Here are the files.....
OTListIt logfile created on: 1/9/2009 2:44:12 PM - Run
OTListIt2 by OldTimer - Version 1.0.3.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1014.07 Mb Total Physical Memory | 586.71 Mb Available Physical Memory | 57.86% Memory free
2.39 Gb Paging File | 1.96 Gb Available in Paging File | 82.14% Paging File free
Paging file location(s): c:\pagefile.sys 1524 3048;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 56.38 Gb Free Space | 75.66% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: OWNER-ED144E44C
Current User Name: Owner
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ========== C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe (Microsoft Corporation)
C:\WINDOWS\system32\LEXBCES.EXE (Lexmark International, Inc.)
C:\WINDOWS\system32\LEXPPS.EXE (Lexmark International, Inc.)
C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
C:\WINDOWS\system32\dla\tfswctrl.exe (Sonic Solutions)
C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe (SupportSoft, Inc.)
C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe (Microsoft Corporation)
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe (IObit)
C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe (Microsoft Corporation)
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe (SupportSoft, Inc.)
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
c:\WINDOWS\system32\ZuneBusEnum.exe (Microsoft Corporation)
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe (Microsoft Corporation)
C:\Program Files\Microsoft Windows OneCare Live\winss.exe (Microsoft Corporation)
C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
C:\WINDOWS\system32\wuauclt.exe (Microsoft Corporation)
C:\Documents and Settings\Owner\Desktop\OTListIt2.exe (OldTimer Tools)
========== (O23) Win32 Services (SafeList) ========== (ALG [On_Demand | Running]) -- C:\WINDOWS\system32\alg File not found
(AppMgmt [On_Demand | Stopped]) -- File not found
(aspnet_state [On_Demand | Stopped]) -- File not found
(CiSvc [On_Demand | Stopped]) -- C:\WINDOWS\system32\cisvc File not found
(ClipSrv [Disabled | Stopped]) -- C:\WINDOWS\system32\clipsrv File not found
(clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- File not found
(COMSysApp [On_Demand | Stopped]) -- File not found
(dmadmin [On_Demand | Stopped]) -- C:\WINDOWS\system32\dmadmin File not found
(Eventlog [Auto | Running]) -- C:\WINDOWS\system32\eventlog.dll (Microsoft Corporation)
(gusvc [On_Demand | Stopped]) -- File not found
(helpsvc [Auto | Running]) -- C:\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll (Microsoft Corporation)
(HidServ [Disabled | Stopped]) -- File not found
(IDriverT [On_Demand | Stopped]) -- File not found
(ImapiService [On_Demand | Stopped]) -- File not found
(JavaQuickStarterService [Auto | Running]) -- File not found
(LexBceS [Auto | Running]) -- C:\WINDOWS\system32\LEXBCES File not found
(MDM [Auto | Running]) -- File not found
(mnmsrvc [Disabled | Stopped]) -- C:\WINDOWS\system32\mnmsrvc File not found
(MSDTC [On_Demand | Stopped]) -- C:\WINDOWS\system32\msdtc [2006/08/29 12:04:54 00,000,000 | ---D | M]
(msfwsvc [Auto | Running]) -- File not found
(MSIServer [On_Demand | Stopped]) -- File not found
(NetDDE [Disabled | Stopped]) -- C:\WINDOWS\system32\netdde File not found
(NetDDEdsdm [Disabled | Stopped]) -- File not found
(Netlogon [On_Demand | Stopped]) -- C:\WINDOWS\system32\netlogon.dll (Microsoft Corporation)
(NtLmSsp [Disabled | Stopped]) -- File not found
(OcHealthMon [Auto | Running]) -- File not found
(OneCareMP [Auto | Running]) -- File not found
(ose [On_Demand | Stopped]) -- File not found
(PlugPlay [Auto | Running]) -- File not found
(PolicyAgent [Auto | Running]) -- File not found
(ProtectedStorage [Auto | Running]) -- File not found
