OTViewIt logfile created on: 8/28/2008 3:56:13 PM - Run 2
OTViewIt by OldTimer - Version 1.0.0.14 Folder = C:\Documents and Settings\debbie\Desktop\Reese Aug 23 2008
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
638.48 Mb Total Physical Memory | 242.30 Mb Available Physical Memory | 37.95% Memory free
937.63 Mb Paging File | 586.14 Mb Available in Paging File | 62.51% Paging File free
Paging file location(s): C:\pagefile.sys 336 672;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.25 Gb Total Space | 23.42 Gb Free Space | 62.86% Space Free | Partition Type: NTFS
Drive D: | 218.50 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DEBBIE1
Current User Name: debbie
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
===== Processes - Non-Microsoft Only =====
[04/11/2005 09:31 AM | 00,360,448 | ---- | M] (ATI Technologies Inc.) - C:\WINDOWS\system32\ati2evxx.exe
[12/17/2003 10:35 PM | 00,032,768 | ---- | M] (Symantec Corporation) - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
[02/22/2005 07:32 PM | 00,038,912 | ---- | M] () - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
[12/17/2003 10:56 PM | 00,651,264 | ---- | M] (Symantec Corporation) - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
[03/13/2008 11:11 PM | 00,075,304 | ---- | M] (Zone Labs, LLC) - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
[04/11/2005 09:31 AM | 00,360,448 | ---- | M] (ATI Technologies Inc.) - C:\WINDOWS\system32\ati2evxx.exe
[04/11/2005 01:00 PM | 00,339,968 | ---- | M] (ATI Technologies, Inc.) - C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[06/10/2008 04:27 AM | 00,144,784 | ---- | M] (Sun Microsystems, Inc.) - C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
[04/01/2005 06:11 PM | 00,794,624 | ---- | M] (Hewlett-Packard Company) - C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe
[02/02/2005 08:12 AM | 00,102,492 | ---- | M] (Synaptics, Inc.) - C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
[02/02/2005 08:11 AM | 00,692,316 | ---- | M] (Synaptics, Inc.) - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
[02/17/2005 02:11 AM | 00,049,152 | ---- | M] (Hewlett-Packard Co.) - C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
[12/03/2004 04:24 PM | 00,290,816 | ---- | M] (Hewlett-Packard ) - C:\Program Files\HPQ\Quick Launch Buttons\eabservr.exe
[12/17/2003 11:00 PM | 00,090,112 | ---- | M] (Symantec Corporation) - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\VPTray.exe
[03/13/2008 11:11 PM | 00,919,016 | ---- | M] (Zone Labs, LLC) - C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
[06/02/2007 09:43 PM | 00,068,856 | ---- | M] (Google Inc.) - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[10/28/2004 10:29 AM | 00,581,632 | ---- | M] (Logitech Inc.) - C:\Program Files\Logitech\SetPoint\KEM.exe
[10/21/2004 02:28 PM | 00,029,696 | ---- | M] (Logitech Inc.) - C:\Program Files\Logitech\SetPoint\KHALMNPR.exe
[03/04/2005 03:16 PM | 00,098,304 | R--- | M] (Hewlett-Packard Development Company, L.P.) - C:\Program Files\HPQ\Shared\hpqwmi.exe
[11/30/2006 10:49 PM | 04,662,776 | ---- | M] (Yahoo! Inc.) - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
[08/28/2008 03:52 PM | 01,299,968 | ---- | M] (OldTimer Tools) - C:\Documents and Settings\debbie\Desktop\Reese Aug 23 2008\OTViewIt.exe
===== Win32 Services - Non-Microsoft Only =====
(Ati HotKey Poller) Ati HotKey Poller [Auto | Running]
[04/11/2005 09:31 AM | 00,360,448 | ---- | M] (ATI Technologies Inc.) - C:\WINDOWS\system32\ati2evxx.exe
(DefWatch) DefWatch [Auto | Running]
[12/17/2003 10:35 PM | 00,032,768 | ---- | M] (Symantec Corporation) - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
(dmadmin) Logical Disk Manager Administrative Service [On_Demand | Stopped]
