Ahhhh, OTViewIt worked! The .txt file is as follows:
OTViewIt logfile created on: 1/14/2009 8:59:29 PM - Run
OTViewIt by OldTimer - Version 1.0.21.0 Folder = C:\Documents and Settings\MD\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1022.41 Mb Total Physical Memory | 389.76 Mb Available Physical Memory | 38.12% Memory free
2.40 Gb Paging File | 1.97 Gb Available in Paging File | 81.89% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 232.88 Gb Total Space | 73.93 Gb Free Space | 31.75% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 279.47 Gb Total Space | 31.55 Gb Free Space | 11.29% Space Free | Partition Type: NTFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive V: | 400.60 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: NIGHTCRAWLER
Current User Name: MD
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Whitelist: On
File Age = 30 Days
========== Processes ========== [2008/09/23 18:53:28 | 00,231,704 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe
[2007/09/17 00:07:00 | 00,155,716 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe
[2004/02/06 22:56:14 | 00,041,025 | ---- | M] (GEMTEKS) -- C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
[2004/05/04 17:37:00 | 05,208,576 | ---- | M] (Linksys) -- C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv4.exe
[2008/09/23 18:53:30 | 00,287,000 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgrsx.exe
[2005/09/12 19:25:32 | 00,077,824 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SOUNDMAN.EXE
[2004/11/02 20:24:46 | 00,032,768 | ---- | M] (Cyberlink Corp.) -- C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[2008/06/10 03:27:04 | 00,144,784 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
[2006/10/12 20:27:20 | 00,304,640 | ---- | M] (Realtime Soft) -- C:\Program Files\UltraMon\UltraMon.exe
[2008/04/13 16:12:33 | 00,033,280 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\rundll32.exe
[2008/11/27 09:47:08 | 01,261,336 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgtray.exe
[2008/12/03 00:46:45 | 00,185,872 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[2008/12/17 09:10:37 | 00,307,704 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
[2009/01/14 20:59:12 | 00,422,912 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\MD\Desktop\OTViewIt.exe
========== (O23) Win32 Services ========== [2006/01/10 02:01:27 | 00,068,096 | ---- | M] () -- C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe -- (Adobe LM Service [On_Demand | Stopped])
[2008/09/23 18:53:28 | 00,231,704 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe -- (avg8wd [Auto | Running])
[2007/01/03 17:40:21 | 00,136,120 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [On_Demand | Stopped])
[2005/11/14 01:06:04 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
[2007/09/17 00:07:00 | 00,155,716 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc [Auto | Running])
[2003/07/28 12:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
[2007/03/25 21:58:37 | 01,174,152 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe -- (Symantec Core LC [Auto | Stopped])
[2006/10/18 19:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc [Auto | Stopped])
File not found -- -- (WUSB54Gv4SVC [Auto | Running])
========== Driver Services ========== [2006/01/12 01:43:10 | 00,019,915 | ---- | M] (Meetinghouse Data Communications) -- C:\WINDOWS\system32\drivers\AegisP.sys -- (AegisP [Auto | Running])
[2005/09/12 19:25:26 | 02,319,680 | R--- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM [On_Demand | Running])
[2008/09/23 18:53:39 | 00,097,928 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (AvgLdx86 [System | Running])
[2008/09/23 18:53:38 | 00,026,824 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (AvgMfx86 [System | Running])
[2005/02/01 18:18:38 | 00,017,992 | ---- | M] (Broadcom Corporation) -- C:\WINDOWS\system32\bcm42rly.sys -- (BCM42RLY [On_Demand | Stopped])
[2003/11/25 07:50:00 | 00,003,151 | ---- | M] (hiyohiyo) -- C:\Program Files\OCCT\CpuInfo.sys -- (CrystalCpuInfo [On_Demand | Stopped])
[2006/01/05 21:26:22 | 00,223,128 | ---- | M] () -- C:\WINDOWS\system32\drivers\dtscsi.sys -- (dtscsi [On_Demand | Running])
[2005/05/03 07:34:02 | 00,027,392 | ---- | M] (SlySoft, Inc.) -- C:\WINDOWS\system32\drivers\ElbyCDFL.sys -- (ElbyCDFL [On_Demand | Running])
[2005/04/21 03:40:36 | 00,010,624 | ---- | M] (Elaborate Bytes AG) -- C:\WINDOWS\system32\drivers\ElbyCDIO.sys -- (ElbyCDIO [Auto | Running])