(RDSessMgr [On_Demand | Stopped]) -- File not found
(RpcLocator [On_Demand | Stopped]) -- File not found
(RSVP [On_Demand | Stopped]) -- C:\WINDOWS\system32\rsvp File not found
(SamSs [Auto | Running]) -- File not found
(SCardSvr [On_Demand | Stopped]) -- C:\WINDOWS\system32\scardsvr File not found
(Spooler [Auto | Running]) -- File not found
(sprtsvc_ddoctorv2 [Auto | Running]) -- File not found
(SwPrv [On_Demand | Stopped]) -- C:\WINDOWS\system32\swprv.dll (Microsoft Corporation)
(SysmonLog [Disabled | Stopped]) -- File not found
(UPS [On_Demand | Stopped]) -- C:\WINDOWS\system32\ups File not found
(Viewpoint Manager Service [Auto | Stopped]) -- File not found
(VSS [On_Demand | Stopped]) -- File not found
(WinDefend [Auto | Stopped]) -- File not found
(winss [Auto | Running]) -- File not found
(WmiApSrv [On_Demand | Stopped]) -- C:\WINDOWS\system32\wbem\wmiapsrv File not found
(WudfSvc [Auto | Running]) -- C:\WINDOWS\system32\WudfSvc.dll (Microsoft Corporation)
(ZuneBusEnum [Auto | Running]) -- C:\WINDOWS\system32\ZuneBusEnum File not found
(ZuneNetworkSvc [On_Demand | Stopped]) -- File not found
(ZuneWlanCfgSvc [On_Demand | Stopped]) -- C:\WINDOWS\system32\ZuneWlanCfgSvc File not found
========== Driver Services (SafeList) ========== (ACPI [Boot | Running]) -- File not found
(AFD [System | Running]) -- File not found
(atapi [Boot | Running]) -- File not found
(audstub [On_Demand | Running]) -- File not found
(Beep [System | Running]) -- File not found
(Cdfs [Disabled | Running]) -- File not found
(Cdrom [System | Running]) -- File not found
(Disk [Boot | Running]) -- File not found
(DMusic [On_Demand | Stopped]) -- C:\WINDOWS\system32\dmusic.dll (Microsoft Corporation)
(drvmcdb [Boot | Running]) -- File not found
(drvnddm [Auto | Running]) -- File not found
(E100B [On_Demand | Running]) -- File not found
(Fdc [On_Demand | Running]) -- File not found
(Fips [System | Running]) -- File not found
(Flpydisk [On_Demand | Running]) -- File not found
(FltMgr [Boot | Running]) -- File not found
(Ftdisk [Boot | Running]) -- File not found
(Gpc [On_Demand | Running]) -- File not found
(HPZipr12 [On_Demand | Stopped]) -- C:\WINDOWS\system32\HPZipr12.dll (HP)
(HTTP [On_Demand | Running]) -- File not found
(i8042prt [System | Running]) -- File not found
(ialm [On_Demand | Running]) -- File not found
(Imapi [System | Running]) -- C:\WINDOWS\system32\imapi File not found
(IntelIde [Boot | Running]) -- File not found
(intelppm [System | Running]) -- File not found
(IpFilterDriver [Auto | Running]) -- File not found
(IpNat [On_Demand | Running]) -- File not found
(IPSec [System | Running]) -- File not found
(isapnp [Boot | Running]) -- File not found
(Kbdclass [System | Running]) -- File not found
(KSecDD [Boot | Running]) -- File not found
(mnmdd [System | Running]) -- C:\WINDOWS\system32\mnmdd.dll (Microsoft Corporation)
(Mouclass [System | Running]) -- File not found
(MountMgr [Boot | Running]) -- File not found
(MpFilter [On_Demand | Running]) -- File not found
(MRxDAV [On_Demand | Running]) -- File not found
(MRxSmb [System | Running]) -- File not found
(Msfs [System | Running]) -- File not found
(MSFWDrv [Auto | Running]) -- File not found
(MSFWHLPR [System | Running]) -- File not found
(mssmbios [On_Demand | Running]) -- File not found
(Mup [Boot | Running]) -- File not found
(NDIS [Boot | Running]) -- File not found
(NdisTapi [On_Demand | Running]) -- File not found
(Ndisuio [On_Demand | Running]) -- File not found
(NdisWan [On_Demand | Running]) -- File not found
(NDProxy [On_Demand | Running]) -- File not found
(NetBIOS [System | Running]) -- File not found
(NetBT [System | Running]) -- File not found
(Npfs [System | Running]) -- File not found
(Ntfs [Disabled | Running]) -- File not found