[08/04/2004 04:00 AM | 00,224,768 | ---- | M] (Microsoft Corp., Veritas Software) - C:\WINDOWS\system32\dmadmin.exe
(gusvc) Google Updater Service [On_Demand | Stopped]
[01/27/2007 10:00 AM | 00,138,168 | ---- | M] (Google) - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
(hpqwmi) HP WMI Interface [On_Demand | Running]
[03/04/2005 03:16 PM | 00,098,304 | R--- | M] (Hewlett-Packard Development Company, L.P.) - C:\Program Files\HPQ\Shared\hpqwmi.exe
(iPodService) iPod Service [On_Demand | Stopped]
[10/13/2004 07:03 PM | 00,327,680 | ---- | M] (Apple Computer, Inc.) - C:\Program Files\iPod\bin\iPodService.exe
(LightScribeService) LightScribeService Direct Disc Labeling Service [Auto | Running]
[02/22/2005 07:32 PM | 00,038,912 | ---- | M] () - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
(Norton AntiVirus Server) Symantec AntiVirus Client [Auto | Running]
[12/17/2003 10:56 PM | 00,651,264 | ---- | M] (Symantec Corporation) - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
(vsmon) TrueVector Internet Monitor [Auto | Running]
[03/13/2008 11:11 PM | 00,075,304 | ---- | M] (Zone Labs, LLC) - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
===== Driver Services - Non-Microsoft Only =====
(AliIde) AliIde [Boot | Running]
[08/17/2001 11:51 AM | 00,005,248 | ---- | M] (Acer Laboratories Inc.) - C:\WINDOWS\system32\drivers\aliide.sys
(AmdK8) AMD Processor Driver [System | Running]
[08/11/2004 07:30 PM | 00,039,424 | ---- | M] (Advanced Micro Devices) - C:\WINDOWS\system32\drivers\AmdK8.sys
(ASCTRM) ASCTRM [Auto | Running]
[11/26/2005 04:00 PM | 00,008,552 | ---- | M] (Windows ® 2000 DDK provider) - C:\WINDOWS\System32\drivers\asctrm.sys
(ati2mtag) ati2mtag [On_Demand | Running]
[04/11/2005 09:33 AM | 01,035,264 | ---- | M] (ATI Technologies Inc.) - C:\WINDOWS\system32\drivers\ati2mtag.sys
(BCM43XX) Broadcom 802.11 Network Adapter Driver [On_Demand | Running]
[03/10/2005 05:41 AM | 00,371,712 | ---- | M] (Broadcom Corporation) - C:\WINDOWS\system32\drivers\BCMWL5.SYS
(BTWUSB) WIDCOMM USB Bluetooth Driver [On_Demand | Stopped]
[01/18/2005 12:52 PM | 00,055,320 | ---- | M] (Broadcom Corporation.) - C:\WINDOWS\system32\drivers\btwusb.sys
(CAMCAUD) Conexant AMC Audio [On_Demand | Running]
[02/18/2005 11:41 AM | 00,038,016 | ---- | M] (Conexant Systems Inc.) - C:\WINDOWS\system32\drivers\camc6aud.sys
(CAMCHALA) CAMCHALA [On_Demand | Running]
[02/18/2005 11:42 AM | 00,349,696 | ---- | M] (Conexant Systems Inc.) - C:\WINDOWS\system32\drivers\camc6hal.sys
(dmboot) dmboot [Disabled | Stopped]
[08/04/2004 04:00 AM | 00,799,744 | ---- | M] (Microsoft Corp., Veritas Software) - C:\WINDOWS\system32\drivers\dmboot.sys
(dmio) dmio [Disabled | Stopped]
[08/04/2004 04:00 AM | 00,153,344 | ---- | M] (Microsoft Corp., Veritas Software) - C:\WINDOWS\system32\drivers\dmio.sys
(dmload) dmload [Disabled | Stopped]
[08/04/2004 04:00 AM | 00,005,888 | ---- | M] (Microsoft Corp., Veritas Software.) - C:\WINDOWS\system32\drivers\dmload.sys
(eabfiltr) eabfiltr [System | Running]
[04/14/2004 10:36 AM | 00,007,432 | ---- | M] (Hewlett-Packard Company) - C:\WINDOWS\system32\drivers\eabfiltr.sys
(eabusb) eabusb [On_Demand | Stopped]
[06/06/2003 02:46 PM | 00,005,220 | ---- | M] (Hewlett-Packard Company) - C:\WINDOWS\system32\drivers\EabUsb.sys
(GEARAspiWDM) GEAR CDRom Filter [On_Demand | Running]
[09/14/2004 05:38 PM | 00,013,872 | ---- | M] (GEAR Software Inc.) - C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
(HSFHWATI) HSFHWATI [On_Demand | Running]
[12/15/2004 11:18 AM | 00,200,192 | ---- | M] (Conexant Systems, Inc.) - C:\WINDOWS\system32\drivers\HSFHWATI.sys
(HSF_DP) HSF_DP [On_Demand | Running]
[12/15/2004 11:18 AM | 01,038,208 | ---- | M] (Conexant Systems, Inc.) - C:\WINDOWS\system32\drivers\HSF_DP.sys
