7C580BBF700}: http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409 -- Windows Genuine Advantage Validation Tool
{20A60F0D-9AFA-4515-A0FD-83BD84642501}: http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab -- Checkers Class
{33564D57-0000-0010-8000-00AA00389B71}: http://download.microsoft.com/download/F/6...922/wmv9VCM.CAB -- Reg Error: Key does not exist or could not be opened.
{3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}: http://office.microsoft.com/officeupdate/content/opuc2.cab -- Office Update Installation Engine
{4871A87A-BFDD-4106-8153-FFDE2BAC2967}: http://dlm.tools.akamai.com/dlmanager/vers...vex-2.2.4.1.cab -- DLM Control
{56762DEC-6B0D-4AB4-A8AD-989993B5D08B}: http://www.eset.eu/buxus/docs/OnlineScanner.cab -- OnlineScanner Control
{5F8469B4-B055-49DD-83F7-62B522420ECC}: http://upload.facebook.com/controls/Facebo...otoUploader.cab -- Facebook Photo Uploader Control
{74C861A1-D548-4916-BC8A-FDE92EDFF62C}: http://mediaplayer.walmart.com/installer/install.cab -- Reg Error: Key does not exist or could not be opened.
{8AD9C840-044E-11D1-B3E9-00805F499D93}: http://java.sun.com/products/plugin/autodl...indows-i586.cab -- Java Plug-in 1.6.0_11
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}: http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab -- Reg Error: Key does not exist or could not be opened.
{A8F2B9BD-A6A0-486A-9744-18920D898429}: http://www.sibelius.com/download/software/...tiveXPlugin.cab -- ScorchPlugin Class
{B8BE5E93-A60C-4D26-A2DC-220313175592}: http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab -- ZoneIntro Class
{C3F79A2B-B9B4-4A66-B012-3EE46475B072}: http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab -- MessengerStatsClient Class
{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}: http://java.sun.com/products/plugin/autodl...indows-i586.cab -- Java Plug-in 1.6.0_11
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_11
{D27CDB6E-AE6D-11CF-96B8-444553540000}: http://download.macromedia.com/pub/shockwa...ash/swflash.cab -- Shockwave Flash Object
Microsoft XML Parser for Java: file://C:\WINDOWS\Java\classes\xmldso.cab -- Reg Error: Key does not exist or could not be opened.

========== (O17) DNS Name Servers ==========

{1B9DDFCC-CF74-4172-AA8F-5A9586A6AEF9} (Servers: | Description: Intel® PRO/100 VE Network Connection)
{44E86920-94C2-473A-BDE4-F3F35EB2E0AC} (Servers: | Description: TRENDnet TEW-424UB Wireless 802.11g 54Mbps USB 2.0 Network Adapter)

========== (O20) Winlogon Notify Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\]
igfxcui: "DllName" = igfxdev.dll -- C:\WINDOWS\SYSTEM32\igfxdev.dll (Intel Corporation)
NavLogon: "DllName" = C:\WINDOWS\system32\NavLogon.dll -- C:\WINDOWS\SYSTEM32\NavLogon.dll ()
WRNotifier: "DllName" = WRLogonNtf.DLL -- C:\WINDOWS\SYSTEM32\WRLogonNtf.DLL (Webroot Software, Inc.)

========== Safeboot Options ==========

"AlternateShell"=cmd.exe

========== CDRom AutoRun Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1

========== Autorun Files on Drives ==========

AUTOEXEC.BAT []
[2004/08/11 16:15:00 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT -- [ NTFS ]

========== MountPoints2 ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3ff550be-bbe5-11dc-9eff-0014d1362be8}\Shell]
""=AutoRun

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3ff550be-bbe5-11dc-9eff-0014d1362be8}\Shell\AutoRun]
""=Auto&Play


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3ff550be-bbe5-11dc-9eff-0014d1362be8}\Shell\AutoRun\command]
""=G:\LaunchU3.exe -- File not found

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3ff550c0-bbe5-11dc-9eff-0014d1362be8}\Shell]
""=AutoRun

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3ff550c0-bbe5-11dc-9eff-0014d1362be8}\Shell\AutoRun]
""=Auto&Play


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3ff550c0-bbe5-11dc-9eff-0014d1362be8}\Shell\AutoRun\command]
""=G:\LaunchU3.exe -- File not found

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b2a55fe8-7e81-11db-9d90-00038a000015}\Shell]
""=AutoRun

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b2a55fe8-7e81-11db-9d90-00038a000015}\Shell\AutoRun]
""=Auto&Play


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b2a55fe8-7e81-11db-9d90-00038a000015}\Shell\AutoRun\command]
""=G:\LaunchU3.exe -- File not found

========== Files/Folders - Created Within 30 Days ==========

[1 C:\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[2009/01/26 20:18:27 | 00,000,000 | ---D | C] -- C:\Program Files\EsetOnlineScanner
[2009/01/26 19:54:32 | 00,001,261 | ---- | C] () -- C:\Documents and Settings\Pamela\Desktop\1233021253772-integrated.jnlp
[2009/01/26 19:46:52 | 00,001,261 | ---- | C] () -- C:\Documents and Settings\Pamela\Desktop\1233020791728-integrated.jnlp
[2009/01/26 19:22:13 | 00,000,000 | ---- | C] () -- C:\jre-6u11-windows-i586-p.exe.bak4
[2009/01/26 19:22:13 | 00,000,000 | ---- | C] () -- C:\jre-6u11-windows-i586-p.exe.bak3
[2009/01/26 19:22:13 | 00,000,000 | ---- | C] () -- C:\jre-6u11-windows-i586-p.exe.bak2
[2009/01/26 19:22:13 | 00,000,000 | ---- | C] () -- C:\jre-6u11-windows-i586-p.exe.bak
[2009/01/26 19:22:13 | 00,000,000 | ---- | C] () -- C:\jre-6u11-windows-i586-p.exe
[2009/01/26 19:01:07 | 00,000,000 | ---D | C] -- C:\_OTMoveIt
[2009/01/26 19:00:27 | 00,348,160 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Pamela\Desktop\OTMoveIt3.exe
[2009/01/26 18:58:51 | 00,000,000 | ---D | C] -- C:\HostsXpert
[2009/01/26 18:58:25 | 00,353,485 | ---- | C] () -- C:\Documents and Settings\Pamela\Desktop\HostsXpert.zip
[2009/01/26 12:55:04 | 00,000,250 | ---- | C] () -- C:\WINDOWS\gmer.ini
[2009/01/26 12:55:00 | 00,884,736 | ---- | C] () -- C:\WINDOWS\gmer.dll
[2009/01/26 12:55:00 | 00,085,969 | ---- | C] (GMER) -- C:\WINDOWS\System32\drivers\gmer.sys
[2009/01/26 12:55:00 | 00,000,080 | ---- | C] () -- C:\WINDOWS\gmer_uninstall.cmd
[2009/01/26 12:54:59 | 00,811,008 | ---- | C] () -- C:\WINDOWS\gmer.exe
[2009/01/26 12:54:50 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pamela\Desktop\gmer
[2009/01/26 12:53:28 | 00,747,873 | ---- | C] () -- C:\Documents and Settings\Pamela\Desktop\gmer.zip
[2009/01/26 12:48:52 | 00,422,912 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Pamela\Desktop\OTViewIt.exe
[2009/01/24 23:02:38 | 00,000,121 | ---- | C] () -- C:\wallpaper_log.html
[2009/01/24 23:01:39 | 00,000,000 | ---D | C] -- C:\Program Files\Animated Screensaver Maker
[2009/01/22 23:08:59 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pamela\My Documents\Screensavers2
[2009/01/22 23:06:37 | 00,201,728 | ---- | C] (ScreenTime Media) -- C:\Documents and Settings\All Users\Documents\Harry Potter Order of the Phoenix.scr
[2009/01/22 23:06:37 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\Harry Potter Order of the Phoenix dir
[2009/01/22 23:04:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\HarryPotter_setup
[2009/01/22 23:03:09 | 00,471,040 | ---- | C] (ScreenTime Media) -- C:\WINDOWS\HarryPotter_screensaver_pc.scr
[2009/01/22 23:03:04 | 00,000,000 | ---D | C] -- C:\WINDOWS\HarryPotter_screensaver_pc dir
[2009/01/22 23:02:15 | 01,806,450 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\HarryPotter_setup.zip
[2009/01/22 19:57:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pamela\My Documents\Temps
[2009/01/21 08:29:33 | 00,261,366 | ---- | C] () -- C:\Documents and Settings\Pamela\Desktop\obamainauguration012009.pdf
[2009/01/19 22:46:00 | 00,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2009/01/19 16:16:57 | 00,000,765 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Calculator.lnk
[2009/01/19 16:16:56 | 00,000,000 | ---D | C] -- C:\Program Files\Moffsoft FreeCalc
[2009/01/19 16:16:13 | 00,782,433 | ---- | C] (Moffsoft ) -- C:\Documents and Settings\All Users\Documents\MoffFreeCalcSetup.exe
[2009/01/18 17:37:41 | 00,000,782 | ---- | C] () -- C:\Documents and Settings\Pamela\Desktop\Windows Media Player.lnk
[2009/01/18 17:30:34 | 00,000,000 | ---D | C] -- C:\Program Files\msn gaming zone
[2009/01/18 17:30:32 | 80,326,2464 | -HS- | C] () -- C:\hiberfil.sys
[2009/01/18 17:12:28 | 00,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2009/01/18 17:08:26 | 16,710,688 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\Pamela\Desktop\IE8-WindowsXP-x86-ENU.exe
[2009/01/13 09:04:38 | 00,001,754 | ---- | C] () -- C:\Documents and Settings\Pamela\Desktop\The Weather Channel Desktop.lnk
[2009/01/13 09:03:32 | 00,000,000 | ---D | C] -- C:\Program Files\The Weather Channel FW
[2009/01/10 16:53:23 | 00,000,000 | -HSD | C] -- C:\RECYCLER
[2009/01/10 13:11:11 | 00,000,000 | ---D | C] -- C:\32788R22FWJFW
[2009/01/09 10:36:53 | 00,000,000 | ---D | C] -- C:\49672c618e1a2f641b2c
[2009/01/08 19:16:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pamela\Local Settings\Application Data\Mozilla
[2009/01/08 19:15:05 | 07,518,240 | ---- | C] (Mozilla) -- C:\Documents and Settings\All Users\Documents\Firefox Setup 3.0.5.exe
[2009/01/08 12:56:35 | 15,452,536 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\Pamela\Desktop\IE7-WindowsXP-x86-enu-2.exe
[2009/01/08 09:07:24 | 00,000,776 | ---- | C] () -- C:\Documents and Settings\Pamela\Desktop\Shortcut to SPYSWEEPER.lnk
[2009/01/08 09:07:16 | 00,000,786 | ---- | C] () -- C:\Documents and Settings\Pamela\Desktop\Shortcut to SpySweeperUI.lnk
[2009/01/08 08:51:14 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pamela\Application Data\Malwarebytes
[2009/01/08 08:51:11 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/01/08 08:51:11 | 00,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/01/08 08:51:09 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/01/08 08:51:08 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/01/08 08:51:08 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/01/07 22:24:28 | 00,000,000 | ---D | C] -- C:\WINDOWS\temp
[2009/01/07 22:11:49 | 00,000,000 | ---D | C] -- C:\MyComboFix
[2009/01/07 21:59:36 | 00,000,211 | ---- | C] () -- C:\Boot.bak
[2009/01/07 21:59:32 | 00,260,272 | ---- | C] () -- C:\cmldr
[2009/01/07 21:59:26 | 00,000,000 | ---D | C] -- C:\cmdcons
[2009/01/07 21:57:18 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2009/01/07 21:57:18 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2009/01/07 21:57:18 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2009/01/07 21:57:18 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2009/01/07 21:57:18 | 00,089,504 | ---- | C] (Smallfrogs Studio) -- C:\WINDOWS\fdsv.exe
[2009/01/07 21:57:18 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2009/01/07 21:57:18 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2009/01/07 21:57:18 | 00,049,152 | ---- | C] () -- C:\WINDOWS\VFIND.exe
[2009/01/07 21:57:18 | 00,028,672 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2009/01/07 21:57:11 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/01/07 21:57:11 | 00,000,000 | ---D | C] -- C:\Qoobox
[2009/01/07 21:07:46 | 00,003,262 | ---- | C] () -- C:\Documents and Settings\Pamela\Application Data\61a44a292ee8cc98
[2009/01/07 21:07:27 | 00,003,262 | ---- | C] () -- C:\Documents and Settings\Pamela\Application Data\f80e9f63a882607b
[2009/01/07 12:12:50 | 00,000,648 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\a-squared Free.lnk
[2009/01/07 12:12:40 | 00,000,000 | ---D | C] -- C:\Program Files\a-squared Free
[2009/01/07 12:12:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pamela\My Documents\a-squared Free
[2009/01/07 11:54:53 | 00,005,120 | -HS- | C] () -- C:\Program Files\Thumbs.db
@Alternate Data Stream - 0 bytes -> C:\Program Files\Thumbs.db:encryptable
[2009/01/07 11:20:34 | 00,003,262 | ---- | C] () -- C:\Documents and Settings\Pamela\Application Data\bc51dcd3ae0b201
[2009/01/07 11:10:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\151917531
[2009/01/07 11:06:47 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pamela\Application Data\s_5849_OTl8fHx8OTl8fHwxMjQzOTc3Njk1fA_
[2009/01/07 11:01:22 | 00,003,262 | ---- | C] () -- C:\Documents and Settings\Pamela\Application Data\46da395f8f0ab0d
[2009/01/07 11:01:16 | 00,000,124 | -H-- | C] () -- C:\Documents and Settings\Pamela\Local Settings\Application Data\Thumbs.db
[2009/01/07 08:06:18 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pamela\Application Data\alot
[2009/01/05 23:24:27 | 00,000,000 | ---D | C] -- C:\Program Files\alot
[2009/01/05 23:24:08 | 00,575,504 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\movie.exe
[2009/01/05 22:36:17 | 00,000,000 | ---D | C] -- C:\Program Files\Twighlightthemoviescreens
[2009/01/05 22:35:00 | 06,044,845 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\Twighlightthemoviescreens1.0.exe
[2009/01/05 21:18:26 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pamela\My Documents\2009 Stuff
[2009/01/05 19:39:21 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pamela\My Documents\World Religions
[2009/01/03 23:06:10 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pamela\My Documents\Picture Motion Browser
[2009/01/03 22:40:25 | 00,081,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xinput1_3.dll
[2009/01/03 22:40:17 | 00,261,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_7.dll
[2009/01/03 22:40:08 | 01,123,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DCompiler_33.dll
[2009/01/03 22:40:08 | 00,443,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx10_33.dll
[2009/01/03 22:39:54 | 03,495,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_33.dll
[2009/01/03 22:39:53 | 00,255,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_6.dll
[2009/01/03 22:39:52 | 00,251,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_5.dll
[2009/01/03 22:39:51 | 03,426,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_32.dll
[2009/01/03 22:39:49 | 00,237,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_4.dll
[2009/01/03 22:39:49 | 00,015,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\x3daudio1_1.dll
[2009/01/03 22:39:48 | 02,414,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_31.dll
[2009/01/03 22:39:47 | 00,236,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_3.dll
[2009/01/03 22:39:46 | 00,230,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_2.dll
[2009/01/03 22:39:46 | 00,062,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xinput1_2.dll
[2009/01/03 22:39:45 | 00,062,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xinput1_1.dll
[2009/01/03 22:39:44 | 00,229,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_1.dll
[2009/01/03 22:39:28 | 02,388,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_30.dll
[2009/01/03 22:39:27 | 00,230,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_0.dll
[2009/01/03 22:39:27 | 00,014,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\x3daudio1_0.dll
[2009/01/03 22:39:26 | 02,332,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_29.dll
[2009/01/03 22:39:25 | 02,323,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_28.dll
[2009/01/03 22:39:24 | 00,061,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xinput9_1_0.dll
[2009/01/03 22:39:23 | 02,319,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_27.dll
[2009/01/03 22:39:21 | 02,297,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_26.dll
[2009/01/03 22:39:20 | 02,337,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_25.dll
[2009/01/03 22:39:17 | 02,222,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_24.dll
[2009/01/03 22:28:03 | 00,000,000 | ---D | C] -- C:\Program Files\Sony
[2009/01/03 19:23:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pamela\Application Data\Media Player Classic
[2009/01/03 19:17:16 | 00,000,000 | ---D | C] -- C:\Program Files\AviSynth 2.5
[2009/01/03 19:17:05 | 00,000,780 | ---- | C] () -- C:\Documents and Settings\Pamela\Desktop\DVD slideshow GUI.lnk
[2009/01/03 19:16:40 | 00,000,000 | ---D | C] -- C:\Program Files\DVD slideshow GUI