(Null [System | Running]) -- File not found
(OMCI [System | Running]) -- File not found
(Parport [On_Demand | Running]) -- File not found
(PartMgr [Boot | Running]) -- File not found
(ParVdm [Auto | Running]) -- File not found
(PCI [Boot | Running]) -- File not found
(PCIIde [Boot | Running]) -- File not found
(PptpMiniport [On_Demand | Running]) -- File not found
(PSched [On_Demand | Running]) -- File not found
(Ptilink [On_Demand | Running]) -- File not found
(PxHelp20 [Boot | Running]) -- File not found
(RasAcd [System | Running]) -- File not found
(Rasl2tp [On_Demand | Running]) -- File not found
(RasPppoe [On_Demand | Running]) -- File not found
(Raspti [On_Demand | Running]) -- File not found
(Rdbss [System | Running]) -- File not found
(RDPCDD [System | Running]) -- File not found
(redbook [System | Running]) -- File not found
(SASDIFSV [System | Running]) -- File not found
(SASENUM [On_Demand | Running]) -- File not found
(SASKUTIL [System | Running]) -- File not found
(senfilt [On_Demand | Running]) -- File not found
(serenum [On_Demand | Running]) -- File not found
(Serial [System | Running]) -- File not found
(smwdm [On_Demand | Running]) -- File not found
(sr [Boot | Running]) -- C:\WINDOWS\system32\wbem\sr.mof ()
(Srv [On_Demand | Running]) -- File not found
(sscdbhk5 [System | Running]) -- File not found
(ssrtln [System | Running]) -- File not found
(swenum [On_Demand | Running]) -- File not found
(sysaudio [On_Demand | Running]) -- File not found
(Tcpip [System | Running]) -- File not found
(TermDD [System | Running]) -- File not found
(tfsnboio [Auto | Running]) -- File not found
(tfsncofs [Auto | Running]) -- File not found
(tfsndrct [Auto | Running]) -- File not found
(tfsndres [Auto | Running]) -- File not found
(tfsnifs [Auto | Running]) -- File not found
(tfsnopio [Auto | Running]) -- File not found
(tfsnpool [Auto | Running]) -- File not found
(tfsnudf [Auto | Running]) -- File not found
(tfsnudfa [Auto | Running]) -- File not found
(Update [On_Demand | Running]) -- File not found
(usbehci [On_Demand | Running]) -- File not found
(usbhub [On_Demand | Running]) -- File not found
(usbprint [On_Demand | Running]) -- File not found
(usbuhci [On_Demand | Running]) -- File not found
(VgaSave [System | Running]) -- C:\WINDOWS\system32\vga.dll (Microsoft Corporation)
(VolSnap [Boot | Running]) -- File not found
(Wanarp [On_Demand | Running]) -- File not found
(Wdf01000 [On_Demand | Running]) -- File not found
(wdmaud [On_Demand | Running]) -- C:\WINDOWS\system32\wdmaud File not found
(WS2IFSL [System | Running]) -- File not found
(WudfPf [Boot | Running]) -- File not found
(zumbus [Auto | Running]) -- File not found
========== Standard Registry (All) ========== ========== Internet Explorer ========== HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://us.rd.yahoo.c...//www.yahoo.comHKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.yahoo.com/HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://ie.search.msn...st/srchcust.htmHKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch =
http://us.rd.yahoo.c...rch/search.htmlHKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ieHKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ie HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.comHKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ieHKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
O1 HOSTS File: (267151 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 9252 more lines...
O2 - BHO: (Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar3.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll (Google Inc.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar3.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar3.dll (Google Inc.)