(LHidKe) Logitech SetPoint HID Mouse Filter Driver [On_Demand | Running]
[10/21/2004 02:30 PM | 00,024,671 | ---- | M] (Logitech, Inc.) - C:\WINDOWS\system32\drivers\LHidKE.Sys
(LHidUsbK) Logitech SetPoint USB Receiver device driver [On_Demand | Running]
[10/21/2004 02:31 PM | 00,038,691 | ---- | M] (Logitech, Inc.) - C:\WINDOWS\system32\drivers\LHidUsbK.sys
(LMouKE) Logitech SetPoint Mouse Filter Driver [On_Demand | Running]
[10/21/2004 02:30 PM | 00,071,535 | ---- | M] (Logitech, Inc.) - C:\WINDOWS\system32\drivers\LMouKE.Sys
(mdmxsdk) mdmxsdk [Auto | Running]
[03/17/2004 07:04 AM | 00,013,059 | ---- | M] (Conexant) - C:\WINDOWS\system32\drivers\mdmxsdk.sys
(mr7910) Photo Viewer [On_Demand | Stopped]
[08/02/2006 11:45 AM | 00,114,560 | ---- | M] (Mars Semiconductor Corp.) - C:\WINDOWS\system32\drivers\mr7910.sys
(NAVAP) NAVAP [On_Demand | Running]
[08/11/2003 05:39 AM | 00,224,768 | ---- | M] (Symantec Corporation) - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Navap.sys
(NAVAPEL) NAVAPEL [Auto | Running]
[08/11/2003 05:39 AM | 00,030,208 | ---- | M] (Symantec Corporation) - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Navapel.sys
(NAVENG) NAVENG [On_Demand | Running]
[08/26/2008 04:00 AM | 00,089,104 | ---- | M] (Symantec Corporation) - C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080826.023\naveng.sys
(NAVEX15) NAVEX15 [On_Demand | Running]
[08/26/2008 04:00 AM | 00,873,552 | ---- | M] (Symantec Corporation) - C:\Program Files\Common Files\Symantec Shared\VirusDefs\20080826.023\navex15.sys
(Ptilink) Direct Parallel Link Driver [On_Demand | Running]
[08/04/2004 04:00 AM | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) - C:\WINDOWS\system32\drivers\ptilink.sys
(PxHelp20) PxHelp20 [Boot | Running]
[01/26/2005 05:03 AM | 00,020,576 | ---- | M] (Sonic Solutions) - C:\WINDOWS\system32\drivers\pxhelp20.sys
(RTL8023xp) Realtek 10/100/1000 NIC Family all in one NDIS XP Driver [On_Demand | Stopped]
[03/03/2005 03:10 PM | 00,074,496 | ---- | M] (Realtek Semiconductor Corporation ) - C:\WINDOWS\system32\drivers\Rtlnicxp.sys
(Secdrv) Secdrv [On_Demand | Stopped]
[11/13/2007 06:25 AM | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) - C:\WINDOWS\system32\drivers\secdrv.sys
(SMCIRDA) SMC IrCC Miniport Device Driver [On_Demand | Stopped]
[08/17/2001 03:10 PM | 00,035,913 | ---- | M] (SMC) - C:\WINDOWS\system32\drivers\smcirda.sys
(srescan) srescan [Boot | Running]
[02/27/2008 03:10 AM | 00,051,176 | ---- | M] (Zone Labs, LLC) - C:\WINDOWS\system32\ZoneLabs\srescan.sys
(SymEvent) SymEvent [On_Demand | Running]
[01/27/2006 05:21 PM | 00,073,496 | ---- | M] (Symantec Corporation) - C:\Program Files\Symantec\SYMEVENT.SYS
(SynTP) Synaptics TouchPad Driver [On_Demand | Running]
[02/02/2005 07:58 AM | 00,191,456 | ---- | M] (Synaptics, Inc.) - C:\WINDOWS\system32\drivers\SynTP.sys
(tifm21) tifm21 [On_Demand | Stopped]
[03/16/2005 08:43 AM | 00,159,488 | ---- | M] (Texas Instruments) - C:\WINDOWS\system32\drivers\tifm21.sys
(tmcomm) tmcomm [Auto | Running]
[10/25/2006 10:50 AM | 00,076,560 | ---- | M] (Trend Micro Inc.) - C:\WINDOWS\system32\drivers\tmcomm.sys
(vsdatant) vsdatant [System | Running]
[03/13/2008 11:11 PM | 00,394,952 | ---- | M] (Zone Labs, LLC) - C:\WINDOWS\system32\vsdatant.sys
(wanatw) WAN Miniport (ATW) [On_Demand | Stopped]
File not found - C:\WINDOWS\System32\DRIVERS\wanatw4.sys
(winachsf) winachsf [On_Demand | Running]
[12/15/2004 11:18 AM | 00,703,232 | ---- | M] (Conexant Systems, Inc.) - C:\WINDOWS\system32\drivers\HSF_CNXT.sys
===== Run Keys =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher" = "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [01/11/2008 10:16 PM | 00,039,792 | ---- | M] (Adobe Systems Incorporated)