========== Files - Modified Within 30 Days ==========

[1 C:\*.tmp files]
[4 C:\WINDOWS\System32\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[2009/01/27 19:00:26 | 00,000,584 | ---- | M] () -- C:\Documents and Settings\Pamela\My Documents\My Sharing Folders.lnk
[2009/01/27 18:56:56 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\WPA.DBL
[2009/01/27 18:56:29 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/01/27 18:56:24 | 00,002,048 | --S- | M] () -- C:\WINDOWS\BOOTSTAT.DAT
[2009/01/27 18:56:23 | 80,326,2464 | -HS- | M] () -- C:\hiberfil.sys
[2009/01/27 06:17:28 | 00,376,056 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/01/26 20:20:28 | 00,002,497 | ---- | M] () -- C:\Documents and Settings\Pamela\Desktop\Word 2003.lnk
[2009/01/26 19:54:33 | 00,001,261 | ---- | M] () -- C:\Documents and Settings\Pamela\Desktop\1233021253772-integrated.jnlp
[2009/01/26 19:53:17 | 00,000,000 | ---- | M] () -- C:\jre-6u11-windows-i586-p.exe
[2009/01/26 19:47:31 | 00,000,000 | ---- | M] () -- C:\jre-6u11-windows-i586-p.exe.bak4
[2009/01/26 19:46:52 | 00,001,261 | ---- | M] () -- C:\Documents and Settings\Pamela\Desktop\1233020791728-integrated.jnlp
[2009/01/26 19:41:16 | 00,000,000 | ---- | M] () -- C:\jre-6u11-windows-i586-p.exe.bak3
[2009/01/26 19:32:47 | 00,000,000 | ---- | M] () -- C:\jre-6u11-windows-i586-p.exe.bak2
[2009/01/26 19:22:13 | 00,000,000 | ---- | M] () -- C:\jre-6u11-windows-i586-p.exe.bak
[2009/01/26 19:00:28 | 00,348,160 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Pamela\Desktop\OTMoveIt3.exe
[2009/01/26 18:58:25 | 00,353,485 | ---- | M] () -- C:\Documents and Settings\Pamela\Desktop\HostsXpert.zip
[2009/01/26 12:55:04 | 00,000,250 | ---- | M] () -- C:\WINDOWS\gmer.ini
[2009/01/26 12:55:00 | 00,884,736 | ---- | M] () -- C:\WINDOWS\gmer.dll
[2009/01/26 12:55:00 | 00,085,969 | ---- | M] (GMER) -- C:\WINDOWS\System32\drivers\gmer.sys
[2009/01/26 12:55:00 | 00,000,080 | ---- | M] () -- C:\WINDOWS\gmer_uninstall.cmd
[2009/01/26 12:54:50 | 00,811,008 | ---- | M] () -- C:\WINDOWS\gmer.exe
[2009/01/26 12:53:30 | 00,747,873 | ---- | M] () -- C:\Documents and Settings\Pamela\Desktop\gmer.zip
[2009/01/26 12:48:53 | 00,422,912 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Pamela\Desktop\OTViewIt.exe
[2009/01/24 23:02:45 | 00,000,121 | ---- | M] () -- C:\wallpaper_log.html
[2009/01/22 23:23:07 | 00,000,874 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/01/22 23:10:52 | 00,012,288 | ---- | M] () -- C:\WINDOWS\impborl.dll
[2009/01/22 23:10:22 | 00,471,040 | ---- | M] (ScreenTime Media) -- C:\WINDOWS\HarryPotter_screensaver_pc.scr
[2009/01/22 23:02:30 | 01,806,450 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\HarryPotter_setup.zip
[2009/01/22 09:45:01 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/01/21 08:29:36 | 00,261,366 | ---- | M] () -- C:\Documents and Settings\Pamela\Desktop\obamainauguration012009.pdf
[2009/01/19 16:16:57 | 00,000,765 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Calculator.lnk
[2009/01/19 16:16:17 | 00,782,433 | ---- | M] (Moffsoft ) -- C:\Documents and Settings\All Users\Documents\MoffFreeCalcSetup.exe
[2009/01/18 21:23:52 | 00,000,281 | RHS- | M] () -- C:\BOOT.INI
[2009/01/18 21:23:51 | 00,000,728 | ---- | M] () -- C:\WINDOWS\WIN.INI
[2009/01/18 17:37:42 | 00,000,782 | ---- | M] () -- C:\Documents and Settings\Pamela\Desktop\Windows Media Player.lnk
[2009/01/18 17:29:47 | 00,004,566 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009/01/18 17:29:35 | 00,445,156 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/01/18 17:29:35 | 00,384,596 | ---- | M] () -- C:\WINDOWS\System32\PERFH009.DAT
[2009/01/18 17:29:35 | 00,054,280 | ---- | M] () -- C:\WINDOWS\System32\PERFC009.DAT
[2009/01/18 17:28:58 | 00,000,057 | ---- | M] () -- C:\WINDOWS\System32\MAPISVC.INF
[2009/01/18 17:17:34 | 00,000,077 | -HS- | M] () -- C:\Documents and Settings\Pamela\My Documents\DESKTOP.INI
[2009/01/18 17:08:46 | 16,710,688 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Pamela\Desktop\IE8-WindowsXP-x86-ENU.exe
[2009/01/13 09:04:38 | 00,001,754 | ---- | M] () -- C:\Documents and Settings\Pamela\Desktop\The Weather Channel Desktop.lnk
[2009/01/12 23:06:18 | 00,026,624 | -HS- | M] () -- C:\Documents and Settings\Pamela\My Documents\Thumbs.db
@Alternate Data Stream - 0 bytes -> C:\Documents and Settings\Pamela\My Documents\Thumbs.db:encryptable
[2009/01/09 19:35:28 | 20,853,704 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009/01/08 19:16:34 | 00,001,602 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/01/08 19:15:37 | 07,518,240 | ---- | M] (Mozilla) -- C:\Documents and Settings\All Users\Documents\Firefox Setup 3.0.5.exe
[2009/01/08 12:56:34 | 15,452,536 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Pamela\Desktop\IE7-WindowsXP-x86-enu-2.exe
[2009/01/08 09:07:24 | 00,000,776 | ---- | M] () -- C:\Documents and Settings\Pamela\Desktop\Shortcut to SPYSWEEPER.lnk
[2009/01/08 09:07:16 | 00,000,786 | ---- | M] () -- C:\Documents and Settings\Pamela\Desktop\Shortcut to SpySweeperUI.lnk
[2009/01/08 08:51:11 | 00,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/01/07 21:08:27 | 04,278,026 | -H-- | M] () -- C:\Documents and Settings\Pamela\Local Settings\Application Data\IconCache.db
[2009/01/07 21:07:46 | 00,003,262 | ---- | M] () -- C:\Documents and Settings\Pamela\Application Data\61a44a292ee8cc98
[2009/01/07 21:07:27 | 00,003,262 | ---- | M] () -- C:\Documents and Settings\Pamela\Application Data\f80e9f63a882607b
[2009/01/07 14:45:00 | 00,000,124 | -H-- | M] () -- C:\Documents and Settings\Pamela\Local Settings\Application Data\Thumbs.db
[2009/01/07 12:12:51 | 00,000,648 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\a-squared Free.lnk
[2009/01/07 11:20:34 | 00,003,262 | ---- | M] () -- C:\Documents and Settings\Pamela\Application Data\bc51dcd3ae0b201
[2009/01/07 11:10:51 | 00,108,424 | ---- | M] () -- C:\Documents and Settings\Pamela\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/01/07 11:01:22 | 00,003,262 | ---- | M] () -- C:\Documents and Settings\Pamela\Application Data\46da395f8f0ab0d
[2009/01/05 23:24:22 | 00,575,504 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\movie.exe
[2009/01/05 22:35:22 | 06,044,845 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\Twighlightthemoviescreens1.0.exe
[2009/01/04 18:39:00 | 00,038,496 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/01/04 18:38:56 | 00,015,504 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/01/04 11:30:30 | 00,015,360 | ---- | M] () -- C:\Documents and Settings\Pamela\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/01/03 23:32:50 | 00,002,341 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/01/03 19:17:05 | 00,000,780 | ---- | M] () -- C:\Documents and Settings\Pamela\Desktop\DVD slideshow GUI.lnk
< End of report >




Extras:
OTViewIt Extras logfile created on: 1/27/2009 7:10:01 PM - Run 3
OTViewIt by OldTimer - Version 1.0.21.0 Folder = C:\Documents and Settings\Pamela\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18241)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

765.98 Mb Total Physical Memory | 293.34 Mb Available Physical Memory | 38.30% Memory free
1.83 Gb Paging File | 1.36 Gb Available in Paging File | 74.67% Paging File free
Paging file location(s): C:\pagefile.sys 1149 1349;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 33.52 Gb Total Space | 4.63 Gb Free Space | 13.82% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PAMANDTRISH
Current User Name: Pamela
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled"=1
"AntiVirusDisableNotify"=0
"FirewallDisableNotify"=0
"UpdatesDisableNotify"=0
"AntiVirusOverride"=1
"FirewallOverride"=0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall"=1
"DoNotAllowExceptions"=0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\IcmpSettings]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[2008/04/13 18:12:34 | 00,141,312 | ---- | M] (Microsoft Corporation) -- %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
[2004/04/07 11:07:32 | 01,135,728 | ---- | M] (America Online, Inc.) -- C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL
[2004/04/07 11:07:34 | 00,496,752 | ---- | M] (America Online, Inc) -- C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL
[2004/09/01 10:56:56 | 00,259,184 | ---- | M] (America Online, Inc.) -- C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0
[2008/04/13 12:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[2007/10/18 10:34:02 | 05,724,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
[2007/10/02 16:18:24 | 00,304,488 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[2008/04/13 18:12:34 | 00,141,312 | ---- | M] (Microsoft Corporation) -- %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
[2004/04/07 11:07:32 | 01,135,728 | ---- | M] (America Online, Inc.) -- C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL
[2004/04/07 11:07:34 | 00,496,752 | ---- | M] (America Online, Inc) -- C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL
[2004/09/01 10:56:56 | 00,259,184 | ---- | M] (America Online, Inc.) -- C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0
[2006/01/21 12:16:30 | 00,036,864 | ---- | M] () -- C:\Program Files\Maple 10\jre\bin\maple.exe:*:Enabled:maple
[2006/01/21 12:15:20 | 00,024,681 | ---- | M] () -- C:\Program Files\Maple 10\jre\bin\java.exe:*:Enabled:java
[2008/04/07 06:25:30 | 00,214,560 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer
[2005/02/15 10:36:40 | 00,565,248 | ---- | M] (Hewlett-Packard) -- C:\Program Files\Hewlett-Packard\HP Software Update\HPWUCli.exe:*:Disabled:HP Software Update Client
File not found -- C:\Program Files\Java\jre1.5.0_11\bin\javaw.exe:*:Enabled:Java™ 2 Platform Standard Edition binary
File not found -- C:\Program Files\Java\jre1.6.0_01\bin\javaw.exe:*:Enabled:Java™ Platform SE binary
[2008/04/13 12:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[2008/06/29 14:23:18 | 02,944,392 | ---- | M] () -- C:\Program Files\Bradford Networks\Persistent Agent\bndaemon.exe:*:Enabled:Bradford Persistent Agent
[2008/08/29 09:18:44 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour
[2007/10/18 10:34:02 | 05,724,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
[2007/10/02 16:18:24 | 00,304,488 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)
[2008/11/20 13:20:48 | 14,294,824 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes

========== (O10) Winsock2 Catalogs ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\]
NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] -- C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)

========== (O18) Protocol Handlers ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2003/12/22 07:38:40 | 00,081,920 | ---- | M] (Hewlett-Packard Company) C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (cetihpz:{CF184AD3-CDCB-4168-A3F7-8E447D129300} (HKLM) [CZipHandler Object])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
ipp: [HKLM - No CLSID value]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2005/09/20 11:33:58 | 00,843,984 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL ipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2007/10/18 10:31:54 | 00,066,072 | ---- | M] (Microsoft Corporation) C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (livecall:{828030A1-22C1-4009-854F-8E305202313F} (HKLM) [Reg Error: Value does not exist or could not be read.])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
msdaipp: [HKLM - No CLSID value]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2005/09/20 11:33:58 | 00,843,984 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2005/09/20 11:33:58 | 00,843,984 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\oledb:{E1D2BF40-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAIPP.BINDER]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2000/04/19 17:47:36 | 00,520,117 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (ms-itss:{0A9007C0-4076-11D3-8789-0000F8105754} (HKLM) [Microsoft Infotech Storage Protocol for IE 4.0])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2007/10/18 10:31:54 | 00,066,072 | ---- | M] (Microsoft Corporation) C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (msnim:{828030A1-22C1-4009-854F-8E305202313F} (HKLM) [Reg Error: Value does not exist or could not be read.])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2007/03/14 12:10:22 | 07,255,384 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (mso-offdap:{3D9F03FA-7A94-11D3-BE81-0050048385D1} (HKLM) [Data Page Pluggable Protocol mso-offdap Handler])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2007/05/10 12:45:34 | 08,069,464 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (mso-offdap11:{32505114-5902-49B2-880A-1F7738E5A384} (HKLM) [Data Page Plugable Protocal mso-offdap11 Handler])

========== (O18) Protocol Filters ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\] - Protocol Filters
[2007/04/19 12:57:40 | 00,046,432 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL text/xml:{807553E5-5146-11D5-A672-00B0D022E945} (HKLM) [Reg Error: Value does not exist or could not be read.]

