System Restore and ERUNT worked fine. Installed Avast and am using it now. Windows updates have all been installed...but not SP 3 as it causes my screen to not work...apparently there are issues with the drivers for my video card, and not sure that any update for the drivers will be coming out or not.
Rooter log:
Rooter.exe (v1.0.1) by Eric_71
¨
Microsoft Windows XP Professional (5.1.2600) Service Pack 2
32_bits - x86 Family 6 Model 14 Stepping 8, GenuineIntel
¨
C:\ [Fixed-NTFS] .. ( Total:68 Go - Free:44 Go )
D:\ [Fixed-FAT32] .. ( Total:5 Go - Free:1 Go )
E:\ [CD_Rom]
¨
Scan : 03:57.57
Path : C:\Documents and Settings\Owner\Desktop\gtg\Rooter.exe
User : Owner ( Administrator -> YES )
¨
----------------------\\ Processes
¨
Locked [System Process] (0)
______ System (4)
______ \SystemRoot\System32\smss.exe (788)
______ \??\C:\WINDOWS\system32\csrss.exe (900)
______ \??\C:\WINDOWS\system32\winlogon.exe (928)
______ C:\WINDOWS\system32\services.exe (976)
______ C:\WINDOWS\system32\lsass.exe (988)
______ C:\WINDOWS\system32\Ati2evxx.exe (1140)
______ C:\WINDOWS\system32\svchost.exe (1160)
______ C:\WINDOWS\system32\svchost.exe (1260)
______ C:\WINDOWS\System32\svchost.exe (1316)
______ C:\WINDOWS\system32\svchost.exe (1592)
______ C:\WINDOWS\system32\svchost.exe (1668)
______ C:\Program Files\Common Files\Microsoft Shared\Ink\KeyboardSurrogate.exe (1688)
______ C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (2040)
______ C:\WINDOWS\SYSTEM32\WISPTIS.EXE (180)
______ C:\WINDOWS\system32\Ati2evxx.exe (244)
______ C:\WINDOWS\System32\tabbtnu.exe (268)
______ C:\WINDOWS\system32\ctfmon.exe (320)
______ C:\WINDOWS\Explorer.EXE (328)
______ C:\Program Files\Alwil Software\Avast4\ashServ.exe (448)
______ C:\Program Files\Common Files\Microsoft Shared\Ink\TCServer.exe (832)
______ C:\Program Files\Common Files\Microsoft Shared\Ink\TabTip.exe (1384)
______ C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe (1412)
______ C:\Program Files\PalmTether\TetherApp.exe (1504)
______ C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (1524)
______ C:\WINDOWS\system32\rundll32.exe (1580)
______ C:\PROGRA~1\PALMTE~1\PALMON~2.EXE (1520)
______ C:\WINDOWS\stsystra.exe (1612)
______ C:\Program Files\Search Settings\SearchSettings.exe (1792)
______ C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe (1800)
______ C:\Program Files\Pure Networks\Network Magic\nmapp.exe (1844)
______ C:\Program Files\QuickTime\QTTask.exe (1872)
______ C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (1896)
______ C:\Program Files\Eraser\eraser.exe (1920)
______ C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (1992)
______ C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE (2004)
______ C:\Program Files\DNA\btdna.exe (188)
______ C:\Program Files\Palm\Hotsync.exe (312)
______ C:\WINDOWS\system32\spoolsv.exe (2200)
______ C:\WINDOWS\system32\svchost.exe (2508)
______ C:\WINDOWS\system32\svchost.exe (2564)
______ C:\Program Files\Citrix\GoToMyPC\g2svc.exe (2592)
______ C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (2672)
______ C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (2724)
______ C:\WINDOWS\system32\svchost.exe (2756)
______ C:\Program Files\Citrix\GoToMyPC\g2comm.exe (2768)
______ C:\WINDOWS\system32\wdfmgr.exe (2804)
______ C:\Program Files\Viewpoint\Common\ViewpointService.exe (2832)
______ C:\Program Files\Citrix\GoToMyPC\g2pre.exe (3052)
______ C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe (3100)
______ C:\Program Files\Citrix\GoToMyPC\g2tray.exe (3196)
______ C:\WINDOWS\system32\wbem\wmiprvse.exe (3824)
______ C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (4024)
______ C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (532)
______ C:\WINDOWS\System32\alg.exe (3944)
______ C:\WINDOWS\System32\svchost.exe (4500)
______ C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (4820)
______ C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (4856)
______ C:\Documents and Settings\Owner\Desktop\gtg\Rooter.exe (5236)
¨
----------------------\\ Device\Harddisk0\
¨
\Device\Harddisk0 [Sectors : 63 x 512 Bytes]
¨
\Device\Harddisk0\Partition1 --[ MBR ]-- (Start_Offset:6292339200 | Length:73723184640)
\Device\Harddisk0\Partition2 (Start_Offset:32256 | Length:6292306944)
¨
----------------------\\ Scheduled Tasks
¨
C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
C:\WINDOWS\Tasks\desktop.ini
C:\WINDOWS\Tasks\SA.DAT
C:\WINDOWS\Tasks\SmartDefrag.job
¨
----------------------\\ Registry
¨
¨
----------------------\\ Files & Folders
¨
----------------------\\ Scan completed at 03:58.10
¨
C:\Rooter$\Rooter_1.txt - (19/06/2009 | 03:58.10)
OTL Log:
OTL logfile created on: 6/19/2009 4:46:19 AM - Run 1
OTL by OldTimer - Version 2.1.1.0 Folder = C:\Documents and Settings\Owner\Desktop\gtg
Windows XP Tablet PC Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.41 Gb Available Physical Memory | 70.45% Memory free
3.84 Gb Paging File | 3.31 Gb Available in Paging File | 86.17% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 68.66 Gb Total Space | 44.53 Gb Free Space | 64.86% Space Free | Partition Type: NTFS
Drive D: | 5.85 Gb Total Space | 1.79 Gb Free Space | 30.60% Space Free | Partition Type: FAT32
Drive E: | 58.54 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: KL
Current User Name: Owner
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Common Files\Microsoft Shared\Ink\KeyboardSurrogate.exe (Microsoft Corporation)
PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\WINDOWS\SYSTEM32\WISPTIS.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\WINDOWS\System32\tabbtnu.exe (Microsoft Corporation)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\Program Files\Common Files\Microsoft Shared\Ink\TCServer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Microsoft Shared\Ink\TabTip.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe ()
PRC - C:\Program Files\PalmTether\TetherApp.exe (June Fabrics Technology, Inc.)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
PRC - C:\Program Files\PalmTether\PalmOneLiveConnect.exe (Palm, Inc.)