"ATIPTA" = C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [04/11/2005 01:00 PM | 00,339,968 | ---- | M] (ATI Technologies, Inc.)
"eabconfg.cpl" = C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start [12/03/2004 04:24 PM | 00,290,816 | ---- | M] (Hewlett-Packard )
"HP Software Update" = C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe [02/17/2005 02:11 AM | 00,049,152 | ---- | M] (Hewlett-Packard Co.)
"hpWirelessAssistant" = C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe [04/01/2005 06:11 PM | 00,794,624 | ---- | M] (Hewlett-Packard Company)
"Logitech Hardware Abstraction Layer" = KHALMNPR.EXE [10/21/2004 02:28 PM | 00,029,696 | ---- | M] (Logitech Inc.)
"LSBWatcher" = c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe [10/14/2004 04:54 PM | 00,253,952 | ---- | M] (Hewlett-Packard Company)
"Pop-Up Stopper" = File not found
"SunJavaUpdateSched" = "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [06/10/2008 04:27 AM | 00,144,784 | ---- | M] (Sun Microsystems, Inc.)
"SynTPEnh" = C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [02/02/2005 08:11 AM | 00,692,316 | ---- | M] (Synaptics, Inc.)
"SynTPLpr" = C:\Program Files\Synaptics\SynTP\SynTPLpr.exe [02/02/2005 08:12 AM | 00,102,492 | ---- | M] (Synaptics, Inc.)
"vptray" = C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe [12/17/2003 11:00 PM | 00,090,112 | ---- | M] (Symantec Corporation)
"ZoneAlarm Client" = "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [03/13/2008 11:11 PM | 00,919,016 | ---- | M] (Zone Labs, LLC)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" = Reg Error: Value load does not exist or could not be read.
"run" = Reg Error: Value run does not exist or could not be read.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg" = C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [06/02/2007 09:43 PM | 00,068,856 | ---- | M] (Google Inc.)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" =
"run" = Reg Error: Value run does not exist or could not be read.
===== Startup Folders =====
[All Users Startup Folder - C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
[10/28/2004 10:29 AM | 00,581,632 | ---- | M] (Logitech Inc.) - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
[debbie Startup Folder - C:\Documents and Settings\debbie\Start Menu\Programs\Startup]
===== BHO's =====
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}]
HKLM CLSID: (Yahoo! Toolbar Helper) - [10/26/2006 11:28 AM | 00,440,384 | ---- | M] (Yahoo! Inc.) C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
HKLM CLSID: (Adobe PDF Reader Link Helper) - [10/22/2006 11:08 PM | 00,062,080 | ---- | M] (Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
HKLM CLSID: (SSVHelper Class) - [06/10/2008 04:27 AM | 00,509,328 | ---- | M] (Sun Microsystems, Inc.) C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
HKLM CLSID: (Google Toolbar Helper) - [01/20/2007 12:55 AM | 02,403,392 | R--- | M] (Google Inc.) c:\Program Files\Google\GoogleToolbar4.dll
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
HKLM CLSID: (Google Toolbar Notifier BHO) - [05/06/2008 01:03 PM | 00,734,704 | ---- | M] (Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
===== Toolbars =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}"
HKLM CLSID: (&Google) - [01/20/2007 12:55 AM | 02,403,392 | R--- | M] (Google Inc.) c:\Program Files\Google\GoogleToolbar4.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}"
HKLM CLSID: (Yahoo! Toolbar) - [10/26/2006 11:28 AM | 00,440,384 | ---- | M] (Yahoo! Inc.) C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}"
HKLM CLSID: (Reg Error: Key does not exist or could not be opened.) - File not found Reg Error: Key does not exist or could not be opened.