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0456ebd7-5f67-4ab6-852e-63781e3f389c}"=Macromedia Flash Player
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}"=Sonic Update Manager
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}"=Microsoft Plus! Photo Story 2 LE
"{0EFC6259-3AD8-4CD2-BC57-D4937AF5CC0E}"=Symantec AntiVirus Client
"{10C69612-017B-45F5-B986-7D113D5A2EA3}"=MSN Toolbar
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}"=Sonic DLA
"{15EE79F4-4ED1-4267-9B0F-351009325D7D}"=HP Software Update
"{17334AAF-C9E7-483B-9F45-E3FCAF07FFA7}"=Intel® PROSet for Wired Connections
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}"=Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}"=Java™ 6 Update 11
"{318AB667-3230-41B5-A617-CB3BF748D371}"=iTunes
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}"=Windows Media Player 10
"{3414C7E8-F883-445E-9994-E410D7E5B1F4}"=Bradford Persistent Agent
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}"=WebFldrs XP
"{35BDEFF1-A610-4956-A00D-15453C116395}"=Internet Explorer Default Page
"{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}"=Google Earth
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}"=Modem On Hold
"{4192EAC0-6B36-4723-B216-D0E86E7757AC}"=Jasc Paint Shop Photo Album 5
"{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}"=Adobe Photoshop Album Starter Edition 3.0
"{508CE775-4BA4-4748-82DF-FE28DA9F03B0}"=Windows Live Messenger
"{582D2A53-F426-4C5E-A2E6-43C1AB36B907}"=Safari
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}"=Dell Driver Reset Tool
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}"=Apple Software Update
"{697836DE-03BB-4C4C-9B06-CAFC93D0A506}"=Webroot Spy Sweeper Enterprise Client
"{6DA9102E-199F-43A0-A36B-6EF48081A658}"=MobileMe Control Panel
"{6E179C77-7335-458D-9537-4F4EAC0181ED}"=Photo Click
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}"=Microsoft Plus! Digital Media Edition Installer
"{728278A1-0BB7-45E4-AC5E-91D7C0FD1EDE}"=EarthLink setup files
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}"=Dell System Restore
"{75E71ADD-042C-4F30-BFAC-A9EC42351313}"=Python 2.4.3
"{78C496B9-5A6B-4692-8C2E-AFFFC34E4961}"=Jasc Paint Shop Pro Studio, Dell Editon
"{7A0EFAFB-AC4B-4B88-8C6B-6731BE88DB68}"=Modem Event Monitor
"{7B478ACE-8512-4A46-ACB2-69D83DF2F6C7}"=Digital Voice Recorder
"{7D1DCBBA-F6F5-42B4-B90B-F04ACE4DFD6C}"=MSN Search Toolbar
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}"=DellSupport
"{7F142D56-3326-11D5-B229-002078017FBF}"=Modem Helper
"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}"=Bonjour
"{8A708DD8-A5E6-11D4-A706-000629E95E20}"=Intel® Extreme Graphics 2 Driver
"{8EF1122E-E90C-4EE9-AB0C-7FDE2BA42C26}"=Musicmatch Jukebox
"{90110409-6000-11D3-8CFE-0150048383C9}"=Microsoft Office Professional Edition 2003
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}"=Sonic RecordNow!
"{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}"=Windows Live installer
"{A8B94669-8654-4126-BD28-D0D2412CDED6}"=TI Connect 1.6
"{AC0EE5B0-A8FB-4D0A-AF03-2EDC518F841B}"=Dell Media Experience
"{AC76BA86-7AD7-1033-7B44-A81300000003}"=Adobe Reader 8.1.3
"{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}"=ABBYY FineReader 6.0 Sprint
"{AF06CAE4-C134-44B1-B699-14FBDB63BD37}"=Dell Picture Studio v3.0
"{AF19F291-F22F-4798-9662-525305AE9E48}"=WordPerfect Office 12
"{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}"=Windows Live Sign-in Assistant
"{B8A432E2-D541-4F48-B9E8-243BEEC3D158}"=Wal-Mart Music Downloads Store
"{C43421C0-0DCB-4F26-8A3B-BF16155F9879}"=TRENDnet TEW-424UB
"{C9618743-1A5C-461E-91C4-E013A3D70F3C}"=Adobe Photoshop Album Starter Edition 3.0.1
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}"=Microsoft .NET Framework 1.1
"{EC4455AB-F155-4CC1-A4C5-88F3777F9886}"=Apple Mobile Device Support
"{F901CA6D-A074-42D3-A11D-33AAE6FFD0C1}"=HP Deskjet 3740
"{F958CA02-BB40-4007-894B-258729456EE4}"=QuickTime
"{FE7D7E78-B9FD-4CAE-B223-10C6E5B307E7}"=Webroot Client
"7-Zip"=7-Zip 4.62
"AC3Filter"=AC3Filter (remove only)
"Ad-Aware SE Personal"=Ad-Aware SE Personal
"Adobe Flash Player ActiveX"=Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin"=Adobe Flash Player 10 Plugin
"alotToolbar"=ALOT Toolbar
"America Online us"=America Online (Choose which version to remove)
"AOL Connectivity Services"=AOL Connectivity Services
"AOLCoach"=AOL Coach Version 1.0(Build:20040229.1 en)
"a-squared Free_is1"=a-squared Free 4.0
"AviSynth"=AviSynth 2.5
"BE37E547-62DF-43C8-AE6A-D03E82BC67A2_is1"=DVD slideshow GUI 0.9.0.9
"Bubblet!"=Bubblet!
"Coupon Printer for Windows4.0"=Coupon Printer for Windows
"Dell Digital Jukebox Driver"=Dell Digital Jukebox Driver
"Dell Photo AIO Printer 924"=Dell Photo AIO Printer 924
"EsetOnlineScanner"=ESET Online Scanner
"HarryPotter_screensaver_pc"=HarryPotter_screensaver_pc Screen Saver
"IDNMitigationAPIs"=Microsoft Internationalized Domain Names Mitigation APIs
"ie7"=Windows Internet Explorer 7
"ie8"=Windows Internet Explorer 8 Beta 2
"InstallShield_{C43421C0-0DCB-4F26-8A3B-BF16155F9879}"=TRENDnet TEW-424UB
"Intel® 537EP V9x DF PCI Modem"=Intel® 537EP V9x DF PCI Modem
"Jasc Paint Shop Pro Studio.01 , Dell Edition 1.0.1.1 Patch"=Jasc Paint Shop Pro Studio.01 , Dell Edition 1.0.1.1 Patch
"LiveUpdate"=LiveUpdate 1.80 (Symantec Corporation)
"Mah Jong Medley"=Mah Jong Medley
"Malwarebytes' Anti-Malware_is1"=Malwarebytes' Anti-Malware
"Maple 10"=Maple 10
"Microsoft .NET Framework 1.1 (1033)"=Microsoft .NET Framework 1.1
"MoffFreeCalc_is1"=Moffsoft FreeCalc
"Mozilla Firefox (3.0.5)"=Mozilla Firefox (3.0.5)
"MSCompPackV1"=Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST"=MSN
"MyEmo"=MyEmoticons
"NLSDownlevelMapping"=Microsoft National Language Support Downlevel APIs
"Pirates of the Caribbean"=Pirates of the Caribbean Screen Saver
"PROSet"=Intel® PRO Network Adapters and Drivers
"RealPlayer 6.0"=RealPlayer
"Shockwave"=Shockwave
"Spybot - Search & Destroy_is1"=Spybot - Search & Destroy 1.3
"StreetPlugin"=Learn2 Player (Uninstall Only)
"The Oregon Trail"=The Oregon Trail
"The Weather Channel Desktop 6"=The Weather Channel Desktop 6
"The Weather Channel Toolbar"=The Weather Channel Toolbar
"TheSky"=Software Bisque TheSky (Remove only)
"TightVNC_is1"=TightVNC 1.2.9
"Twighlightthemoviescreens 1.0_is1"=Twighlightthemoviescreens 1.0
"ViewpointMediaPlayer"=Viewpoint Media Player
"Winamp"=Winamp
"Windows Media Format Runtime"=Windows Media Format 11 runtime
"Windows Media Player"=Windows Media Player 11
"Windows XP Service Pack"=Windows XP Service Pack 3
"WMFDist11"=Windows Media Format 11 runtime
"wmp11"=Windows Media Player 11
"Wudf01000"=Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xena Season One"=Xena Season One Screen Saver
"Xvid_is1"=Xvid 1.1.3 final uninstall

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"ESPN Java Check"=ESPN Java Check
"Move Networks Player - IE"=Move Networks Media Player for Internet Explorer

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"ESPN Java Check"=ESPN Java Check
"Move Networks Player - IE"=Move Networks Media Player for Internet Explorer

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/24/2009 7:02:50 AM | Computer Name = PAMANDTRISH | Source = WebrootSpySweeperService | ID = 0
Description =

Error - 1/24/2009 10:44:40 PM | Computer Name = PAMANDTRISH | Source = WebrootSpySweeperService | ID = 0
Description =

Error - 1/25/2009 11:21:28 AM | Computer Name = PAMANDTRISH | Source = WebrootSpySweeperService | ID = 0
Description =

Error - 1/26/2009 10:06:45 AM | Computer Name = PAMANDTRISH | Source = WebrootSpySweeperService | ID = 0
Description =

Error - 1/26/2009 2:50:00 PM | Computer Name = PAMANDTRISH | Source = Norton AntiVirus | ID = 16711685
Description = Virus Found!Virus name: Trojan Horse in File: C:\Program Files\Common
Files\Ndm399a2rL.exe by: Realtime Protection scan. Action: Quarantine succeeded
: Access denied

Error - 1/26/2009 9:05:46 PM | Computer Name = PAMANDTRISH | Source = WebrootSpySweeperService | ID = 0
Description =

Error - 1/27/2009 12:26:46 AM | Computer Name = PAMANDTRISH | Source = Norton AntiVirus | ID = 16711685
Description = Virus Found!Virus name: Downloader.MisleadApp in File: C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\msiconf.exe.vir
by: Realtime Protection scan. Action: Quarantine succeeded : Access denied

Error - 1/27/2009 8:17:41 AM | Computer Name = PAMANDTRISH | Source = WebrootSpySweeperService | ID = 0
Description =

Error - 1/27/2009 9:04:20 AM | Computer Name = PAMANDTRISH | Source = Norton AntiVirus | ID = 16711685
Description = Virus Found!Virus name: Trojan Horse in File: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP8\A0000416.exe
by: Realtime Protection scan. Action: Quarantine succeeded : Access denied

Error - 1/27/2009 8:56:31 PM | Computer Name = PAMANDTRISH | Source = WebrootSpySweeperService | ID = 0
Description =

[ System Events ]
Error - 1/27/2009 8:53:22 PM | Computer Name = PAMANDTRISH | Source = DCOM | ID = 10010
Description = The server {0BDEAA4D-0722-406F-BD43-10935AC25E0E} did not register
with DCOM within the required timeout.

Error - 1/27/2009 8:55:23 PM | Computer Name = PAMANDTRISH | Source = DCOM | ID = 10010
Description = The server {0BDEAA4D-0722-406F-BD43-10935AC25E0E} did not register
with DCOM within the required timeout.

Error - 1/27/2009 8:56:31 PM | Computer Name = PAMANDTRISH | Source = Service Control Manager | ID = 7000
Description = The DM1Service service failed to start due to the following error:
%%2

Error - 1/27/2009 8:56:31 PM | Computer Name = PAMANDTRISH | Source = Service Control Manager | ID = 7000
Description = The Norton AntiVirus Auto-Protect Service service failed to start
due to the following error: %%3

Error - 1/27/2009 8:59:53 PM | Computer Name = PAMANDTRISH | Source = DCOM | ID = 10010
Description = The server {0BDEAA4D-0722-406F-BD43-10935AC25E0E} did not register
with DCOM within the required timeout.

Error - 1/27/2009 9:01:58 PM | Computer Name = PAMANDTRISH | Source = DCOM | ID = 10010
Description = The server {0BDEAA4D-0722-406F-BD43-10935AC25E0E} did not register
with DCOM within the required timeout.

Error - 1/27/2009 9:03:59 PM | Computer Name = PAMANDTRISH | Source = DCOM | ID = 10010
Description = The server {0BDEAA4D-0722-406F-BD43-10935AC25E0E} did not register
with DCOM within the required timeout.

Error - 1/27/2009 9:06:00 PM | Computer Name = PAMANDTRISH | Source = DCOM | ID = 10010
Description = The server {0BDEAA4D-0722-406F-BD43-10935AC25E0E} did not register
with DCOM within the required timeout.

Error - 1/27/2009 9:08:00 PM | Computer Name = PAMANDTRISH | Source = DCOM | ID = 10010
Description = The server {0BDEAA4D-0722-406F-BD43-10935AC25E0E} did not register
with DCOM within the required timeout.

Error - 1/27/2009 9:10:01 PM | Computer Name = PAMANDTRISH | Source = DCOM | ID = 10010
Description = The server {0BDEAA4D-0722-406F-BD43-10935AC25E0E} did not register
with DCOM within the required timeout.


< End of report >

#11 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,304 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:05:47 PM

Posted 27 January 2009 - 08:46 PM

Hello, wartburgtrack33
We need to uninstall one or more programs
Please click on Start > Control Panel > Add/Remove Programs and uninstall the following programs(if present):
Spybot - Search & Destroy 1.3

We need to execute an OTMoveIt3 script
  • Please download OTMoveIt3 by OldTimer and save it to your desktop.
  • Double click the Posted Image icon on your desktop.
  • Paste the following code under the Posted Image area. Do not include the word "Code".
    :files
    C:\jre-6u11-windows-i586-p.exe*
    C:\RECYCLER
    C:\32788R22FWJFW
    C:\49672c618e1a2f641b2c
    C:\WINDOWS\temp
    C:\MyComboFix
    C:\Boot.bak
    C:\WINDOWS\SWXCACLS.exe
    C:\WINDOWS\SWREG.exe
    C:\WINDOWS\SWSC.exe
    C:\WINDOWS\sed.exe
    C:\WINDOWS\fdsv.exe
    C:\WINDOWS\grep.exe
    C:\WINDOWS\zip.exe
    C:\WINDOWS\VFIND.exe
    C:\WINDOWS\NIRCMD.exe
    C:\Documents and Settings\Pamela\Application Data\61a44a292ee8cc98
    C:\Documents and Settings\Pamela\Application Data\f80e9f63a882607b
    C:\Documents and Settings\All Users\Application Data\151917531
    C:\Documents and Settings\Pamela\Application Data\s_5849_OTl8fHx8OTl8fHwxMjQzOTc3Njk1fA_
    C:\Documents and Settings\Pamela\Application Data\bc51dcd3ae0b201
    C:\Documents and Settings\Pamela\Application Data\46da395f8f0ab0d
    C:\Documents and Settings\All Users\Documents\movie.exe
  • Push the large Posted Image button.
  • OTMI3 may ask to reboot the machine. Please do so if asked.
  • Copy/Paste the contents under the Posted Image line here in your next reply.
  • If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
In your next reply, please include the following:
  • OTMoveIt3's Log
  • A New OTVIewIt Main.txt
  • A New OTViewIt Extra.txt

BillyIII
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#12 wartburgtrack33

wartburgtrack33
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:06:47 PM

Posted 27 January 2009 - 09:12 PM

OK I did all of that. I was able to remove Spybot on add/remove. Here are the logs.

