Symptoms:
- McAfee "Buffer Overflow Blocked" at startup
- Windows Update disabled
- Web sites are blocked and IE is often redirected
- Regedit disabled (I can now access but changes aren't saved)
- Registry keys renamed to %fystem... vice %system...
- PWS.LDPinchIE pops up periodically in malware scans...I delete it and it returns
- McAfee AV unable to scan
- NOHH06760.exe appears periodically in malware scans...also returns after reboot
After days of working this, any/all help is appreciated. glrk
OTListIt logfile created on: 4/19/2009 2:39:35 PM - Run 2
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1022.98 Mb Total Physical Memory | 502.55 Mb Available Physical Memory | 49.13% Memory free
2.40 Gb Paging File | 2.00 Gb Available in Paging File | 83.23% Paging File free
Paging file location(s): c:\pagefile.sys 1536 3072;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 96.97 Gb Free Space | 65.07% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: MAINCOMPUTER
Current User Name: Mom and Dad
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe (ScanSoft, Inc.)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe (Roxio)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\MouseWare\system\em_exec.exe (Logitech Inc.)
PRC - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe ()
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\WINDOWS\system32\CTsvcCDA.exe (Creative Technology Ltd)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
PRC - c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
PRC - C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe (Creative Technology Ltd)
PRC - c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\WINDOWS\system32\PnkBstrA.exe ()
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\WINDOWS\system32\MsPMSPSv.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\OTListIt2.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (AdobeActiveFileMonitor [Auto | Running]) -- C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe ()
SRV - (Apple Mobile Device [Auto | Running]) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (Bonjour Service [Auto | Running]) -- C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (Creative Service for CDROM Access [Auto | Running]) -- C:\WINDOWS\system32\CTsvcCDA.exe (Creative Technology Ltd)
SRV - (getPlus® Helper [On_Demand | Stopped]) -- C:\Program Files\NOS\bin\getPlus_HelperSvc.exe (NOS Microsystems Ltd.)
SRV - (gusvc [On_Demand | Stopped]) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (iPod Service [On_Demand | Running]) -- C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (mcmscsvc [Auto | Running]) -- C:\Program Files\McAfee\MSC\mcmscsvc.exe (McAfee, Inc.)
SRV - (McNASvc [Auto | Running]) -- c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe (McAfee, Inc.)
SRV - (McODS [Auto | Stopped]) -- C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV - (McProxy [Auto | Running]) -- c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe (McAfee, Inc.)
SRV - (McShield [Unknown | Running]) -- C:\Program Files\McAfee\VirusScan\Mcshield.exe (McAfee, Inc.)
SRV - (McSysmon [On_Demand | Running]) -- C:\Program Files\McAfee\VirusScan\mcsysmon.exe (McAfee, Inc.)
SRV - (MpfService [Auto | Running]) -- C:\Program Files\McAfee\MPF\MPFSrv.exe (McAfee, Inc.)
SRV - (NVSvc [Auto | Running]) -- C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (PnkBstrA [Auto | Running]) -- C:\WINDOWS\system32\PnkBstrA.exe ()
SRV - (usnjsvc [On_Demand | Stopped]) -- C:\Program Files\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (Viewpoint Manager Service [Auto | Running]) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (WLSetupSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
SRV - (WMDM PMSP Service [Auto | Running]) -- C:\WINDOWS\system32\MsPMSPSv.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (Cdr4_xp [System | Running]) -- C:\WINDOWS\System32\drivers\cdr4_xp.sys (Sonic Solutions)
DRV - (Cdralw2k [System | Running]) -- C:\WINDOWS\System32\drivers\cdralw2k.sys (Sonic Solutions)
DRV - (cdudf_xp [System | Running]) -- C:\WINDOWS\System32\drivers\cdudf_xp.sys (Roxio)
DRV - (ctsfm2k [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ctsfm2k.sys (Creative Technology Ltd)
DRV - (dvd_2K [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\Dvd_2k.sys (Roxio)
DRV - (E100B [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (gameenum [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HSFHWBS2 [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (HSF_DP [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (L8042pr2 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\L8042pr2.Sys (Logitech, Inc.)
DRV - (LCcfltr [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\LCcFltr.Sys (Logitech, Inc.)
DRV - (LHidFlt2 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\LHidFlt2.Sys (Logitech, Inc.)
DRV - (LHidUsb [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\LHidUsb.Sys (Logitech, Inc.)