O4 - HKLM..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2 File not found
O4 - HKLM..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe File not found
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe File not found
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe File not found
O4 - HKLM..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe" File not found
O4 - HKLM..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe File not found
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime File not found
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe File not found
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" File not found
O4 - HKLM..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r File not found
O4 - HKLM..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide File not found
O4 - HKLM..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe" File not found
O4 - HKCU..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup File not found
O4 - HKCU..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe File not found
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop File not found
O4 - Startup: C:\Documents and Settings\Owner\Start Menu\Programs\Startup\desktop File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_11.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag File not found
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs File not found
O15 - HKLM\..Trusted Sites: 46 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Sites: 51 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B}
http://www.eset.eu/b...lineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8}
http://www.mpix.com/...geUploader3.cab (Aurigma Image Uploader 3.5 Control)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload.ma...ent/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler: - about - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - cdl - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - dvd - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler: - file - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - ftp - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - gopher - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - http - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - http\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - http\oledb - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - https - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - https\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - https\oledb - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - ipp - No CLSID value found
O18 - Protocol\Handler: - ipp\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - its - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler: - javascript - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - local - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mailto - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mhtml - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mk - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - msdaipp - No CLSID value found
O18 - Protocol\Handler: - msdaipp\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - msdaipp\oledb - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - ms-its - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler: - ms-itss - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - mso-offdap - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - mso-offdap11 - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - res - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - sysimage - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - tv - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler: - vbscript - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - wia - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/octet-stream - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-complus - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-msdownload - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - Class Install Handler - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - deflate - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - gzip - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - lzdhtml - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/webviewhtml - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - See sections below for AppInitDlls and Winlogon settings
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9}C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9}C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153}C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5}C:\WINDOWS\system32\WPDShServiceObj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: (Browseui preloader) - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: (Component Categories cache daemon) - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
========== HKLM Winlogon Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell" = explorer.exe
>C:\WINDOWS\explorer File not found
"UserInit" = C:\WINDOWS\system32\userinit.exe,
>C:\WINDOWS\system32\userinit File not found
"UIHost" = logonui.exe
>C:\WINDOWS\system32\logonui File not found
"VMApplet" = rundll32 shell32,Control_RunDLL "sysdm.cpl"
>C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
>C:\WINDOWS\system32\sysdm File not found
========== Winlogon Notify Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\]
!SASWinLogon: "DllName" = C:\Program Files\SUPERAntiSpyware\SASWINLO.dll -- C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