[2004/10/25 20:02:00 | 00,021,664 | ---- | M] (EnTech Taiwan) -- C:\WINDOWS\system32\drivers\Entech.sys -- (ENTECH [On_Demand | Stopped])
[2009/01/13 21:00:14 | 00,085,969 | ---- | M] (GMER) -- C:\WINDOWS\system32\drivers\gmer.sys -- (gmer [On_Demand | Stopped])
[2004/03/03 21:30:54 | 00,005,504 | ---- | M] (Ahead Software AG) -- C:\WINDOWS\system32\drivers\imagedrv.sys -- (imagedrv [Boot | Running])
[2004/03/03 21:30:54 | 00,125,184 | ---- | M] (Ahead Software AG) -- C:\WINDOWS\system32\drivers\imagesrv.sys -- (imagesrv [Boot | Running])
[2001/08/17 05:51:32 | 00,018,688 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\irsir.sys -- (irsir [On_Demand | Running])
[2008/04/13 10:39:48 | 00,014,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\kbdhid.sys -- (kbdhid [System | Running])
[2007/09/17 00:07:00 | 06,853,088 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv [On_Demand | Running])
[2005/09/12 19:26:36 | 00,053,376 | R--- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\drivers\nvax.sys -- (nvax [On_Demand | Stopped])
[2005/09/12 19:26:46 | 00,033,536 | R--- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD [On_Demand | Running])
[2005/09/12 19:26:46 | 00,012,928 | R--- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus [On_Demand | Running])
[2005/09/12 19:26:36 | 00,414,464 | R--- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\drivers\nvapu.sys -- (nvnforce [On_Demand | Stopped])
[2004/08/04 04:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink [On_Demand | Running])
[2006/09/27 13:53:22 | 00,036,560 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\system32\drivers\pxhelp20.sys -- (PxHelp20 [Boot | Running])
[2005/10/19 23:00:04 | 00,243,328 | R--- | M] (Ralink Technology Inc.) -- C:\WINDOWS\system32\drivers\RT2500.sys -- (RT2500 [On_Demand | Stopped])
[2007/01/19 23:11:07 | 00,031,644 | ---- | M] (PowerISO Computing, Inc.) -- C:\WINDOWS\System32\drivers\scdemu.sys -- (SCDEmu [System | Running])
[2007/11/13 02:25:53 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv [On_Demand | Stopped])
[2006/01/05 21:15:14 | 00,664,064 | ---- | M] () -- C:\WINDOWS\system32\drivers\sptd.sys -- (sptd [Boot | Running])
[2007/02/15 13:14:28 | 00,019,840 | ---- | M] (Generic) -- C:\WINDOWS\system32\drivers\StMp3Rec.sys -- (StMp3Rec [On_Demand | Stopped])
[2006/01/06 14:33:51 | 00,010,344 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\symlcbrd.sys -- (symlcbrd [Auto | Running])
[2006/09/24 20:23:14 | 00,003,584 | ---- | M] (Realtime Soft) -- C:\WINDOWS\system32\drivers\UltraMonMirror.sys -- (UltraMonMirror [On_Demand | Running])
[2006/09/24 20:22:52 | 00,011,776 | ---- | M] (Realtime Soft) -- C:\Program Files\Common Files\Realtime Soft\UltraMonMirrorDrv\x32\UltraMonUtility.sys -- (UltraMonUtility [Auto | Running])
[2002/11/02 16:40:06 | 00,090,496 | R--- | M] (ATMEL) -- C:\WINDOWS\system32\drivers\WLUSBXP2.sys -- (USBFVNETR [On_Demand | Stopped])
[2004/08/04 04:00:00 | 00,012,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\ws2ifsl.sys -- (WS2IFSL [System | Running])
[2004/05/04 17:25:00 | 00,239,488 | R--- | M] (Ralink Technology Inc.) -- C:\WINDOWS\system32\drivers\rt2500usb.sys -- (WUSB54GPV4SRV [On_Demand | Stopped])
[2004/08/19 07:21:00 | 00,189,568 | ---- | M] (Marvell) -- C:\WINDOWS\system32\drivers\yk51x86.sys -- (yukonwxp [On_Demand | Stopped])
========== (R ) Internet Explorer ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]
"Default_Page_URL"=http://go.microsoft.com/fwlink/?LinkId=69157
"Default_Search_URL"=http://go.microsoft.com/fwlink/?LinkId=54896
"Local Page"=%SystemRoot%\system32\blank.htm
"Search Page"=http://go.microsoft.com/fwlink/?LinkId=54896
"Start Page"=http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search]
"CustomizeSearch"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
"SearchAssistant"=http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main]
"Local Page"=C:\WINDOWS\system32\blank.htm
"Search Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
"Start Page"=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURL]
"provider"=
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" (HKLM) -- C:\WINDOWS\system32\shdocvw.dll (Microsoft Corporation)
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = 0
========== (O1) Hosts File ========== HOSTS File = (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
First 25 entries...