OTMoveIt:
========== FILES ==========
C:\jre-6u11-windows-i586-p.exe moved successfully.
C:\jre-6u11-windows-i586-p.exe.bak moved successfully.
C:\jre-6u11-windows-i586-p.exe.bak2 moved successfully.
C:\jre-6u11-windows-i586-p.exe.bak3 moved successfully.
C:\jre-6u11-windows-i586-p.exe.bak4 moved successfully.
C:\RECYCLER\S-1-5-21-2869354029-3859267071-476805174-1006 moved successfully.
C:\RECYCLER\S-1-5-21-2869354029-3859267071-476805174-1005 moved successfully.
C:\RECYCLER moved successfully.
C:\32788R22FWJFW moved successfully.
C:\49672c618e1a2f641b2c\update moved successfully.
C:\49672c618e1a2f641b2c moved successfully.
C:\WINDOWS\temp\hsperfdata_SYSTEM moved successfully.
Folder move failed. C:\WINDOWS\temp scheduled to be moved on reboot.
C:\MyComboFix moved successfully.
C:\Boot.bak moved successfully.
C:\WINDOWS\SWXCACLS.exe moved successfully.
C:\WINDOWS\SWREG.exe moved successfully.
C:\WINDOWS\SWSC.exe moved successfully.
C:\WINDOWS\sed.exe moved successfully.
C:\WINDOWS\fdsv.exe moved successfully.
C:\WINDOWS\grep.exe moved successfully.
C:\WINDOWS\zip.exe moved successfully.
C:\WINDOWS\VFIND.exe moved successfully.
C:\WINDOWS\NIRCMD.exe moved successfully.
C:\Documents and Settings\Pamela\Application Data\61a44a292ee8cc98 moved successfully.
C:\Documents and Settings\Pamela\Application Data\f80e9f63a882607b moved successfully.
C:\Documents and Settings\All Users\Application Data\151917531 moved successfully.
C:\Documents and Settings\Pamela\Application Data\s_5849_OTl8fHx8OTl8fHwxMjQzOTc3Njk1fA_ moved successfully.
C:\Documents and Settings\Pamela\Application Data\bc51dcd3ae0b201 moved successfully.
C:\Documents and Settings\Pamela\Application Data\46da395f8f0ab0d moved successfully.
C:\Documents and Settings\All Users\Documents\movie.exe moved successfully.

OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 01272009_200033

Files moved on Reboot...
Folder move failed. C:\WINDOWS\temp scheduled to be moved on reboot.


OTVI Main:
OTViewIt logfile created on: 1/27/2009 8:09:07 PM - Run 4
OTViewIt by OldTimer - Version 1.0.21.0 Folder = C:\Documents and Settings\Pamela\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18241)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

765.98 Mb Total Physical Memory | 294.14 Mb Available Physical Memory | 38.40% Memory free
1.83 Gb Paging File | 1.35 Gb Available in Paging File | 74.10% Paging File free
Paging file location(s): C:\pagefile.sys 1149 1349;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 33.52 Gb Total Space | 4.62 Gb Free Space | 13.78% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PAMANDTRISH
Current User Name: Pamela
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days

========== Processes ==========

[2008/12/17 08:32:06 | 00,419,448 | ---- | M] (Emsi Software GmbH) -- C:\Program Files\a-squared Free\a2service.exe
[2004/04/07 11:07:32 | 01,135,728 | ---- | M] (America Online, Inc.) -- C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
[2008/11/07 14:28:16 | 00,132,424 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
[2008/06/29 14:23:18 | 02,944,392 | ---- | M] () -- C:\Program Files\Bradford Networks\Persistent Agent\bndaemon.exe
[2008/08/29 09:18:44 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe
[2003/05/21 00:22:36 | 00,032,768 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
[2009/01/27 12:37:47 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
[2003/06/19 22:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
[2003/05/21 00:27:46 | 00,610,304 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
[2005/03/30 15:03:26 | 01,872,384 | ---- | M] (Webroot Software, Inc.) -- C:\Program Files\Webroot\Enterprise\CommAgent\CommAgent.exe
[2008/04/13 18:12:40 | 00,218,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SYSTEM32\WBEM\wmiprvse.exe
[2008/04/13 18:12:29 | 00,069,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\notepad.exe
[2004/10/14 13:42:54 | 01,404,928 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\Core\smax4pnp.exe
[2003/09/03 19:12:44 | 00,221,184 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
[2004/01/07 00:01:00 | 00,110,592 | ---- | M] (Sonic Solutions) -- C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
[2005/03/15 07:58:08 | 00,135,168 | ---- | M] (Musicmatch, Inc.) -- C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
[2004/12/06 00:05:00 | 00,127,035 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\dla\tfswctrl.exe
[2005/03/15 07:58:08 | 00,053,248 | ---- | M] (Musicmatch Inc.) -- C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe
[2003/05/21 00:21:18 | 00,090,112 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\VPTray.exe
[2004/03/04 09:46:24 | 00,172,032 | ---- | M] (HP) -- C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\hpztsb10.exe
[2003/12/22 07:38:42 | 00,241,664 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
[2005/02/16 23:11:42 | 00,049,152 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe
[2005/09/20 09:32:24 | 00,077,824 | ---- | M] (Intel Corporation) -- C:\WINDOWS\SYSTEM32\hkcmd.exe
[2005/09/20 09:36:20 | 00,114,688 | ---- | M] (Intel Corporation) -- C:\WINDOWS\SYSTEM32\igfxpers.exe
[2005/06/06 22:46:24 | 00,057,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
[2005/10/21 09:40:26 | 00,430,080 | ---- | M] (Dell) -- C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
[2008/04/07 06:25:21 | 00,185,896 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[2008/07/16 10:19:00 | 00,435,616 | ---- | M] (Webroot Software, Inc.) -- C:\Program Files\Webroot\Client\SpySweeperUI.exe
[2008/06/29 14:23:18 | 02,612,616 | ---- | M] () -- C:\Program Files\Bradford Networks\Persistent Agent\bncsaui.exe
[2005/10/28 06:41:52 | 00,491,520 | ---- | M] ( ) -- C:\WINDOWS\SYSTEM32\dlcccoms.exe
[2008/08/03 17:02:20 | 00,036,352 | ---- | M] () -- C:\Program Files\Winamp\winampa.exe
[2008/10/15 01:04:34 | 00,039,792 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
[2008/11/20 13:20:54 | 00,290,088 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunesHelper.exe
[2005/03/30 15:03:44 | 00,212,992 | ---- | M] (Webroot Software, Inc.) -- C:\Program Files\Webroot\Enterprise\Spy Sweeper\SpySweeperTray.exe
[2009/01/27 12:37:47 | 00,136,600 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
[2007/03/15 10:09:36 | 00,460,784 | ---- | M] (Gteko Ltd.) -- C:\Program Files\DellSupport\DSAgnt.exe
[2007/10/18 10:34:02 | 05,724,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe
[2007/07/20 06:29:07 | 00,068,856 | ---- | M] (Google Inc.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[2006/09/11 03:40:32 | 00,218,032 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
[2008/06/10 16:18:10 | 00,785,520 | ---- | M] (The Weather Channel Interactive, Inc.) -- C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe
[2006/12/22 10:17:32 | 00,598,016 | ---- | M] () -- C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe
[2008/11/20 13:20:44 | 00,536,872 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe
[2007/10/18 10:31:54 | 00,098,328 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\usnsvc.exe
[2008/08/22 03:16:40 | 00,637,984 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\iexplore.exe
[2008/08/22 03:16:40 | 00,637,984 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\iexplore.exe
[2007/09/20 09:35:36 | 00,118,336 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
[2008/08/22 03:16:40 | 00,637,984 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\iexplore.exe
[2009/01/26 12:48:53 | 00,422,912 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Pamela\Desktop\OTViewIt.exe

========== (O23) Win32 Services ==========

[2008/12/17 08:32:06 | 00,419,448 | ---- | M] (Emsi Software GmbH) -- C:\Program Files\a-squared Free\a2service.exe -- (a2free [Auto | Running])
[2004/04/07 11:07:32 | 01,135,728 | ---- | M] (America Online, Inc.) -- C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe -- (AOL ACS [Auto | Running])
[2008/11/07 14:28:16 | 00,132,424 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running])
[2004/07/15 00:49:26 | 00,032,768 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
[2008/06/29 14:23:18 | 02,944,392 | ---- | M] () -- C:\Program Files\Bradford Networks\Persistent Agent\bndaemon.exe -- (BNPagent [Auto | Running])
[2008/08/29 09:18:44 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service [Auto | Running])
[2003/05/21 00:22:36 | 00,032,768 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe -- (DefWatch [Auto | Running])
[2005/10/28 06:41:52 | 00,491,520 | ---- | M] ( ) -- C:\WINDOWS\SYSTEM32\dlcccoms.exe -- (dlcc_device [On_Demand | Running])
File not found -- -- (DM1Service [Auto | Stopped])
[2007/03/07 14:47:46 | 00,076,848 | ---- | M] () -- C:\Program Files\DellSupport\brkrsvc.exe -- (DSBrokerService [On_Demand | Stopped])
[2007/01/24 08:10:32 | 00,138,168 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [On_Demand | Stopped])
[2005/11/14 00:06:04 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
[2008/11/20 13:20:44 | 00,536,872 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Running])
[2009/01/27 12:37:47 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
[2003/06/19 22:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE -- (MDM [Auto | Running])
File not found -- -- (navapsvc [Auto | Stopped])
[2003/12/17 12:59:48 | 00,143,360 | ---- | M] (Intel® Corporation) -- C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe -- (NetSvc [On_Demand | Stopped])
[2003/05/21 00:27:46 | 00,610,304 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe -- (Norton AntiVirus Server [Auto | Running])
[2003/07/28 11:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
[2007/10/18 10:31:54 | 00,098,328 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\usnsvc.exe -- (usnjsvc [On_Demand | Running])
[2005/03/30 15:03:26 | 01,872,384 | ---- | M] (Webroot Software, Inc.) -- C:\Program Files\Webroot\Enterprise\CommAgent\CommAgent.exe -- (WebrootCommAgentService [Auto | Running])
[2005/03/30 15:03:46 | 01,812,992 | ---- | M] (Webroot Software, Inc.) -- C:\Program Files\Webroot\Enterprise\Spy Sweeper\SpySweeper.exe -- (WebrootSpySweeperService [Auto | Stopped])
[2007/10/25 14:27:54 | 00,266,240 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\installer\WLSetupSvc.exe -- (WLSetupSvc [On_Demand | Stopped])
[2006/10/18 19:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])

========== Driver Services ==========

[2007/07/02 21:06:02 | 00,021,035 | ---- | M] (Meetinghouse Data Communications) -- C:\WINDOWS\SYSTEM32\DRIVERS\AegisP.sys -- (AegisP [Auto | Running])
[2001/08/17 12:51:56 | 00,005,248 | ---- | M] (Acer Laboratories Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\ALIIDE.SYS -- (AliIde [Boot | Running])
[2008/04/13 12:36:39 | 00,043,008 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\amdagp.sys -- (amdagp [Boot | Running])
[2001/08/17 12:52:00 | 00,026,496 | ---- | M] (Advanced System Products, Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\ASC.SYS -- (asc [Boot | Running])
[2001/08/17 12:51:58 | 00,014,848 | ---- | M] (Advanced System Products, Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\ASC3550.SYS -- (asc3550 [Boot | Running])
[2001/08/17 12:51:54 | 00,006,656 | ---- | M] (CMD Technology, Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\CMDIDE.SYS -- (CmdIde [Boot | Running])
[2001/08/17 12:52:16 | 00,179,584 | ---- | M] (Mylex Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\DAC2W2K.SYS -- (dac2w2k [Boot | Running])
[2004/12/01 02:22:00 | 00,087,488 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\DRIVERS\drvmcdb.sys -- (drvmcdb [Boot | Running])
[2004/11/23 01:56:00 | 00,040,480 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\DRIVERS\drvnddm.sys -- (drvnddm [Auto | Running])
[2006/10/05 15:07:28 | 00,004,736 | ---- | M] (Gteko Ltd.) -- C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys -- (DSproct [On_Demand | Running])
[2007/02/25 11:10:48 | 00,005,376 | --S- | M] (Gteko Ltd.) -- C:\WINDOWS\SYSTEM32\DRIVERS\dsunidrv.sys -- (dsunidrv [Auto | Running])
[2004/02/10 14:49:14 | 00,154,112 | ---- | M] (Intel Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\e100b325.sys -- (E100B [On_Demand | Running])
[2008/04/17 12:12:54 | 00,015,464 | ---- | M] (GEAR Software Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys -- (GEARAspiWDM [On_Demand | Running])
[2009/01/26 12:55:00 | 00,085,969 | ---- | M] (GMER) -- C:\WINDOWS\SYSTEM32\DRIVERS\gmer.sys -- (gmer [On_Demand | Stopped])
[2005/09/20 10:00:54 | 01,302,332 | ---- | M] (Intel Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\ialmnt5.sys -- (ialm [On_Demand | Running])
[2004/03/05 21:14:42 | 01,233,525 | ---- | M] (Intel Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\IntelC51.sys -- (IntelC51 [On_Demand | Running])
[2004/03/05 21:15:34 | 00,647,929 | ---- | M] (Intel Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\IntelC52.sys -- (IntelC52 [On_Demand | Running])
[2004/06/15 21:52:40 | 00,061,157 | ---- | M] (Intel Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\IntelC53.sys -- (IntelC53 [On_Demand | Running])
[2008/04/13 12:39:48 | 00,014,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\kbdhid.sys -- (kbdhid [System | Stopped])
[2001/08/17 12:57:38 | 00,016,128 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\MODEMCSA.sys -- (MODEMCSA [On_Demand | Running])
[2004/03/05 21:13:38 | 00,037,048 | ---- | M] (Intel Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\mohfilt.sys -- (mohfilt [On_Demand | Running])
[2001/08/17 12:52:12 | 00,017,280 | ---- | M] (American Megatrends Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\MRAID35X.SYS -- (mraid35x [Boot | Running])
[2003/05/02 20:08:18 | 00,224,256 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Navap.sys -- (NAVAP [On_Demand | Running])
[2003/05/02 20:08:22 | 00,030,208 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Navapel.sys -- (NAVAPEL [Auto | Running])
[2009/01/23 03:00:00 | 00,089,104 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090123.003\NAVENG.SYS -- (NAVENG [On_Demand | Running])
[2009/01/23 03:00:00 | 00,876,112 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090123.003\NAVEX15.SYS -- (NAVEX15 [On_Demand | Running])
[2004/08/03 21:29:56 | 01,897,408 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\NV4_MINI.SYS -- (nv [On_Demand | Stopped])
[2004/08/04 04:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\PTILINK.SYS -- (Ptilink [On_Demand | Running])
[2007/03/07 17:51:00 | 00,043,528 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\DRIVERS\pxhelp20.sys -- (PxHelp20 [Boot | Running])
[2001/08/17 12:52:20 | 00,040,320 | ---- | M] (QLogic Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\QL1080.SYS -- (ql1080 [Boot | Running])
[2001/08/17 12:52:20 | 00,045,312 | ---- | M] (QLogic Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\QL12160.SYS -- (ql12160 [Boot | Running])
[2001/08/17 12:52:18 | 00,049,024 | ---- | M] (QLogic Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\QL1280.SYS -- (ql1280 [Boot | Running])
[2006/12/26 13:58:02 | 00,189,312 | ---- | M] (Realtek Semiconductor Corporation ) -- C:\WINDOWS\SYSTEM32\DRIVERS\RTL8187B.sys -- (RTL8187B [On_Demand | Stopped])
[2007/11/13 04:25:53 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\SYSTEM32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])
[2004/09/17 08:02:54 | 00,732,928 | ---- | M] (Creative Technology Ltd.) -- C:\WINDOWS\SYSTEM32\DRIVERS\senfilt.sys -- (senfilt [On_Demand | Running])
[2008/04/13 12:36:39 | 00,040,960 | ---- | M] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\SYSTEM32\DRIVERS\sisagp.sys -- (sisagp [Boot | Running])
[2005/01/27 14:31:06 | 00,260,352 | ---- | M] (Analog Devices, Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\smwdm.sys -- (smwdm [On_Demand | Running])
[2001/08/17 13:07:44 | 00,019,072 | ---- | M] (Adaptec, Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\SPARROW.SYS -- (Sparrow [Boot | Running])
[2004/07/14 10:29:04 | 00,005,627 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\DRIVERS\sscdbhk5.sys -- (sscdbhk5 [System | Running])
[2008/07/16 10:15:34 | 00,020,336 | ---- | M] (Webroot Software Inc (www.webroot.com)) -- C:\WINDOWS\SYSTEM32\DRIVERS\ssfs0BB9.sys -- (SSFS0BB9 [Boot | Running])
[2008/07/16 10:15:34 | 00,021,872 | ---- | M] (Webroot Software Inc (www.webroot.com)) -- C:\WINDOWS\SYSTEM32\DRIVERS\SSHRMD.SYS -- (SSHRMD [Boot | Running])
[2008/07/16 10:15:36 | 00,163,696 | ---- | M] (Webroot Software Inc (www.webroot.com)) -- C:\WINDOWS\SYSTEM32\DRIVERS\SSIDRV.SYS -- (SSIDRV [Boot | Running])
[2004/07/14 10:28:50 | 00,023,545 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\DRIVERS\ssrtln.sys -- (ssrtln [System | Running])
[2001/08/17 13:07:34 | 00,016,256 | ---- | M] (Symbios Logic Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\SYMC810.SYS -- (symc810 [Boot | Running])
[2001/08/17 13:07:36 | 00,032,640 | ---- | M] (LSI Logic) -- C:\WINDOWS\SYSTEM32\DRIVERS\SYMC8XX.SYS -- (symc8xx [Boot | Running])
[2005/03/15 14:33:52 | 00,123,208 | ---- | M] (Symantec Corporation) -- C:\Program Files\Symantec\SYMEVENT.SYS -- (SymEvent [On_Demand | Running])
[2001/08/17 13:07:40 | 00,028,384 | ---- | M] (LSI Logic) -- C:\WINDOWS\SYSTEM32\DRIVERS\SYM_HI.SYS -- (sym_hi [Boot | Running])
[2001/08/17 13:07:42 | 00,030,688 | ---- | M] (LSI Logic) -- C:\WINDOWS\SYSTEM32\DRIVERS\SYM_U3.SYS -- (sym_u3 [Boot | Running])
[2004/12/06 00:05:00 | 00,025,883 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\dla\tfsnboio.sys -- (tfsnboio [Auto | Running])
[2004/12/06 00:05:00 | 00,034,843 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\dla\tfsncofs.sys -- (tfsncofs [Auto | Running])
[2004/12/06 00:05:00 | 00,004,123 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\dla\tfsndrct.sys -- (tfsndrct [Auto | Running])
[2004/12/06 00:05:00 | 00,002,239 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\dla\tfsndres.sys -- (tfsndres [Auto | Running])
[2004/12/06 00:05:00 | 00,086,586 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\dla\tfsnifs.sys -- (tfsnifs [Auto | Running])
[2004/12/06 00:05:00 | 00,015,227 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\dla\tfsnopio.sys -- (tfsnopio [Auto | Running])
[2004/12/06 00:05:00 | 00,006,363 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\dla\tfsnpool.sys -- (tfsnpool [Auto | Running])
[2004/12/06 00:05:00 | 00,098,714 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\dla\tfsnudf.sys -- (tfsnudf [Auto | Running])
[2004/12/06 00:05:00 | 00,100,603 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\SYSTEM32\dla\tfsnudfa.sys -- (tfsnudfa [Auto | Running])
[2004/02/04 09:27:56 | 00,049,536 | ---- | M] (Texas Instruments Incorporated) -- C:\WINDOWS\SYSTEM32\DRIVERS\tiehdusb.sys -- (TIEHDUSB [On_Demand | Stopped])
[2001/08/17 12:52:22 | 00,036,736 | ---- | M] (Promise Technology, Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\ULTRA.SYS -- (ultra [Boot | Running])
[2003/01/10 15:13:04 | 00,033,588 | ---- | M] (America Online, Inc.) -- C:\WINDOWS\SYSTEM32\DRIVERS\wanatw4.sys -- (wanatw [On_Demand | Running])