DRV - (LMouFlt2 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\LMouFlt2.Sys (Logitech, Inc.)
DRV - (mdmxsdk [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (mfeavfk [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfebopk [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mfehidk [System | Running]) -- C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mferkdk [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (mfesmfk [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (mmc_2K [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\Mmc_2k.sys (Roxio)
DRV - (MODEMCSA [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV - (MPFP [System | Running]) -- C:\WINDOWS\System32\Drivers\Mpfp.sys (McAfee, Inc.)
DRV - (nv [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (OMCI [System | Running]) -- C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS (Dell Computer Corporation)
DRV - (ossrv [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ctoss2k.sys (Creative Technology Ltd.)
DRV - (P16X [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\P16X.sys (Creative Technology Ltd.)
DRV - (pfc [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (PfModNT [Auto | Running]) -- C:\WINDOWS\system32\PfModNT.sys (Creative Technology Ltd.)
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (pwd_2k [System | Running]) -- C:\WINDOWS\System32\drivers\pwd_2K.sys (Roxio)
DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (UdfReadr_xp [System | Running]) -- C:\WINDOWS\System32\drivers\udfreadr_xp.sys (Roxio)
DRV - (USBAAPL [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\usbaapl.sys (Apple, Inc.)
DRV - (winachsf [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p...ER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn...st/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.excite.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = localhost;*.local
FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/03/14 05:48:13 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{73F85829-5F05-4B33-9D3C-C237E7153002}: C:\DOCUMENTS AND SETTINGS\MOM AND DAD\LOCAL SETTINGS\APPLICATION DATA\{73F85829-5F05-4B33-9D3C-C237E7153002} [2009/04/13 03:08:08 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{A731DEAD-E34A-4BF0-911F-4140B6246AD8}: C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.MAINCOMPUTER\LOCAL SETTINGS\APPLICATION DATA\{A731DEAD-E34A-4BF0-911F-4140B6246AD8} [2009/04/16 20:37:36 | 00,000,000 | ---D | M]
O1 HOSTS File: (305173 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-domains-registrations.com
O1 - Hosts: 127.0.0.1 www.1-domains-registrations.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 10509 more lines...
O3 - HKLM\..\Toolbar: (&Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O4 - HKLM..\Run: [adaptecdirectcd] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" (Roxio)
O4 - HKLM..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [adobe reader speed launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [applesyncnotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup (Creative Technology Ltd)
O4 - HKLM..\Run: [ituneshelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [Logitech Utility] Logi_MwX.Exe (Logitech Inc.)
O4 - HKLM..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey (McAfee, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install ()
O4 - HKLM..\Run: [opwarese2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" (ScanSoft, Inc.)
O4 - HKLM..\Run: [quicktime task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [updreg] C:\WINDOWS\UpdReg.EXE (Creative Technology Ltd.)
O4 - HKCU..\Run: [aim6] File not found
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe (Logitech Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = _ [binary data]