crypt32chain: "DllName" = crypt32.dll -- C:\WINDOWS\system32\crypt32.dll (Microsoft Corporation)
cryptnet: "DllName" = cryptnet.dll -- C:\WINDOWS\system32\cryptnet.dll (Microsoft Corporation)
cscdll: "DllName" = cscdll.dll -- C:\WINDOWS\system32\cscdll.dll (Microsoft Corporation)
dimsntfy: "DllName" = %SystemRoot%\System32\dimsntfy.dll -- C:\WINDOWS\system32\dimsntfy.dll (Microsoft Corporation)
igfxcui: "DllName" = igfxdev.dll -- C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
ScCertProp: "DllName" = wlnotify.dll -- C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
Schedule: "DllName" = wlnotify.dll -- C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
sclgntfy: "DllName" = sclgntfy.dll -- C:\WINDOWS\system32\sclgntfy.dll (Microsoft Corporation)
SensLogn: "DllName" = WlNotify.dll -- C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
termsrv: "DllName" = wlnotify.dll -- C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
WgaLogon: "DllName" = WgaLogon.dll -- C:\WINDOWS\system32\WgaLogon.dll (Microsoft Corporation)
wlballoon: "DllName" = wlnotify.dll -- C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
========== IFEO "Debugger" Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\]
Your Image File Name Here without a path:"Debugger" = C:\WINDOWS\system32\ntsd File not found
========== Shell Execute Hooks ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}" (HKLM) -- C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}" (HKLM) -- C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}" (HKLM) -- C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
========== HKLM *SecurityProviders* ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders]
"SecurityProviders" = msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
>C:\WINDOWS\system32\msapsspc.dll (Microsoft Corporation)
>C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
>C:\WINDOWS\system32\digest.dll (Microsoft Corporation)
>C:\WINDOWS\system32\msnsspc.dll (Microsoft Corporation)
========== LSA *Authentication Packages* ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Authentication Packages" = msv1_0,
>C:\WINDOWS\system32\msv1_0.dll (Microsoft Corporation)
========== LSA *Security Packages* ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Security Packages" = kerberos,msv1_0,schannel,wdigest,
>C:\WINDOWS\system32\kerberos.dll (Microsoft Corporation)
>C:\WINDOWS\system32\msv1_0.dll (Microsoft Corporation)
>C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
>C:\WINDOWS\system32\wdigest.dll (Microsoft Corporation)
========== Safeboot Options ========== "AlternateShell" = cmd.exe
========== CDRom AutoRun Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1
========== Autorun Files on Drives ========== AUTOEXEC.BAT []
C:\AUTOEXEC File not found -- [ NTFS ]
========== MountPoints2 ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9e4eceaa-6f85-11dd-ad12-0011113ff907}\Shell]
"" = AutoRun
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9e4eceaa-6f85-11dd-ad12-0011113ff907}\Shell\AutoRun]
"" = Auto&Play
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{cc128c52-4cf0-11db-ab3d-0011113ff907}\Shell]
"" = AutoRun
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{cc128c52-4cf0-11db-ab3d-0011113ff907}\Shell\AutoRun]
"" = Auto&Play
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F\Shell]
"" = AutoRun
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F\Shell\AutoRun]
"" = Auto&Play
========== Files/Folders - Created Within 30 Days ========== [1 C:\WINDOWS\System32\*.tmp files]
[7 C:\WINDOWS\*.tmp files]
[2009/01/09 14:43:21 | 00,419,328 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTListIt2.exe
[2009/01/08 15:18:53 | 00,268,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mucltui.dll
[2009/01/08 15:18:53 | 00,208,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\muweb.dll
[2009/01/08 15:18:53 | 00,027,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mucltui.dll.mui
[2009/01/08 14:30:34 | 00,000,000 | ---D | C] -- C:\Rooter$
[2009/01/08 14:30:22 | 00,268,052 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Rooter.exe
[2009/01/07 22:56:25 | 00,091,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\msfwdrv.sys
[2009/01/07 22:56:23 | 00,116,416 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\msfwhlpr.sys
[2009/01/07 22:55:40 | 00,053,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\MpFilter.sys
[2009/01/07 22:51:45 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Windows OneCare Live
[2009/01/07 22:48:48 | 00,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2009/01/07 22:41:24 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\scripting
[2009/01/07 22:41:23 | 00,000,000 | ---D | C] -- C:\WINDOWS\l2schemas
[2009/01/07 22:41:22 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\en
[2009/01/07 22:41:22 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\bits
[2009/01/07 22:40:11 | 00,000,000 | ---D | C] -- C:\WINDOWS\ServicePackFiles
[2009/01/07 22:38:41 | 00,000,000 | ---D | C] -- C:\WINDOWS\network diagnostic
[2009/01/07 22:34:42 | 00,000,000 | -H-D | C] -- C:\WINDOWS\$NtServicePackUninstall$
[2009/01/07 22:34:40 | 00,000,000 | ---D | C] -- C:\WINDOWS\EHome
[2009/01/07 22:20:57 | 00,000,330 | -H-- | C] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/01/07 22:17:52 | 00,000,000 | ---D | C] -- C:\Program Files\Windows Defender
