OTListIt logfile created on: 1/16/2009 6:59:00 PM - Run
OTListIt2 by OldTimer - Version 1.0.3.0 Folder = C:\Documents and Settings\Kim\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.50 Gb Total Physical Memory | 0.96 Gb Available Physical Memory | 63.84% Memory free
2.11 Gb Paging File | 1.65 Gb Available in Paging File | 78.53% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 55.87 Gb Total Space | 8.15 Gb Free Space | 14.58% Space Free | Partition Type: NTFS
Drive D: | 48.83 Gb Total Space | 5.61 Gb Free Space | 11.49% Space Free | Partition Type: NTFS
Drive E: | 97.65 Gb Total Space | 26.17 Gb Free Space | 26.80% Space Free | Partition Type: NTFS
Drive F: | 47.85 Gb Total Space | 4.53 Gb Free Space | 9.47% Space Free | Partition Type: NTFS
Drive G: | 39.42 Gb Total Space | 24.55 Gb Free Space | 62.28% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: INTERNET
Current User Name: Kim
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\Hpqdirec.exe (Hewlett-Packard Co.)
C:\Documents and Settings\Kim\Desktop\OTListIt2.exe (OldTimer Tools)
========== (O23) Win32 Services (SafeList) ==========
(Apple Mobile Device [Disabled | Stopped]) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
(aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
(aswUpdSv [Auto | Running]) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
(avast! Antivirus [Auto | Running]) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
(avast! Mail Scanner [On_Demand | Running]) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
(avast! Web Scanner [On_Demand | Running]) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
(clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
(iPod Service [Disabled | Stopped]) -- C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
(JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
(MSSQLSERVER [Auto | Running]) -- C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe (Microsoft Corporation)
(MSSQLServerADHelper [On_Demand | Stopped]) -- C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe (Microsoft Corporation)
(NVSvc [Auto | Running]) -- C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
(Pml Driver HPZ12 [On_Demand | Stopped]) -- C:\WINDOWS\system32\HPZipm12.exe (HP)
(RoxLiveShare10 [Disabled | Stopped]) -- File not found
(SessionLauncher [Disabled | Stopped]) -- File not found
(SQLSERVERAGENT [On_Demand | Stopped]) -- C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlagent.EXE (Microsoft Corporation)
(usnjsvc [Disabled | Stopped]) -- C:\Program Files\MSN Messenger\usnsvc.exe (Microsoft Corporation)
(WMPNetworkSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
(Aavmker4 [System | Running]) -- C:\WINDOWS\system32\drivers\aavmker4.sys (ALWIL Software)
(aswFsBlk [Auto | Running]) -- C:\WINDOWS\system32\drivers\aswFsBlk.sys (ALWIL Software)
(aswMon2 [Auto | Running]) -- C:\WINDOWS\system32\drivers\aswmon2.sys (ALWIL Software)
(aswRdr [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\aswRdr.sys (ALWIL Software)
(aswSP [System | Running]) -- C:\WINDOWS\system32\drivers\aswSP.sys (ALWIL Software)
(aswTdi [System | Running]) -- C:\WINDOWS\system32\drivers\aswTdi.sys (ALWIL Software)
(Cdr4_xp [System | Running]) -- C:\WINDOWS\system32\drivers\cdr4_xp.sys (Sonic Solutions)
(Cdralw2k [System | Running]) -- C:\WINDOWS\system32\drivers\cdralw2k.sys (Sonic Solutions)
(ctsfm2k [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
(E100B [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\e100b325.sys (Intel Corporation)
(GEARAspiWDM [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
(HCF_MSFT [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\HCF_MSFT.sys (Conexant)
(HPZid412 [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\hpzid412.sys (HP)
(HPZipr12 [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\HPZipr12.sys (HP)
(HPZius12 [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\HPZius12.sys (HP)
(kbdhid [System | Running]) -- C:\WINDOWS\system32\drivers\kbdhid.sys (Microsoft Corporation)
(nv [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
(OMCI [System | Running]) -- C:\WINDOWS\system32\drivers\omci.sys (Dell Computer Corporation)
(ossrv [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
(P17 [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\P17.sys (Creative Technology Ltd.)
(PD0620VID [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\P0620Vid.sys (Creative Technology Ltd.)