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 (Microsoft Corporation)
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html ()
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html ()
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html ()
O9 - Extra Button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll (AOL LLC)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.micros...tes/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {17492023-c23a-453e-a040-c7c580bbf700} http://go.microsoft....k/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} http://www.nvidia.com/content/DriverDownlo.../sysreqlab2.cab (System Requirements Lab Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O33 - MountPoints2\{efdc6b6b-2559-11dd-805b-0007e96a13cc}\Shell\AutoRun\command - "" = F:\wd_windows_tools\WDEULA.exe -- File not found
O33 - MountPoints2\{f099617e-417f-11dd-8075-0007e96a13cc}\Shell - "" = AutoRun
O33 - MountPoints2\{f099617e-417f-11dd-8075-0007e96a13cc}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{f099617e-417f-11dd-8075-0007e96a13cc}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -- File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
========== Files/Folders - Created Within 30 Days ==========
[7 C:\WINDOWS\*.tmp files]
[2009/04/19 13:42:26 | 00,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2009/04/19 09:14:24 | 00,076,500 | ---- | C] () -- C:\DOCUME~1\MOMAND~1\My Documents\Hold.dbx
[2009/04/19 09:08:12 | 82,614,384 | ---- | C] () -- C:\DOCUME~1\MOMAND~1\My Documents\Sent Items.dbx
[2009/04/19 09:08:12 | 00,646,256 | ---- | C] () -- C:\DOCUME~1\MOMAND~1\My Documents\Ryan.dbx
[2009/04/19 09:08:11 | 00,899,696 | ---- | C] () -- C:\DOCUME~1\MOMAND~1\My Documents\Recipes.dbx
[2009/04/19 09:08:11 | 00,009,404 | ---- | C] () -- C:\DOCUME~1\MOMAND~1\My Documents\Pop3uidl.dbx
[2009/04/19 09:07:59 | 39,208,432 | ---- | C] () -- C:\DOCUME~1\MOMAND~1\My Documents\Mom.dbx
[2009/04/19 09:07:59 | 00,266,096 | ---- | C] () -- C:\DOCUME~1\MOMAND~1\My Documents\Insurance.dbx
[2009/04/19 09:07:59 | 00,202,736 | ---- | C] () -- C:\DOCUME~1\MOMAND~1\My Documents\Kevin.dbx
[2009/04/19 09:07:43 | 02,485,872 | ---- | C] () -- C:\DOCUME~1\MOMAND~1\My Documents\Hill AFB .dbx
[2009/04/19 09:07:21 | 17,375,472 | ---- | C] () -- C:\DOCUME~1\MOMAND~1\My Documents\Fiesta Potluck -April 18th.dbx
[2009/04/19 09:07:21 | 00,720,496 | ---- | C] () -- C:\DOCUME~1\MOMAND~1\My Documents\Deleted Items.dbx
[2009/04/19 09:07:21 | 00,060,116 | ---- | C] () -- C:\DOCUME~1\MOMAND~1\My Documents\Drafts.dbx
[2009/04/19 09:07:20 | 24,406,256 | ---- | C] () -- C:\DOCUME~1\MOMAND~1\My Documents\Dad.dbx
[2009/04/19 09:07:20 | 02,103,536 | ---- | C] () -- C:\DOCUME~1\MOMAND~1\My Documents\College.dbx
[2009/04/19 09:07:20 | 01,089,776 | ---- | C] () -- C:\DOCUME~1\MOMAND~1\My Documents\Travel Stuff.dbx
[2009/04/19 09:07:20 | 00,139,376 | ---- | C] () -- C:\DOCUME~1\MOMAND~1\My Documents\2008 Taxes.dbx
[2009/04/19 09:07:20 | 00,139,376 | ---- | C] () -- C:\DOCUME~1\MOMAND~1\My Documents\2007 Taxes.dbx
[2009/04/19 09:05:44 | 01,301,616 | ---- | C] () -- C:\DOCUME~1\MOMAND~1\My Documents\Inbox.dbx
[2009/04/19 09:05:44 | 00,191,188 | ---- | C] () -- C:\DOCUME~1\MOMAND~1\My Documents\Outbox.dbx
[2009/04/19 09:05:44 | 00,074,720 | ---- | C] () -- C:\DOCUME~1\MOMAND~1\My Documents\Folders.dbx
[2009/04/19 09:05:44 | 00,009,656 | ---- | C] () -- C:\DOCUME~1\MOMAND~1\My Documents\Offline.dbx
[2009/04/19 08:54:50 | 00,000,000 | ---D | C] -- C:\_OTListIt
[2009/04/19 08:46:27 | 00,501,248 | ---- | C] (OldTimer Tools) -- C:\OTListIt2.exe
[2009/04/18 17:18:41 | 00,002,616 | ---- | C] () -- C:\WINDOWS\System32\tmp.reg
[2009/04/18 17:18:16 | 00,000,000 | ---D | C] -- C:\SmitfraudFix
