Dear Stamper19:
Thank you so much for your attention to my problem.
I have followed your instructions. Here are the three logs you requested:
MalwareBytes Log
Malwarebytes' Anti-Malware 1.25
Database version: 1092
Windows 5.1.2600 Service Pack 2
11:23:10 AM 8/28/2008
mbam-log-08-28-2008 (11-23-10).txt
Scan type: Quick Scan
Objects scanned: 44567
Time elapsed: 6 minute(s), 45 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\solution.solution (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\solution.solution.1 (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{892b2785-b0d0-4aa2-ae6a-0ed60b00a979} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{00476c87-a276-49bf-86bc-ff005732430b} (Trojan.BHO) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowMyComputer (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
MalwareBytes did require a reboot to complete it's process. Following the reboot I executed OTViewIt:
OT View It Log:
OTViewIt logfile created on: 8/28/2008 11:41:59 AM - Run 1
OTViewIt by OldTimer - Version 1.0.0.14 Folder = C:\Documents and Settings\Owner\My Documents\My Received Files\Software Packages
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
990.42 Mb Total Physical Memory | 516.05 Mb Available Physical Memory | 52.10% Memory free
2.33 Gb Paging File | 1.87 Gb Available in Paging File | 80.27% Paging File free
Paging file location(s): C:\pagefile.sys 1488 2976;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 128.00 Gb Total Space | 109.81 Gb Free Space | 85.79% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: YOUR-K8L3QTHB26
Current User Name: Owner
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
===== Processes - Non-Microsoft Only =====
[12/16/2003 07:42 PM | 00,311,363 | ---- | M] (Intel Corporation ) - C:\WINDOWS\system32\S24EvMon.exe
[12/16/2003 07:47 PM | 00,376,832 | ---- | M] (Intel Corporation) - C:\WINDOWS\system32\ZCfgSvc.exe
[12/10/2003 05:36 AM | 00,086,016 | ---- | M] (Intel® Corporation) - C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
[11/20/2003 06:19 PM | 00,098,304 | ---- | M] (Synaptics, Inc.) - C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
[11/20/2003 06:18 PM | 00,499,712 | ---- | M] (Synaptics, Inc.) - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
[07/29/2008 02:57 PM | 01,398,024 | ---- | M] (Trend Micro Inc.) - C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
[05/08/2007 04:24 PM | 00,054,840 | ---- | M] (Hewlett-Packard) - C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
[02/07/2006 08:36 AM | 00,077,824 | ---- | M] (Intel Corporation) - C:\WINDOWS\system32\hkcmd.exe
[02/07/2006 08:40 AM | 00,118,784 | ---- | M] (Intel Corporation) - C:\WINDOWS\system32\igfxpers.exe
[06/10/2008 04:09 PM | 00,029,744 | ---- | M] (Google) - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
[05/20/2008 03:17 PM | 00,737,280 | ---- | M] (Apple Inc.) - C:\Program Files\AirPort\APAgent.exe
[05/27/2008 10:50 AM | 00,413,696 | ---- | M] (Apple Inc.) - C:\Program Files\QuickTime\QTTask.exe
[07/30/2008 10:47 AM | 00,289,064 | ---- | M] (Apple Inc.) - C:\Program Files\iTunes\iTunesHelper.exe
[06/10/2008 04:09 PM | 00,068,856 | ---- | M] (Google Inc.) - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[08/26/2008 01:07 PM | 01,576,176 | ---- | M] (SUPERAntiSpyware.com) - C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
[05/11/2005 11:23 PM | 00,282,624 | ---- | M] (Hewlett-Packard Co.) - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
[11/04/2004 07:36 PM | 00,425,984 | ---- | M] (Hewlett-Packard Co.) - C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
[06/10/2008 04:09 PM | 00,029,744 | ---- | M] (Google) - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
[07/22/2008 08:42 PM | 00,116,040 | ---- | M] (Apple Inc.) - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
[07/24/2007 03:17 PM | 00,229,376 | ---- | M] (Apple Inc.) - C:\Program Files\Bonjour\mDNSResponder.exe
[06/10/2008 04:08 PM | 00,137,200 | ---- | M] (Google) - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
[12/16/2003 07:41 PM | 00,122,880 | ---- | M] (Intel Corporation) - C:\WINDOWS\system32\RegSrvc.exe
[05/12/2005 12:40 AM | 00,204,800 | ---- | M] (Hewlett-Packard Co.) - C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
[07/29/2008 02:57 PM | 00,698,888 | ---- | M] (Trend Micro Inc.) - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
[12/24/2007 05:41 PM | 00,333,064 | ---- | M] (Trend Micro Inc.) - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
[07/30/2008 10:47 AM | 00,532,264 | ---- | M] (Apple Inc.) - C:\Program Files\iPod\bin\iPodService.exe
[08/09/2007 03:27 AM | 00,073,728 | ---- | M] (HP) - C:\WINDOWS\system32\HPZipm12.exe
[12/16/2003 07:43 PM | 00,184,320 | ---- | M] (Intel) - C:\WINDOWS\system32\1XConfig.exe
[02/26/2008 02:19 PM | 00,648,456 | ---- | M] (Trend Micro Inc.) - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
