Here's the Malwarebytes log:
Malwarebytes' Anti-Malware 1.41
Database version: 2866
Windows 5.1.2600 Service Pack 3
9/27/2009 7:34:35 PM
mbam-log-2009-09-27 (19-34-35).txt
Scan type: Full Scan (C:\|D:\|)
Objects scanned: 232643
Time elapsed: 1 hour(s), 6 minute(s), 59 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1491\A0109549.sys (Rootkit.TDSS) -> Quarantined and deleted successfully.
_________________
I only see one log for OTL. Here it is:
OTS logfile created on: 9/27/2009 7:42:44 PM - Run 2
OTS by OldTimer - Version 3.0.12.1 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
501.71 Mb Total Physical Memory | 181.61 Mb Available Physical Memory | 36.20% Memory free
1.20 Gb Paging File | 0.86 Gb Available in Paging File | 71.68% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 182.07 Gb Total Space | 161.35 Gb Free Space | 88.62% Space Free | Partition Type: NTFS
Drive D: | 4.23 Gb Total Space | 1.68 Gb Free Space | 39.77% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: YOUR-E0A65F95D4
Current User Name: Owner
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: Off
File Age = 30 Days
[Processes - Safe List]
alcwzrd.exe -> C:\WINDOWS\ALCWZRD.EXE -> [2004/09/24 21:06:46 | 02,559,488 | ---- | M] (RealTek Semicoductor Corp.)
calmain.exe -> C:\Program Files\Canon\CAL\CALMAIN.exe -> [2005/06/02 16:54:34 | 00,086,606 | ---- | M] (Canon Inc.)
explorer.exe -> C:\WINDOWS\Explorer.EXE -> [2008/04/13 19:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation)
hkcmd.exe -> C:\WINDOWS\System32\hkcmd.exe -> [2004/08/20 18:51:14 | 00,118,784 | ---- | M] (Intel Corporation)
igfxtray.exe -> C:\WINDOWS\System32\igfxtray.exe -> [2004/08/20 18:55:14 | 00,155,648 | ---- | M] (Intel Corporation)
ipclient.exe -> C:\Program Files\EarthLink TotalAccess\FastLane2\IPClient.exe -> [2005/08/10 22:10:36 | 00,380,928 | R--- | M] (Visual Networks)
ipmon32.exe -> C:\Program Files\EarthLink TotalAccess\FastLane2\IPMon32.exe -> [2005/08/10 22:10:36 | 00,122,880 | R--- | M] (Visual Networks)
khalmnpr.exe -> C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE -> [2009/02/19 00:28:52 | 00,076,304 | ---- | M] (Logitech, Inc.)
lexbces.exe -> C:\WINDOWS\System32\LEXBCES.EXE -> [2003/08/29 08:54:16 | 00,307,200 | ---- | M] (Lexmark International, Inc.)
lexpps.exe -> C:\WINDOWS\System32\LEXPPS.EXE -> [2003/08/29 08:50:24 | 00,174,592 | ---- | M] (Lexmark International, Inc.)
mcagent.exe -> C:\Program Files\McAfee.com\Agent\mcagent.exe -> [2009/01/08 21:30:26 | 00,645,328 | ---- | M] (McAfee, Inc.)
mcmscsvc.exe -> C:\Program Files\McAfee\MSC\mcmscsvc.exe -> [2009/01/08 21:30:26 | 00,797,864 | ---- | M] (McAfee, Inc.)
mcnasvc.exe -> c:\program files\common files\mcafee\mna\mcnasvc.exe -> [2009/01/09 12:31:16 | 02,482,848 | ---- | M] (McAfee, Inc.)
mcproxy.exe -> c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe -> [2009/01/09 09:06:52 | 00,359,952 | ---- | M] (McAfee, Inc.)
mcshield.exe -> C:\Program Files\McAfee\VirusScan\Mcshield.exe -> [2009/03/25 11:05:48 | 00,144,704 | ---- | M] (McAfee, Inc.)
mcsysmon.exe -> C:\Program Files\McAfee\VirusScan\mcsysmon.exe -> [2009/03/24 00:03:18 | 00,606,736 | ---- | M] (McAfee, Inc.)
mdm.exe -> C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE -> [2003/06/20 00:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation)
msmsgs.exe -> C:\Program Files\Messenger\msmsgs.exe -> [2008/04/13 19:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)
opwarese2.exe -> C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe -> [2003/05/08 12:00:58 | 00,049,152 | ---- | M] (ScanSoft, Inc.)