[2009/04/18 17:17:06 | 01,831,732 | ---- | C] () -- C:\SmitfraudFix.exe
[2009/04/18 15:54:32 | 00,000,000 | ---D | C] -- C:\WINDOWS\pss
[2009/04/18 12:30:23 | 00,000,000 | ---D | C] -- C:\Rooter$
[2009/04/18 12:30:19 | 00,267,612 | ---- | C] () -- C:\Rooter.exe
[2009/04/18 12:24:01 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/04/18 12:23:05 | 00,000,611 | ---- | C] () -- C:\DOCUME~1\MOMAND~1\Desktop\NTREGOPT.lnk
[2009/04/18 12:23:05 | 00,000,592 | ---- | C] () -- C:\DOCUME~1\MOMAND~1\Desktop\ERUNT.lnk
[2009/04/18 12:23:05 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/04/18 12:22:38 | 00,791,393 | ---- | C] (Lars Hederer ) -- C:\erunt_setup.exe
[2009/04/18 12:21:16 | 00,021,504 | ---- | C] (Doug Knox) -- C:\SysRestorePoint.exe
[2009/04/18 11:47:59 | 00,001,341 | ---- | C] () -- C:\regtools.vbs
[2009/04/17 22:23:29 | 06,216,032 | ---- | C] (Microsoft Corporation) -- C:\windowsupdateagent30-x86.exe
[2009/04/17 18:13:26 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Mom and Dad\Application Data\Malwarebytes
[2009/04/17 18:13:19 | 00,000,696 | ---- | C] () -- C:\DOCUME~1\ALLUSE~1\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/04/17 18:13:18 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/04/17 18:13:16 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/04/17 18:13:14 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/04/17 18:13:14 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/04/17 18:12:47 | 00,089,448 | ---- | C] () -- C:\WINDOWS\System32\drivers\7589167f.sys
[2009/04/16 22:02:45 | 00,245,725 | ---- | C] () -- C:\DOCUME~1\MOMAND~1\Desktop\Address Book.WAB
[2009/04/16 08:31:24 | 00,109,010 | ---- | C] () -- C:\WINDOWS\System32\drivers\57ad7fb2.sys
[2009/04/15 20:06:31 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/04/14 14:21:45 | 00,401,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\rpcss.dll
[2009/04/14 14:21:45 | 00,284,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\pdh.dll
[2009/04/14 14:21:44 | 00,473,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\fastprox.dll
[2009/04/14 14:21:44 | 00,227,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmiprvse.exe
[2009/04/14 14:21:44 | 00,110,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\services.exe
[2009/04/14 14:21:43 | 00,729,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\lsasrv.dll
[2009/04/14 14:21:43 | 00,617,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\advapi32.dll
[2009/04/14 14:21:43 | 00,453,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmiprvsd.dll
[2009/04/14 14:21:42 | 00,714,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntdll.dll
[2009/04/14 14:20:47 | 00,002,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xpsp4res.dll
[2009/04/14 14:20:46 | 01,203,922 | ---- | C] () -- C:\WINDOWS\System32\dllcache\sysmain.sdb
[2009/04/14 14:20:45 | 00,215,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wordpad.exe
[2009/04/13 03:08:08 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Mom and Dad\Local Settings\Application Data\{73F85829-5F05-4B33-9D3C-C237E7153002}
[2009/04/13 03:08:08 | 00,000,000 | ---- | C] () -- C:\WINDOWS\Vgazey.bin
[2009/04/13 03:08:07 | 00,000,408 | ---- | C] () -- C:\WINDOWS\Xqataf.dat
[2009/04/13 02:49:38 | 00,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2009/04/11 13:37:00 | 00,002,137 | ---- | C] () -- C:\DOCUME~1\ALLUSE~1\Desktop\iTunes.lnk
[2009/04/11 13:36:32 | 00,000,000 | ---D | C] -- C:\Program Files\iPod
[2009/04/11 13:36:29 | 00,000,000 | ---D | C] -- C:\Program Files\iTunes
[2009/04/11 13:36:29 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/04/11 00:15:02 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Mom and Dad\Local Settings\Application Data\Help