[08/27/2008 02:10 PM | 01,299,968 | ---- | M] (OldTimer Tools) - C:\Documents and Settings\Owner\My Documents\My Received Files\Software Packages\OTViewIt.exe
===== Win32 Services - Non-Microsoft Only =====
(Apple Mobile Device) Apple Mobile Device [Auto | Running]
[07/22/2008 08:42 PM | 00,116,040 | ---- | M] (Apple Inc.) - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
(Bonjour Service) Bonjour Service [Auto | Running]
[07/24/2007 03:17 PM | 00,229,376 | ---- | M] (Apple Inc.) - C:\Program Files\Bonjour\mDNSResponder.exe
(dmadmin) Logical Disk Manager Administrative Service [On_Demand | Stopped]
[08/04/2004 01:56 AM | 00,224,768 | ---- | M] (Microsoft Corp., Veritas Software) - C:\WINDOWS\system32\dmadmin.exe
(GoogleDesktopManager-022208-143751) Google Desktop Manager 5.7.802.22438 [On_Demand | Stopped]
[06/10/2008 04:09 PM | 00,029,744 | ---- | M] (Google) - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
(gusvc) Google Updater Service [Auto | Running]
[06/10/2008 04:08 PM | 00,137,200 | ---- | M] (Google) - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
(iPod Service) iPod Service [On_Demand | Running]
[07/30/2008 10:47 AM | 00,532,264 | ---- | M] (Apple Inc.) - C:\Program Files\iPod\bin\iPodService.exe
(Pml Driver HPZ12) Pml Driver HPZ12 [Auto | Running]
[08/09/2007 03:27 AM | 00,073,728 | ---- | M] (HP) - C:\WINDOWS\system32\HPZipm12.exe
(RegSrvc) RegSrvc [Auto | Running]
[12/16/2003 07:41 PM | 00,122,880 | ---- | M] (Intel Corporation) - C:\WINDOWS\system32\RegSrvc.exe
(S24EventMonitor) Spectrum24 Event Monitor [Auto | Running]
[12/16/2003 07:42 PM | 00,311,363 | ---- | M] (Intel Corporation ) - C:\WINDOWS\system32\S24EvMon.exe
(SfCtlCom) Trend Micro Central Control Component [Auto | Running]
[07/29/2008 02:57 PM | 00,698,888 | ---- | M] (Trend Micro Inc.) - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
(TMBMServer) Trend Micro Unauthorized Change Prevention Service [Auto | Running]
[12/24/2007 05:41 PM | 00,333,064 | ---- | M] (Trend Micro Inc.) - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
(tmproxy) Trend Micro Proxy Service [On_Demand | Running]
[02/26/2008 02:19 PM | 00,648,456 | ---- | M] (Trend Micro Inc.) - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
===== Driver Services - Non-Microsoft Only =====
(aeaudio) aeaudio [On_Demand | Running]
[04/01/2002 04:15 PM | 00,004,816 | ---- | M] (Andrea Electronics Corporation) - C:\WINDOWS\system32\drivers\aeaudio.sys
(ASCTRM) ASCTRM [Auto | Running]
[06/23/2004 02:11 PM | 00,008,552 | ---- | M] (Windows ® 2000 DDK provider) - C:\WINDOWS\System32\drivers\asctrm.sys
(dmboot) dmboot [Disabled | Stopped]
[08/04/2004 12:07 AM | 00,799,744 | ---- | M] (Microsoft Corp., Veritas Software) - C:\WINDOWS\system32\drivers\dmboot.sys
(dmio) dmio [Disabled | Stopped]
[08/04/2004 12:07 AM | 00,153,344 | ---- | M] (Microsoft Corp., Veritas Software) - C:\WINDOWS\system32\drivers\dmio.sys
(dmload) dmload [Disabled | Stopped]
[03/31/2003 08:00 AM | 00,005,888 | ---- | M] (Microsoft Corp., Veritas Software.) - C:\WINDOWS\system32\drivers\dmload.sys
(GEARAspiWDM) GEARAspiWDM [On_Demand | Running]
[01/29/2008 12:01 PM | 00,016,168 | ---- | M] (GEAR Software Inc.) - C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
(HPZid412) IEEE-1284.4 Driver HPZid412 [On_Demand | Running]
[12/14/2004 12:07 PM | 00,051,120 | R--- | M] (HP) - C:\WINDOWS\system32\drivers\HPZid412.sys
(HPZipr12) Print Class Driver for IEEE-1284.4 HPZipr12 [On_Demand | Running]
[12/14/2004 12:07 PM | 00,016,496 | R--- | M] (HP) - C:\WINDOWS\system32\drivers\HPZipr12.sys
(HPZius12) USB to IEEE-1284.4 Translation Driver HPZius12 [On_Demand | Running]
[03/08/2005 07:52 AM | 00,021,744 | ---- | M] (HP) - C:\WINDOWS\system32\drivers\HPZius12.sys
(HSFHWICH) HSFHWICH [On_Demand | Running]
[10/14/2003 10:08 PM | 00,197,120 | ---- | M] (Conexant Systems, Inc.) - C:\WINDOWS\system32\drivers\HSFHWICH.sys
(HSF_DP) HSF_DP [On_Demand | Running]
[10/14/2003 10:04 PM | 01,043,072 | ---- | M] (Conexant Systems, Inc.) - C:\WINDOWS\system32\drivers\HSF_DP.sys
(ialm) ialm [On_Demand | Running]
[02/07/2006 09:04 AM | 01,399,615 | ---- | M] (Intel Corporation) - C:\WINDOWS\system32\drivers\ialmnt5.sys
(MDC8021X) AEGIS Protocol (IEEE 802.1x) v2.2.1.0 [Auto | Running]
[06/23/2004 02:39 PM | 00,014,037 | ---- | M] (Meetinghouse Data Communications) - C:\WINDOWS\system32\drivers\mdc8021x.sys
(mdmxsdk) mdmxsdk [Auto | Running]
[04/09/2003 07:48 PM | 00,011,043 | ---- | M] (Conexant) - C:\WINDOWS\system32\drivers\mdmxsdk.sys
(MxlW2k) MxlW2k [On_Demand | Running]
[06/23/2004 03:25 PM | 00,028,352 | ---- | M] (MusicMatch, Inc.) - C:\WINDOWS\System32\drivers\MxlW2k.sys
(Ptilink) Direct Parallel Link Driver [On_Demand | Running]
[03/31/2003 08:00 AM | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) - C:\WINDOWS\system32\drivers\ptilink.sys
(rmedia) Ricoh MediaCard Driver [Boot | Running]
[10/20/2003 10:09 PM | 00,065,664 | ---- | M] (REDC) - C:\WINDOWS\system32\drivers\Rmedia.sys
(RTL8023) Realtek RTL8139/810x/8169/8110 all in one NDIS NT Driver [On_Demand | Running]