ots.exe -> C:\Documents and Settings\Owner\Desktop\OTS.exe -> [2009/09/24 22:22:54 | 00,514,560 | ---- | M] (OldTimer Tools)
pdvdserv.exe -> C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe -> [2003/10/31 22:42:40 | 00,032,768 | ---- | M] (Cyberlink Corp.)
prismxl.sys -> C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS -> [2004/11/17 09:19:53 | 00,172,032 | ---- | M] (New Boundary Technologies, Inc.)
qttask.exe -> C:\Program Files\QuickTime\qttask.exe -> [2004/11/17 09:17:35 | 00,098,304 | ---- | M] (Apple Computer, Inc.)
setpoint.exe -> C:\Program Files\Logitech\SetPoint\SetPoint.exe -> [2009/02/19 00:33:08 | 00,809,488 | ---- | M] (Logitech, Inc.)
shwiconem.exe -> C:\Program Files\Digital Media Reader\shwiconem.exe -> [2004/10/18 17:05:12 | 00,135,168 | ---- | M] (Alcor Micro, Corp.)
soundman.exe -> C:\WINDOWS\SOUNDMAN.EXE -> [2004/09/23 22:27:18 | 00,077,824 | ---- | M] (Realtek Semiconductor Corp.)
taskpanl.exe -> C:\Program Files\EarthLink TotalAccess\TaskPanl.exe -> [2005/09/01 17:24:56 | 00,942,080 | ---- | M] (EarthLink, Inc.)
wdfmgr.exe -> C:\WINDOWS\System32\wdfmgr.exe -> [2004/08/11 04:45:04 | 00,038,912 | ---- | M] (Microsoft Corporation)
wkufind.exe -> C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe -> [2003/06/07 06:32:32 | 00,050,688 | ---- | M] (Microsoft® Corporation)
wmonitor.exe -> C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe -> [2005/01/26 11:47:42 | 00,065,604 | ---- | M] (Boingo Wireless, Inc.)
wzqkpick.exe -> C:\Program Files\WinZip\WZQKPICK.EXE -> [2008/09/23 11:20:00 | 00,415,072 | R--- | M] (WinZip Computing, S.L.)
zhotkey.exe -> C:\WINDOWS\zHotkey.exe -> [2004/05/17 21:30:04 | 00,543,232 | ---- | M] ()
[Win32 Services - Safe List]
(aspnet_state) ASP.NET State Service [Win32_Own | On_Demand | Stopped] -> C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe -> [2004/07/15 02:49:26 | 00,032,768 | ---- | M] (Microsoft Corporation)
(CCALib8) Canon Camera Access Library 8 [Win32_Own | Auto | Running] -> C:\Program Files\Canon\CAL\CALMAIN.exe -> [2005/06/02 16:54:34 | 00,086,606 | ---- | M] (Canon Inc.)
(EarthLinkMonitor) EarthLink Monitor Service [Win32_Own | Auto | Running] -> C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe -> [2005/01/26 11:47:42 | 00,065,604 | ---- | M] (Boingo Wireless, Inc.)
(helpsvc) Help and Support [Win32_Shared | Auto | Running] -> C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -> [2008/04/13 19:12:02 | 00,038,400 | ---- | M] (Microsoft Corporation)
(LBTServ) Logitech Bluetooth Service [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe -> [2009/02/19 00:30:20 | 00,121,360 | ---- | M] (Logitech, Inc.)
(LexBceS) LexBce Server [Win32_Own | Auto | Running] -> C:\WINDOWS\System32\LEXBCES.EXE -> [2003/08/29 08:54:16 | 00,307,200 | ---- | M] (Lexmark International, Inc.)
(mcmscsvc) McAfee Services [Win32_Own | Auto | Running] -> C:\Program Files\McAfee\MSC\mcmscsvc.exe -> [2009/01/08 21:30:26 | 00,797,864 | ---- | M] (McAfee, Inc.)
(McNASvc) McAfee Network Agent [Win32_Own | Auto | Running] -> c:\program files\common files\mcafee\mna\mcnasvc.exe -> [2009/01/09 12:31:16 | 02,482,848 | ---- | M] (McAfee, Inc.)