[2009/04/11 00:15:02 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Mom and Dad\Application Data\Help
[2009/04/11 00:14:09 | 00,006,780 | ---- | C] () -- C:\DOCUME~1\MOMAND~1\My Documents\Untitled Music CD ProjectHGJGKGGJK.cl5
[2009/04/05 09:51:32 | 00,000,849 | ---- | C] () -- C:\DOCUME~1\MOMAND~1\Desktop\Burn CD & DVDs with Roxio.lnk
[2009/03/26 13:33:17 | 00,199,640 | ---- | C] () -- C:\DOCUME~1\MOMAND~1\My Documents\kevin expenses.pdf
[2009/03/21 08:06:58 | 00,989,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kernel32.dll
[2009/03/02 00:01:46 | 00,303,104 | ---- | C] () -- C:\WINDOWS\System32\FXStudioDLL.dll
[2009/03/02 00:01:45 | 00,235,532 | ---- | C] () -- C:\WINDOWS\System32\loadimage.dll
[2009/03/02 00:01:45 | 00,131,072 | ---- | C] () -- C:\WINDOWS\System32\RapBoxDSP.dll
[2009/03/02 00:01:45 | 00,126,976 | ---- | C] () -- C:\WINDOWS\System32\NewWaveAnzeige.dll
[2009/03/02 00:01:45 | 00,081,920 | ---- | C] () -- C:\WINDOWS\System32\eJ_Tool.dll
[2009/03/02 00:01:45 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\fader.dll
[2009/03/02 00:01:44 | 00,360,448 | ---- | C] () -- C:\WINDOWS\System32\pxd32d5.dll
[2009/03/02 00:01:44 | 00,307,200 | ---- | C] () -- C:\WINDOWS\System32\fxstudio.dll
[2009/03/02 00:01:44 | 00,075,976 | ---- | C] () -- C:\WINDOWS\System32\Bassdec.dll
[2009/03/02 00:01:44 | 00,032,768 | ---- | C] () -- C:\WINDOWS\System32\WndRgn.dll
[2009/03/02 00:01:44 | 00,029,696 | ---- | C] () -- C:\WINDOWS\System32\pthread.dll
[2009/02/27 07:53:52 | 00,297,472 | ---- | C] () -- C:\WINDOWS\System32\snuscauoytnf.dll
[2009/02/26 04:57:12 | 00,621,056 | ---- | C] () -- C:\WINDOWS\System32\nsfB5.dll
[2009/02/05 09:48:06 | 00,671,744 | ---- | C] () -- C:\WINDOWS\System32\nsg37.dll
[2008/11/21 15:47:52 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2008/11/21 15:45:16 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dtu100.dll.manifest
[2008/11/21 15:45:16 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dpl100.dll.manifest
[2008/11/21 15:44:16 | 00,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll
[2008/03/09 13:08:29 | 00,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll
[2007/12/28 22:28:46 | 00,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll
[2007/12/28 22:28:46 | 00,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll
[2007/12/28 22:28:46 | 00,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll
[2007/12/10 00:24:31 | 00,022,328 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2007/10/26 20:52:31 | 00,000,021 | ---- | C] () -- C:\WINDOWS\atid.ini
[2007/09/26 21:47:02 | 00,000,231 | ---- | C] () -- C:\WINDOWS\AC3API.INI
[2007/09/26 21:45:43 | 00,002,092 | ---- | C] () -- C:\WINDOWS\System32\P16X.ini
[2007/09/26 21:45:43 | 00,000,026 | ---- | C] () -- C:\WINDOWS\System32\ctzapxx.ini
[2007/09/26 21:45:42 | 00,047,616 | ---- | C] () -- C:\WINDOWS\System32\P16X.dll
[2007/09/26 21:45:40 | 00,065,536 | ---- | C] ( ) -- C:\WINDOWS\System32\A3d.dll
[2007/09/26 21:45:37 | 00,006,175 | ---- | C] () -- C:\WINDOWS\MIXDEF.INI
[2007/09/26 21:45:37 | 00,005,917 | ---- | C] () -- C:\WINDOWS\SBMIXDEF.INI
[2007/09/26 21:45:35 | 00,000,064 | ---- | C] () -- C:\WINDOWS\P16x.ini
[2007/09/26 21:44:16 | 00,000,245 | ---- | C] () -- C:\WINDOWS\SBWIN.INI
[2007/09/26 19:29:37 | 00,012,288 | ---- | C] () -- C:\WINDOWS\System32\e100bmsg.dll
[2007/09/26 17:43:10 | 00,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2007/09/26 17:33:40 | 00,008,704 | ---- | C] () -- C:\WINDOWS\System32\CNMVS7L.DLL
[2007/09/26 17:32:30 | 00,000,532 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