[08/13/2003 06:27 PM | 00,065,280 | ---- | M] (Realtek Semiconductor Corporation ) - C:\WINDOWS\system32\drivers\Rtlnic51.sys
(s24trans) WLAN Transport [Auto | Running]
[09/15/2003 01:20 PM | 00,011,258 | ---- | M] (Intel Corporation) - C:\WINDOWS\system32\drivers\s24trans.sys
(SABProcEnum) SABProcEnum [On_Demand | Stopped]
File not found - C:\PROGRA~1\MOZILL~1\SABProcEnum.sys
(SASDIFSV) SASDIFSV [System | Running]
[05/28/2008 10:33 AM | 00,008,944 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) - C:\Program Files\SUPERAntiSpyware\sasdifsv.sys
(SASENUM) SASENUM [On_Demand | Running]
[05/28/2008 10:33 AM | 00,007,408 | R--- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) - C:\Program Files\SUPERAntiSpyware\SASENUM.SYS
(SASKUTIL) SASKUTIL [System | Running]
[05/28/2008 10:33 AM | 00,055,024 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) - C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
(Secdrv) Secdrv [On_Demand | Stopped]
[11/13/2007 06:25 AM | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) - C:\WINDOWS\system32\drivers\secdrv.sys
(smwdm) smwdm [On_Demand | Running]
[01/13/2004 07:40 PM | 00,612,032 | ---- | M] (Analog Devices, Inc.) - C:\WINDOWS\system32\drivers\smwdm.sys
(SynTP) Synaptics TouchPad Driver [On_Demand | Running]
[11/20/2003 06:15 PM | 00,178,528 | ---- | M] (Synaptics, Inc.) - C:\WINDOWS\system32\drivers\SynTP.sys
(tmactmon) tmactmon [Auto | Running]
[12/24/2007 05:37 PM | 00,052,496 | ---- | M] (Trend Micro Inc.) - C:\WINDOWS\system32\drivers\tmactmon.sys
(tmcomm) tmcomm [Auto | Running]
[12/24/2007 05:37 PM | 00,138,384 | ---- | M] (Trend Micro Inc.) - C:\WINDOWS\system32\drivers\tmcomm.sys
(tmevtmgr) tmevtmgr [Auto | Running]
[12/24/2007 05:37 PM | 00,052,240 | ---- | M] (Trend Micro Inc.) - C:\WINDOWS\system32\drivers\tmevtmgr.sys
(tmpreflt) tmpreflt [Auto | Running]
[07/18/2008 07:08 PM | 00,036,368 | ---- | M] (Trend Micro Inc.) - C:\WINDOWS\system32\drivers\tmpreflt.sys
(tmtdi) Trend Micro TDI Driver [System | Running]
[02/15/2008 11:37 PM | 00,065,936 | ---- | M] (Trend Micro Inc.) - C:\WINDOWS\system32\drivers\tmtdi.sys
(tmxpflt) tmxpflt [Auto | Running]
[07/18/2008 07:08 PM | 00,205,328 | ---- | M] (Trend Micro Inc.) - C:\WINDOWS\system32\drivers\tmxpflt.sys
(USBAAPL) Apple Mobile USB Driver [On_Demand | Stopped]
[07/10/2008 09:35 AM | 00,032,000 | ---- | M] (Apple, Inc.) - C:\WINDOWS\system32\drivers\usbaapl.sys
(vsapint) vsapint [Auto | Running]
[07/18/2008 06:51 PM | 01,195,448 | ---- | M] (Trend Micro Inc.) - C:\WINDOWS\system32\drivers\vsapint.sys
(w22n51) Intel® PRO/Wireless 2200 Adapter Driver [On_Demand | Running]
[01/02/2004 05:52 AM | 01,646,720 | ---- | M] (Intel® Corporation) - C:\WINDOWS\system32\drivers\w22n51.sys
(wanatw) WAN Miniport (ATW) [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\DRIVERS\wanatw4.sys
(winachsf) winachsf [On_Demand | Running]
[10/14/2003 10:05 PM | 00,679,808 | ---- | M] (Conexant Systems, Inc.) - C:\WINDOWS\system32\drivers\HSF_CNXT.sys
===== Run Keys =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher" = "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [01/11/2008 10:16 PM | 00,039,792 | ---- | M] (Adobe Systems Incorporated)
"AirPort Base Station Agent" = "C:\Program Files\AirPort\APAgent.exe" [05/20/2008 03:17 PM | 00,737,280 | ---- | M] (Apple Inc.)
"AppleSyncNotifier" = C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [07/10/2008 09:47 AM | 00,116,040 | ---- | M] (Apple Inc.)
"Google Desktop Search" = "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup [06/10/2008 04:09 PM | 00,029,744 | ---- | M] (Google)
"HP Software Update" = C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [05/08/2007 04:24 PM | 00,054,840 | ---- | M] (Hewlett-Packard)
"igfxhkcmd" = C:\WINDOWS\system32\hkcmd.exe [02/07/2006 08:36 AM | 00,077,824 | ---- | M] (Intel Corporation)
"igfxpers" = C:\WINDOWS\system32\igfxpers.exe [02/07/2006 08:40 AM | 00,118,784 | ---- | M] (Intel Corporation)
"igfxtray" = C:\WINDOWS\system32\igfxtray.exe [02/07/2006 08:39 AM | 00,094,208 | ---- | M] (Intel Corporation)
"iTunesHelper" = "C:\Program Files\iTunes\iTunesHelper.exe" [07/30/2008 10:47 AM | 00,289,064 | ---- | M] (Apple Inc.)
"PRONoMgr.exe" = C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe [12/10/2003 05:36 AM | 00,086,016 | ---- | M] (Intel® Corporation)
"QuickTime Task" = "C:\Program Files\QuickTime\QTTask.exe" -atboottime [05/27/2008 10:50 AM | 00,413,696 | ---- | M] (Apple Inc.)
"SynTPEnh" = C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [11/20/2003 06:18 PM | 00,499,712 | ---- | M] (Synaptics, Inc.)
"SynTPLpr" = C:\Program Files\Synaptics\SynTP\SynTPLpr.exe [11/20/2003 06:19 PM | 00,098,304 | ---- | M] (Synaptics, Inc.)
"UfSeAgnt.exe" = "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe" [07/29/2008 02:57 PM | 01,398,024 | ---- | M] (Trend Micro Inc.)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" = Reg Error: Value load does not exist or could not be read.