(pfc [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
(PRISM_A02 [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\WUSB20XP.sys (GlobespanVirata, Inc.)
(Ptilink [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
(PxHelp20 [Boot | Running]) -- C:\WINDOWS\system32\drivers\pxhelp20.sys (Sonic Solutions)
(ROOTMODEM [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\rootmdm.sys (Microsoft Corporation)
(SASDIFSV [System | Running]) -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
(SASENUM [On_Demand | Running]) -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
(SASKUTIL [System | Running]) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
(Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
(SONYPVU1 [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\SONYPVU1.SYS (Sony Corporation)
(USBAAPL [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\usbaapl.sys (Apple, Inc.)
(usb_rndisx [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\usb8023x.sys (Microsoft Corporation)
(wceusbsh [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\wceusbsh.sys (Microsoft Corporation)
========== Standard Registry (All) ==========
========== Internet Explorer ==========
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.google.com/ie
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://ie.search.msn...st/srchcust.htm
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch =
http://us.rd.yahoo.com/customize/ie/defaul...rch/search.html
HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions =
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://search.yahoo.com/search?p={searchTe...-8&fr=b1ie7
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com
HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = www.direcwaysupport.com;192.168.0.*;127.0.0.1;<local>
O1 HOSTS File: (850 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.jizzonline.com
O1 - Hosts: 127.0.0.1 www.xnxxmovies.com
O1 - Hosts: 127.0.0.1 iwant18.com
O1 - Hosts: 127.0.0.1 www.sexhungryjoes.com
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll File not found
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - Reg Error: Key does not exist or could not be opened. File not found
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKCU\..\Toolbar: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar: (no name) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key does not exist or could not be opened. File not found
O3 - HKCU\..\Toolbar: (no name) - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - Reg Error: Key does not exist or could not be opened. File not found
O3 - HKCU\..\Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key does not exist or could not be opened. File not found
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKCU..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp (AOL LLC)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (Yahoo! Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe File not found
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe File not found
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe File not found
O9 - Extra 'Tools' menuitem : PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe File not found
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Sites: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Sites: (msn in My Computer)
O15 - HKCU\..Trusted Sites: objects.aol.com (* is out of zone range - 5)
O15 - HKCU\..Trusted Sites: 73 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {00000055-9980-0010-8000-00AA00389B71}
http://codecs.micros...cs/i386/fhg.CAB (Reg Error: Key does not exist or could not be opened.)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83}
http://upload.facebook.com/controls/2008.1...toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF}
http://www.ipix.com/viewers/ipixx.cab (iPIX ActiveX Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://fpdownload.macromedia.com/get/shock...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {4C57C98A-E582-46E4-8FD8-5EBDC94CEA39}
http://www.mindjet.c.../MjMmViewer.cab (Reg Error: Key does not exist or could not be opened.)
O16 - DPF: {8613571C-30D2-4BD4-9710-3DFDBADE8190}
https://umdpacs.umdn...l/amiviewer.cab (AMI Pictorial Control CWeb 2.1 SPa05)
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5}
https://umdpacs.umdn...tall/msxml4.cab (XML DOM Document 4.0)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {A8B3A7FE-9C8D-4F15-9B01-8805BDF43B1B}
https://umdpacs.umdn...l/amiviewer.cab (AMI Pictorial Control CWeb 2.1 SPa06)
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF}
http://messenger.msn.com/download/MsnMesse...pDownloader.cab (MsnMessengerSetupDownloadControl Class)
O16 - DPF: {B9A296D4-38AC-4566-8168-F7ACAF7D35E6}
http://imlive.com/Ch...VideoContol.cab (Eyeball Video Session Control)
O16 - DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab (Java Plug-in 1.5.0_05)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078}
http://www.symantec....ta/SymAData.cab (ActiveDataInfo Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://download.macromedia.com/pub/shockwa...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7}
https://www-secure.symantec.com/techsupp/ac.../ActiveData.cab (ActiveDataObj Class)
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6}
http://chat.msn.com/bin/msnchat45.cab (MSN Chat Control 4.5)
O16 - DPF: ChatSpace Full Java Client 3.1.0.235N
http://205.177.13.50...a/cfsn31235.cab (Reg Error: Key does not exist or could not be opened.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key does not exist or could not be opened.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key does not exist or could not be opened.)