[2007/09/26 17:25:05 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2006/10/22 13:22:00 | 01,662,976 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2006/10/22 13:22:00 | 01,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2006/10/22 13:22:00 | 00,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2006/10/22 13:22:00 | 00,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2006/10/22 13:22:00 | 00,212,992 | ---- | C] () -- C:\WINDOWS\System32\nvapi.dll
[2003/07/28 15:19:00 | 01,470,464 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2003/07/28 15:19:00 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2002/09/03 11:11:56 | 00,000,613 | ---- | C] () -- C:\WINDOWS\win.ini
[2002/09/03 11:06:05 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini
[2002/05/15 11:13:20 | 00,081,920 | R--- | C] () -- C:\WINDOWS\System32\SipCal.dll
[1999/09/17 19:12:54 | 00,044,344 | ---- | C] () -- C:\WINDOWS\System32\Seqcal.sys
========== Files - Modified Within 30 Days ==========
[4 C:\WINDOWS\System32\*.tmp files]
[7 C:\WINDOWS\*.tmp files]
[2009/04/19 14:40:34 | 00,109,010 | ---- | M] () -- C:\WINDOWS\System32\drivers\57ad7fb2.sys
[2009/04/19 14:40:34 | 00,089,448 | ---- | M] () -- C:\WINDOWS\System32\drivers\7589167f.sys
[2009/04/19 13:42:41 | 00,013,736 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/04/19 13:27:33 | 00,027,040 | ---- | M] () -- C:\WINDOWS\System32\Config.MPF
[2009/04/19 13:24:08 | 00,088,566 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2009/04/19 13:23:47 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/04/19 13:23:43 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/04/19 13:16:15 | 00,305,173 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2009/04/19 09:14:56 | 01,301,616 | ---- | M] () -- C:\DOCUME~1\MOMAND~1\My Documents\Inbox.dbx
[2009/04/19 09:14:56 | 00,191,188 | ---- | M] () -- C:\DOCUME~1\MOMAND~1\My Documents\Outbox.dbx
[2009/04/19 09:14:56 | 00,074,720 | ---- | M] () -- C:\DOCUME~1\MOMAND~1\My Documents\Folders.dbx
[2009/04/19 09:14:56 | 00,009,656 | ---- | M] () -- C:\DOCUME~1\MOMAND~1\My Documents\Offline.dbx
[2009/04/19 08:46:53 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\OTListIt2.exe
[2009/04/18 17:32:33 | 00,000,613 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/04/18 17:32:33 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/04/18 17:32:33 | 00,000,211 | -HS- | M] () -- C:\boot.ini
[2009/04/18 17:25:35 | 00,002,616 | ---- | M] () -- C:\WINDOWS\System32\tmp.reg
[2009/04/18 17:25:32 | 00,000,848 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20090419-131615.backup
[2009/04/18 17:17:09 | 01,831,732 | ---- | M] () -- C:\SmitfraudFix.exe
[2009/04/18 12:30:23 | 00,267,612 | ---- | M] () -- C:\Rooter.exe
[2009/04/18 12:23:05 | 00,000,611 | ---- | M] () -- C:\DOCUME~1\MOMAND~1\Desktop\NTREGOPT.lnk
[2009/04/18 12:23:05 | 00,000,592 | ---- | M] () -- C:\DOCUME~1\MOMAND~1\Desktop\ERUNT.lnk
[2009/04/18 12:22:42 | 00,791,393 | ---- | M] (Lars Hederer ) -- C:\erunt_setup.exe
[2009/04/18 12:21:22 | 00,021,504 | ---- | M] (Doug Knox) -- C:\SysRestorePoint.exe
[2009/04/18 11:48:11 | 00,001,341 | ---- | M] () -- C:\regtools.vbs
[2009/04/17 22:58:01 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/04/17 22:23:38 | 06,216,032 | ---- | M] (Microsoft Corporation) -- C:\windowsupdateagent30-x86.exe
[2009/04/17 18:13:19 | 00,000,696 | ---- | M] () -- C:\DOCUME~1\ALLUSE~1\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/04/17 06:57:29 | 00,002,137 | ---- | M] () -- C:\DOCUME~1\ALLUSE~1\Desktop\iTunes.lnk
[2009/04/17 06:39:56 | 82,614,384 | ---- | M] () -- C:\DOCUME~1\MOMAND~1\My Documents\Sent Items.dbx
[2009/04/17 06:38:28 | 01,089,776 | ---- | M] () -- C:\DOCUME~1\MOMAND~1\My Documents\Travel Stuff.dbx
[2009/04/17 06:38:26 | 00,266,096 | ---- | M] () -- C:\DOCUME~1\MOMAND~1\My Documents\Insurance.dbx
[2009/04/17 06:38:24 | 00,646,256 | ---- | M] () -- C:\DOCUME~1\MOMAND~1\My Documents\Ryan.dbx