"run" = Reg Error: Value run does not exist or could not be read.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware" = C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [08/26/2008 01:07 PM | 01,576,176 | ---- | M] (SUPERAntiSpyware.com)
"swg" = C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [06/10/2008 04:09 PM | 00,068,856 | ---- | M] (Google Inc.)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" =
"run" = Reg Error: Value run does not exist or could not be read.
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" =
"run" = Reg Error: Value run does not exist or could not be read.
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" =
"run" = Reg Error: Value run does not exist or could not be read.
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" =
"run" = Reg Error: Value run does not exist or could not be read.
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" =
"run" = Reg Error: Value run does not exist or could not be read.
[HKEY_USERS\S-1-5-21-3422090608-1729408543-1775048222-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware" = C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [08/26/2008 01:07 PM | 01,576,176 | ---- | M] (SUPERAntiSpyware.com)
"swg" = C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [06/10/2008 04:09 PM | 00,068,856 | ---- | M] (Google Inc.)
[HKEY_USERS\S-1-5-21-3422090608-1729408543-1775048222-1003\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" =
"run" = Reg Error: Value run does not exist or could not be read.
===== Startup Folders =====
[All Users Startup Folder - C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
[05/11/2005 11:23 PM | 00,282,624 | ---- | M] (Hewlett-Packard Co.) - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
[11/04/2004 07:50 PM | 00,053,248 | ---- | M] (Hewlett-Packard Co.) - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
[Default User Startup Folder - C:\Documents and Settings\Default User\Start Menu\Programs\Startup]
[Owner Startup Folder - C:\Documents and Settings\Owner\Start Menu\Programs\Startup]
===== BHO's =====
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
HKLM CLSID: (Adobe PDF Reader Link Helper) - [10/22/2006 11:08 PM | 00,062,080 | ---- | M] (Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
HKLM CLSID: (Google Toolbar Helper) - [06/10/2008 04:09 PM | 02,549,368 | R--- | M] (Google Inc.) c:\Program Files\Google\GoogleToolbar1.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
HKLM CLSID: (Google Toolbar Notifier BHO) - [07/29/2008 12:57 PM | 00,734,704 | ---- | M] (Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
===== Toolbars =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}"
HKLM CLSID: (&Google) - [06/10/2008 04:09 PM | 02,549,368 | R--- | M] (Google Inc.) c:\Program Files\Google\GoogleToolbar1.dll
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}"
HKLM CLSID: (Reg Error: Key does not exist or could not be opened.) - File not found Reg Error: Key does not exist or could not be opened.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
HKLM CLSID: (&Google) - [06/10/2008 04:09 PM | 02,549,368 | R--- | M] (Google Inc.) c:\Program Files\Google\GoogleToolbar1.dll
[HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
HKLM CLSID: (&Google) - [06/10/2008 04:09 PM | 02,549,368 | R--- | M] (Google Inc.) c:\Program Files\Google\GoogleToolbar1.dll
[HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
HKLM CLSID: (&Google) - [06/10/2008 04:09 PM | 02,549,368 | R--- | M] (Google Inc.) c:\Program Files\Google\GoogleToolbar1.dll
[HKEY_USERS\S-1-5-21-3422090608-1729408543-1775048222-1003\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}"
HKLM CLSID: (Reg Error: Key does not exist or could not be opened.) - File not found Reg Error: Key does not exist or could not be opened.
[HKEY_USERS\S-1-5-21-3422090608-1729408543-1775048222-1003\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
HKLM CLSID: (&Google) - [06/10/2008 04:09 PM | 02,549,368 | R--- | M] (Google Inc.) c:\Program Files\Google\GoogleToolbar1.dll
===== Policies =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
Unable to open key or key not present!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"dontdisplaylastusername" = 0
"legalnoticecaption" =
"legalnoticetext" =
"shutdownwithoutlogon" = 1
"undockwithoutlogon" = 1
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun" = 145
"NoSaveSettings" = 0
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
Unable to open key or key not present!
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun" = 145
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
Unable to open key or key not present!
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun" = 145
[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
Unable to open key or key not present!
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun" = 145
[HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
Unable to open key or key not present!
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun" = 145
[HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
Unable to open key or key not present!
[HKEY_USERS\S-1-5-21-3422090608-1729408543-1775048222-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun" = 145
"NoSaveSettings" = 0
[HKEY_USERS\S-1-5-21-3422090608-1729408543-1775048222-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
Unable to open key or key not present!
===== Desktop Components =====
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"FriendlyName" = "My Current Home Page"
"Source" = "About:Home"
"SubscribedURL" = "About:Home"
===== Shared Task Scheduler =====
===== AppInit_Dlls =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls]
"C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL" - [06/10/2008 04:09 PM | 00,112,128 | ---- | M] (Google) C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll
===== Lsa Authentication Packages =====
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\Authentication Packages]
"C:\WINDOWS\system32\yayyVllM" - File not found
===== Lsa Security Packages =====
===== Authorized Applications List =====
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = C:\WINDOWS\system32\sessmgr.exe [08/04/2004 01:56 AM | 00,140,800 | ---- | M] (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = C:\WINDOWS\system32\sessmgr.exe [08/04/2004 01:56 AM | 00,140,800 | ---- | M] (Microsoft Corporation)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe [07/24/2007 03:17 PM | 00,229,376 | ---- | M] (Apple Inc.)
"C:\Program Files\AirPort\APAgent.exe" = C:\Program Files\AirPort\APAgent.exe [05/20/2008 03:17 PM | 00,737,280 | ---- | M] (Apple Inc.)
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe [07/30/2008 10:47 AM | 20,252,968 | ---- | M] (Apple Inc.)