O18 - Protocol\Handler: - about - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - cdl - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - cdo - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - dvd - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler: - file - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - ftp - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - gopher - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - http - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - http\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - http\oledb - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - https - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - https\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - https\oledb - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - ipp - No CLSID value found
O18 - Protocol\Handler: - ipp\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - its - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler: - javascript - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - livecall - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler: - local - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mailto - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mhtml - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mk - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler: - msdaipp - No CLSID value found
O18 - Protocol\Handler: - msdaipp\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - msdaipp\oledb - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - ms-its - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler: - msnim - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler: - mso-offdap - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler: - res - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - sysimage - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - tv - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler: - vbscript - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler: - wia - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/octet-stream - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-complus - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-msdownload - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - Class Install Handler - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - deflate - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - gzip - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - lzdhtml - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/webviewhtml - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O20 - See sections below for AppInitDlls and Winlogon settings
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9}C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9}C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153}C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5}C:\WINDOWS\system32\wpdshserviceobj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: (Browseui preloader) - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: (Component Categories cache daemon) - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
========== HKLM Winlogon Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell" = Explorer.exe
>C:\WINDOWS\explorer.exe (Microsoft Corporation)
"UserInit" = C:\WINDOWS\system32\userinit.exe,
>C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
"UIHost" = logonui.exe
>C:\WINDOWS\system32\logonui.exe (Microsoft Corporation)
"VMApplet" = rundll32 shell32,Control_RunDLL "sysdm.cpl"
>C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
>C:\WINDOWS\system32\sysdm.cpl (Microsoft Corporation)
========== Winlogon Notify Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\]
crypt32chain: "DllName" = crypt32.dll -- C:\WINDOWS\system32\crypt32.dll (Microsoft Corporation)
cryptnet: "DllName" = cryptnet.dll -- C:\WINDOWS\system32\cryptnet.dll (Microsoft Corporation)
cscdll: "DllName" = cscdll.dll -- C:\WINDOWS\system32\cscdll.dll (Microsoft Corporation)
dimsntfy: "DllName" = %SystemRoot%\System32\dimsntfy.dll -- C:\WINDOWS\system32\dimsntfy.dll (Microsoft Corporation)
ScCertProp: "DllName" = wlnotify.dll -- C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
Schedule: "DllName" = wlnotify.dll -- C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
sclgntfy: "DllName" = sclgntfy.dll -- C:\WINDOWS\system32\sclgntfy.dll (Microsoft Corporation)
SensLogn: "DllName" = WlNotify.dll -- C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
termsrv: "DllName" = wlnotify.dll -- C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
WgaLogon: "DllName" = WgaLogon.dll -- C:\WINDOWS\system32\WgaLogon.dll (Microsoft Corporation)
wlballoon: "DllName" = wlnotify.dll -- C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
========== IFEO "Debugger" Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\]
Your Image File Name Here without a path:"Debugger" = C:\WINDOWS\system32\ntsd.exe (Microsoft Corporation)
========== Shell Execute Hooks ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}" (HKLM) -- C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}" (HKLM) -- C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
========== HKLM *SecurityProviders* ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders]
"SecurityProviders" = msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll
>C:\WINDOWS\system32\msapsspc.dll (Microsoft Corporation)
>C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
>C:\WINDOWS\system32\digest.dll (Microsoft Corporation)
>C:\WINDOWS\system32\msnsspc.dll (Microsoft Corporation)
========== LSA *Authentication Packages* ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Authentication Packages" = msv1_0,