[2009/04/17 06:38:22 | 00,899,696 | ---- | M] () -- C:\DOCUME~1\MOMAND~1\My Documents\Recipes.dbx
[2009/04/17 06:38:16 | 17,375,472 | ---- | M] () -- C:\DOCUME~1\MOMAND~1\My Documents\Fiesta Potluck -April 18th.dbx
[2009/04/17 06:38:06 | 39,208,432 | ---- | M] () -- C:\DOCUME~1\MOMAND~1\My Documents\Mom.dbx
[2009/04/17 06:37:36 | 02,103,536 | ---- | M] () -- C:\DOCUME~1\MOMAND~1\My Documents\College.dbx
[2009/04/17 06:37:32 | 02,485,872 | ---- | M] () -- C:\DOCUME~1\MOMAND~1\My Documents\Hill AFB .dbx
[2009/04/17 06:37:32 | 00,202,736 | ---- | M] () -- C:\DOCUME~1\MOMAND~1\My Documents\Kevin.dbx
[2009/04/17 06:37:28 | 00,139,376 | ---- | M] () -- C:\DOCUME~1\MOMAND~1\My Documents\2008 Taxes.dbx
[2009/04/17 06:37:28 | 00,139,376 | ---- | M] () -- C:\DOCUME~1\MOMAND~1\My Documents\2007 Taxes.dbx
[2009/04/17 06:37:26 | 24,406,256 | ---- | M] () -- C:\DOCUME~1\MOMAND~1\My Documents\Dad.dbx
[2009/04/17 06:37:06 | 00,720,496 | ---- | M] () -- C:\DOCUME~1\MOMAND~1\My Documents\Deleted Items.dbx
[2009/04/17 06:37:06 | 00,076,500 | ---- | M] () -- C:\DOCUME~1\MOMAND~1\My Documents\Hold.dbx
[2009/04/17 06:37:06 | 00,060,116 | ---- | M] () -- C:\DOCUME~1\MOMAND~1\My Documents\Drafts.dbx
[2009/04/17 06:26:03 | 00,000,000 | ---- | M] () -- C:\WINDOWS\Vgazey.bin
[2009/04/17 06:20:52 | 00,009,404 | ---- | M] () -- C:\DOCUME~1\MOMAND~1\My Documents\Pop3uidl.dbx
[2009/04/16 18:44:18 | 00,002,483 | ---- | M] () -- C:\DOCUME~1\MOMAND~1\Desktop\Word.lnk
[2009/04/16 15:00:49 | 00,183,808 | ---- | M] () -- C:\Documents and Settings\Mom and Dad\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/16 14:53:37 | 00,000,408 | ---- | M] () -- C:\WINDOWS\Xqataf.dat
[2009/04/16 06:56:07 | 00,000,520 | ---- | M] () -- C:\DOCUME~1\MOMAND~1\My Documents\spider.sav
[2009/04/15 22:00:36 | 10,727,75168 | ---- | M] () -- C:\WINDOWS\MEMORY.DMP
[2009/04/15 03:16:53 | 00,356,120 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/04/15 03:16:53 | 00,311,604 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/04/15 03:16:53 | 00,039,992 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/04/15 03:05:54 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009/04/15 01:27:00 | 00,000,352 | ---- | M] () -- C:\WINDOWS\tasks\McDefragTask.job
[2009/04/12 22:51:58 | 00,000,739 | ---- | M] () -- C:\DOCUME~1\ALLUSE~1\Desktop\MySpaceIM.lnk
[2009/04/11 12:48:56 | 00,121,344 | ---- | M] () -- C:\DOCUME~1\MOMAND~1\My Documents\Home Costs 07.xls
[2009/04/11 12:41:44 | 00,002,481 | ---- | M] () -- C:\DOCUME~1\MOMAND~1\Desktop\Excel.lnk
[2009/04/11 00:14:09 | 00,006,780 | ---- | M] () -- C:\DOCUME~1\MOMAND~1\My Documents\Untitled Music CD ProjectHGJGKGGJK.cl5
[2009/04/09 13:16:52 | 00,245,725 | ---- | M] () -- C:\DOCUME~1\MOMAND~1\Desktop\Address Book.WAB
[2009/04/09 07:57:49 | 00,019,968 | ---- | M] () -- C:\DOCUME~1\MOMAND~1\My Documents\My medication list.doc
[2009/04/06 15:32:54 | 00,038,496 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/04/06 15:32:46 | 00,015,504 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/04/06 08:57:24 | 24,921,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009/04/05 09:51:32 | 00,000,849 | ---- | M] () -- C:\DOCUME~1\MOMAND~1\Desktop\Burn CD & DVDs with Roxio.lnk
[2009/03/27 00:58:38 | 01,203,922 | ---- | M] () -- C:\WINDOWS\System32\dllcache\sysmain.sdb
[2009/03/26 13:33:17 | 00,199,640 | ---- | M] () -- C:\DOCUME~1\MOMAND~1\My Documents\kevin expenses.pdf
[2009/03/25 11:06:30 | 00,040,552 | ---- | M] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfesmfk.sys
[2009/03/25 11:06:28 | 00,214,024 | ---- | M] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfehidk.sys
[2009/03/25 11:06:28 | 00,079,880 | ---- | M] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfeavfk.sys