===== HKLM Winlogon Settings =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell]
"Explorer.exe" - [06/13/2007 06:23 AM | 01,033,216 | ---- | M] (Microsoft Corporation) C:\WINDOWS\explorer.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit]
"C:\WINDOWS\system32\userinit.exe" - [08/04/2004 01:56 AM | 00,024,576 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\userinit.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UIHost]
"logonui.exe" - [08/04/2004 01:56 AM | 00,514,560 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\logonui.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet]
"rundll32 shell32" - [10/25/2007 11:36 PM | 08,454,656 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
"Control_RunDLL "sysdm.cpl"" - [08/04/2004 01:56 AM | 00,298,496 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\sysdm.cpl
===== User's Winlogon Settings =====
===== Winlogon Notify Settings =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
"DllName" = C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL [08/26/2008 01:07 PM | 00,352,256 | ---- | M] (SUPERAntiSpyware.com)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
"DllName" = C:\WINDOWS\system32\igfxdev.dll [02/07/2006 08:35 AM | 00,139,264 | ---- | M] (Intel Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Sebring]
"DllName" = C:\WINDOWS\system32\LgNotify.dll [12/16/2003 07:49 PM | 00,110,592 | ---- | M] (Intel Corporation)
===== Safeboot Options =====
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot]
"AlternateShell" = cmd.exe
===== Disabled MsConfig Items =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\NeroFilterCheck]
"command" = C:\WINDOWS\system32\NeroCheck.exe [07/09/2001 06:50 AM | 00,155,648 | ---- | M] (Ahead Software Gmbh)
"item" = NeroFilterCheck
"inimapping" = 0
"hkey" = HKLM
"key" = Software\Microsoft\Windows\CurrentVersion\Run
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\RemoteControl]
"command" = C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [10/31/2003 10:42 PM | 00,032,768 | ---- | M] (Cyberlink Corp.)
"item" = RemoteControl
"inimapping" = 0
"hkey" = HKLM
"key" = Software\Microsoft\Windows\CurrentVersion\Run
===== DNS Name Servers =====
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{5E31996B-0F89-4058-811C-4AA14CD39DF4}]
Servers: | Description: Intel® PRO/Wireless 2200BG Network Connection
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{63D1FC3A-9990-492E-A116-CF4B3E4EB733}]
Servers: | Description: 1394 Net Adapter
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{8BD11811-DED8-427E-A88B-972686A6C494}]
Servers: | Description: Realtek RTL8139/810x Family Fast Ethernet NIC
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{C5A47A86-4660-4342-A7DF-BED79A54BB46}]
Servers: | Description: 1394 Net Adapter
===== CDRom AutoRun Settings =====
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1
===== Autorun Files on Drives =====
AUTOEXEC.BAT []
[06/23/2004 01:39 PM | 00,000,000 | ---- | M] () C:\AUTOEXEC.BAT [ NTFS ]
===== MountPoints2 =====
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{46a389b0-3e01-11dd-8d65-00032520bb6e}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{46a389b0-3e01-11dd-8d65-00032520bb6e}\Shell\Autoplay]
"MUIVerb" = C:\WINDOWS\system32\shell32.dll [10/25/2007 11:36 PM | 08,454,656 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{46a389b0-3e01-11dd-8d65-00032520bb6e}\Shell\Autoplay\DropTarget]
"CLSID" = {f26a669a-bcbb-4e37-abf9-7325da15f931}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{76926d01-f699-11dc-8cef-00032520b44f}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{76926d01-f699-11dc-8cef-00032520b44f}\Shell\Autoplay]
"MUIVerb" = C:\WINDOWS\system32\shell32.dll [10/25/2007 11:36 PM | 08,454,656 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{76926d01-f699-11dc-8cef-00032520b44f}\Shell\Autoplay\DropTarget]
"CLSID" = {f26a669a-bcbb-4e37-abf9-7325da15f931}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a677f650-c9c1-11d8-88b8-00038a000015}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a677f650-c9c1-11d8-88b8-00038a000015}\Shell\Autoplay]
"MUIVerb" = C:\WINDOWS\system32\shell32.dll [10/25/2007 11:36 PM | 08,454,656 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a677f650-c9c1-11d8-88b8-00038a000015}\Shell\Autoplay\DropTarget]
"CLSID" = {f26a669a-bcbb-4e37-abf9-7325da15f931}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d8c50775-c53c-11d8-88b0-000325098867}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d8c50775-c53c-11d8-88b0-000325098867}\Shell\Autoplay]
"MUIVerb" = C:\WINDOWS\system32\shell32.dll [10/25/2007 11:36 PM | 08,454,656 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d8c50775-c53c-11d8-88b0-000325098867}\Shell\Autoplay\DropTarget]
"CLSID" = {f26a669a-bcbb-4e37-abf9-7325da15f931}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f7c28841-c9eb-11d8-9cc1-806d6172696f}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f7c28841-c9eb-11d8-9cc1-806d6172696f}\Shell\Autoplay]
"MUIVerb" = C:\WINDOWS\system32\shell32.dll [10/25/2007 11:36 PM | 08,454,656 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f7c28841-c9eb-11d8-9cc1-806d6172696f}\Shell\Autoplay\DropTarget]
"CLSID" = {f26a669a-bcbb-4e37-abf9-7325da15f931}
===== Hosts File =====
HOSTS File = (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
First 25 entries...