127.0.0.1 localhost
========== (O2) BHO's ========== [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (HKLM) -- C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
{3049C3E9-B461-4BC5-8870-4C09146192CA} (HKLM) -- C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} (HKLM) -- C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (HKLM) -- C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
{A057A204-BACC-4D26-9990-79A187E2698E} (HKLM) -- C:\Program Files\AVG\AVG8\avgtoolbar.dll (AVG, Technologies CZ, s.r.o )
========== (O3) Toolbars ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
"{A057A204-BACC-4D26-9990-79A187E2698E}" (HKLM) -- C:\Program Files\AVG\AVG8\avgtoolbar.dll (AVG, Technologies CZ, s.r.o )
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{C4069E3A-68F1-403E-B40E-20066696354B}" (HKLM) -- Reg Error: Key does not exist or could not be opened. File not found
"{A057A204-BACC-4D26-9990-79A187E2698E}" (HKLM) -- C:\Program Files\AVG\AVG8\avgtoolbar.dll (AVG, Technologies CZ, s.r.o )
========== (O4) Run Keys ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
"CloneCDTray"="C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s (SlySoft, Inc.)
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
"NvCplDaemon"=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
"NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\\nTune.exe" clear (NVIDIA)
"NvMediaCenter"=RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
"NVMixerTray"="C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" (NVIDIA Corporation)
"nwiz"=nwiz.exe /install ()
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" (Cyberlink Corp.)
"SoundMan"=SOUNDMAN.EXE (Realtek Semiconductor Corp.)
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" (Sun Microsystems, Inc.)
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)
"UltraMon"="C:\Program Files\UltraMon\UltraMon.exe" /auto (Realtime Soft)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1 (Adobe Systems Incorporated)
========== (O4) Startup Folders ========== [1999/11/04 15:06:48 | 00,113,664 | ---- | M] (Adobe Systems, Inc.) -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
[2005/09/23 22:05:26 | 00,029,696 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
========== (O6 & O7) Current Version Policies ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveAutoRun"=67108863
"NoDriveTypeAutoRun"=323
"NoDrives"=0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"DisableRegistryTools"=0
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
========== (O8) IE Context Menu Extensions ========== [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\]
E&xport to Microsoft Excel: C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE [2003/08/13 02:34:38 | 10,073,144 | ---- | M] (Microsoft Corporation)
========== (O9) IE Extensions ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}: Menu: Sun Java Console -- %ProgramFiles%\Java\jre1.6.0_07\bin\npjpi160_07.dll [2008/06/10 03:27:02 | 00,132,496 | ---- | M] (Sun Microsystems, Inc.)
{92780B25-18CC-41C8-B9BE-3C9C571A8263}: Button: Research -- %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [2003/07/14 22:57:08 | 00,040,512 | ---- | M] (Microsoft Corporation)
{B13B4423-2647-4cfc-A4B3-C7D56CB83487}: Button: Share in Hello -- %ProgramFiles%\Hello\PicasaCapture.dll [2005/01/11 18:09:26 | 00,303,104 | ---- | M] (Picasa, Inc.)
{B13B4423-2647-4cfc-A4B3-C7D56CB83487}: Menu: Share in H&ello -- %ProgramFiles%\Hello\PicasaCapture.dll [2005/01/11 18:09:26 | 00,303,104 | ---- | M] (Picasa, Inc.)
{e2e2dd38-d088-4134-82b7-f2ba38496583}: Menu: @xpsp3res.dll,-20001 -- %SystemRoot%\network diagnostic\xpnetdiag.exe [2008/04/13 10:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Button: Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2008/04/13 16:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}: Menu: Windows Messenger -- %ProgramFiles%\Messenger\msmsgs.exe [2008/04/13 16:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\]
CmdMapping\\{08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_07\bin\npjpi160_07.dll [Sun Java Console] -> [2008/06/10 03:27:02 | 00,132,496 | ---- | M] (Sun Microsystems, Inc.)