"{4982D40A-C53B-4615-B15B-B5B5E98D167C}"
HKLM CLSID: (Reg Error: Key does not exist or could not be opened.) - File not found Reg Error: Key does not exist or could not be opened.
"{C4069E3A-68F1-403E-B40E-20066696354B}"
HKLM CLSID: (Reg Error: Key does not exist or could not be opened.) - File not found Reg Error: Key does not exist or could not be opened.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}"
HKLM CLSID: (Reg Error: Key does not exist or could not be opened.) - File not found Reg Error: Key does not exist or could not be opened.
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
HKLM CLSID: (&Google) - [01/20/2007 12:55 AM | 02,403,392 | R--- | M] (Google Inc.) c:\Program Files\Google\GoogleToolbar4.dll
"{4982D40A-C53B-4615-B15B-B5B5E98D167C}"
HKLM CLSID: (Reg Error: Key does not exist or could not be opened.) - File not found Reg Error: Key does not exist or could not be opened.
"{E6AE90A4-1B01-47F0-AA78-E6B122E145E9}"
HKLM CLSID: (Reg Error: Key does not exist or could not be opened.) - File not found Reg Error: Key does not exist or could not be opened.
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}"
HKLM CLSID: (Yahoo! Toolbar) - [10/26/2006 11:28 AM | 00,440,384 | ---- | M] (Yahoo! Inc.) C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
===== Policies =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
Unable to open key or key not present!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"dontdisplaylastusername" = 0
"legalnoticecaption" =
"legalnoticetext" =
"shutdownwithoutlogon" = 1
"undockwithoutlogon" = 1
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun" = 145
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
Unable to open key or key not present!
===== Desktop Components =====
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"FriendlyName" = "My Current Home Page"
"Source" = "About:Home"
"SubscribedURL" = "About:Home"
===== Shared Task Scheduler =====
===== AppInit_Dlls =====
===== Lsa Authentication Packages =====
===== Lsa Security Packages =====
===== Authorized Applications List =====
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = C:\WINDOWS\system32\sessmgr.exe [08/04/2004 04:00 AM | 00,140,800 | ---- | M] (Microsoft Corporation)
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe File not found
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe File not found
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe File not found
"%windir%\Network Diagnostic\xpnetdiag.exe" = C:\WINDOWS\network diagnostic\xpnetdiag.exe [10/10/2006 08:44 AM | 00,557,568 | ---- | M] (Microsoft Corporation)
"C:\Program Files\MSN Messenger\msnmsgr.exe" = C:\Program Files\MSN Messenger\msnmsgr.exe [01/24/2006 11:37 AM | 07,094,272 | ---- | M] (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = C:\WINDOWS\system32\sessmgr.exe [08/04/2004 04:00 AM | 00,140,800 | ---- | M] (Microsoft Corporation)
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe File not found
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe [10/13/2004 07:12 PM | 08,759,808 | ---- | M] (Apple Computer, Inc.)
"C:\Program Files\Yahoo!\Messenger\YPager.exe" = C:\Program Files\Yahoo!\Messenger\YPager.exe File not found
"C:\Program Files\Yahoo!\Messenger\YServer.exe" = C:\Program Files\Yahoo!\Messenger\YServer.exe [11/30/2006 10:49 PM | 00,091,640 | ---- | M] (Yahoo! Inc.)