========== (R ) Internet Explorer ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=http://go.microsoft.com/fwlink/?LinkId=69157
"Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896
"Default_Secondary_Page_URL"=
"Extensions Off Page"=about:NoAdd-ons
"Local Page"=C:\WINDOWS\system32\blank.htm
"Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896
"Security Risk Page"=about:SecurityRisk
"Start Page"=http://go.microsoft.com/fwlink/?LinkId=69157

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search]
"CustomizeSearch"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
"Default_Search_URL"=http://www.google.com/ie
"SearchAssistant"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\WINDOWS\system32\blank.htm
"Page_Transitions"=
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"SearchMigratedDefaultName"=Google
"SearchMigratedDefaultURL"=http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
"Start Page"=http://exchange.wartburg.edu/

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURL]
""=

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\SYSTEM32\ieframe.dll (Microsoft Corporation)

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=http://www.dell4me.com/myway
"First Home Page"=http://www.dell4me.com/myway
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=http://www.dell4me.com/myway
"First Home Page"=http://www.dell4me.com/myway
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome

[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main]

[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main]

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\WINDOWS\system32\blank.htm
"Page_Transitions"=
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"SearchMigratedDefaultName"=Google
"SearchMigratedDefaultURL"=http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
"Start Page"=http://exchange.wartburg.edu/

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\Software\Microsoft\Internet Explorer\SearchURL]
""=

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\SYSTEM32\ieframe.dll (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0

========== (O1) Hosts File ==========

HOSTS File = (812 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
First 25 entries...
127.0.0.1 localhost
r3HQZ]'TA!HF& 7Zi2E 3'BM.˾2͘GY}!":}am5 # Webroot SpySweeper entry

========== (O2) BHO's ==========

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (HKLM) -- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
{3049C3E9-B461-4BC5-8870-4C09146192CA} (HKLM) -- C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
{5CA3D70E-1895-11CF-8E15-001234567890} (HKLM) -- C:\WINDOWS\SYSTEM32\dla\tfswshx.dll (Sonic Solutions)
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (HKLM) -- C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
{7E853D72-626A-48EC-A868-BA8D5E23E045} (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
{9030D464-4C02-4ABF-8ECC-5164760863C6} (HKLM) -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
{AA1F9DDB-E605-4ba6-81D4-E427DEE012AD} (HKLM) -- C:\WINDOWS\SYSTEM32\TwcToolbarBho.dll ()
{AA58ED58-01DD-4d91-8333-CF10577473F7} (HKLM) -- c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)
{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (HKLM) -- C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll (Google Inc.)
{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} (HKLM) -- C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll (Microsoft Corporation)
{d2ce3e00-f94a-4740-988e-03dc2f38c34f} (HKLM) -- C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll (Microsoft Corp.)
{DBC80044-A445-435b-BC74-9C25C1C588A9} (HKLM) -- C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
{E7E6F031-17CE-4C07-BC86-EABFE594F69C} (HKLM) -- C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)

========== (O3) Toolbars ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414}" (HKLM) -- C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll (Microsoft Corp.)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" (HKLM) -- c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{2E5E800E-6AC0-411E-940A-369530A35E43}" (HKLM) -- C:\WINDOWS\SYSTEM32\TwcToolbarIe7.dll ()

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}" (HKLM) -- C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll (Microsoft Corporation)

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" (HKLM) -- c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" (HKLM) -- c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{604BC32A-9680-40D1-9AC6-E06B23A1BA4C}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}" (HKLM) -- C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll (Microsoft Corporation)

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" (HKLM) -- c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)

[HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{5BED3930-2E9E-76D8-BACC-80DF2188D455}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" (HKLM) -- c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)

[HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{5BED3930-2E9E-76D8-BACC-80DF2188D455}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" (HKLM) -- c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" (HKLM) -- c:\Program Files\Google\GoogleToolbar2.dll (Google Inc.)

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{604BC32A-9680-40D1-9AC6-E06B23A1BA4C}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}" (HKLM) -- C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found

========== (O4) Run Keys ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" (Adobe Systems Incorporated)
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
"AppleSyncNotifier"=C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
"bncsaui.exe"=%ProgramFiles%\Bradford Networks\Persistent Agent\bncsaui.exe ()
"dla"=C:\WINDOWS\system32\dla\tfswctrl.exe (Sonic Solutions)
"DLCCCATS"=rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16 ()
"dlccmon.exe"="C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe" (Dell)
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" (Hewlett-Packard Company)
"HP Software Update"=C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe (Hewlett-Packard Co.)
"HPDJ Taskbar Utility"=C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe (HP)
"igfxhkcmd"=C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
"igfxpers"=C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
"igfxtray"=C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
"IntelMeM"=C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe (Intel Corporation)
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
"mmtask"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe" (Musicmatch Inc.)
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" (Musicmatch, Inc.)
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
"SoundMAXPnP"=C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r (Sonic Solutions)
"vptray"=C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe (Symantec Corporation)
"Webroot Spy Sweeper, Enterprise Edition"=C:\Program Files\Webroot\Enterprise\Spy Sweeper\SpySweeperTray.exe (Webroot Software, Inc.)
"WebrootClientUI"="C:\Program Files\Webroot\Client\SpySweeperUI.exe" (Webroot Software, Inc.)
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" ()

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" /startup (Gteko Ltd.)
"DW6"="C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe" (The Weather Channel Interactive, Inc.)
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler (Macrovision Corporation)
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (Microsoft Corporation)
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" /startup (Gteko Ltd.)
"DW6"="C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe" (The Weather Channel Interactive, Inc.)
"ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler (Macrovision Corporation)
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (Microsoft Corporation)
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)

========== (O4) Startup Folders ==========

[2004/09/01 10:56:34 | 00,156,784 | -H-- | M] (America Online, Inc.) -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
[2005/09/20 18:10:04 | 00,238,080 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Desktop Search.lnk = C:\Program Files\MSN Toolbar Suite\DS\02.05.0001.1119\en-us\bin\WindowsSearch.exe
[2006/12/22 10:17:32 | 00,598,016 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Wireless Configuration Utility HW.14.lnk = C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe

========== (O6 & O7) Current Version Policies ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"AllowLegacyWebView"=1
"AllowUnhashedWebView"=1
"NoCDBurning"=0
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"DisableRegistryTools"=0

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
"NoDriveAutoRun"=67108863

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145
"NoDriveAutoRun"=67108863

[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0

========== (O8) IE Context Menu Extensions ==========

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\]
&MSN Search: C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-us\msntb.dll [2005/06/15 20:02:08 | 00,577,232 | ---- | M] (Microsoft Corporation)
&Search: Reg Error: Value does not exist or could not be read. File not found
&Yahoo! Search: File not found
E&xport to Microsoft Excel: C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE [2008/10/13 11:29:28 | 10,351,944 | ---- | M] (Microsoft Corporation)
Open in new background tab: C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1110\en-us\msntabres.dll [2005/08/01 16:18:58 | 00,078,848 | ---- | M] (Microsoft Corporation)
Open in new foreground tab: C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1110\en-us\msntabres.dll [2005/08/01 16:18:58 | 00,078,848 | ---- | M] (Microsoft Corporation)
Yahoo! &Dictionary: File not found
Yahoo! &Maps: File not found
Yahoo! &SMS: File not found

[HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE [2008/10/13 11:29:28 | 10,351,944 | ---- | M] (Microsoft Corporation)

[HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE [2008/10/13 11:29:28 | 10,351,944 | ---- | M] (Microsoft Corporation)

[HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: Reg Error: Key does not exist or could not be opened. File not found

[HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: Reg Error: Key does not exist or could not be opened. File not found

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\Software\Microsoft\Internet Explorer\MenuExt\]
&MSN Search: C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1082\en-us\msntb.dll [2005/06/15 20:02:08 | 00,577,232 | ---- | M] (Microsoft Corporation)
&Search: Reg Error: Value does not exist or could not be read. File not found
&Yahoo! Search: File not found
E&xport to Microsoft Excel: C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE [2008/10/13 11:29:28 | 10,351,944 | ---- | M] (Microsoft Corporation)
Open in new background tab: C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1110\en-us\msntabres.dll [2005/08/01 16:18:58 | 00,078,848 | ---- | M] (Microsoft Corporation)
Open in new foreground tab: C:\Program Files\MSN Toolbar Suite\TAB\02.05.0000.1110\en-us\msntabres.dll [2005/08/01 16:18:58 | 00,078,848 | ---- | M] (Microsoft Corporation)
Yahoo! &Dictionary: File not found
Yahoo! &Maps: File not found
Yahoo! &SMS: File not found

========== (O9) IE Extensions ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}: Menu: Sun Java Console -- %SystemRoot%\SYSTEM32\msjava.dll [2003/02/28 17:26:26 | 00,947,472 | ---- | M] (Microsoft Corporation)
{2E5E800E-6AC0-411E-940A-369530A35E43}: Button: The Weather Channel -- Reg Error: Key does not exist or could not be opened. File not found
{2E5E800E-6AC0-411E-940A-369530A35E43}: Menu: The Weather Channel -- File not found
{92780B25-18CC-41C8-B9BE-3C9C571A8263}: Button: Research -- %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [2007/04/19 13:10:18 | 00,063,840 | ---- | M] (Microsoft Corporation)
{e2e2dd38-d088-4134-82b7-f2ba38496583}: Menu: @xpsp3res.dll,-20001 -- %SystemRoot%\network diagnostic\xpnetdiag.exe [2008/04/13 12:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Button: Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2008/04/13 18:12:28 | 01,695,232 | -HS- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Menu: Windows Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2008/04/13 18:12:28 | 01,695,232 | -HS- | M] (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %SystemRoot%\SYSTEM32\msjava.dll [Web Browser Applet Control] -> [2003/02/28 17:26:26 | 00,947,472 | ---- | M] (Microsoft Corporation)
CmdMapping\\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2007/04/19 13:10:18 | 00,063,840 | ---- | M] (Microsoft Corporation)
CmdMapping\\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} [HKLM] -> [Reg Error: Value MenuText does not exist or could not be read.] -> File not found
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 18:12:28 | 01,695,232 | -HS- | M] (Microsoft Corporation)

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %SystemRoot%\SYSTEM32\msjava.dll [Web Browser Applet Control] -> [2003/02/28 17:26:26 | 00,947,472 | ---- | M] (Microsoft Corporation)
CmdMapping\\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2007/04/19 13:10:18 | 00,063,840 | ---- | M] (Microsoft Corporation)
CmdMapping\\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} [HKLM] -> [Reg Error: Value MenuText does not exist or could not be read.] -> File not found
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 18:12:28 | 01,695,232 | -HS- | M] (Microsoft Corporation)

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %SystemRoot%\SYSTEM32\msjava.dll [Web Browser Applet Control] -> [2003/02/28 17:26:26 | 00,947,472 | ---- | M] (Microsoft Corporation)
CmdMapping\\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2007/04/19 13:10:18 | 00,063,840 | ---- | M] (Microsoft Corporation)
CmdMapping\\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} [HKLM] -> [Reg Error: Value MenuText does not exist or could not be read.] -> File not found
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 18:12:28 | 01,695,232 | -HS- | M] (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %SystemRoot%\SYSTEM32\msjava.dll [Web Browser Applet Control] -> [2003/02/28 17:26:26 | 00,947,472 | ---- | M] (Microsoft Corporation)
CmdMapping\\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2007/04/19 13:10:18 | 00,063,840 | ---- | M] (Microsoft Corporation)
CmdMapping\\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} [HKLM] -> [Reg Error: Value MenuText does not exist or could not be read.] -> File not found
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 18:12:28 | 01,695,232 | -HS- | M] (Microsoft Corporation)

========== (O12) Internet Explorer Plugins ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\]
PluginsPage: "" = http://activex.microsoft.com/controls/find...=%s&mime=%s
PluginsPageFriendlyName: "" = Microsoft ActiveX Gallery

========== (O13) Default Prefixes ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
""=http://

========== (O15) Trusted Sites ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
1 domain(s) and sub-domain(s) not assigned to a zone.