>C:\WINDOWS\system32\msv1_0.dll (Microsoft Corporation)
========== LSA *Security Packages* ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Security Packages" = kerberos,msv1_0,schannel,wdigest,
>C:\WINDOWS\system32\kerberos.dll (Microsoft Corporation)
>C:\WINDOWS\system32\msv1_0.dll (Microsoft Corporation)
>C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
>C:\WINDOWS\system32\wdigest.dll (Microsoft Corporation)
========== Safeboot Options ==========
"AlternateShell" = cmd.exe
========== CDRom AutoRun Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1
========== Autorun Files on Drives ==========
AUTOEXEC.BAT []
C:\AUTOEXEC.BAT () -- [ NTFS ]
========== Files/Folders - Created Within 30 Days ==========
[4 C:\WINDOWS\*.tmp files]
[2009/01/16 11:25:35 | 00,419,328 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Kim\Desktop\OTListIt2.exe
[2009/01/15 19:10:05 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Kim\Desktop\Endoscopic Access to ITF
[2009/01/15 17:53:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Kim\Desktop\Lothrop Procedure
[2009/01/15 15:49:31 | 00,019,968 | ---- | C] () -- C:\Documents and Settings\Kim\Desktop\pulled.doc
[2009/01/15 13:02:55 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Kim\Desktop\Mucinous Carcinoma
[2009/01/13 08:14:13 | 00,042,266 | ---- | C] () -- C:\Documents and Settings\Kim\Desktop\me4.jpg
[2009/01/13 08:13:01 | 00,039,971 | ---- | C] () -- C:\Documents and Settings\Kim\Desktop\me3.jpg
[2009/01/13 08:10:07 | 00,027,668 | ---- | C] () -- C:\Documents and Settings\Kim\Desktop\me2.jpg
[2009/01/13 08:09:24 | 00,043,645 | ---- | C] () -- C:\Documents and Settings\Kim\Desktop\me1.jpg
[2009/01/12 11:00:12 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft ActiveSync
[2009/01/12 10:42:54 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/01/12 10:42:49 | 00,000,695 | ---- | C] () -- C:\Documents and Settings\Kim\Desktop\SpywareBlaster.lnk
[2009/01/12 10:42:46 | 00,000,000 | ---D | C] -- C:\Program Files\SpywareBlaster
[2009/01/12 10:41:23 | 00,000,000 | ---D | C] -- C:\Program Files\Sunbelt Software
[2009/01/12 10:13:44 | 00,180,736 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Kim\Desktop\OTCleanIt.exe
[2009/01/12 09:29:46 | 00,001,714 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/01/12 09:29:45 | 00,023,152 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2009/01/12 09:29:44 | 00,050,864 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2009/01/12 09:29:43 | 00,026,944 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2009/01/12 09:29:40 | 00,097,480 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\AvastSS.scr
[2009/01/12 09:29:38 | 00,111,184 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2009/01/12 09:29:38 | 00,094,032 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2009/01/12 09:29:38 | 00,093,296 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2009/01/12 09:29:38 | 00,020,560 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2009/01/12 09:29:12 | 01,236,208 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\aswBoot.exe
[2009/01/12 09:29:12 | 00,380,928 | ---- | C] () -- C:\WINDOWS\System32\actskin4.ocx
[2009/01/12 09:29:09 | 00,000,000 | ---D | C] -- C:\Program Files\Alwil Software
[2009/01/12 09:14:23 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Avg8
[2009/01/12 09:09:26 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2009/01/12 09:09:20 | 00,000,785 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/01/12 09:09:17 | 00,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2009/01/12 09:09:17 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Kim\Application Data\SUPERAntiSpyware.com
[2009/01/12 09:06:52 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard
[2009/01/12 06:46:02 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Kim\Application Data\Malwarebytes
[2009/01/12 06:45:59 | 00,000,701 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/01/12 06:45:58 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/01/12 06:45:56 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/01/12 06:45:55 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/01/12 06:45:55 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/01/12 06:40:06 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/01/12 06:39:02 | 00,000,616 | ---- | C] () -- C:\Documents and Settings\Kim\Desktop\NTREGOPT.lnk
[2009/01/12 06:39:02 | 00,000,597 | ---- | C] () -- C:\Documents and Settings\Kim\Desktop\ERUNT.lnk
[2009/01/12 06:38:58 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/01/12 06:37:50 | 00,021,504 | ---- | C] (Doug Knox) -- C:\Documents and Settings\Kim\Desktop\SysRestorePoint.exe
[2009/01/10 12:45:02 | 00,001,739 | ---- | C] () -- C:\Documents and Settings\Kim\Desktop\HijackThis.lnk
[2009/01/10 12:44:58 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2009/01/09 11:09:53 | 00,000,000 | ---D | C] -- C:\Program Files\YPOPs
[2009/01/08 13:51:54 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Kim\Application Data\BookmarkBridge
[2009/01/05 06:05:32 | 00,002,137 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/01/05 06:04:30 | 00,000,000 | ---D | C] -- C:\Program Files\iPod
[2009/01/05 06:04:21 | 00,000,000 | ---D | C] -- C:\Program Files\iTunes
[2009/01/05 06:04:21 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2009/01/01 22:10:44 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Kim\Desktop\NYE 2009
[2009/01/01 22:08:22 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Kim\Desktop\Atlantic City 2008
[2009/01/01 09:11:57 | 02,205,067 | ---- | C] () -- C:\Documents and Settings\Kim\Desktop\2008 110.jpg