PRC - C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Search Settings\SearchSettings.exe (Spigot, Inc.)
PRC - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe (Pure Networks, Inc.)
PRC - C:\Program Files\Pure Networks\Network Magic\nmapp.exe (Pure Networks, Inc.)
PRC - C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files\Eraser\eraser.exe (The Eraser Project)
PRC - C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
PRC - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
PRC - C:\Program Files\AIM6\aim6.exe (AOL LLC)
PRC - C:\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
PRC - C:\Program Files\Palm\Hotsync.exe (PalmSource, Inc)
PRC - C:\Program Files\Citrix\GoToMyPC\g2svc.exe (Citrix Online, a division of Citrix Systems, Inc.)
PRC - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)
PRC - C:\Program Files\Citrix\GoToMyPC\g2comm.exe (Citrix Online, a division of Citrix Systems, Inc.)
PRC - C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\Citrix\GoToMyPC\g2pre.exe (Citrix Online, a division of Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\GoToMyPC\g2tray.exe (Citrix Online, a division of Citrix Systems, Inc.)
PRC - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe (Pure Networks, Inc.)
PRC - C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
PRC - C:\Program Files\AIM6\aolsoftware.exe (AOL LLC)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
PRC - C:\Documents and Settings\Owner\Desktop\gtg\OTL.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (aswUpdSv [Auto | Running]) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (Ati HotKey Poller [Auto | Running]) -- C:\WINDOWS\system32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (avast! Antivirus [Auto | Running]) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner [On_Demand | Running]) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner [On_Demand | Running]) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (GoToMyPC [Auto | Running]) -- C:\Program Files\Citrix\GoToMyPC\g2svc.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (gusvc [On_Demand | Stopped]) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (MDM [Auto | Running]) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (nmraapache [On_Demand | Stopped]) -- C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe (Pure Networks, Inc.)
SRV - (nmservice [Auto | Running]) -- C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe (Pure Networks, Inc.)
SRV - (ose [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (PrismXL [Auto | Running]) -- C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS (New Boundary Technologies, Inc.)
SRV - (UMWdf [Auto | Running]) -- C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
SRV - (Viewpoint Manager Service [Auto | Running]) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
========== Driver Services (SafeList) ==========
DRV - (Aavmker4 [System | Running]) -- C:\WINDOWS\System32\drivers\aavmker4.sys (ALWIL Software)
DRV - (AliIde [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (asc [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550 [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (aswFsBlk [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys (ALWIL Software)
DRV - (aswMon2 [Auto | Running]) -- C:\WINDOWS\System32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswRdr [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswSP [System | Running]) -- C:\WINDOWS\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswTdi [System | Running]) -- C:\WINDOWS\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (ati2mtag [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (CmdIde [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (dac2w2k [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (e1express [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\e1e5132.sys (Intel Corporation)
DRV - (el575nd5 [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\el575nd5.sys (3Com Corporation)
DRV - (FinePnt [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\FpHidDrv.sys (FinePoint Innovations)
DRV - (HDAudBus [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\HDAudBus.sys (Windows ® Server 2003 DDK provider)
DRV - (iaStor [Boot | Running]) -- C:\WINDOWS\SYSTEM32\DRIVERS\IASTOR.SYS (Intel Corporation)
DRV - (MBAMSwissArmy [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (mraid35x [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (MSTabBtn [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\MSTabBtn.sys (Windows ® 2000 DDK provider)
DRV - (n558 [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\n558.sys ()
DRV - (NETw5x32 [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\NETw5x32.sys (Intel Corporation)
DRV - (palmmdm [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\palmmdm.sys (June Fabrics Technology Inc.)
DRV - (PalmUSBD [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\PalmUSBD.sys (PalmSource, Inc.)
DRV - (pnarp [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\pnarp.sys (Pure Networks, Inc.)
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (purendis [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\purendis.sys (Pure Networks, Inc.)
DRV - (ql1080 [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql12160 [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1280 [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (ROOTMODEM [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\RootMdm.sys (Microsoft Corporation)
DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sisagp [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (SMNDIS5 [On_Demand | Stopped]) -- C:\Program Files\Verizon Wireless\VZAccess Manager\SMNDIS5.sys (Smith Micro Software, Inc.)