[2009/01/07 21:33:59 | 00,001,355 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2009/01/06 22:31:48 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2009/01/05 22:50:33 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/01/05 22:49:41 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/01/05 20:37:54 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2009/01/05 20:37:48 | 00,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2009/01/05 20:37:48 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
[2008/12/30 21:24:29 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Application Data\Malwarebytes
[2008/12/30 21:24:27 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2008/12/30 21:24:25 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2008/12/30 21:24:24 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2008/12/30 21:24:24 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2008/12/30 14:29:50 | 00,000,000 | ---D | C] -- C:\Program Files\EsetOnlineScanner
[2008/12/26 18:31:52 | 00,000,000 | ---D | C] -- C:\Program Files\Fisher-Price
[2008/12/26 18:28:22 | 00,010,368 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\hidusb.sys
[2008/12/26 11:36:31 | 00,001,602 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2008/12/26 11:22:53 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Application Data\IObit
[2008/12/26 10:58:29 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SITEguard
[2008/12/26 10:56:37 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\iS3
[2008/12/26 10:56:36 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2008/12/18 09:33:14 | 00,045,568 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Copy of D1 28day schedule ending 01102009.xls
========== Files - Modified Within 30 Days ========== [1 C:\WINDOWS\System32\*.tmp files]
[7 C:\WINDOWS\*.tmp files]
[2009/01/09 14:43:21 | 00,419,328 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTListIt2.exe
[2009/01/09 12:36:37 | 00,000,432 | ---- | M] () -- C:\WINDOWS\tasks\XoftSpySE 2.job
[2009/01/09 12:36:35 | 00,000,438 | ---- | M] () -- C:\WINDOWS\tasks\RegCure Program Check.job
[2009/01/09 12:36:30 | 00,002,500 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/01/09 12:35:39 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/01/09 12:35:36 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/01/09 00:51:15 | 09,089,400 | -H-- | M] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\IconCache.db
[2009/01/08 16:55:40 | 00,001,355 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009/01/08 14:30:22 | 00,268,052 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Rooter.exe
[2009/01/07 22:51:50 | 00,000,330 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/01/07 22:50:29 | 00,406,328 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/01/07 22:50:29 | 00,063,528 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/01/07 22:50:28 | 00,477,846 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/01/07 22:49:52 | 00,070,712 | ---- | M] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/01/07 22:48:14 | 00,251,880 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/01/07 22:38:28 | 00,250,048 | RHS- | M] () -- C:\ntldr
[2008/12/31 12:11:03 | 00,000,373 | ---- | M] () -- C:\WINDOWS\cdplayer.ini
[2008/12/26 14:27:27 | 00,001,602 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2008/12/18 09:33:14 | 00,045,568 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Copy of D1 28day schedule ending 01102009.xls
[2008/12/13 01:40:02 | 03,593,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\mshtml.dll
[2008/12/13 01:40:02 | 03,593,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mshtml.dll
[2008/12/10 21:50:00 | 00,000,355 | ---- | M] () -- C:\WINDOWS\LEXSTAT.INI
========== LOP Check ========== [2009/01/06 22:31:48 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data
[2008/12/30 21:52:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Adobe
[2008/02/06 16:08:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AOL
[2007/12/16 09:17:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AOL Downloads
[2007/04/04 14:12:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AOL OCP
[2008/10/02 10:56:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Apple
[2008/10/02 10:56:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Apple Computer
[2008/06/30 23:05:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Comcast
[2008/07/10 16:01:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FLEXnet
[2006/11/18 20:51:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Google
[2008/10/16 09:30:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Lavasoft
[2008/12/30 21:24:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/01/08 20:09:43 | 00,000,000 | --SD | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft
[2007/05/01 19:59:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2009/01/06 22:31:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2008/12/26 10:58:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SITEguard
[2008/10/16 09:48:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2008/12/26 11:36:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2009/01/05 20:37:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2007/08/30 14:29:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SupportSoft
[2006/12/08 21:12:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Trymedia
[2007/12/16 09:00:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2006/11/26 12:46:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2007/02/24 13:36:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\yahoo!