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" = C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe File not found
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" = C:\Program Files\Common Files\AOL\ACS\AOLDial.exe File not found
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe File not found
"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe [11/03/2006 03:17 AM | 00,010,800 | ---- | M] (AOL LLC)
"C:\Program Files\Common Files\AOL\1133036626\ee\aolsoftware.exe" = C:\Program Files\Common Files\AOL\1133036626\ee\aolsoftware.exe [11/02/2005 11:01 PM | 00,050,792 | ---- | M] (America Online, Inc.)
"C:\Program Files\Common Files\AOL\1133036626\ee\aim6.exe" = C:\Program Files\Common Files\AOL\1133036626\ee\aim6.exe [01/09/2006 03:31 PM | 00,050,792 | ---- | M] (America Online, Inc.)
"C:\WINDOWS\system32\ZoneLabs\vsmon.exe" = C:\WINDOWS\system32\ZoneLabs\vsmon.exe [03/13/2008 11:11 PM | 00,075,304 | ---- | M] (Zone Labs, LLC)
"%windir%\Network Diagnostic\xpnetdiag.exe" = C:\WINDOWS\network diagnostic\xpnetdiag.exe [10/10/2006 08:44 AM | 00,557,568 | ---- | M] (Microsoft Corporation)
"C:\Program Files\MSN Messenger\msnmsgr.exe" = C:\Program Files\MSN Messenger\msnmsgr.exe [01/24/2006 11:37 AM | 07,094,272 | ---- | M] (Microsoft Corporation)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [11/30/2006 10:49 PM | 04,662,776 | ---- | M] (Yahoo! Inc.)
===== HKLM Winlogon Settings =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell]
"Explorer.exe" - [06/13/2007 06:23 AM | 01,033,216 | ---- | M] (Microsoft Corporation) C:\WINDOWS\explorer.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit]
"C:\WINDOWS\system32\userinit.exe" - [08/04/2004 04:00 AM | 00,024,576 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\userinit.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UIHost]
"logonui.exe" - [08/04/2004 04:00 AM | 00,514,560 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\logonui.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet]
"rundll32 shell32" - [10/25/2007 11:36 PM | 08,454,656 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
"Control_RunDLL "sysdm.cpl"" - [08/04/2004 04:00 AM | 00,298,496 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\sysdm.cpl
===== User's Winlogon Settings =====
===== Winlogon Notify Settings =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
"DllName" = C:\WINDOWS\system32\ati2evxx.dll [04/11/2005 09:31 AM | 00,046,080 | ---- | M] (ATI Technologies Inc.)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
"DllName" = C:\WINDOWS\system32\NavLogon.dll [12/17/2003 10:51 PM | 00,045,056 | ---- | M] ()
===== Safeboot Options =====
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot]
"AlternateShell" = cmd.exe
===== Disabled MsConfig Items =====
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\services]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupfolder]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Aim6]
"key" = SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"item" = aim6
"hkey" = HKCU
"command" = C:\Program Files\AIM6\aim6.exe [10/04/2007 11:20 AM | 00,050,528 | ---- | M] (AOL LLC)
"inimapping" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Cpqset]
"key" = SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"item" = cpqset
"hkey" = HKLM
"command" = C:\Program Files\HPQ\Default Settings\Cpqset.exe [02/17/2005 05:01 PM | 00,233,534 | ---- | M] ()
"inimapping" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\HostManager]
"key" = SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"item" = AOLSoftware
"hkey" = HKLM
"command" = C:\Program Files\Common Files\AOL\1133036626\ee\aolsoftware.exe [11/02/2005 11:01 PM | 00,050,792 | ---- | M] (America Online, Inc.)
"inimapping" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\iTunesHelper]
"key" = SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"item" = iTunesHelper
"hkey" = HKLM
"command" = C:\Program Files\iTunes\iTunesHelper.exe [10/13/2004 07:04 PM | 00,278,528 | ---- | M] (Apple Computer, Inc.)
"inimapping" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\MSMSGS]
"key" = SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"item" = msmsgs
"hkey" = HKCU
"command" = C:\Program Files\Messenger\msmsgs.exe [10/13/2004 12:24 PM | 01,694,208 | ---- | M] (Microsoft Corporation)
"inimapping" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\QuickTime Task]
"key" = SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"item" = qttask
"hkey" = HKLM
"command" = C:\Program Files\QuickTime\qttask.exe [04/29/2005 09:02 AM | 00,098,304 | ---- | M] (Apple Computer, Inc.)