127.0.0.1 localhost
[Files/Folders - Created Within 30 days]
[08/16/2008 01:38 PM | ---D | C] - C:\Archive
[08/16/2008 02:04 PM | 10,386,02240 | -HS- | C] () - C:\hiberfil.sys
[08/28/2008 11:14 AM | 00,017,144 | ---- | C] (Malwarebytes Corporation) - C:\WINDOWS\System32\drivers\mbam.sys
[08/28/2008 11:14 AM | 00,038,472 | ---- | C] (Malwarebytes Corporation) - C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[1 C:\WINDOWS\System32\*.tmp files]
[08/15/2008 05:07 PM | 00,806,970 | -HS- | C] () - C:\WINDOWS\System32\MopqYcdd.ini2
[08/15/2008 05:07 PM | 00,807,148 | -HS- | C] () - C:\WINDOWS\System32\MopqYcdd.ini
[08/16/2008 09:34 AM | 00,000,345 | -HS- | C] () - C:\WINDOWS\System32\MllVyyay.ini2
[08/16/2008 09:34 AM | 00,777,227 | -HS- | C] () - C:\WINDOWS\System32\MllVyyay.ini
[08/16/2008 10:33 PM | 00,002,206 | ---- | C] () - C:\WINDOWS\System32\wpa.dbl
[08/16/2008 12:41 PM | ---D | C] - C:\WINDOWS\System32\SuperAdBlocker.com
[08/27/2008 02:10 PM | ---D | C] - C:\WINDOWS\System32\CatRoot_bak
[1 C:\WINDOWS\*.tmp files]
[08/16/2008 01:23 PM | ---D | C] - C:\WINDOWS\ERDNT
[08/08/2008 11:36 AM | 00,000,284 | ---- | C] () - C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[08/15/2008 02:19 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At1.job
[08/15/2008 02:19 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At10.job
[08/15/2008 02:19 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At11.job
[08/15/2008 02:19 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At12.job
[08/15/2008 02:19 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At13.job
[08/15/2008 02:19 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At14.job
[08/15/2008 02:19 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At15.job
[08/15/2008 02:19 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At16.job
[08/15/2008 02:19 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At17.job
[08/15/2008 02:19 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At18.job
[08/15/2008 02:19 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At19.job
[08/15/2008 02:19 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At2.job
[08/15/2008 02:19 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At20.job
[08/15/2008 02:19 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At21.job
[08/15/2008 02:19 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At22.job
[08/15/2008 02:19 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At23.job
[08/15/2008 02:19 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At24.job
[08/15/2008 02:19 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At3.job
[08/15/2008 02:19 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At4.job
[08/15/2008 02:19 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At5.job
[08/15/2008 02:19 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At6.job
[08/15/2008 02:19 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At7.job
[08/15/2008 02:19 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At8.job
[08/15/2008 02:19 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At9.job
[08/15/2008 02:46 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At25.job
[08/15/2008 02:46 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At26.job
[08/15/2008 02:46 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At27.job
[08/15/2008 02:46 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At28.job
[08/15/2008 02:46 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At29.job
[08/15/2008 02:46 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At30.job
[08/15/2008 02:46 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At31.job
[08/15/2008 02:46 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At32.job
[08/15/2008 02:46 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At33.job
[08/15/2008 02:46 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At34.job
[08/15/2008 02:46 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At35.job
[08/15/2008 02:46 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At36.job
[08/15/2008 02:46 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At37.job
[08/15/2008 02:46 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At38.job
[08/15/2008 02:46 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At39.job
[08/15/2008 02:46 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At40.job
[08/15/2008 02:46 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At41.job
[08/15/2008 02:46 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At42.job
[08/15/2008 02:46 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At43.job
[08/15/2008 02:46 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At44.job
[08/15/2008 02:46 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At45.job
[08/15/2008 02:46 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At46.job
[08/15/2008 02:46 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At47.job
[08/15/2008 02:46 PM | 00,000,350 | ---- | C] () - C:\WINDOWS\tasks\At48.job
[08/19/2008 02:52 PM | 00,000,330 | -H-- | C] () - C:\WINDOWS\tasks\MP Scheduled Scan.job
[08/15/2008 11:44 PM | ---D | C] - C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[08/28/2008 11:14 AM | ---D | C] - C:\Documents and Settings\All Users\Application Data\Malwarebytes
[08/15/2008 11:44 PM | ---D | C] - C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
[08/28/2008 11:15 AM | ---D | C] - C:\Documents and Settings\Owner\Application Data\Malwarebytes
[08/02/2008 07:12 PM | 00,060,928 | ---- | C] () - C:\Documents and Settings\Owner\My Documents\Joseph Johns Funeral Bulletin.doc
[08/02/2008 08:56 PM | 00,025,600 | ---- | C] () - C:\Documents and Settings\Owner\My Documents\Joe McCune Letters to Mark About Jesus Bible Verses.doc
[08/04/2008 10:01 AM | ---D | C] - C:\Documents and Settings\Owner\My Documents\Mt Calvary Crisis Documents
[08/08/2008 11:55 AM | 00,047,491 | ---- | C] () - C:\Documents and Settings\Owner\My Documents\PayPal Payment Details - Brown Death Messiah.pdf
[08/09/2008 08:11 PM | 00,026,112 | ---- | C] () - C:\Documents and Settings\Owner\My Documents\Well.doc
[08/20/2008 08:56 AM | ---D | C] - C:\Documents and Settings\Owner\My Documents\Missional Leadership