========== (O16) DPF ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\]
{14B87622-7E19-4EA8-93B3-97215F77A6BC}: http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab -- MessengerStatsClient Class
{17492023-C23A-453E-A040-C7C580BBF700}: http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409 -- Windows Genuine Advantage Validation Tool
{20A60F0D-9AFA-4515-A0FD-83BD84642501}: http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab -- Checkers Class
{33564D57-0000-0010-8000-00AA00389B71}: http://download.microsoft.com/download/F/6...922/wmv9VCM.CAB -- Reg Error: Key does not exist or could not be opened.
{3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}: http://office.microsoft.com/officeupdate/content/opuc2.cab -- Office Update Installation Engine
{4871A87A-BFDD-4106-8153-FFDE2BAC2967}: http://dlm.tools.akamai.com/dlmanager/vers...vex-2.2.4.1.cab -- DLM Control
{56762DEC-6B0D-4AB4-A8AD-989993B5D08B}: http://www.eset.eu/buxus/docs/OnlineScanner.cab -- OnlineScanner Control
{5F8469B4-B055-49DD-83F7-62B522420ECC}: http://upload.facebook.com/controls/Facebo...otoUploader.cab -- Facebook Photo Uploader Control
{74C861A1-D548-4916-BC8A-FDE92EDFF62C}: http://mediaplayer.walmart.com/installer/install.cab -- Reg Error: Key does not exist or could not be opened.
{8AD9C840-044E-11D1-B3E9-00805F499D93}: http://java.sun.com/products/plugin/autodl...indows-i586.cab -- Java Plug-in 1.6.0_11
{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}: http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab -- Reg Error: Key does not exist or could not be opened.
{A8F2B9BD-A6A0-486A-9744-18920D898429}: http://www.sibelius.com/download/software/...tiveXPlugin.cab -- ScorchPlugin Class
{B8BE5E93-A60C-4D26-A2DC-220313175592}: http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab -- ZoneIntro Class
{C3F79A2B-B9B4-4A66-B012-3EE46475B072}: http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab -- MessengerStatsClient Class
{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}: http://java.sun.com/products/plugin/autodl...indows-i586.cab -- Java Plug-in 1.6.0_11
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}: http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -- Java Plug-in 1.6.0_11
{D27CDB6E-AE6D-11CF-96B8-444553540000}: http://download.macromedia.com/pub/shockwa...ash/swflash.cab -- Shockwave Flash Object
Microsoft XML Parser for Java: file://C:\WINDOWS\Java\classes\xmldso.cab -- Reg Error: Key does not exist or could not be opened.

========== (O17) DNS Name Servers ==========

{1B9DDFCC-CF74-4172-AA8F-5A9586A6AEF9} (Servers: | Description: Intel® PRO/100 VE Network Connection)
{44E86920-94C2-473A-BDE4-F3F35EB2E0AC} (Servers: | Description: TRENDnet TEW-424UB Wireless 802.11g 54Mbps USB 2.0 Network Adapter)

========== (O20) Winlogon Notify Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\]
igfxcui: "DllName" = igfxdev.dll -- C:\WINDOWS\SYSTEM32\igfxdev.dll (Intel Corporation)
NavLogon: "DllName" = C:\WINDOWS\system32\NavLogon.dll -- C:\WINDOWS\SYSTEM32\NavLogon.dll ()
WRNotifier: "DllName" = WRLogonNtf.DLL -- C:\WINDOWS\SYSTEM32\WRLogonNtf.DLL (Webroot Software, Inc.)

========== Safeboot Options ==========

"AlternateShell"=cmd.exe

========== CDRom AutoRun Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1

========== Autorun Files on Drives ==========

AUTOEXEC.BAT []
[2004/08/11 16:15:00 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT -- [ NTFS ]

========== MountPoints2 ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3ff550be-bbe5-11dc-9eff-0014d1362be8}\Shell]
""=AutoRun

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3ff550be-bbe5-11dc-9eff-0014d1362be8}\Shell\AutoRun]
""=Auto&Play


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3ff550be-bbe5-11dc-9eff-0014d1362be8}\Shell\AutoRun\command]
""=G:\LaunchU3.exe -- File not found

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3ff550c0-bbe5-11dc-9eff-0014d1362be8}\Shell]
""=AutoRun

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3ff550c0-bbe5-11dc-9eff-0014d1362be8}\Shell\AutoRun]
""=Auto&Play


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3ff550c0-bbe5-11dc-9eff-0014d1362be8}\Shell\AutoRun\command]
""=G:\LaunchU3.exe -- File not found

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b2a55fe8-7e81-11db-9d90-00038a000015}\Shell]
""=AutoRun

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b2a55fe8-7e81-11db-9d90-00038a000015}\Shell\AutoRun]
""=Auto&Play


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b2a55fe8-7e81-11db-9d90-00038a000015}\Shell\AutoRun\command]
""=G:\LaunchU3.exe -- File not found

========== Files/Folders - Created Within 30 Days ==========

[1 C:\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[2009/01/27 19:19:23 | 00,014,029 | ---- | C] () -- C:\Documents and Settings\Pamela\Desktop\banner.gif
[2009/01/26 20:18:27 | 00,000,000 | ---D | C] -- C:\Program Files\EsetOnlineScanner
[2009/01/26 19:54:32 | 00,001,261 | ---- | C] () -- C:\Documents and Settings\Pamela\Desktop\1233021253772-integrated.jnlp
[2009/01/26 19:46:52 | 00,001,261 | ---- | C] () -- C:\Documents and Settings\Pamela\Desktop\1233020791728-integrated.jnlp
[2009/01/26 19:01:07 | 00,000,000 | ---D | C] -- C:\_OTMoveIt
[2009/01/26 19:00:27 | 00,348,160 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Pamela\Desktop\OTMoveIt3.exe
[2009/01/26 18:58:51 | 00,000,000 | ---D | C] -- C:\HostsXpert
[2009/01/26 18:58:25 | 00,353,485 | ---- | C] () -- C:\Documents and Settings\Pamela\Desktop\HostsXpert.zip
[2009/01/26 12:55:04 | 00,000,250 | ---- | C] () -- C:\WINDOWS\gmer.ini
[2009/01/26 12:55:00 | 00,884,736 | ---- | C] () -- C:\WINDOWS\gmer.dll
[2009/01/26 12:55:00 | 00,085,969 | ---- | C] (GMER) -- C:\WINDOWS\System32\drivers\gmer.sys
[2009/01/26 12:55:00 | 00,000,080 | ---- | C] () -- C:\WINDOWS\gmer_uninstall.cmd
[2009/01/26 12:54:59 | 00,811,008 | ---- | C] () -- C:\WINDOWS\gmer.exe
[2009/01/26 12:54:50 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pamela\Desktop\gmer
[2009/01/26 12:53:28 | 00,747,873 | ---- | C] () -- C:\Documents and Settings\Pamela\Desktop\gmer.zip
[2009/01/26 12:48:52 | 00,422,912 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Pamela\Desktop\OTViewIt.exe
[2009/01/24 23:02:38 | 00,000,121 | ---- | C] () -- C:\wallpaper_log.html
[2009/01/24 23:01:39 | 00,000,000 | ---D | C] -- C:\Program Files\Animated Screensaver Maker
[2009/01/22 23:08:59 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pamela\My Documents\Screensavers2
[2009/01/22 23:06:37 | 00,201,728 | ---- | C] (ScreenTime Media) -- C:\Documents and Settings\All Users\Documents\Harry Potter Order of the Phoenix.scr
[2009/01/22 23:06:37 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\Harry Potter Order of the Phoenix dir
[2009/01/22 23:04:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\HarryPotter_setup
[2009/01/22 23:03:09 | 00,471,040 | ---- | C] (ScreenTime Media) -- C:\WINDOWS\HarryPotter_screensaver_pc.scr
[2009/01/22 23:03:04 | 00,000,000 | ---D | C] -- C:\WINDOWS\HarryPotter_screensaver_pc dir
[2009/01/22 23:02:15 | 01,806,450 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\HarryPotter_setup.zip
[2009/01/22 19:57:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pamela\My Documents\Temps
[2009/01/21 08:29:33 | 00,261,366 | ---- | C] () -- C:\Documents and Settings\Pamela\Desktop\obamainauguration012009.pdf
[2009/01/19 22:46:00 | 00,000,000 | ---D | C] -- C:\WINDOWS\ie8updates
[2009/01/19 16:16:57 | 00,000,765 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Calculator.lnk
[2009/01/19 16:16:56 | 00,000,000 | ---D | C] -- C:\Program Files\Moffsoft FreeCalc
[2009/01/19 16:16:13 | 00,782,433 | ---- | C] (Moffsoft ) -- C:\Documents and Settings\All Users\Documents\MoffFreeCalcSetup.exe
[2009/01/18 17:37:41 | 00,000,782 | ---- | C] () -- C:\Documents and Settings\Pamela\Desktop\Windows Media Player.lnk
[2009/01/18 17:30:34 | 00,000,000 | ---D | C] -- C:\Program Files\msn gaming zone
[2009/01/18 17:30:32 | 80,326,2464 | -HS- | C] () -- C:\hiberfil.sys
[2009/01/18 17:12:28 | 00,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2009/01/18 17:08:26 | 16,710,688 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\Pamela\Desktop\IE8-WindowsXP-x86-ENU.exe
[2009/01/13 09:04:38 | 00,001,754 | ---- | C] () -- C:\Documents and Settings\Pamela\Desktop\The Weather Channel Desktop.lnk
[2009/01/13 09:03:32 | 00,000,000 | ---D | C] -- C:\Program Files\The Weather Channel FW
[2009/01/08 19:16:43 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pamela\Local Settings\Application Data\Mozilla
[2009/01/08 19:15:05 | 07,518,240 | ---- | C] (Mozilla) -- C:\Documents and Settings\All Users\Documents\Firefox Setup 3.0.5.exe
[2009/01/08 12:56:35 | 15,452,536 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\Pamela\Desktop\IE7-WindowsXP-x86-enu-2.exe
[2009/01/08 09:07:24 | 00,000,776 | ---- | C] () -- C:\Documents and Settings\Pamela\Desktop\Shortcut to SPYSWEEPER.lnk
[2009/01/08 09:07:16 | 00,000,786 | ---- | C] () -- C:\Documents and Settings\Pamela\Desktop\Shortcut to SpySweeperUI.lnk
[2009/01/08 08:51:14 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pamela\Application Data\Malwarebytes
[2009/01/08 08:51:11 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/01/08 08:51:11 | 00,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/01/08 08:51:09 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/01/08 08:51:08 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/01/08 08:51:08 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/01/07 22:24:28 | 00,000,000 | ---D | C] -- C:\WINDOWS\temp
[2009/01/07 21:59:32 | 00,260,272 | ---- | C] () -- C:\cmldr
[2009/01/07 21:59:26 | 00,000,000 | ---D | C] -- C:\cmdcons
[2009/01/07 21:57:11 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/01/07 21:57:11 | 00,000,000 | ---D | C] -- C:\Qoobox
[2009/01/07 12:12:50 | 00,000,648 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\a-squared Free.lnk
[2009/01/07 12:12:40 | 00,000,000 | ---D | C] -- C:\Program Files\a-squared Free
[2009/01/07 12:12:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pamela\My Documents\a-squared Free
[2009/01/07 11:54:53 | 00,005,120 | -HS- | C] () -- C:\Program Files\Thumbs.db
@Alternate Data Stream - 0 bytes -> C:\Program Files\Thumbs.db:encryptable
[2009/01/07 11:01:16 | 00,000,124 | -H-- | C] () -- C:\Documents and Settings\Pamela\Local Settings\Application Data\Thumbs.db
[2009/01/07 08:06:18 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pamela\Application Data\alot
[2009/01/05 23:24:27 | 00,000,000 | ---D | C] -- C:\Program Files\alot
[2009/01/05 22:36:17 | 00,000,000 | ---D | C] -- C:\Program Files\Twighlightthemoviescreens
[2009/01/05 22:35:00 | 06,044,845 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\Twighlightthemoviescreens1.0.exe
[2009/01/05 21:18:26 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pamela\My Documents\2009 Stuff
[2009/01/05 19:39:21 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pamela\My Documents\World Religions
[2009/01/03 23:06:10 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pamela\My Documents\Picture Motion Browser
[2009/01/03 22:40:25 | 00,081,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xinput1_3.dll
[2009/01/03 22:40:17 | 00,261,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_7.dll
[2009/01/03 22:40:08 | 01,123,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DCompiler_33.dll
[2009/01/03 22:40:08 | 00,443,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx10_33.dll
[2009/01/03 22:39:54 | 03,495,784 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_33.dll
[2009/01/03 22:39:53 | 00,255,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_6.dll
[2009/01/03 22:39:52 | 00,251,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_5.dll
[2009/01/03 22:39:51 | 03,426,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_32.dll
[2009/01/03 22:39:49 | 00,237,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_4.dll
[2009/01/03 22:39:49 | 00,015,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\x3daudio1_1.dll
[2009/01/03 22:39:48 | 02,414,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_31.dll
[2009/01/03 22:39:47 | 00,236,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_3.dll
[2009/01/03 22:39:46 | 00,230,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_2.dll
[2009/01/03 22:39:46 | 00,062,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xinput1_2.dll
[2009/01/03 22:39:45 | 00,062,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xinput1_1.dll
[2009/01/03 22:39:44 | 00,229,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_1.dll
[2009/01/03 22:39:28 | 02,388,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_30.dll
[2009/01/03 22:39:27 | 00,230,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xactengine2_0.dll
[2009/01/03 22:39:27 | 00,014,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\x3daudio1_0.dll
[2009/01/03 22:39:26 | 02,332,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_29.dll
[2009/01/03 22:39:25 | 02,323,664 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_28.dll
[2009/01/03 22:39:24 | 00,061,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xinput9_1_0.dll
[2009/01/03 22:39:23 | 02,319,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_27.dll
[2009/01/03 22:39:21 | 02,297,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_26.dll
[2009/01/03 22:39:20 | 02,337,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_25.dll
[2009/01/03 22:39:17 | 02,222,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_24.dll
[2009/01/03 22:28:03 | 00,000,000 | ---D | C] -- C:\Program Files\Sony
[2009/01/03 19:23:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Pamela\Application Data\Media Player Classic
[2009/01/03 19:17:16 | 00,000,000 | ---D | C] -- C:\Program Files\AviSynth 2.5
[2009/01/03 19:17:05 | 00,000,780 | ---- | C] () -- C:\Documents and Settings\Pamela\Desktop\DVD slideshow GUI.lnk
[2009/01/03 19:16:40 | 00,000,000 | ---D | C] -- C:\Program Files\DVD slideshow GUI