DRV - (Sparrow [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (STHDA [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (symc810 [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (symc8xx [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (sym_hi [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (sym_u3 [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (tifm21 [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\tifm21.sys (Texas Instruments)
DRV - (ultra [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft...p...&ar=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft...amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft...p...ER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.westathome.net/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "AIM Search"
FF - prefs.js..browser.search.defaulturl: "http://slirsredirect...fftrie7&query="
FF - prefs.js..browser.search.openintab: true
FF - prefs.js..browser.search.selectedEngine: "IMDb"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.0.2
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:6.9.93
FF - prefs.js..extensions.enabledItems: {c2f863cd-0429-48c7-bb54-db756a951760}:5.20.1.1
FF - prefs.js..extensions.enabledItems: {59c81df5-4b7a-477b-912d-4e0fdf64e5f2}:0.9.84
FF - prefs.js..extensions.enabledItems: [email protected]:1.9
FF - prefs.js..extensions.enabledItems: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:0.9.10.1
FF - prefs.js..extensions.enabledItems: {d37dc5d0-431d-44e5-8c91-49419370caa1}:2.5.33
FF - prefs.js..extensions.enabledItems: {B9C8BE50-7105-4ec6-8FB4-4935C0671648}:0.5.98
FF - prefs.js..extensions.enabledItems: {3112ca9c-de6d-4884-a869-9855de68056c}:3.1.20081127W
FF - prefs.js..extensions.enabledItems: {77b819fa-95ad-4f2c-ac7c-486b356188a9}:1.5.20090525
FF - prefs.js..extensions.enabledItems: {a6e4a4eb-d169-4e99-8988-250fcbafe767}:1.5.45.0
FF - prefs.js..extensions.enabledItems: morningCoffee@shaneliesegang:1.33
FF - prefs.js..extensions.enabledItems: {916ab64c-bc3e-471b-8e60-29551922a7ba}:1.300.244
FF - prefs.js..extensions.enabledItems: {eeb97566-866d-4551-b292-7de53fb9fe24}:1.2.0.8
FF - prefs.js..extensions.enabledItems: {37E4D8EA-8BDA-4831-8EA1-89053939A250}:2.2.0.2
FF - prefs.js..extensions.enabledItems: [email protected]:2.2
FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.7.3
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.10
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.11
FF - prefs.js..extensions.enabledItems: {29852C08-1E91-4889-A6BF-C77F91D6A8F3}:1.8.50
FF - prefs.js..keyword.URL: "http://search.freeca...&type=58819&p="
FF - HKLM\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\FIREFOX [2009/04/27 14:32:17 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/06/12 12:22:35 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/06/18 04:57:50 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.21\extensions\\Components: C:\PROGRAM FILES\MOZILLA THUNDERBIRD\COMPONENTS [2009/06/02 20:14:04 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.21\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA THUNDERBIRD\PLUGINS
[2009/04/27 13:00:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Extensions
[2009/04/27 13:00:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/06/19 03:57:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\ovkbgi6b.default\extensions
[2009/06/12 12:22:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\ovkbgi6b.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2009/05/27 14:33:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\ovkbgi6b.default\extensions\{29852C08-1E91-4889-A6BF-C77F91D6A8F3}
[2009/04/27 13:21:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\ovkbgi6b.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009/04/27 13:21:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\ovkbgi6b.default\extensions\{340c2bbc-ce74-4362-90b5-7c26312808ef}
[2009/05/27 14:33:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\ovkbgi6b.default\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
[2009/04/27 13:21:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\ovkbgi6b.default\extensions\{4B19DDFD-180C-4f31-9DA5-7C6459178E25}
[2009/04/27 13:21:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\ovkbgi6b.default\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}
[2009/06/04 11:30:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\ovkbgi6b.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}
[2009/05/23 02:14:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\ovkbgi6b.default\extensions\{82955283-343d-4b6c-bd3c-d147000058c8}(2)
[2009/06/01 10:36:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\ovkbgi6b.default\extensions\{916ab64c-bc3e-471b-8e60-29551922a7ba}
[2009/04/27 13:21:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\ovkbgi6b.default\extensions\{9b9d2aaa-ae26-4447-a7a1-633a32b19ddd}
[2009/04/27 13:21:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\ovkbgi6b.default\extensions\{a6e4a4eb-d169-4e99-8988-250fcbafe767}
[2009/04/27 13:21:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\ovkbgi6b.default\extensions\{B9C8BE50-7105-4ec6-8FB4-4935C0671648}
[2009/04/27 13:21:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\ovkbgi6b.default\extensions\{BA979AD0-A3C5-4b32-A47E-4550BF00ECC7}
[2009/05/14 16:45:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\ovkbgi6b.default\extensions\{c2f863cd-0429-48c7-bb54-db756a951760}
[2009/04/27 13:21:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\ovkbgi6b.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/05/12 18:59:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\ovkbgi6b.default\extensions\{d37dc5d0-431d-44e5-8c91-49419370caa1}