CmdMapping\\{461CC20B-FB6E-4f16-8FE8-C29359DB100E} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{92780B25-18CC-41C8-B9BE-3C9C571A8263} [HKLM] -> %ProgramFiles%\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2003/07/14 22:57:08 | 00,040,512 | ---- | M] (Microsoft Corporation)
CmdMapping\\{B13B4423-2647-4cfc-A4B3-C7D56CB83487} [HKLM] -> %ProgramFiles%\Hello\PicasaCapture.dll [IECmdExecute Class] -> [2005/01/11 18:09:26 | 00,303,104 | ---- | M] (Picasa, Inc.)
CmdMapping\\{D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} [HKLM] -> [Reg Error: Key does not exist or could not be opened.] -> File not found
CmdMapping\\{e2e2dd38-d088-4134-82b7-f2ba38496583} [HKLM] -> %SystemRoot%\network diagnostic\xpnetdiag.exe [@xpsp3res.dll,-20001] -> [2008/04/13 10:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation)
CmdMapping\\{FB5F1910-F110-11d2-BB9E-00C04F795683} [HKLM] -> %ProgramFiles%\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 16:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)
========== (O12) Internet Explorer Plugins ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\]
PluginsPage: "" =
http://activex.micro...d...=%s&mime=%sPluginsPageFriendlyName: "" = Microsoft ActiveX Gallery
========== (O13) Default Prefixes ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix]
""=http://
========== (O15) Trusted Sites ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\]
1 domain(s) and sub-domain(s) not assigned to a zone.
========== (O16) DPF ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\]
{238F6F83-B8B4-11CF-8771-00A024541EE3}:
https://desktop.pill...ca32/wficat.cab -- Citrix ICA Client
{7F8C8173-AD80-4807-AA75-5672F22B4582}:
http://download.zone...anner371420.cab -- ICSScanner Class
{8AD9C840-044E-11D1-B3E9-00805F499D93}:
http://java.sun.com/...indows-i586.cab -- Java Plug-in 1.6.0_07
{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}:
http://java.sun.com/...indows-i586.cab -- Java Plug-in 1.5.0_06
{CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}:
http://java.sun.com/...indows-i586.cab -- Java Plug-in 1.5.0_11
{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}:
http://java.sun.com/...indows-i586.cab -- Java Plug-in 1.6.0_01
{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}:
http://java.sun.com/...indows-i586.cab -- Java Plug-in 1.6.0_03
{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:
http://java.sun.com/...indows-i586.cab -- Java Plug-in 1.6.0_05
{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:
http://java.sun.com/...indows-i586.cab -- Java Plug-in 1.6.0_07
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}:
http://java.sun.com/...indows-i586.cab -- Java Plug-in 1.6.0_07
{D27CDB6E-AE6D-11CF-96B8-444553540000}:
http://fpdownload.ma...ash/swflash.cab -- Shockwave Flash Object
========== (O17) DNS Name Servers ========== {1D518D19-F9C8-45FA-A495-7A3292CB9A16} (Servers: | Description: Compex iWavePort WLU11A Mod2)
{3AA7DD55-83CE-4C3A-82ED-F845AEEAEE63} (Servers: | Description: Marvell Yukon 88E8001/8003/8010 PCI Gigabit Ethernet Controller)
{684C85FE-D5EF-40A8-A7AD-F34BD6637623} (Servers: | Description: Linksys Wireless-G PCI Adapter)
{9B22FA66-3812-4B36-88C7-DC43A1EC6AC0} (Servers: | Description: 1394 Net Adapter)
{B4D893FF-E36A-47EA-AE79-929083227F37} (Servers: | Description: Linksys Wireless-G USB Network Adapter)
{F13C56DC-6F2F-4FC0-B572-357AE40C41A5} (Servers: | Description: )
========== Safeboot Options ========== "AlternateShell"=cmd.exe
========== CDRom AutoRun Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1
========== Autorun Files on Drives ========== AUTOEXEC.BAT []
[2006/01/04 22:20:36 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT -- [ NTFS ]