========== Files - Modified Within 30 Days ==========

[1 C:\*.tmp files]
[4 C:\WINDOWS\System32\*.tmp files]
[1 C:\WINDOWS\*.tmp files]
[2009/01/27 20:06:09 | 00,000,584 | ---- | M] () -- C:\Documents and Settings\Pamela\My Documents\My Sharing Folders.lnk
[2009/01/27 20:03:28 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\WPA.DBL
[2009/01/27 20:01:53 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/01/27 20:01:48 | 80,326,2464 | -HS- | M] () -- C:\hiberfil.sys
[2009/01/27 20:01:48 | 00,002,048 | --S- | M] () -- C:\WINDOWS\BOOTSTAT.DAT
[2009/01/27 19:18:30 | 00,014,029 | ---- | M] () -- C:\Documents and Settings\Pamela\Desktop\banner.gif
[2009/01/27 06:17:28 | 00,376,056 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/01/26 20:20:28 | 00,002,497 | ---- | M] () -- C:\Documents and Settings\Pamela\Desktop\Word 2003.lnk
[2009/01/26 19:54:33 | 00,001,261 | ---- | M] () -- C:\Documents and Settings\Pamela\Desktop\1233021253772-integrated.jnlp
[2009/01/26 19:46:52 | 00,001,261 | ---- | M] () -- C:\Documents and Settings\Pamela\Desktop\1233020791728-integrated.jnlp
[2009/01/26 19:00:28 | 00,348,160 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Pamela\Desktop\OTMoveIt3.exe
[2009/01/26 18:58:25 | 00,353,485 | ---- | M] () -- C:\Documents and Settings\Pamela\Desktop\HostsXpert.zip
[2009/01/26 12:55:04 | 00,000,250 | ---- | M] () -- C:\WINDOWS\gmer.ini
[2009/01/26 12:55:00 | 00,884,736 | ---- | M] () -- C:\WINDOWS\gmer.dll
[2009/01/26 12:55:00 | 00,085,969 | ---- | M] (GMER) -- C:\WINDOWS\System32\drivers\gmer.sys
[2009/01/26 12:55:00 | 00,000,080 | ---- | M] () -- C:\WINDOWS\gmer_uninstall.cmd
[2009/01/26 12:54:50 | 00,811,008 | ---- | M] () -- C:\WINDOWS\gmer.exe
[2009/01/26 12:53:30 | 00,747,873 | ---- | M] () -- C:\Documents and Settings\Pamela\Desktop\gmer.zip
[2009/01/26 12:48:53 | 00,422,912 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Pamela\Desktop\OTViewIt.exe
[2009/01/24 23:02:45 | 00,000,121 | ---- | M] () -- C:\wallpaper_log.html
[2009/01/22 23:23:07 | 00,000,874 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/01/22 23:10:52 | 00,012,288 | ---- | M] () -- C:\WINDOWS\impborl.dll
[2009/01/22 23:10:22 | 00,471,040 | ---- | M] (ScreenTime Media) -- C:\WINDOWS\HarryPotter_screensaver_pc.scr
[2009/01/22 23:02:30 | 01,806,450 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\HarryPotter_setup.zip
[2009/01/22 09:45:01 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/01/21 08:29:36 | 00,261,366 | ---- | M] () -- C:\Documents and Settings\Pamela\Desktop\obamainauguration012009.pdf
[2009/01/19 16:16:57 | 00,000,765 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Calculator.lnk
[2009/01/19 16:16:17 | 00,782,433 | ---- | M] (Moffsoft ) -- C:\Documents and Settings\All Users\Documents\MoffFreeCalcSetup.exe
[2009/01/18 21:23:52 | 00,000,281 | RHS- | M] () -- C:\BOOT.INI
[2009/01/18 21:23:51 | 00,000,728 | ---- | M] () -- C:\WINDOWS\WIN.INI
[2009/01/18 17:37:42 | 00,000,782 | ---- | M] () -- C:\Documents and Settings\Pamela\Desktop\Windows Media Player.lnk
[2009/01/18 17:29:47 | 00,004,566 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009/01/18 17:29:35 | 00,445,156 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/01/18 17:29:35 | 00,384,596 | ---- | M] () -- C:\WINDOWS\System32\PERFH009.DAT
[2009/01/18 17:29:35 | 00,054,280 | ---- | M] () -- C:\WINDOWS\System32\PERFC009.DAT
[2009/01/18 17:28:58 | 00,000,057 | ---- | M] () -- C:\WINDOWS\System32\MAPISVC.INF
[2009/01/18 17:17:34 | 00,000,077 | -HS- | M] () -- C:\Documents and Settings\Pamela\My Documents\DESKTOP.INI
[2009/01/18 17:08:46 | 16,710,688 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Pamela\Desktop\IE8-WindowsXP-x86-ENU.exe
[2009/01/13 09:04:38 | 00,001,754 | ---- | M] () -- C:\Documents and Settings\Pamela\Desktop\The Weather Channel Desktop.lnk
[2009/01/12 23:06:18 | 00,026,624 | -HS- | M] () -- C:\Documents and Settings\Pamela\My Documents\Thumbs.db
@Alternate Data Stream - 0 bytes -> C:\Documents and Settings\Pamela\My Documents\Thumbs.db:encryptable
[2009/01/09 19:35:28 | 20,853,704 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009/01/08 19:16:34 | 00,001,602 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/01/08 19:15:37 | 07,518,240 | ---- | M] (Mozilla) -- C:\Documents and Settings\All Users\Documents\Firefox Setup 3.0.5.exe
[2009/01/08 12:56:34 | 15,452,536 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Pamela\Desktop\IE7-WindowsXP-x86-enu-2.exe
[2009/01/08 09:07:24 | 00,000,776 | ---- | M] () -- C:\Documents and Settings\Pamela\Desktop\Shortcut to SPYSWEEPER.lnk
[2009/01/08 09:07:16 | 00,000,786 | ---- | M] () -- C:\Documents and Settings\Pamela\Desktop\Shortcut to SpySweeperUI.lnk
[2009/01/08 08:51:11 | 00,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/01/07 21:08:27 | 04,278,026 | -H-- | M] () -- C:\Documents and Settings\Pamela\Local Settings\Application Data\IconCache.db
[2009/01/07 14:45:00 | 00,000,124 | -H-- | M] () -- C:\Documents and Settings\Pamela\Local Settings\Application Data\Thumbs.db
[2009/01/07 12:12:51 | 00,000,648 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\a-squared Free.lnk
[2009/01/07 11:10:51 | 00,108,424 | ---- | M] () -- C:\Documents and Settings\Pamela\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/01/05 22:35:22 | 06,044,845 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\Twighlightthemoviescreens1.0.exe
[2009/01/04 18:39:00 | 00,038,496 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/01/04 18:38:56 | 00,015,504 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/01/04 11:30:30 | 00,015,360 | ---- | M] () -- C:\Documents and Settings\Pamela\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/01/03 23:32:50 | 00,002,341 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/01/03 19:17:05 | 00,000,780 | ---- | M] () -- C:\Documents and Settings\Pamela\Desktop\DVD slideshow GUI.lnk
< End of report >



OTVI Extras:
OTViewIt Extras logfile created on: 1/27/2009 8:09:07 PM - Run 4
OTViewIt by OldTimer - Version 1.0.21.0 Folder = C:\Documents and Settings\Pamela\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18241)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

765.98 Mb Total Physical Memory | 294.14 Mb Available Physical Memory | 38.40% Memory free
1.83 Gb Paging File | 1.35 Gb Available in Paging File | 74.10% Paging File free
Paging file location(s): C:\pagefile.sys 1149 1349;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 33.52 Gb Total Space | 4.62 Gb Free Space | 13.78% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PAMANDTRISH
Current User Name: Pamela
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Whitelist: On
File Age = 30 Days

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled"=1
"AntiVirusDisableNotify"=0
"FirewallDisableNotify"=0
"UpdatesDisableNotify"=0
"AntiVirusOverride"=1
"FirewallOverride"=0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall"=1
"DoNotAllowExceptions"=0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\IcmpSettings]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[2008/04/13 18:12:34 | 00,141,312 | ---- | M] (Microsoft Corporation) -- %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
[2004/04/07 11:07:32 | 01,135,728 | ---- | M] (America Online, Inc.) -- C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL
[2004/04/07 11:07:34 | 00,496,752 | ---- | M] (America Online, Inc) -- C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL
[2004/09/01 10:56:56 | 00,259,184 | ---- | M] (America Online, Inc.) -- C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0
[2008/04/13 12:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[2007/10/18 10:34:02 | 05,724,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
[2007/10/02 16:18:24 | 00,304,488 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
[2008/04/13 18:12:34 | 00,141,312 | ---- | M] (Microsoft Corporation) -- %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
[2004/04/07 11:07:32 | 01,135,728 | ---- | M] (America Online, Inc.) -- C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL
[2004/04/07 11:07:34 | 00,496,752 | ---- | M] (America Online, Inc) -- C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL
[2004/09/01 10:56:56 | 00,259,184 | ---- | M] (America Online, Inc.) -- C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0
[2006/01/21 12:16:30 | 00,036,864 | ---- | M] () -- C:\Program Files\Maple 10\jre\bin\maple.exe:*:Enabled:maple
[2006/01/21 12:15:20 | 00,024,681 | ---- | M] () -- C:\Program Files\Maple 10\jre\bin\java.exe:*:Enabled:java
[2008/04/07 06:25:30 | 00,214,560 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer
[2005/02/15 10:36:40 | 00,565,248 | ---- | M] (Hewlett-Packard) -- C:\Program Files\Hewlett-Packard\HP Software Update\HPWUCli.exe:*:Disabled:HP Software Update Client
File not found -- C:\Program Files\Java\jre1.5.0_11\bin\javaw.exe:*:Enabled:Java™ 2 Platform Standard Edition binary
File not found -- C:\Program Files\Java\jre1.6.0_01\bin\javaw.exe:*:Enabled:Java™ Platform SE binary
[2008/04/13 12:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation) -- %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
[2008/06/29 14:23:18 | 02,944,392 | ---- | M] () -- C:\Program Files\Bradford Networks\Persistent Agent\bndaemon.exe:*:Enabled:Bradford Persistent Agent
[2008/08/29 09:18:44 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour
[2007/10/18 10:34:02 | 05,724,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger
[2007/10/02 16:18:24 | 00,304,488 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)
[2008/11/20 13:20:48 | 14,294,824 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes

========== (O10) Winsock2 Catalogs ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\]
NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] -- C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)

========== (O18) Protocol Handlers ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2003/12/22 07:38:40 | 00,081,920 | ---- | M] (Hewlett-Packard Company) C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (cetihpz:{CF184AD3-CDCB-4168-A3F7-8E447D129300} (HKLM) [CZipHandler Object])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
ipp: [HKLM - No CLSID value]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2005/09/20 11:33:58 | 00,843,984 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL ipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2007/10/18 10:31:54 | 00,066,072 | ---- | M] (Microsoft Corporation) C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (livecall:{828030A1-22C1-4009-854F-8E305202313F} (HKLM) [Reg Error: Value does not exist or could not be read.])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
msdaipp: [HKLM - No CLSID value]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2005/09/20 11:33:58 | 00,843,984 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\0x00000001:{E1D2BF42-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAMON.BINDER]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\] - Protocol Handlers
[2005/09/20 11:33:58 | 00,843,984 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL msdaipp\oledb:{E1D2BF40-A96B-11d1-9C6B-0000F875AC61} (HKLM) [HKLM - MSDAIPP.BINDER]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2000/04/19 17:47:36 | 00,520,117 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (ms-itss:{0A9007C0-4076-11D3-8789-0000F8105754} (HKLM) [Microsoft Infotech Storage Protocol for IE 4.0])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2007/10/18 10:31:54 | 00,066,072 | ---- | M] (Microsoft Corporation) C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (msnim:{828030A1-22C1-4009-854F-8E305202313F} (HKLM) [Reg Error: Value does not exist or could not be read.])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2007/03/14 12:10:22 | 07,255,384 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (mso-offdap:{3D9F03FA-7A94-11D3-BE81-0050048385D1} (HKLM) [Data Page Pluggable Protocol mso-offdap Handler])

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\]
[2007/05/10 12:45:34 | 08,069,464 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (mso-offdap11:{32505114-5902-49B2-880A-1F7738E5A384} (HKLM) [Data Page Plugable Protocal mso-offdap11 Handler])

========== (O18) Protocol Filters ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\] - Protocol Filters
[2007/04/19 12:57:40 | 00,046,432 | ---- | M] (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL text/xml:{807553E5-5146-11D5-A672-00B0D022E945} (HKLM) [Reg Error: Value does not exist or could not be read.]