[2009/04/27 13:21:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\ovkbgi6b.default\extensions\{dc572301-7619-498c-a57d-39143191b318}
[2009/06/01 10:36:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\ovkbgi6b.default\extensions\{eeb97566-866d-4551-b292-7de53fb9fe24}
[2009/04/27 13:21:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\ovkbgi6b.default\extensions\[email protected]
[2009/04/27 13:21:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\ovkbgi6b.default\extensions\[email protected]
[2009/04/27 13:21:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\ovkbgi6b.default\extensions\morningCoffee@shaneliesegang
[2009/04/27 13:21:26 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\ovkbgi6b.default\extensions\[email protected]
[2009/06/12 12:22:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\ovkbgi6b.default\extensions\staged-xpis
[2009/05/09 04:51:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\ovkbgi6b.default\extensions\[email protected]
[2009/05/14 16:45:49 | 00,001,739 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\Mozilla\FireFox\Profiles\ovkbgi6b.default\searchplugins\aim-search.xml
[2007/06/13 10:26:19 | 00,005,350 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\Mozilla\FireFox\Profiles\ovkbgi6b.default\searchplugins\avatarlog.xml
[2008/11/15 15:02:34 | 00,005,179 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\Mozilla\FireFox\Profiles\ovkbgi6b.default\searchplugins\BitTorrent.xml
[2009/06/16 20:31:17 | 00,000,950 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\Mozilla\FireFox\Profiles\ovkbgi6b.default\searchplugins\icqplugin-1.xml
[2009/02/27 23:50:04 | 00,000,950 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\Mozilla\FireFox\Profiles\ovkbgi6b.default\searchplugins\icqplugin.xml
[2008/06/29 03:10:01 | 00,000,908 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\Mozilla\FireFox\Profiles\ovkbgi6b.default\searchplugins\IMDB.xml
[2009/06/16 20:31:17 | 00,002,091 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\Mozilla\FireFox\Profiles\ovkbgi6b.default\searchplugins\quotations-book---search.xml
[2009/06/01 10:36:49 | 00,001,734 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\Mozilla\FireFox\Profiles\ovkbgi6b.default\searchplugins\search-the-web.xml
[2008/06/29 03:10:02 | 00,001,108 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\Mozilla\FireFox\Profiles\ovkbgi6b.default\searchplugins\wikipedia.xml
[2009/02/04 21:21:57 | 00,000,655 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\Mozilla\FireFox\Profiles\ovkbgi6b.default\searchplugins\yahoo-search-1.xml
[2009/02/04 21:21:57 | 00,000,595 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\Mozilla\FireFox\Profiles\ovkbgi6b.default\searchplugins\yahoo-search.xml
[2009/06/16 19:55:29 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/06/12 12:22:28 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/06/12 12:22:27 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/06/12 12:22:28 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/04/09 00:51:14 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/04/09 00:51:14 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2008/08/21 15:04:00 | 00,000,925 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\conduit.xml
[2009/04/09 00:51:14 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/04/09 00:51:14 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/04/09 00:51:14 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/04/09 00:51:14 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/05/06 18:39:54 | 00,000,780 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Dealio Toolbar) - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\DealioToolbarIE.dll (Spigot, Inc.)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O2 - BHO: (SearchSettings Class) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb128\SearchSettings.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (Dealio Toolbar) - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\DealioToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (AOL Toolbar) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (IE Toolbar)
O3 - HKLM\..\Toolbar: (&RoboForm) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" ()
O4 - HKLM..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay (ATI Technologies Inc.)
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent File not found
O4 - HKLM..\Run: [Gateway Extended Warranty] "C:\Program Files\Gateway\GWCares\GWCares.exe" (BillP Studios)
O4 - HKLM..\Run: [GoToMyPC] "C:\Program Files\Citrix\GoToMyPC\g2svc.exe" -logon (Citrix Online, a division of Citrix Systems, Inc.)
O4 - HKLM..\Run: [HotSync] "C:\Program Files\PalmSource\Desktop\HotSync.exe" -AllUsers File not found
O4 - HKLM..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplash (Pure Networks, Inc.)
O4 - HKLM..\Run: [nmctxth] "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" (Pure Networks, Inc.)
O4 - HKLM..\Run: [PalmTether] "C:\Program Files\PalmTether\TetherApp.exe" (June Fabrics Technology, Inc.)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe (Spigot, Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [TabletTip] "C:\Program Files\Common Files\microsoft shared\ink\tabtip.exe" /resume (Microsoft Corporation)
O4 - HKLM..\Run: [TabletWizard] C:\WINDOWS\help\SplshWrp.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-us ee://aol/imApp /HIDEBL (AOL LLC)
O4 - HKCU..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe" (BitTorrent, Inc.)
O4 - HKCU..\Run: [EPSON Stylus CX4400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICAA.EXE /FU "C:\WINDOWS\TEMP\E_S703.tmp" /EF "HKCU" (SEIKO EPSON CORPORATION)
O4 - HKCU..\Run: [Eraser] C:\Program Files\Eraser\eraser.exe -hide (The Eraser Project)
O4 - HKCU..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet (Yahoo! Inc.)