========== Files - Modified Within 30 Days ==========
[10 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[2009/01/16 18:33:27 | 00,002,626 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2009/01/16 12:13:44 | 00,000,494 | ---- | M] () -- C:\hpfr5550.xml
[2009/01/16 11:25:36 | 00,419,328 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Kim\Desktop\OTListIt2.exe
[2009/01/15 20:33:01 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/01/15 15:55:20 | 00,019,968 | ---- | M] () -- C:\Documents and Settings\Kim\Desktop\pulled.doc
[2009/01/15 14:59:39 | 00,681,472 | -HS- | M] () -- C:\Documents and Settings\Kim\Desktop\Thumbs.db
[2009/01/14 14:38:56 | 00,000,776 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/01/14 14:38:56 | 00,000,272 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/01/14 14:38:56 | 00,000,211 | -HS- | M] () -- C:\boot.ini
[2009/01/14 14:37:14 | 00,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/01/14 14:15:24 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/01/14 14:15:18 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/01/14 14:15:16 | 16,096,37888 | -HS- | M] () -- C:\hiberfil.sys
[2009/01/13 11:57:39 | 00,104,448 | ---- | M] () -- C:\Documents and Settings\Kim\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/01/13 08:13:01 | 00,039,971 | ---- | M] () -- C:\Documents and Settings\Kim\Desktop\me3.jpg
[2009/01/13 08:10:07 | 00,027,668 | ---- | M] () -- C:\Documents and Settings\Kim\Desktop\me2.jpg
[2009/01/13 08:09:24 | 00,043,645 | ---- | M] () -- C:\Documents and Settings\Kim\Desktop\me1.jpg
[2009/01/13 08:05:02 | 00,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2009/01/12 15:55:02 | 00,688,604 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/01/12 15:55:02 | 00,552,488 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/01/12 15:55:02 | 00,123,390 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/01/12 10:42:49 | 00,000,695 | ---- | M] () -- C:\Documents and Settings\Kim\Desktop\SpywareBlaster.lnk
[2009/01/12 10:13:50 | 00,180,736 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Kim\Desktop\OTCleanIt.exe
[2009/01/12 09:29:46 | 00,001,714 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/01/12 09:09:20 | 00,000,785 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/01/12 06:45:59 | 00,000,701 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/01/12 06:39:02 | 00,000,616 | ---- | M] () -- C:\Documents and Settings\Kim\Desktop\NTREGOPT.lnk
[2009/01/12 06:39:02 | 00,000,597 | ---- | M] () -- C:\Documents and Settings\Kim\Desktop\ERUNT.lnk
[2009/01/10 12:45:02 | 00,001,739 | ---- | M] () -- C:\Documents and Settings\Kim\Desktop\HijackThis.lnk
[2009/01/10 12:40:04 | 00,000,544 | ---- | M] () -- C:\Documents and Settings\Kim\My Documents\My Sharing Folders.lnk
[2009/01/09 20:35:28 | 20,853,704 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009/01/06 03:29:15 | 00,002,137 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/01/04 18:38:22 | 00,038,496 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/01/04 18:38:18 | 00,015,504 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/01/01 22:14:08 | 02,205,067 | ---- | M] () -- C:\Documents and Settings\Kim\Desktop\2008 110.jpg
[2008/12/30 00:41:20 | 00,000,287 | ---- | M] () -- C:\WINDOWS\wininit.ini
[2008/12/18 21:01:19 | 00,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
========== LOP Check ==========
[2009/01/12 10:42:54 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data
[2009/01/05 06:05:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2008/08/27 20:36:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\acccore
[2008/02/02 01:38:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Adobe
[2008/01/01 19:12:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ahead
[2008/08/18 23:41:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AOL
[2008/02/18 00:49:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AOL Downloads
[2007/06/03 03:39:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AOL OCP
[2007/07/04 16:45:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Apple
[2006/12/30 14:24:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/01/12 09:14:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Avg8
[2006/03/06 20:16:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DIGStream
[2008/01/06 12:44:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\InstallShield
[2004/10/24 19:40:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ipswitch
[2009/01/12 06:45:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2006/02/15 22:11:30 | 00,000,000 | --SD | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft
[2005/03/26 18:15:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MSN6
[2004/11/20 18:33:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Napster
[2007/10/06 23:35:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Pinnacle
[2005/06/20 22:18:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\QuickTime
[2008/08/19 01:20:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Roxio
[2008/01/06 12:54:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc
[2008/01/06 12:51:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sonic
[2009/01/12 09:17:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/01/12 09:09:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2005/11/21 23:27:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Symantec
[2009/01/12 15:08:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/01/12 06:05:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2006/07/29 21:20:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/09/26 22:48:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Yahoo!