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0456ebd7-5f67-4ab6-852e-63781e3f389c}"=Macromedia Flash Player
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}"=Sonic Update Manager
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}"=Microsoft Plus! Photo Story 2 LE
"{0EFC6259-3AD8-4CD2-BC57-D4937AF5CC0E}"=Symantec AntiVirus Client
"{10C69612-017B-45F5-B986-7D113D5A2EA3}"=MSN Toolbar
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}"=Sonic DLA
"{15EE79F4-4ED1-4267-9B0F-351009325D7D}"=HP Software Update
"{17334AAF-C9E7-483B-9F45-E3FCAF07FFA7}"=Intel® PROSet for Wired Connections
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}"=Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}"=Java™ 6 Update 11
"{318AB667-3230-41B5-A617-CB3BF748D371}"=iTunes
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}"=Windows Media Player 10
"{3414C7E8-F883-445E-9994-E410D7E5B1F4}"=Bradford Persistent Agent
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}"=WebFldrs XP
"{35BDEFF1-A610-4956-A00D-15453C116395}"=Internet Explorer Default Page
"{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}"=Google Earth
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}"=Modem On Hold
"{4192EAC0-6B36-4723-B216-D0E86E7757AC}"=Jasc Paint Shop Photo Album 5
"{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}"=Adobe Photoshop Album Starter Edition 3.0
"{508CE775-4BA4-4748-82DF-FE28DA9F03B0}"=Windows Live Messenger
"{582D2A53-F426-4C5E-A2E6-43C1AB36B907}"=Safari
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}"=Dell Driver Reset Tool
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}"=Apple Software Update
"{697836DE-03BB-4C4C-9B06-CAFC93D0A506}"=Webroot Spy Sweeper Enterprise Client
"{6DA9102E-199F-43A0-A36B-6EF48081A658}"=MobileMe Control Panel
"{6E179C77-7335-458D-9537-4F4EAC0181ED}"=Photo Click
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}"=Microsoft Plus! Digital Media Edition Installer
"{728278A1-0BB7-45E4-AC5E-91D7C0FD1EDE}"=EarthLink setup files
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}"=Dell System Restore
"{75E71ADD-042C-4F30-BFAC-A9EC42351313}"=Python 2.4.3
"{78C496B9-5A6B-4692-8C2E-AFFFC34E4961}"=Jasc Paint Shop Pro Studio, Dell Editon
"{7A0EFAFB-AC4B-4B88-8C6B-6731BE88DB68}"=Modem Event Monitor
"{7B478ACE-8512-4A46-ACB2-69D83DF2F6C7}"=Digital Voice Recorder
"{7D1DCBBA-F6F5-42B4-B90B-F04ACE4DFD6C}"=MSN Search Toolbar
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}"=DellSupport
"{7F142D56-3326-11D5-B229-002078017FBF}"=Modem Helper
"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}"=Bonjour
"{8A708DD8-A5E6-11D4-A706-000629E95E20}"=Intel® Extreme Graphics 2 Driver
"{8EF1122E-E90C-4EE9-AB0C-7FDE2BA42C26}"=Musicmatch Jukebox
"{90110409-6000-11D3-8CFE-0150048383C9}"=Microsoft Office Professional Edition 2003
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}"=Sonic RecordNow!
"{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}"=Windows Live installer
"{A8B94669-8654-4126-BD28-D0D2412CDED6}"=TI Connect 1.6
"{AC0EE5B0-A8FB-4D0A-AF03-2EDC518F841B}"=Dell Media Experience
"{AC76BA86-7AD7-1033-7B44-A81300000003}"=Adobe Reader 8.1.3
"{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}"=ABBYY FineReader 6.0 Sprint
"{AF06CAE4-C134-44B1-B699-14FBDB63BD37}"=Dell Picture Studio v3.0
"{AF19F291-F22F-4798-9662-525305AE9E48}"=WordPerfect Office 12
"{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}"=Windows Live Sign-in Assistant
"{B8A432E2-D541-4F48-B9E8-243BEEC3D158}"=Wal-Mart Music Downloads Store
"{C43421C0-0DCB-4F26-8A3B-BF16155F9879}"=TRENDnet TEW-424UB
"{C9618743-1A5C-461E-91C4-E013A3D70F3C}"=Adobe Photoshop Album Starter Edition 3.0.1
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}"=Microsoft .NET Framework 1.1
"{EC4455AB-F155-4CC1-A4C5-88F3777F9886}"=Apple Mobile Device Support
"{F901CA6D-A074-42D3-A11D-33AAE6FFD0C1}"=HP Deskjet 3740
"{F958CA02-BB40-4007-894B-258729456EE4}"=QuickTime
"{FE7D7E78-B9FD-4CAE-B223-10C6E5B307E7}"=Webroot Client
"7-Zip"=7-Zip 4.62
"AC3Filter"=AC3Filter (remove only)
"Ad-Aware SE Personal"=Ad-Aware SE Personal
"Adobe Flash Player ActiveX"=Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin"=Adobe Flash Player 10 Plugin
"alotToolbar"=ALOT Toolbar
"America Online us"=America Online (Choose which version to remove)
"AOL Connectivity Services"=AOL Connectivity Services
"AOLCoach"=AOL Coach Version 1.0(Build:20040229.1 en)
"a-squared Free_is1"=a-squared Free 4.0
"AviSynth"=AviSynth 2.5
"BE37E547-62DF-43C8-AE6A-D03E82BC67A2_is1"=DVD slideshow GUI 0.9.0.9
"Bubblet!"=Bubblet!
"Coupon Printer for Windows4.0"=Coupon Printer for Windows
"Dell Digital Jukebox Driver"=Dell Digital Jukebox Driver
"Dell Photo AIO Printer 924"=Dell Photo AIO Printer 924
"EsetOnlineScanner"=ESET Online Scanner
"HarryPotter_screensaver_pc"=HarryPotter_screensaver_pc Screen Saver
"IDNMitigationAPIs"=Microsoft Internationalized Domain Names Mitigation APIs
"ie7"=Windows Internet Explorer 7
"ie8"=Windows Internet Explorer 8 Beta 2
"InstallShield_{C43421C0-0DCB-4F26-8A3B-BF16155F9879}"=TRENDnet TEW-424UB
"Intel® 537EP V9x DF PCI Modem"=Intel® 537EP V9x DF PCI Modem
"Jasc Paint Shop Pro Studio.01 , Dell Edition 1.0.1.1 Patch"=Jasc Paint Shop Pro Studio.01 , Dell Edition 1.0.1.1 Patch
"LiveUpdate"=LiveUpdate 1.80 (Symantec Corporation)
"Mah Jong Medley"=Mah Jong Medley
"Malwarebytes' Anti-Malware_is1"=Malwarebytes' Anti-Malware
"Maple 10"=Maple 10
"Microsoft .NET Framework 1.1 (1033)"=Microsoft .NET Framework 1.1
"MoffFreeCalc_is1"=Moffsoft FreeCalc
"Mozilla Firefox (3.0.5)"=Mozilla Firefox (3.0.5)
"MSCompPackV1"=Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST"=MSN
"MyEmo"=MyEmoticons
"NLSDownlevelMapping"=Microsoft National Language Support Downlevel APIs
"Pirates of the Caribbean"=Pirates of the Caribbean Screen Saver
"PROSet"=Intel® PRO Network Adapters and Drivers
"RealPlayer 6.0"=RealPlayer
"Shockwave"=Shockwave
"StreetPlugin"=Learn2 Player (Uninstall Only)
"The Oregon Trail"=The Oregon Trail
"The Weather Channel Desktop 6"=The Weather Channel Desktop 6
"The Weather Channel Toolbar"=The Weather Channel Toolbar
"TheSky"=Software Bisque TheSky (Remove only)
"TightVNC_is1"=TightVNC 1.2.9
"Twighlightthemoviescreens 1.0_is1"=Twighlightthemoviescreens 1.0
"ViewpointMediaPlayer"=Viewpoint Media Player
"Winamp"=Winamp
"Windows Media Format Runtime"=Windows Media Format 11 runtime
"Windows Media Player"=Windows Media Player 11
"Windows XP Service Pack"=Windows XP Service Pack 3
"WMFDist11"=Windows Media Format 11 runtime
"wmp11"=Windows Media Player 11
"Wudf01000"=Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xena Season One"=Xena Season One Screen Saver
"Xvid_is1"=Xvid 1.1.3 final uninstall

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"ESPN Java Check"=ESPN Java Check
"Move Networks Player - IE"=Move Networks Media Player for Internet Explorer

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-2869354029-3859267071-476805174-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"ESPN Java Check"=ESPN Java Check
"Move Networks Player - IE"=Move Networks Media Player for Internet Explorer

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 1/25/2009 11:21:28 AM | Computer Name = PAMANDTRISH | Source = WebrootSpySweeperService | ID = 0
Description =

Error - 1/26/2009 10:06:45 AM | Computer Name = PAMANDTRISH | Source = WebrootSpySweeperService | ID = 0
Description =

Error - 1/26/2009 2:50:00 PM | Computer Name = PAMANDTRISH | Source = Norton AntiVirus | ID = 16711685
Description = Virus Found!Virus name: Trojan Horse in File: C:\Program Files\Common
Files\Ndm399a2rL.exe by: Realtime Protection scan. Action: Quarantine succeeded
: Access denied

Error - 1/26/2009 9:05:46 PM | Computer Name = PAMANDTRISH | Source = WebrootSpySweeperService | ID = 0
Description =

Error - 1/27/2009 12:26:46 AM | Computer Name = PAMANDTRISH | Source = Norton AntiVirus | ID = 16711685
Description = Virus Found!Virus name: Downloader.MisleadApp in File: C:\Qoobox\Quarantine\C\WINDOWS\SYSTEM32\msiconf.exe.vir
by: Realtime Protection scan. Action: Quarantine succeeded : Access denied

Error - 1/27/2009 8:17:41 AM | Computer Name = PAMANDTRISH | Source = WebrootSpySweeperService | ID = 0
Description =

Error - 1/27/2009 9:04:20 AM | Computer Name = PAMANDTRISH | Source = Norton AntiVirus | ID = 16711685
Description = Virus Found!Virus name: Trojan Horse in File: C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP8\A0000416.exe
by: Realtime Protection scan. Action: Quarantine succeeded : Access denied

Error - 1/27/2009 8:56:31 PM | Computer Name = PAMANDTRISH | Source = WebrootSpySweeperService | ID = 0
Description =

Error - 1/27/2009 9:55:03 PM | Computer Name = PAMANDTRISH | Source = WebrootSpySweeperService | ID = 0
Description =

Error - 1/27/2009 10:01:56 PM | Computer Name = PAMANDTRISH | Source = WebrootSpySweeperService | ID = 0
Description =

[ System Events ]
Error - 1/27/2009 9:50:15 PM | Computer Name = PAMANDTRISH | Source = DCOM | ID = 10010
Description = The server {0BDEAA4D-0722-406F-BD43-10935AC25E0E} did not register
with DCOM within the required timeout.

Error - 1/27/2009 9:52:16 PM | Computer Name = PAMANDTRISH | Source = DCOM | ID = 10010
Description = The server {0BDEAA4D-0722-406F-BD43-10935AC25E0E} did not register
with DCOM within the required timeout.

Error - 1/27/2009 9:55:04 PM | Computer Name = PAMANDTRISH | Source = Service Control Manager | ID = 7000
Description = The DM1Service service failed to start due to the following error:
%%2

Error - 1/27/2009 9:55:04 PM | Computer Name = PAMANDTRISH | Source = Service Control Manager | ID = 7000
Description = The Norton AntiVirus Auto-Protect Service service failed to start
due to the following error: %%3

Error - 1/27/2009 9:57:30 PM | Computer Name = PAMANDTRISH | Source = DCOM | ID = 10010
Description = The server {0BDEAA4D-0722-406F-BD43-10935AC25E0E} did not register
with DCOM within the required timeout.

Error - 1/27/2009 9:59:32 PM | Computer Name = PAMANDTRISH | Source = DCOM | ID = 10010
Description = The server {0BDEAA4D-0722-406F-BD43-10935AC25E0E} did not register
with DCOM within the required timeout.

Error - 1/27/2009 10:01:56 PM | Computer Name = PAMANDTRISH | Source = Service Control Manager | ID = 7000
Description = The DM1Service service failed to start due to the following error:
%%2

Error - 1/27/2009 10:01:56 PM | Computer Name = PAMANDTRISH | Source = Service Control Manager | ID = 7000
Description = The Norton AntiVirus Auto-Protect Service service failed to start
due to the following error: %%3

Error - 1/27/2009 10:06:21 PM | Computer Name = PAMANDTRISH | Source = DCOM | ID = 10010
Description = The server {0BDEAA4D-0722-406F-BD43-10935AC25E0E} did not register
with DCOM within the required timeout.

Error - 1/27/2009 10:08:21 PM | Computer Name = PAMANDTRISH | Source = DCOM | ID = 10010
Description = The server {0BDEAA4D-0722-406F-BD43-10935AC25E0E} did not register
with DCOM within the required timeout.


< End of report >

#13 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,304 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:05:47 PM

Posted 28 January 2009 - 06:12 AM

Hello, wartburgtrack33
Congratulations! You now appear clean! :thumbup2:

Are things running okay? Do you have any more questions?

System Still Slow?
You may wish to try StartupLite. Simply download this tool to your desktop and run it. It will explain any optional auto-start programs on your system, and offer the option to stop these programs from starting at startup. This will result in fewer programs running when you boot your system, and should improve preformance.
If that does not work, you can try the steps mentioned in Slow Computer/browser? Check Here First; It May Not Be Malware


We Need to Clean Up Our Mess
  • Please reopen Posted Image on your desktop.
  • Push the large "Cleanup" button
  • Allow your system to reboot
Reset System Restore
Windows' "System Restore" feature can cause malware files to be cached and retained by your system. Resetting System Restore will clean these files from your system, and will allow you to use System Restore without fear of reinfection.
  • Go to Start > Programs > Accessories > System Tools and click "System Restore".
  • Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the R.P. a name then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Then go to Start > Run and type: Cleanmgr
  • Click "OK".
  • Click the "More Options" Tab.
  • Click "Clean Up" in the System Restore section to remove all previous restore points except the newly created one.
Note: You should only do this once, not on a regular basis!
You will not be able to restore computer to any earlier than today!

Recommendations
Below are some recommendations to lower your chances of (re)infection.
  • Install Spyware Blaster and update it regularly
    If you wish, the commercial version provides automatic updating.
  • Install the MVPs hosts file, and update it regularly
    You can use the HostMan host file manager to do this automaticly if you wish.
    For more information on the hosts file, and what it can do for you, you can view the Tutorial on the Hosts file
  • Install an Anti-Spyware program, and update it regularly
    Malware Byte's Anti Malware is an excellent Anti-Spyware scanner. It's scan times are usually under ten minutes, and has excellent detection and removal rates.
    SUPERAntiSpyware is another good scanner with high detection and removal rates.
    Both programs are free for non commercial home use but provide a resident and do not nag if you purchase the paid versions.
  • Keep Windows (and your other Microsoft software) up to date!
    I cannot stress how important this is enough. Often holes are found in Internet Explorer or Windows itself that require patching. Sometimes these holes will allow an attacker unrestricted access to your computer.

    If you are using Windows XP or earlier
    Visit the Microsoft Update Website and follow the on screen instructions to setup Microsoft Update. Also follow the instructions to update your system. Please REBOOT and repeat this process until there are no more updates to install!!

    If you are using Windows Vista
    • Click the "Start Menu" (or Windows Orb)
    • Click "All Programs"
    • Click "Windows Update"
    • On the left, choose "Change Settings"
    • Ensure that the checkbox "Use Microsoft Update" at the bottom of the window is checked.
    • Press OK and accept the UAC prompt.
      Note: You shouldn't need to check this checkbox every single time you update, only the first time.
    • Click "Check for Updates" in the upper left corner.
    • Follow the instructions to install the latest updates.
    • Reboot and repeat the "Check for Updates" until there are no more critical updates to install
  • Keep your other software up to date as well
    Software does not need to be made by Microsoft to be insecure. You can use the Secunia Online Software occasionally to help you check for out of date software on your machine.
  • Stay up to date!
    The MOST IMPORTANT part of any security setup is keeping the software up to date. Malware writers release new variants every single day. If your software updates don't keep up, then the malware will always be one step ahead. Not a good thing :).
BillyIII
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image

#14 wartburgtrack33

wartburgtrack33
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:06:47 PM

Posted 28 January 2009 - 01:45 PM

Things seem to be working just fine now, except the internet went out in my dorm this morning. I had to find another computer just to respond. I will follow your suggestions as soon as I get the it back.

Thanks for your work! :thumbup2:

#15 Billy O'Neal

Billy O'Neal

    Visual C++ STL Maintainer


  • Malware Response Team
  • 12,304 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Redmond, Washington
  • Local time:05:47 PM

Posted 28 January 2009 - 03:05 PM

Hello, wartburgtrack33
You're very welcome :D

Since this issue appears resolved, this topic has been closed.

If you need this topic reopened, please send me or another moderator a PM.

Everyone else please begin a new topic.

BillyIII
Twitter - My statements do not establish the official position of Microsoft Corporation, and are my own personal opinion. (But you already knew that, right?)
Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users