O4 - HKCU..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" (Siber Systems)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HotSync Manager.lnk = C:\Program Files\Palm\Hotsync.exe (PalmSource, Inc)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html File not found
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000 (Microsoft Corporation)
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html File not found
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html File not found
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html File not found
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - File not found
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - File not found
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - File not found
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - File not found
O9 - Extra Button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (IE Toolbar)
O9 - Extra 'Tools' menuitem : AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - Reg Error: Value error. File not found
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - File not found
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [Bluetooth Namespace] - C:\WINDOWS\system32\wshbth.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://support.gatew...r/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.4.2)
O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.4.2)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp4.dll (Pure Networks, Inc.)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - x-sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\GoToMyPC: DllName - C:\Program Files\Citrix\GoToMyPC\G2WinLogon.dll - C:\Program Files\Citrix\GoToMyPC\G2WinLogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O20 - Winlogon\Notify\loginkey: DllName - C:\Program Files\Common Files\Microsoft Shared\Ink\loginkey.dll - C:\Program Files\Common Files\Microsoft Shared\Ink\loginkey.dll (Microsoft Corporation)
O20 - Winlogon\Notify\TabBtnWL: DllName - TabBtnWL.dll - C:\WINDOWS\system32\TabBtnWL.dll (Microsoft Corporation)
O20 - Winlogon\Notify\tpgwlnotify: DllName - tpgwlnot.dll - C:\WINDOWS\system32\tpgwlnot.dll (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/06/22 05:32:11 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2004/09/13 13:15:24 | 00,000,053 | -HS- | M] () - D:\Autorun.inf -- [ FAT32 ]
O32 - AutoRun File - [2006/09/03 21:30:00 | 00,000,062 | R--- | M] () - E:\autorun.inf -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009/06/19 03:58:37 | 00,000,000 | ---D | M]
========== Files/Folders - Created Within 30 Days ==========
[2009/06/19 03:58:10 | 00,000,000 | ---D | C] -- C:\Rooter$
[2009/06/19 03:40:29 | 00,051,376 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2009/06/19 03:40:29 | 00,026,944 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2009/06/19 03:40:29 | 00,023,152 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2009/06/19 03:40:29 | 00,001,709 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/06/19 03:40:28 | 00,114,768 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2009/06/19 03:40:28 | 00,097,480 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\AvastSS.scr
[2009/06/19 03:40:28 | 00,094,032 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2009/06/19 03:40:28 | 00,093,296 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2009/06/19 03:40:28 | 00,020,560 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2009/06/19 03:40:15 | 01,256,296 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\aswBoot.exe
[2009/06/19 03:40:15 | 00,380,928 | ---- | C] () -- C:\WINDOWS\System32\actskin4.ocx
[2009/06/19 03:40:12 | 00,000,000 | ---D | C] -- C:\Program Files\Alwil Software
[2009/06/19 02:07:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Application Data\Malwarebytes
[2009/06/19 02:07:47 | 00,038,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/06/19 02:07:46 | 00,019,096 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/06/19 02:07:46 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/06/19 02:07:46 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/06/19 02:06:57 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/06/19 02:06:23 | 00,000,611 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\NTREGOPT.lnk
[2009/06/19 02:06:23 | 00,000,592 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\ERUNT.lnk
[2009/06/19 02:06:23 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/06/18 22:15:45 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner\My Documents\FB
[2009/06/18 21:40:46 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\gtg
[2009/06/18 15:00:08 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner\My Documents\Jasc
[2009/06/18 14:56:55 | 00,001,732 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\WinZip.lnk
[2009/06/18 14:49:03 | 13,727,048 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\winzip121.exe
[2009/06/18 04:59:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner\My Documents\Downloads
[2009/06/18 04:57:54 | 00,000,706 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\BitTorrent.lnk
[2009/06/18 04:57:54 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Application Data\BitTorrent
[2009/06/18 04:57:47 | 00,000,000 | ---D | C] -- C:\Program Files\DNA
[2009/06/18 04:57:47 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Application Data\DNA
[2009/06/18 04:57:46 | 00,000,000 | ---D | C] -- C:\Program Files\BitTorrent
[2009/06/18 04:57:19 | 01,739,664 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\BitTorrent-6.1.2.exe
[2009/06/17 15:07:10 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Application Data\Mobipocket
[2009/06/17 15:06:53 | 00,001,934 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mobipocket Reader.lnk
[2009/06/17 15:06:51 | 00,000,000 | ---D | C] -- C:\Program Files\Mobipocket.com
[2009/06/17 15:06:20 | 05,606,400 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\mobireadersetup.msi
[2009/06/17 05:38:38 | 00,001,072 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Shortcut to Ahrimans-Prophecy-Strategy-Guide.pdf.lnk
[2009/06/17 04:53:39 | 00,156,285 | ---- | C] () -- C:\WINDOWS\Ahriman's Prophecy Uninstaller.exe
[2009/06/17 04:53:39 | 00,000,740 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Ahriman's Prophecy.lnk
[2009/06/17 04:53:34 | 00,000,000 | ---D | C] -- C:\Program Files\Ahriman's Prophecy
[2009/06/17 02:37:59 | 00,001,511 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Shortcut to Aveyond Ultimate.pdf.lnk
[2009/06/16 22:19:30 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\ODBC
[2009/06/15 09:59:03 | 00,021,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\hidserv.dll