[2006/12/08 21:35:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
[2008/12/30 21:24:29 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\Owner\Application Data
[2008/02/06 16:11:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\acccore
[2008/12/30 21:52:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Adobe
[2008/05/11 22:25:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\AdobeUM
[2008/10/02 10:57:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Apple Computer
[2006/11/19 16:24:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Google
[2006/12/08 01:07:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Help
[2006/08/29 14:43:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Identities
[2008/12/26 11:31:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\IObit
[2006/12/07 01:06:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\KewlBoxPrefs
[2006/11/19 22:56:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Leadertech
[2006/12/18 19:36:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Macromedia
[2008/12/30 21:24:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Malwarebytes
[2009/01/08 12:23:31 | 00,000,000 | --SD | M] -- C:\Documents and Settings\Owner\Application Data\Microsoft
[2008/11/03 21:58:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Move Networks
[2008/09/11 08:40:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Mozilla
[2007/06/07 10:15:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Musicmatch
[2007/08/15 17:49:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Netscape
[2008/02/25 18:02:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Real
[2006/11/30 22:57:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Snapfish
[2006/11/19 22:56:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Sonic
[2006/09/01 15:21:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\Sun
[2009/01/05 20:37:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
[2008/09/30 11:27:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\U3
[2007/08/15 17:53:53 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Owner\Application Data\yahoo!
[2008/12/05 21:34:01 | 00,000,284 | ---- | M] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2001/08/18 07:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2009/01/07 22:51:50 | 00,000,330 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2009/01/09 12:36:35 | 00,000,438 | ---- | M] () -- C:\WINDOWS\Tasks\RegCure Program Check.job
[2008/07/24 02:01:28 | 00,000,372 | ---- | M] () -- C:\WINDOWS\Tasks\RegCure.job
[2009/01/09 12:35:39 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT
[2009/01/09 12:36:37 | 00,000,432 | ---- | M] () -- C:\WINDOWS\Tasks\XoftSpySE 2.job
[2008/11/03 08:04:53 | 00,000,362 | ---- | M] () -- C:\WINDOWS\Tasks\XoftSpySE.job
========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 0 bytes -> %UserProfile%\My Documents\Thumbs.db:encryptable
< End of report >
OTListIt Extras logfile created on: 1/9/2009 2:44:12 PM - Run
OTListIt2 by OldTimer - Version 1.0.3.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1014.07 Mb Total Physical Memory | 586.71 Mb Available Physical Memory | 57.86% Memory free
2.39 Gb Paging File | 1.96 Gb Available in Paging File | 82.14% Paging File free
Paging file location(s): c:\pagefile.sys 1524 3048;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 56.38 Gb Free Space | 75.66% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: OWNER-ED144E44C
Current User Name: Owner
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm [@ = chm.file] -- C:\WINDOWS\hh File not found
.hlp [@ = hlpfile] -- C:\WINDOWS\system32\winhlp32 File not found
.hta [@ = htafile] -- C:\WINDOWS\system32\mshta File not found
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore File not found
.inf [@ = inffile] -- C:\WINDOWS\system32\notepad File not found
.ini [@ = inifile] -- C:\WINDOWS\system32\notepad File not found
.js [@ = JSFile] -- C:\WINDOWS\system32\wscript File not found
.jse [@ = JSEFile] -- C:\WINDOWS\system32\wscript File not found
.reg [@ = regfile] -- C:\WINDOWS\regedit File not found
.txt [@ = txtfile] -- C:\WINDOWS\system32\notepad File not found
.vbe [@ = VBEFile] -- C:\WINDOWS\system32\wscript File not found
.vbs [@ = VBSFile] -- C:\WINDOWS\system32\wscript File not found
.wsf [@ = WSFFile] -- C:\WINDOWS\system32\wscript File not found
.wsh [@ = WSHFile] -- C:\WINDOWS\system32\wscript File not found
========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts]
========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 File not found
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 File not found
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 File not found
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 File not found
========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0076E1AC-9E7B-4B9F-A62A-4CC9511AD8E3}" = Zune Language Pack (FR)
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{13515135-48BB-4184-8C1F-2FAE0138E200}" = TBS WMP Plug-in
"{1F63ED0B-EDD2-4037-B6AB-1358C624AF48}" = Scan
"{205C26CB-6D52-458C-A87F-1EE77F9625C6}" = Intel® PRO Network Connections
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{24D7346D-D4B4-45E8-98EA-75EC14B42DD8}" = Adobe ExtendScript Toolkit 2
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java