[08/28/2008 11:14 AM | 00,000,696 | ---- | C] () - C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[08/22/2008 04:55 PM | 00,001,740 | ---- | C] () - C:\Documents and Settings\Owner\Favorites\Desktop\HijackThis.lnk
[08/15/2008 11:42 PM | ---D | C] - C:\Program Files\Common Files\Wise Installation Wizard
[08/02/2008 08:46 PM | ---D | C] - C:\Program Files\iPod
[08/08/2008 11:35 AM | ---D | C] - C:\Program Files\Apple Software Update
[08/10/2008 09:06 PM | ---D | C] - C:\Program Files\Microsoft Silverlight
[08/15/2008 11:44 PM | ---D | C] - C:\Program Files\SUPERAntiSpyware
[08/19/2008 02:49 PM | ---D | C] - C:\Program Files\Windows Defender
[08/28/2008 11:14 AM | ---D | C] - C:\Program Files\Malwarebytes' Anti-Malware
[Files/Folders - Modified Within 30 days]
[08/16/2008 01:38 PM | ---D | M] - C:\Archive
[08/19/2008 02:49 PM | -H-D | M] - C:\Config.Msi
[08/28/2008 11:14 AM | R--D | M] - C:\Program Files
[08/28/2008 11:25 AM | 10,386,02240 | -HS- | M] () - C:\hiberfil.sys
[08/28/2008 11:25 AM | ---D | M] - C:\WINDOWS
[08/17/2008 03:01 PM | 00,017,144 | ---- | M] (Malwarebytes Corporation) - C:\WINDOWS\System32\drivers\mbam.sys
[08/17/2008 03:01 PM | 00,038,472 | ---- | M] (Malwarebytes Corporation) - C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[08/26/2008 12:01 PM | ---D | M] - C:\WINDOWS\System32\drivers\etc
[1 C:\WINDOWS\System32\*.tmp files]
[08/15/2008 11:43 PM | 00,806,970 | -HS- | M] () - C:\WINDOWS\System32\MopqYcdd.ini2
[08/15/2008 11:43 PM | 00,807,148 | -HS- | M] () - C:\WINDOWS\System32\MopqYcdd.ini
[08/16/2008 02:03 PM | ---D | M] - C:\WINDOWS\System32\wbem
[08/16/2008 02:04 PM | ---D | M] - C:\WINDOWS\System32\config
[08/16/2008 09:34 AM | 00,000,345 | -HS- | M] () - C:\WINDOWS\System32\MllVyyay.ini2
[08/16/2008 09:35 AM | 00,777,227 | -HS- | M] () - C:\WINDOWS\System32\MllVyyay.ini
[08/20/2008 09:50 PM | ---D | M] - C:\WINDOWS\System32\SuperAdBlocker.com
[08/27/2008 02:23 PM | ---D | M] - C:\WINDOWS\System32\CatRoot
[08/27/2008 02:23 PM | ---D | M] - C:\WINDOWS\System32\CatRoot_bak
[08/27/2008 04:06 PM | 00,002,206 | ---- | M] () - C:\WINDOWS\System32\wpa.dbl
[08/28/2008 11:08 AM | RHSD | M] - C:\WINDOWS\System32\dllcache
[08/28/2008 11:14 AM | ---D | M] - C:\WINDOWS\System32\drivers
[08/28/2008 11:28 AM | ---D | M] - C:\WINDOWS\System32\CatRoot2
[1 C:\WINDOWS\*.tmp files]
[08/15/2008 06:12 PM | 00,000,797 | ---- | M] () - C:\WINDOWS\win.ini
[08/15/2008 06:19 PM | ---D | M] - C:\WINDOWS\ie7updates
[08/15/2008 06:26 PM | 00,001,374 | ---- | M] () - C:\WINDOWS\imsins.BAK
[08/15/2008 06:26 PM | -H-D | M] - C:\WINDOWS\$hf_mig$
[08/16/2008 01:23 PM | ---D | M] - C:\WINDOWS\ERDNT
[08/16/2008 02:03 PM | ---D | M] - C:\WINDOWS\Registration
[08/18/2008 12:14 PM | --SD | M] - C:\WINDOWS\Downloaded Program Files
[08/19/2008 02:49 PM | -HSD | M] - C:\WINDOWS\Installer
[08/20/2008 09:50 PM | 00,002,229 | ---- | M] () - C:\WINDOWS\mozver.dat
[08/27/2008 02:10 PM | ---D | M] - C:\WINDOWS\Debug
[08/27/2008 02:10 PM | ---D | M] - C:\WINDOWS\Prefetch
[08/27/2008 04:02 PM | ---D | M] - C:\WINDOWS\Help
[08/27/2008 04:03 PM | ---D | M] - C:\WINDOWS\SoftwareDistribution
[08/28/2008 11:08 AM | -H-D | M] - C:\WINDOWS\inf
[08/28/2008 11:25 AM | 00,002,048 | --S- | M] () - C:\WINDOWS\bootstat.dat
[08/28/2008 11:28 AM | --SD | M] - C:\WINDOWS\Tasks
[08/28/2008 11:40 AM | ---D | M] - C:\WINDOWS\system32
[08/28/2008 11:40 AM | ---D | M] - C:\WINDOWS\Temp
[08/15/2008 02:19 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At1.job
[08/15/2008 02:19 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At2.job
[08/15/2008 02:19 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At3.job
[08/15/2008 02:19 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At4.job
[08/15/2008 02:19 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At5.job
[08/15/2008 02:19 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At6.job
[08/15/2008 02:19 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At7.job
[08/15/2008 02:19 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At8.job
[08/15/2008 02:19 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At9.job
[08/15/2008 02:46 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At25.job
[08/15/2008 02:46 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At26.job
[08/15/2008 02:46 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At27.job
[08/15/2008 02:46 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At28.job
[08/15/2008 02:46 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At29.job
[08/15/2008 02:46 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At30.job
[08/15/2008 02:46 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At31.job
[08/15/2008 02:46 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At32.job
[08/15/2008 02:46 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At33.job
[08/20/2008 08:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At21.job
[08/20/2008 08:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At45.job
[08/22/2008 05:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At18.job
[08/22/2008 05:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At42.job
[08/22/2008 10:00 AM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At11.job
[08/22/2008 10:00 AM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At35.job
[08/22/2008 11:00 AM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At12.job
[08/22/2008 11:00 AM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At36.job
[08/23/2008 05:23 PM | 00,000,284 | ---- | M] () - C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[08/23/2008 06:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At19.job
[08/23/2008 06:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At43.job
[08/23/2008 07:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At20.job
[08/23/2008 07:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At44.job
[08/23/2008 09:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At22.job
[08/23/2008 09:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At46.job
[08/23/2008 10:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At23.job
[08/23/2008 10:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At47.job
[08/24/2008 09:00 AM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At10.job
[08/24/2008 09:00 AM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At34.job
[08/24/2008 11:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At24.job