[2009/06/15 09:59:03 | 00,021,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hidserv.dll
[2009/06/14 23:04:20 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/06/14 23:03:43 | 00,000,736 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Aveyond.lnk
[2009/06/14 23:03:35 | 00,000,000 | ---D | C] -- C:\Program Files\Shockwave.com
[2009/06/14 22:51:19 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Application Data\PlayFirst
[2009/06/14 22:17:15 | 33,113,448 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Install_DinerDashHometownHero.EXE
[2009/06/14 22:02:06 | 00,001,974 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Parking Dash.lnk
[2009/06/14 21:56:34 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PlayFirst
[2009/06/11 13:00:35 | 00,000,000 | ---D | C] -- C:\WINDOWS\.jagex_cache_32
[2009/06/08 13:05:42 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Application Data\Google
[2009/06/03 08:25:19 | 00,000,000 | ---D | C] -- C:\Program Files\AlfaClock Free Edition
[2009/06/02 20:13:36 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/06/02 17:40:51 | 00,202,072 | R--- | C] (Coupons, Inc.) -- C:\WINDOWS\System32\cpnprt2.cid
[2009/06/02 17:40:50 | 00,000,000 | ---D | C] -- C:\WINDOWS\Cache
[2009/06/02 17:40:49 | 00,000,000 | ---D | C] -- C:\Program Files\Coupons
[2009/06/02 17:40:12 | 01,277,680 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\CouponPrinter.exe
[2009/06/01 11:42:55 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\LogFiles
[2009/06/01 10:57:25 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\BadgeHelp
[2009/06/01 05:35:16 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\HHJMJXRAYG
[2009/05/28 08:15:49 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner\My Documents\Frank
[2009/05/28 08:15:48 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner\My Documents\New Folder
[2009/05/27 22:18:33 | 00,049,889 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\frank.jpg
[2009/05/26 10:39:31 | 00,000,000 | ---D | C] -- C:\WINDOWS\CSC
[2009/05/24 13:08:35 | 00,001,800 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Network Magic.lnk
[2009/05/24 13:08:11 | 00,023,992 | ---- | C] (Pure Networks, Inc.) -- C:\WINDOWS\System32\drivers\pnarp.sys
[2009/05/24 13:08:06 | 00,025,272 | ---- | C] (Pure Networks, Inc.) -- C:\WINDOWS\System32\drivers\purendis.sys
[2009/05/23 04:13:03 | 00,000,384 | ---- | C] () -- C:\WINDOWS\tasks\SmartDefrag.job
[2009/05/21 07:26:16 | 00,013,824 | ---- | C] () -- C:\Documents and Settings\Owner\My Documents\Graph.xls
[2009/05/20 17:17:00 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\CSIMJXRAYG
[2009/05/20 17:12:56 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\OFJMJXRAYG
[2009/05/20 17:12:55 | 00,000,000 | ---D | C] -- C:\Program Files\BadgeHelp
[2009/05/20 12:40:39 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner\My Documents\Kim
[2009/05/06 18:39:37 | 00,484,352 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
[2009/05/04 21:53:49 | 00,000,021 | ---- | C] () -- C:\WINDOWS\atid.ini
[2009/04/27 12:36:18 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009/04/24 14:45:46 | 00,098,304 | ---- | C] () -- C:\WINDOWS\System32\FpWinTab.dll
[2007/08/15 07:27:18 | 00,009,600 | ---- | C] () -- C:\WINDOWS\System32\drivers\n558.sys
[2007/07/01 06:12:14 | 03,145,728 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll
[2007/07/01 05:59:22 | 00,517,632 | ---- | C] () -- C:\WINDOWS\System32\ff_x264.dll
[2007/06/17 06:43:56 | 00,405,504 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll
[2007/06/12 06:21:26 | 00,208,896 | ---- | C] () -- C:\WINDOWS\System32\ff_theora.dll
[2007/01/09 12:05:50 | 00,026,112 | ---- | C] () -- C:\WINDOWS\System32\ff_wmv9.dll
[2005/06/22 07:13:13 | 00,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2005/06/22 05:12:17 | 00,000,449 | ---- | C] () -- C:\WINDOWS\System32\emver.ini
[2005/06/22 05:12:17 | 00,000,426 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2005/06/22 05:11:38 | 00,000,702 | ---- | C] () -- C:\WINDOWS\win.ini
[2005/06/22 05:11:33 | 00,000,231 | ---- | C] () -- C:\WINDOWS\system.ini
[2004/11/24 14:25:52 | 00,335,872 | ---- | C] ( ) -- C:\WINDOWS\System32\drvc.dll
[2004/10/03 12:50:54 | 00,129,024 | ---- | C] () -- C:\WINDOWS\System32\ff_mpeg2enc.dll
[2003/01/07 15:05:08 | 00,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[1998/08/16 05:00:00 | 00,004,096 | ---- | C] () -- C:\WINDOWS\System32\sysres.dll
========== Files - Modified Within 30 Days ==========
[2009/06/19 04:44:21 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/06/19 04:43:13 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\Owner\Local Settings\desktop.ini
[2009/06/19 04:43:05 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/06/19 03:40:29 | 00,001,709 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2009/06/19 03:40:28 | 00,002,626 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2009/06/19 02:06:23 | 00,000,611 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\NTREGOPT.lnk
[2009/06/19 02:06:23 | 00,000,592 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\ERUNT.lnk
[2009/06/18 14:56:55 | 00,001,732 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\WinZip.lnk
[2009/06/18 14:49:07 | 13,727,048 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\winzip121.exe
[2009/06/18 04:57:54 | 00,000,706 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\BitTorrent.lnk
[2009/06/18 04:57:19 | 01,739,664 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\BitTorrent-6.1.2.exe
[2009/06/17 17:30:52 | 00,004,096 | ---- | M] () -- C:\WINDOWS\System32\crash
[2009/06/17 15:06:53 | 00,001,934 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mobipocket Reader.lnk
[2009/06/17 15:06:20 | 05,606,400 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\mobireadersetup.msi
[2009/06/17 11:27:56 | 00,038,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/06/17 11:27:44 | 00,019,096 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/06/17 05:38:38 | 00,001,072 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Shortcut to Ahrimans-Prophecy-Strategy-Guide.pdf.lnk
[2009/06/17 04:53:39 | 00,156,285 | ---- | M] () -- C:\WINDOWS\Ahriman's Prophecy Uninstaller.exe
[2009/06/17 04:53:39 | 00,000,740 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Ahriman's Prophecy.lnk
[2009/06/17 02:37:59 | 00,001,511 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Shortcut to Aveyond Ultimate.pdf.lnk
[2009/06/16 19:55:00 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/06/16 00:34:49 | 00,001,729 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2009/06/14 23:03:43 | 00,000,736 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Aveyond.lnk