[2009/03/25 11:06:28 | 00,035,272 | ---- | M] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mfebopk.sys
[2009/03/25 11:05:54 | 00,034,216 | ---- | M] (McAfee, Inc.) -- C:\WINDOWS\System32\drivers\mferkdk.sys
[2009/03/22 00:32:59 | 01,579,330 | -H-- | M] () -- C:\Documents and Settings\Mom and Dad\Local Settings\Application Data\IconCache.db
[2009/03/21 08:06:58 | 00,989,696 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\kernel32.dll
[2009/03/21 08:06:58 | 00,989,696 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kernel32.dll
========== Alternate Data Streams ==========
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >
ROOTER Report
Microsoft Windows XP Home Edition (5.1.2600) Service Pack 3
A:\ [Removable] (Total:0 Mo/Free:0 Mo)
C:\ [Fixed] - NTFS - (Total:152617 Mo/Free:997 Mo)
D:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
E:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
Sun 04/19/2009|14:36
----------------------\\ Processes..
--Locked-- [System Process]
---------- System
---------- \SystemRoot\System32\smss.exe
---------- \??\C:\WINDOWS\system32\csrss.exe
---------- \??\C:\WINDOWS\system32\winlogon.exe
---------- C:\WINDOWS\system32\services.exe
---------- C:\WINDOWS\system32\lsass.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\System32\svchost.exe
---------- C:\WINDOWS\System32\svchost.exe
---------- C:\WINDOWS\System32\svchost.exe
---------- C:\WINDOWS\system32\spoolsv.exe
---------- C:\WINDOWS\Explorer.EXE
---------- C:\Program Files\McAfee.com\Agent\mcagent.exe
---------- C:\Program Files\Java\jre6\bin\jusched.exe
---------- C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
---------- C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
---------- C:\Program Files\iTunes\iTunesHelper.exe
---------- C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
---------- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
---------- C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
---------- C:\Program Files\Logitech\MouseWare\system\em_exec.exe
---------- C:\WINDOWS\System32\svchost.exe
---------- C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
---------- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
---------- C:\Program Files\Bonjour\mDNSResponder.exe
---------- C:\WINDOWS\system32\CTsvcCDA.exe
---------- C:\Program Files\Java\jre6\bin\jqs.exe
---------- C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
---------- c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
---------- C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
---------- c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
---------- C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
---------- C:\Program Files\McAfee\MPF\MPFSrv.exe
---------- C:\WINDOWS\system32\nvsvc32.exe
---------- C:\WINDOWS\system32\PnkBstrA.exe
---------- C:\WINDOWS\System32\locator.exe
---------- C:\WINDOWS\System32\svchost.exe
---------- C:\Program Files\Viewpoint\Common\ViewpointService.exe
---------- C:\WINDOWS\system32\MsPMSPSv.exe
---------- C:\WINDOWS\system32\wscntfy.exe
---------- C:\Program Files\iPod\bin\iPodService.exe
---------- C:\WINDOWS\System32\alg.exe
---------- C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
---------- C:\Program Files\Internet Explorer\iexplore.exe
---------- C:\WINDOWS\system32\cmd.exe
---------- C:\Rooter$\RK.exe
----------------------\\ Search..
----------------------\\ ROOTKIT !!
----------------------\\ Cracks & Keygens..
C:\DOCUME~1\MOMAND~1\My Documents\LimeWire\Saved\FL Studio 6.0.8 + Crack.aka Fruity loops+all plugins unlocked!(XXL Edition)\FL Studio 6.0.8 + Crack.aka Fruity loops+all plugins unlocked!(XXL Edition).rar
1 - "C:\Rooter$\Rooter_1.txt" - Sat 04/18/2009|12:31
2 - "C:\Rooter$\Rooter_2.txt" - Sun 04/19/2009|14:37