AUTORUN.INF [[autorun] | OPEN=SETUP.EXE /AUTORUN | ICON=SETUP.EXE,1 | | shell\configure=&Configure... | shell\configure\command=SETUP.EXE | | shell\install=&Install... | shell\install\command=SETUP.EXE | ]
[2003/08/14 18:13:50 | 00,000,184 | RH-- | M] () -- V:\AUTORUN.INF -- [ CDFS ]
========== MountPoints2 ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4df0b066-a7bf-11da-8d4f-000129d3cb90}\Shell\AutoRun\command]
""=D:\setupSNK.exe -- File not found
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{74d07948-7db8-11da-94a6-806d6172696f}\Shell]
""=AutoRun
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{74d07948-7db8-11da-94a6-806d6172696f}\Shell\AutoRun]
""=Auto&Play
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{74d07948-7db8-11da-94a6-806d6172696f}\Shell\AutoRun\command]
""=D:\SETUP.EXE -- File not found
========== Files/Folders - Created Within 30 Days ========== [4 C:\WINDOWS\*.tmp files]
[2009/01/14 20:48:40 | 00,422,912 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\MD\Desktop\OTViewIt.exe
[2009/01/13 21:17:50 | 00,000,000 | ---D | C] -- C:\rsit
[2009/01/13 21:17:37 | 00,781,851 | ---- | C] () -- C:\Documents and Settings\MD\Desktop\RSIT.exe
[2009/01/13 21:00:15 | 00,000,250 | ---- | C] () -- C:\WINDOWS\gmer.ini
[2009/01/13 21:00:14 | 00,884,736 | ---- | C] () -- C:\WINDOWS\gmer.dll
[2009/01/13 21:00:14 | 00,811,008 | ---- | C] () -- C:\WINDOWS\gmer.exe
[2009/01/13 21:00:14 | 00,085,969 | ---- | C] (GMER) -- C:\WINDOWS\System32\drivers\gmer.sys
[2009/01/13 21:00:14 | 00,000,080 | ---- | C] () -- C:\WINDOWS\gmer_uninstall.cmd
[2009/01/13 20:59:57 | 00,811,008 | ---- | C] () -- C:\Documents and Settings\MD\Desktop\gmer.exe
[2009/01/07 00:11:06 | 04,557,944 | ---- | C] (W3i, LLC) -- C:\Documents and Settings\MD\Desktop\ffdshow.exe
[2009/01/06 23:26:11 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/01/06 23:26:11 | 00,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/01/06 23:26:08 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/01/06 23:26:07 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/01/06 23:15:28 | 02,697,296 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\MD\Desktop\mbam-setup.exe
[2009/01/06 23:11:07 | 00,000,000 | ---D | C] -- C:\BACKUP REGISTRY
[2009/01/06 23:10:28 | 00,000,611 | ---- | C] () -- C:\Documents and Settings\MD\Desktop\NTREGOPT.lnk
[2009/01/06 23:10:27 | 00,000,592 | ---- | C] () -- C:\Documents and Settings\MD\Desktop\ERUNT.lnk
[2009/01/06 23:10:23 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/01/06 23:09:42 | 00,791,393 | ---- | C] (Lars Hederer ) -- C:\Documents and Settings\MD\Desktop\erunt_setup.exe
[2009/01/06 23:09:10 | 00,000,000 | -HSD | C] -- C:\RECYCLER
[2009/01/06 23:03:39 | 00,401,720 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\MD\Desktop\HiJackThis.exe
[2009/01/06 22:42:00 | 00,000,000 | ---D | C] -- C:\WINDOWS\temp
[2009/01/06 22:38:23 | 00,000,000 | ---D | C] -- C:\ComboFix
[2009/01/06 21:50:01 | 00,000,000 | ---D | C] -- C:\SAV32CLI
[2009/01/06 21:40:02 | 00,000,211 | ---- | C] () -- C:\Boot.bak
[2009/01/06 21:39:59 | 00,260,272 | ---- | C] () -- C:\cmldr
[2009/01/06 21:39:54 | 00,000,000 | ---D | C] -- C:\cmdcons
[2009/01/06 21:39:00 | 00,028,672 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2009/01/06 21:38:59 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2009/01/06 21:38:59 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2009/01/06 21:38:59 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2009/01/06 21:38:59 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2009/01/06 21:38:59 | 00,089,504 | ---- | C] (Smallfrogs Studio) -- C:\WINDOWS\fdsv.exe
[2009/01/06 21:38:59 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2009/01/06 21:38:59 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2009/01/06 21:38:59 | 00,049,152 | ---- | C] () -- C:\WINDOWS\VFIND.exe
[2009/01/06 20:13:20 | 00,000,000 | ---D | C] -- C:\SDFix