[2009/06/14 22:18:02 | 33,113,448 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Install_DinerDashHometownHero.EXE
[2009/06/14 22:02:06 | 00,001,974 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Parking Dash.lnk
[2009/06/12 12:16:01 | 00,280,536 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/06/12 11:57:50 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009/06/09 19:20:20 | 00,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/06/08 09:13:24 | 00,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/06/02 17:40:51 | 00,202,072 | R--- | M] (Coupons, Inc.) -- C:\WINDOWS\System32\cpnprt2.cid
[2009/06/02 17:40:13 | 01,277,680 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\CouponPrinter.exe
[2009/05/27 22:18:34 | 00,049,889 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\frank.jpg
[2009/05/26 04:16:29 | 00,000,384 | ---- | M] () -- C:\WINDOWS\tasks\SmartDefrag.job
[2009/05/24 13:08:35 | 00,001,800 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Network Magic.lnk
[2009/05/21 07:26:16 | 00,013,824 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\Graph.xls
[2009/05/20 12:23:35 | 00,029,696 | ---- | M] () -- C:\Documents and Settings\Owner\My Documents\Medicalcurrent.xls
========== Alternate Data Streams ==========
@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E6088A0C
< End of report >
Extras log:
OTL Extras logfile created on: 6/19/2009 4:46:19 AM - Run 1
OTL by OldTimer - Version 2.1.1.0 Folder = C:\Documents and Settings\Owner\Desktop\gtg
Windows XP Tablet PC Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.41 Gb Available Physical Memory | 70.45% Memory free
3.84 Gb Paging File | 3.31 Gb Available in Paging File | 86.17% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 68.66 Gb Total Space | 44.53 Gb Free Space | 64.86% Space Free | Partition Type: NTFS
Drive D: | 5.85 Gb Total Space | 1.79 Gb Free Space | 30.60% Space Free | Partition Type: FAT32
Drive E: | 58.54 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: KL
Current User Name: Owner
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url [@ = InternetShortcut] -- rundll32.exe shdocvw.dll,OpenURL %l
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"67:UDP" = 67:UDP:*:Enabled:DHCP Discovery Service
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL File not found
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL File not found
C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL (America Online, Inc.)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL File not found
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL File not found
C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL (America Online, Inc.)
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger (Yahoo! Inc.)
C:\Program Files\deepinvent\MailStore Home\MailStoreLocal.exe:*:Enabled:MailStore Home (deepinvent Software GmbH)
C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader (AOL LLC)
C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM (AOL LLC)
C:\Program Files\Tencent\QQ Games\QQGames.exe:*:Enabled:QQ Games (Tencent America LLC)
C:\Program Files\Tencent\QQ Games\QQGamesD.exe:*:Enabled:QQ Games Downloader ()
C:\Program Files\Tencent\QQ Games\Update\Update.exe:*:Enabled:QQ Games Updater ()
C:\Documents and Settings\Owner\My Documents\FreeFTP\FREEFTP.EXE:*:Enabled:FreeFTP (Internet File Transfer Program) (Brandyware Software)
C:\Program Files\DNA\btdna.exe:*:Enabled:DNA (BitTorrent, Inc.)
C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent (BitTorrent, Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0B1AAC97-8563-41D9-AE47-58E6A222F0E1}" = Search Settings 1.2.1
"{0CAD092C-5D1E-48AD-A845-E1EBA9AF1AF8}" = Tablet PC Tutorials for Microsoft Windows XP SP2
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{2BD74F5D-4089-4064-B6AF-8E8A93022650}" = Office 2003 Setup Files
"{342126E1-173C-4585-BFBE-3EBDD20E3E9E}" = Mobipocket Reader 6.2
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3F262ADC-5AD2-48E5-A586-44315E04A9E2}" = Microsoft Picture It! Library 10
"{42756145-9997-4D28-809B-8756BFD00106}" = Microsoft Picture It! Premium 10
"{578B6EF9-119B-4FB8-8377-7DAFA9588B97}" = Network Magic
"{58F4D4FD-1814-4068-B316-C28FC776C6DD}" = GoToMyPC
"{607398CF-354B-4E21-B1BC-549424BFD04C}" = TIPCI
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{7148F0A8-6813-11D6-A77B-00B0D0142000}" = Java 2 Runtime Environment, SE v1.4.2
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{805F1F1F-3CBB-45A6-BED5-DA1AF489E1EB}" = ATI Catalyst Control Center
"{82EF8297-C8B2-4CA8-9430-FF2BC8C40414}" = GWCares
"{90437E5F-0A9E-4B63-AD8B-D232897D18BF}" = ATI Parental Control & Encoder
"{91110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{94C3BB3A-56A1-43DE-A242-8B41F46E97EF}" = Dealio Toolbar v4.0
"{9F7FC79B-3059-4264-9450-39EB368E3225}" = Microsoft Digital Image Library 9 - Blocker
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1.2
"{B80CC46C-5839-4A48-B051-3CACF23A2718}_is1" = Eraser 5.86
"{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
"{C66BE4C2-E583-473D-8719-AE05CD7EDEE2}" = PalmTether
"{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime
"{C9507D0D-1A9C-486E-91D6-33A71CCA55F2}" = Pure Networks Platform
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240B8}" = WinZip 12.1
"{E9B64F7A-1CBC-4D04-A71C-3C12B2BD049A}_is1" = Free CD to WAV MP3 WMA AMR AC3 AAC Ripper 3.5
"{FD6034A3-655C-49F0-B496-D4CBFD74D7A7}" = Palm Desktop by ACCESS
"Abcc Free Music to Mp3 Amr aac ogg Converter_is1" = Abcc Free Music to Mp3 Amr aac ogg Converter 3.0
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Ahriman's Prophecy" = Ahriman's Prophecy
"AI RoboForm" = AI RoboForm (All Users)
"Aim Plugin for QQ Games" = Aim Plugin for QQ Games
"AIM_6" = AIM 6
"AIMTunes" = AIMTunes
"AlfaClock Free Edition_is1" = AlfaClock Free Edition version 1.99 build May 2, 2007
"All ATI Software" = ATI - Software Uninstall Utility
"America Online us" = America Online (Choose which version to remove)
"AOL Spyware Protection" = AOL Spyware Protection
"AOL Toolbar" = AOL Toolbar
"ATI Display Driver" = ATI Display Driver
"avast!" = avast! Antivirus
"Aveyond" = Aveyond
"Cool Timer_is1" = Cool Timer 3.6
"Coupon Printer for Windows4.0" = Coupon Printer for Windows
"Diner Dash Hometown Hero - Gourmet" = Diner Dash Hometown Hero - Gourmet
"EPSON Printer and Utilities" = EPSON Printer Software
"EPSON Scanner" = EPSON Scan
"ERUNT_is1" = ERUNT 1.1j
"Free Mp3 Wma Converter_is1" = Free Mp3 Wma Converter V 1.8.0
"InstallShield_{607398CF-354B-4E21-B1BC-549424BFD04C}" = Texas Instruments PCIxx21/x515/xx12 drivers.