"inimapping" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\RealTray]
"key" = SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"item" = RealPlay
"hkey" = HKLM
"command" = C:\Program Files\Real\RealPlayer\realplay.exe [11/26/2005 04:00 PM | 00,026,112 | ---- | M] (RealNetworks, Inc.)
"inimapping" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\SeePassword]
"key" = SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"item" = SeePassword
"hkey" = HKLM
"command" = C:\Program Files\SeePassword\SeePassword.exe File not found
"inimapping" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\swg]
"key" = SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"item" = GoogleToolbarNotifier
"hkey" = HKCU
"command" = C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [06/02/2007 09:43 PM | 00,068,856 | ---- | M] (Google Inc.)
"inimapping" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Yahoo! Pager]
"key" = SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"item" = YahooMessenger
"hkey" = HKCU
"command" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [11/30/2006 10:49 PM | 04,662,776 | ---- | M] (Yahoo! Inc.)
"inimapping" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\state]
"system.ini" = 0
"win.ini" = 0
"bootini" = 0
"services" = 0
"startup" = 2
===== DNS Name Servers =====
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{5CD601CE-5361-4CA1-BD69-03B359C1B08A}]
Servers: | Description: Realtek RTL8139/810x Family Fast Ethernet NIC
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{6C523C9D-A4E4-4BF5-97FA-D2338CCF41CF}]
Servers: | Description: Broadcom 802.11b/g WLAN
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{9E24E003-31B7-40F1-A1DE-5C8952BF3F24}]
Servers: | Description:
===== CDRom AutoRun Settings =====
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1
===== MountPoints2 =====
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{44b0806a-c5ce-11dc-a75a-0014a519bcd9}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{44b0806a-c5ce-11dc-a75a-0014a519bcd9}\Shell\Autoplay]
"MUIVerb" = C:\WINDOWS\system32\shell32.dll [10/25/2007 11:36 PM | 08,454,656 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{44b0806a-c5ce-11dc-a75a-0014a519bcd9}\Shell\Autoplay\DropTarget]
"CLSID" = {f26a669a-bcbb-4e37-abf9-7325da15f931}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{44b0806b-c5ce-11dc-a75a-0014a519bcd9}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{44b0806b-c5ce-11dc-a75a-0014a519bcd9}\Shell\Autoplay]
"MUIVerb" = C:\WINDOWS\system32\shell32.dll [10/25/2007 11:36 PM | 08,454,656 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{44b0806b-c5ce-11dc-a75a-0014a519bcd9}\Shell\Autoplay\DropTarget]
"CLSID" = {f26a669a-bcbb-4e37-abf9-7325da15f931}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{44b0806c-c5ce-11dc-a75a-0014a519bcd9}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{44b0806c-c5ce-11dc-a75a-0014a519bcd9}\Shell\Autoplay]
"MUIVerb" = C:\WINDOWS\system32\shell32.dll [10/25/2007 11:36 PM | 08,454,656 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{44b0806c-c5ce-11dc-a75a-0014a519bcd9}\Shell\Autoplay\DropTarget]
"CLSID" = {f26a669a-bcbb-4e37-abf9-7325da15f931}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{44b0806d-c5ce-11dc-a75a-0014a519bcd9}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{44b0806d-c5ce-11dc-a75a-0014a519bcd9}\Shell\Autoplay]
"MUIVerb" = C:\WINDOWS\system32\shell32.dll [10/25/2007 11:36 PM | 08,454,656 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{44b0806d-c5ce-11dc-a75a-0014a519bcd9}\Shell\Autoplay\DropTarget]
"CLSID" = {f26a669a-bcbb-4e37-abf9-7325da15f931}
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e570c203-5e4b-11da-a503-0014a519bcd9}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e570c203-5e4b-11da-a503-0014a519bcd9}\Shell\Autoplay]
"MUIVerb" = C:\WINDOWS\system32\shell32.dll [10/25/2007 11:36 PM | 08,454,656 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e570c203-5e4b-11da-a503-0014a519bcd9}\Shell\Autoplay\DropTarget]
"CLSID" = {f26a669a-bcbb-4e37-abf9-7325da15f931}
===== Hosts File =====
HOSTS File = (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
First 25 entries...