[2009/01/06 20:13:07 | 01,529,241 | ---- | C] () -- C:\SDFix.exe
[2009/01/06 19:46:42 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/01/06 19:46:42 | 00,000,000 | ---D | C] -- C:\Qoobox
[2009/01/06 19:41:07 | 02,911,074 | R--- | C] () -- C:\Documents and Settings\MD\Desktop\ComboFix.exe
[2009/01/06 19:37:50 | 00,000,000 | ---D | C] -- C:\RESTORE
[2009/01/06 19:25:53 | 00,002,026 | ---- | C] () -- C:\VArestorepolicies.inf
[2009/01/06 19:24:27 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard
[2009/01/06 19:24:12 | 05,824,544 | ---- | C] () -- C:\Documents and Settings\MD\Desktop\SUPERAntiSpyware.exe
[2009/01/06 19:20:29 | 00,000,724 | ---- | C] () -- C:\Documents and Settings\MD\Desktop\Firefox.lnk
[2008/12/21 13:24:28 | 05,790,043 | ---- | C] () -- C:\Documents and Settings\MD\Desktop\Zoom.Player.Home.MAX.v6.00_CRKEXE.rar
[2008/12/17 13:05:26 | 00,000,000 | ---D | C] -- C:\spoolerlogs
========== Files - Modified Within 30 Days ========== [3 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[2009/01/14 20:59:12 | 00,422,912 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\MD\Desktop\OTViewIt.exe
[2009/01/14 02:55:39 | 31,971,582 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/01/13 21:47:36 | 00,012,598 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/01/13 21:47:25 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/01/13 21:17:37 | 00,781,851 | ---- | M] () -- C:\Documents and Settings\MD\Desktop\RSIT.exe
[2009/01/13 21:00:15 | 00,000,250 | ---- | M] () -- C:\WINDOWS\gmer.ini
[2009/01/13 21:00:14 | 00,884,736 | ---- | M] () -- C:\WINDOWS\gmer.dll
[2009/01/13 21:00:14 | 00,085,969 | ---- | M] (GMER) -- C:\WINDOWS\System32\drivers\gmer.sys
[2009/01/13 21:00:14 | 00,000,080 | ---- | M] () -- C:\WINDOWS\gmer_uninstall.cmd
[2009/01/13 20:46:12 | 00,050,725 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/01/07 00:11:07 | 04,557,944 | ---- | M] (W3i, LLC) -- C:\Documents and Settings\MD\Desktop\ffdshow.exe
[2009/01/06 23:26:11 | 00,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/01/06 23:15:30 | 02,697,296 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\MD\Desktop\mbam-setup.exe
[2009/01/06 23:10:28 | 00,000,611 | ---- | M] () -- C:\Documents and Settings\MD\Desktop\NTREGOPT.lnk
[2009/01/06 23:10:27 | 00,000,592 | ---- | M] () -- C:\Documents and Settings\MD\Desktop\ERUNT.lnk
[2009/01/06 23:09:42 | 00,791,393 | ---- | M] (Lars Hederer ) -- C:\Documents and Settings\MD\Desktop\erunt_setup.exe
[2009/01/06 23:03:39 | 00,401,720 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\MD\Desktop\HiJackThis.exe
[2009/01/06 22:40:47 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/01/06 21:40:02 | 00,000,281 | RHS- | M] () -- C:\boot.ini
[2009/01/06 21:38:37 | 02,911,074 | R--- | M] () -- C:\Documents and Settings\MD\Desktop\ComboFix.exe
[2009/01/06 21:29:57 | 00,096,384 | ---- | M] () -- C:\WINDOWS\System32\drivers\sptd3325.sys
[2009/01/06 20:13:10 | 01,529,241 | ---- | M] () -- C:\SDFix.exe
[2009/01/06 19:24:18 | 05,824,544 | ---- | M] () -- C:\Documents and Settings\MD\Desktop\SUPERAntiSpyware.exe
[2009/01/06 19:21:19 | 00,000,724 | ---- | M] () -- C:\Documents and Settings\MD\Desktop\Firefox.lnk
[2009/01/05 13:48:01 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/01/04 18:41:24 | 00,038,496 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/01/04 18:41:20 | 00,015,504 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/01/03 13:40:39 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2008/12/22 09:21:15 | 00,368,010 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2008/12/21 13:26:53 | 05,790,043 | ---- | M] () -- C:\Documents and Settings\MD\Desktop\Zoom.Player.Home.MAX.v6.00_CRKEXE.rar
< End of report >
---------------------Extras.txt file is in the next post.