[2009/01/12 09:09:17 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Kim\Application Data
[2005/10/18 19:00:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\.gaim
[2008/08/27 20:39:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\acccore
[2007/12/13 00:03:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\Adobe
[2008/05/21 06:16:15 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\AdobeUM
[2005/10/26 18:04:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\Ahead
[2007/05/24 01:25:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\Aim
[2009/01/08 13:43:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\Apple Computer
[2008/05/24 10:56:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\BitTorrent
[2009/01/08 13:52:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\BookmarkBridge
[2007/01/26 20:03:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\Creative
[2005/10/07 13:00:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\CyberLink
[2007/02/08 23:03:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\Digitope
[2007/12/30 21:50:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\DivX
[2008/01/01 19:04:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\DVD Flick
[2007/12/25 14:09:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\Facebook
[2007/10/07 20:11:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\FileZilla
[2007/07/15 21:42:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\Grisoft
[2005/10/10 15:39:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\Help
[2005/02/15 23:07:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\Hewlett-Packard
[2004/10/24 19:00:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\Identities
[2007/12/30 14:39:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\ImgBurn
[2004/10/24 19:40:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\Ipswitch
[2009/01/05 04:34:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\Lavasoft
[2005/10/11 10:31:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\Leadertech
[2004/10/30 19:44:09 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\Macromedia
[2009/01/12 06:46:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\Malwarebytes
[2009/01/05 05:31:54 | 00,000,000 | --SD | M] -- C:\Documents and Settings\Kim\Application Data\Microsoft
[2007/02/24 20:33:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\Mobipocket
[2008/09/01 09:39:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\Mozilla
[2005/03/26 18:15:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\MSN6
[2007/02/22 21:16:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\MySpace
[2007/11/11 23:05:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\NPresenter
[2005/10/15 13:47:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\Publish Providers
[2005/08/06 11:38:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\Real
[2008/01/06 13:20:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\Roxio
[2005/10/15 13:47:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\Sony
[2008/01/07 21:04:16 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\Sony Corporation
[2008/01/15 18:56:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\Sony Setup
[2007/10/06 23:42:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\Steinberg
[2005/08/08 18:24:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\Sun
[2009/01/12 09:09:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\SUPERAntiSpyware.com
[2005/10/10 19:42:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\Symantec
[2005/10/26 17:50:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\Syntrillium
[2007/04/05 16:22:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\Walgreens
[2008/01/06 11:59:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\WinRAR
[2008/09/26 22:48:57 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Kim\Application Data\yahoo!
[2007/09/10 23:08:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Kim\Application Data\Yahoo! Messenger
[2009/01/15 20:33:01 | 00,000,284 | ---- | M] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2002/08/29 07:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2005/04/26 04:44:36 | 00,000,350 | ---- | M] () -- C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp officejet 6100 series#1098664698.job
[2009/01/14 14:15:24 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 120 bytes -> %AllUsersProfile%\Application Data\TEMP:5C321E34
@Alternate Data Stream - 0 bytes -> %UserProfile%\My Documents\Thumbs.db:encryptable
@Alternate Data Stream - 0 bytes -> %UserProfile%\Desktop\Thumbs.db:encryptable
< End of report >