[08/24/2008 11:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At48.job
[08/26/2008 01:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At14.job
[08/26/2008 01:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At38.job
[08/26/2008 02:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At15.job
[08/26/2008 02:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At39.job
[08/26/2008 03:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At16.job
[08/26/2008 03:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At40.job
[08/27/2008 04:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At17.job
[08/27/2008 04:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At41.job
[08/27/2008 12:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At13.job
[08/27/2008 12:00 PM | 00,000,350 | ---- | M] () - C:\WINDOWS\tasks\At37.job
[08/28/2008 11:25 AM | 00,000,006 | -H-- | M] () - C:\WINDOWS\tasks\SA.DAT
[08/28/2008 11:28 AM | 00,000,330 | -H-- | M] () - C:\WINDOWS\tasks\MP Scheduled Scan.job
[08/15/2008 11:44 PM | ---D | M] - C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[08/19/2008 02:49 PM | --SD | M] - C:\Documents and Settings\All Users\Application Data\Microsoft
[08/26/2008 11:22 AM | ---D | M] - C:\Documents and Settings\All Users\Application Data\Google Updater
[08/28/2008 11:14 AM | ---D | M] - C:\Documents and Settings\All Users\Application Data\Malwarebytes
[08/15/2008 11:44 PM | ---D | M] - C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
[08/16/2008 09:06 AM | ---D | M] - C:\Documents and Settings\Owner\Application Data\Apple Computer
[08/28/2008 11:15 AM | ---D | M] - C:\Documents and Settings\Owner\Application Data\Malwarebytes
[08/19/2008 02:49 PM | ---D | M] - C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft
[08/22/2008 01:08 PM | ---D | M] - C:\Documents and Settings\Owner\Local Settings\Application Data\CutePDF Writer
[08/28/2008 11:24 AM | 09,097,254 | -H-- | M] () - C:\Documents and Settings\Owner\Local Settings\Application Data\IconCache.db
[08/28/2008 11:25 AM | ---D | M] - C:\Documents and Settings\Owner\Local Settings\Application Data\ApplicationHistory
[08/02/2008 07:12 PM | 00,060,928 | ---- | M] () - C:\Documents and Settings\Owner\My Documents\Joseph Johns Funeral Bulletin.doc
[08/02/2008 08:56 PM | 00,025,600 | ---- | M] () - C:\Documents and Settings\Owner\My Documents\Joe McCune Letters to Mark About Jesus Bible Verses.doc
[08/08/2008 11:55 AM | 00,047,491 | ---- | M] () - C:\Documents and Settings\Owner\My Documents\PayPal Payment Details - Brown Death Messiah.pdf
[08/10/2008 12:04 AM | 00,026,112 | ---- | M] () - C:\Documents and Settings\Owner\My Documents\Well.doc
[08/19/2008 03:13 PM | ---D | M] - C:\Documents and Settings\Owner\My Documents\Sermons
[08/19/2008 11:11 PM | ---D | M] - C:\Documents and Settings\Owner\My Documents\My Received Files
[08/22/2008 05:21 PM | ---D | M] - C:\Documents and Settings\Owner\My Documents\Missional Leadership
[08/22/2008 10:56 PM | ---D | M] - C:\Documents and Settings\Owner\My Documents\Mt Calvary Crisis Documents
[08/22/2008 12:50 PM | ---D | M] - C:\Documents and Settings\Owner\My Documents\Parish Reports
[08/24/2008 09:07 AM | ---D | M] - C:\Documents and Settings\Owner\My Documents\Youth
[08/25/2008 12:23 AM | ---D | M] - C:\Documents and Settings\Owner\My Documents\Newsletter Articles
[08/28/2008 11:14 AM | 00,000,696 | ---- | M] () - C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[08/22/2008 04:55 PM | 00,001,740 | ---- | M] () - C:\Documents and Settings\Owner\Favorites\Desktop\HijackThis.lnk
[08/15/2008 11:42 PM | ---D | M] - C:\Program Files\Common Files\Wise Installation Wizard
< End of report >
OT View It Extras Log
OTViewIt Extras logfile created on: 8/28/2008 11:41:59 AM - Run 1
OTViewIt by OldTimer - Version 1.0.0.14 Folder = C:\Documents and Settings\Owner\My Documents\My Received Files\Software Packages
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
990.42 Mb Total Physical Memory | 516.05 Mb Available Physical Memory | 52.10% Memory free
2.33 Gb Paging File | 1.87 Gb Available in Paging File | 80.27% Paging File free
Paging file location(s): C:\pagefile.sys 1488 2976;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 128.00 Gb Total Space | 109.81 Gb Free Space | 85.79% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
===== File Associations =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.bat [@ = batfile] - File not found -
.cmd [@ = cmdfile] - File not found -
.com [@ = comfile] - File not found -
.exe [@ = exefile] - File not found -
.html [@ = FirefoxHTML] - [07/16/2008 05:54 PM | 07,667,312 | ---- | M] (Mozilla Corporation) - C:\Program Files\Mozilla Firefox\firefox.exe
.pif [@ = piffile] - File not found -
.scr [@ = scrfile] - File not found -
===== Uninstall List =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{08CA9554-B5FE-4313-938F-D4A417B81175}" = QuickTime
"{09984AEC-6B9F-4ca7-B78D-CB44D4771DA3}" = Destinations
"{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}" = MSXML 6.0 Parser (KB933579)
"{0DC86BEC-5CE3-413A-BB61-C40A3D186B24}" = Scan
"{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}" = Security Update for CAPICOM (KB931906)
"{0FF18B53-CA57-40BB-B562-21A27B662005}" = 1600
"{14BEB6DF-A499-4A38-8E06-E173BCD5C087}" = ScannerCopy
"{181821B7-82AA-44DA-9DAF-EF254CCB670A}" = Fax
"{19991EAD-C273-47EB-87E8-0D274925230B}" = OEB Resource Driver
"{1AD5F465-8282-4DAD-B957-E09C0B783D18}" = InstantShare
"{1B680FBA-E317-4E93-AF43-3B59798A4BE0}" = Copy
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{272EC8BA-5A08-4ea1-A189-684466A06B02}" = cp_dwShrek2Albums1
"{2BA00471-0328-3743-93BD-FA813353A783}" = Microsoft .NET Framework 3.0 Service Pack 1
"{2CADCEAB-D5DA-44D6-B5FC-7DEE87AB3C0C}" = Unload
"{30C19FF2-7FBA-4d09-B9DE-1659977F64F6}" = TrayApp
"{342C7C88-D335-4bc2-8CF1-281857629CE2}" = HP PSC & OfficeJet 4.7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3762DB2D-71BD-421F-9E55-C74DA7DF4D07}" = CueTour
"{391E18CE-7D3B-45E9-A8F0-34E77F14F47A}" = ProductContext
"{3C0BAFCA-BDB8-492B-8845-DC0A4B4C1823}" = HPDeskjet5400Series
"{3DE0053C-FD9A-483E-B7C9-B06E4392206E}" = iTunes
"{442BE28B-782B-4DC0-B490-E70A403B1C69}" = Readme
"{45EBDA59-D33B-433A-956E-B2F236468B56}" = MUSICMATCH® Jukebox
"{47BF1BD6-DCAC-