127.0.0.1 localhost
[Files/Folders - Created Within 30 days]
[1 C:\WINDOWS\System32\*.tmp files]
[08/18/2008 05:59 PM | ---D | C] - C:\WINDOWS\System32\CatRoot_bak
[07/31/2008 01:42 PM | ---D | C] - C:\Documents and Settings\debbie\Desktop\July 2008
[08/23/2008 09:49 PM | ---D | C] - C:\Documents and Settings\debbie\Desktop\July&Aug 2008 Reese
[08/25/2008 06:18 PM | ---D | C] - C:\Documents and Settings\debbie\Desktop\Reese Aug 23 2008
[08/27/2008 02:27 PM | 00,001,734 | ---- | C] () - C:\Documents and Settings\debbie\Desktop\HijackThis.lnk
[08/27/2008 02:27 PM | ---D | C] - C:\Program Files\Trend Micro
[Files/Folders - Modified Within 30 days]
[08/19/2008 07:55 PM | 00,000,211 | RHS- | M] () - C:\boot.ini
[08/28/2008 02:37 PM | ---D | M] - C:\WINDOWS
[08/28/2008 02:56 PM | -HSD | M] - C:\System Volume Information
[08/28/2008 03:46 PM | ---D | M] - C:\eudora attachements
[08/28/2008 03:56 PM | R--D | M] - C:\Program Files
[08/28/2008 11:07 AM | 66,956,9024 | -HS- | M] () - C:\hiberfil.sys
[1 C:\WINDOWS\System32\*.tmp files]
[08/19/2008 06:52 PM | ---D | M] - C:\WINDOWS\System32\CatRoot
[08/19/2008 06:52 PM | ---D | M] - C:\WINDOWS\System32\CatRoot_bak
[08/26/2008 06:04 PM | ---D | M] - C:\WINDOWS\System32\CatRoot2
[08/28/2008 02:56 PM | ---D | M] - C:\WINDOWS\System32\Restore
[08/28/2008 11:08 AM | 00,352,186 | -H-- | M] () - C:\WINDOWS\System32\vsconfig.xml
[08/28/2008 11:09 AM | 00,001,158 | ---- | M] () - C:\WINDOWS\System32\wpa.dbl
[08/28/2008 11:20 AM | ---D | M] - C:\WINDOWS\System32\ZoneLabs
[08/06/2008 12:45 PM | -HSD | M] - C:\WINDOWS\Installer
[08/18/2008 05:59 PM | ---D | M] - C:\WINDOWS\Debug
[08/18/2008 05:59 PM | ---D | M] - C:\WINDOWS\system32
[08/19/2008 06:53 PM | -H-D | M] - C:\WINDOWS\$hf_mig$
[08/19/2008 07:55 PM | 00,000,227 | ---- | M] () - C:\WINDOWS\system.ini
[08/19/2008 07:55 PM | 00,000,603 | ---- | M] () - C:\WINDOWS\win.ini
[08/20/2008 11:25 PM | --SD | M] - C:\WINDOWS\Downloaded Program Files
[08/26/2008 06:04 PM | -H-D | M] - C:\WINDOWS\inf
[08/28/2008 03:23 PM | ---D | M] - C:\WINDOWS\Internet Logs
[08/28/2008 03:56 PM | ---D | M] - C:\WINDOWS\Prefetch
[08/28/2008 11:07 AM | 00,002,048 | --S- | M] () - C:\WINDOWS\bootstat.dat
[08/28/2008 11:08 AM | ---D | M] - C:\WINDOWS\Temp
[08/28/2008 11:07 AM | 00,000,006 | -H-- | M] () - C:\WINDOWS\tasks\SA.DAT
[08/28/2008 03:56 PM | ---D | M] - C:\Documents and Settings\All Users\Application Data\Viewpoint
[08/27/2008 03:38 PM | 06,916,378 | -H-- | M] () - C:\Documents and Settings\debbie\Local Settings\Application Data\IconCache.db
[08/01/2008 07:32 PM | ---D | M] - C:\Documents and Settings\debbie\Desktop\July 2008
[08/23/2008 10:04 PM | ---D | M] - C:\Documents and Settings\debbie\Desktop\July&Aug 2008 Reese
[08/27/2008 02:29 PM | 00,001,734 | ---- | M] () - C:\Documents and Settings\debbie\Desktop\HijackThis.lnk
[08/28/2008 03:54 PM | ---D | M] - C:\Documents and Settings\debbie\Desktop\Reese Aug 23 2008
< End of report >