"Learn_to_Play_Bridge" = Learn to Play Bridge
"Learn_to_Play_Bridge_2" = Learn to Play Bridge 2
"MailStore Home_is1" = MailStore Home 3.0.2.2448
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Mozilla Firefox (3.0.11)" = Mozilla Firefox (3.0.11)
"Mozilla Thunderbird (2.0.0.21)" = Mozilla Thunderbird (2.0.0.21)
"Network MagicUninstall" = Network Magic
"Parking Dash" = Parking Dash
"PictureItPrem_v10" = Microsoft Picture It! Premium 10
"Port Magic" = Pure Networks Port Magic
"PROSet" = Intel® PRO Network Connections Drivers
"QQ Bubble Arena" = QQ Bubble Arena
"QQ Games" = QQ Games
"QQ Pool" = QQ Pool
"QQ Treasure Hunter" = QQ Treasure Hunter
"RealPlayer 6.0" = RealPlayer Basic
"Smart Defrag_is1" = Smart Defrag 1.11
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"StreetPlugin" = Learn2 Player (Uninstall Only)
"ViewpointMediaPlayer" = Viewpoint Media Player
"VZAccess Manager" = VZAccess Manager
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"XP Codec Pack" = XP Codec Pack
"Yahoo! Messenger" = Yahoo! Messenger
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"BitTorrent" = BitTorrent
"BitTorrent DNA" = DNA
"GoToMeeting" = GoToMeeting 4.1.0.366
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 6/19/2009 3:16:18 AM | Computer Name = KL | Source = ESENT | ID = 465
Description = wuauclt (3600) Corruption was detected during soft recovery in logfile
C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log. The failing checksum record
is located at position END. Data not matching the log-file fill pattern first appeared
in sector 54 (0x00000036). This logfile has been damaged and is unusable.
Error - 6/19/2009 3:16:19 AM | Computer Name = KL | Source = ESENT | ID = 465
Description = wuauclt (3600) Corruption was detected during soft recovery in logfile
C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log. The failing checksum record
is located at position END. Data not matching the log-file fill pattern first appeared
in sector 54 (0x00000036). This logfile has been damaged and is unusable.
Error - 6/19/2009 3:16:20 AM | Computer Name = KL | Source = ESENT | ID = 465
Description = wuauclt (3600) Corruption was detected during soft recovery in logfile
C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log. The failing checksum record
is located at position END. Data not matching the log-file fill pattern first appeared
in sector 54 (0x00000036). This logfile has been damaged and is unusable.
Error - 6/19/2009 3:16:25 AM | Computer Name = KL | Source = ESENT | ID = 454
Description = wuauclt (3600) Database recovery/restore failed with unexpected error
-501.
Error - 6/19/2009 4:46:47 AM | Computer Name = KL | Source = PerfNet | ID = 2004
Description = Unable to open the Server service. Server performance data will not
be returned. Error code returned is in data DWORD 0.
Error - 6/19/2009 5:00:49 AM | Computer Name = KL | Source = Application Hang | ID = 1002
Description = Hanging application OTL.exe, version 2.1.1.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 6/19/2009 5:25:06 AM | Computer Name = KL | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.3156, faulting
module shell32.dll, version 6.0.2900.3402, fault address 0x00192000.
Error - 6/19/2009 5:29:39 AM | Computer Name = KL | Source = Application Hang | ID = 1002
Description = Hanging application mbam.exe, version 1.38.0.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 6/19/2009 5:30:18 AM | Computer Name = KL | Source = Application Error | ID = 1000
Description = Faulting application explorer.exe, version 6.0.2900.3156, faulting
module shell32.dll, version 6.0.2900.3402, fault address 0x00192000.
Error - 6/19/2009 5:44:32 AM | Computer Name = KL | Source = PerfNet | ID = 2004
Description = Unable to open the Server service. Server performance data will not
be returned. Error code returned is in data DWORD 0.
< End of report >