(McODS) McAfee Scanner [Win32_Own | On_Demand | Stopped] -> C:\Program Files\McAfee\VirusScan\mcods.exe -> [2009/04/01 14:21:30 | 00,365,072 | ---- | M] (McAfee, Inc.)
(McProxy) McAfee Proxy Service [Win32_Own | Auto | Running] -> c:\Program Files\Common Files\McAfee\McProxy\McProxy.exe -> [2009/01/09 09:06:52 | 00,359,952 | ---- | M] (McAfee, Inc.)
(McShield) McAfee Real-time Scanner [Win32_Own | Unknown | Running] -> C:\Program Files\McAfee\VirusScan\Mcshield.exe -> [2009/03/25 11:05:48 | 00,144,704 | ---- | M] (McAfee, Inc.)
(McSysmon) McAfee SystemGuards [Win32_Own | On_Demand | Running] -> C:\Program Files\McAfee\VirusScan\mcsysmon.exe -> [2009/03/24 00:03:18 | 00,606,736 | ---- | M] (McAfee, Inc.)
(MDM) Machine Debug Manager [Win32_Own | Auto | Running] -> C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE -> [2003/06/20 00:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation)
(ose) Office Source Engine [Win32_Own | On_Demand | Stopped] -> C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -> [2003/07/28 13:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation)
(PrismXL) PrismXL [Win32_Own | Auto | Running] -> C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS -> [2004/11/17 09:19:53 | 00,172,032 | ---- | M] (New Boundary Technologies, Inc.)
(UMWdf) Windows User Mode Driver Framework [Win32_Own | Auto | Running] -> C:\WINDOWS\System32\wdfmgr.exe -> [2004/08/11 04:45:04 | 00,038,912 | ---- | M] (Microsoft Corporation)
[Driver Services - Safe List]
(AliIde) AliIde [Kernel | Boot | Running] -> C:\WINDOWS\system32\DRIVERS\aliide.sys -> [2001/08/17 22:51:56 | 00,005,248 | ---- | M] (Acer Laboratories Inc.)
(amdagp) AMD AGP Bus Filter Driver [Kernel | Boot | Running] -> C:\WINDOWS\system32\DRIVERS\amdagp.sys -> [2008/04/13 13:36:39 | 00,043,008 | ---- | M] (Advanced Micro Devices, Inc.)
(asc) asc [Kernel | Boot | Running] -> C:\WINDOWS\system32\DRIVERS\asc.sys -> [2001/08/17 22:52:00 | 00,026,496 | ---- | M] (Advanced System Products, Inc.)
(asc3550) asc3550 [Kernel | Boot | Running] -> C:\WINDOWS\system32\DRIVERS\asc3550.sys -> [2001/08/17 22:51:58 | 00,014,848 | ---- | M] (Advanced System Products, Inc.)
(ASCTRM) ASCTRM [Kernel | Auto | Running] -> C:\WINDOWS\System32\drivers\asctrm.sys -> [2004/11/17 09:17:06 | 00,008,552 | ---- | M] (Windows (R) 2000 DDK provider)
(BW2NDIS5) BW2NDIS5 [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\Drivers\BW2NDIS5.sys -> [2004/11/01 14:16:34 | 00,017,536 | R--- | M] (Printing Communications Assoc., Inc. (PCAUSA))
(CmdIde) CmdIde [Kernel | Boot | Running] -> C:\WINDOWS\system32\DRIVERS\cmdide.sys -> [2001/08/17 22:51:54 | 00,006,656 | ---- | M] (CMD Technology, Inc.)
(dac2w2k) dac2w2k [Kernel | Boot | Running] -> C:\WINDOWS\system32\DRIVERS\dac2w2k.sys -> [2001/08/17 22:52:16 | 00,179,584 | ---- | M] (Mylex Corporation)
(E100B) Intel(R) PRO Adapter Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\e100b325.sys -> [2004/02/10 16:49:14 | 00,154,112 | ---- | M] (Intel Corporation)
(ENUM1394) %1394\031887&040892.DeviceDesc% [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\enum1394.sys -> [2001/08/17 16:46:40 | 00,006,400 | ---- | M] (Microsoft Corporation)
(HdAudAddService) Microsoft UAA Function Driver for High Definition Audio Service [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\drivers\HdAudio.sys -> [2004/03/17 18:10:40 | 00,113,664 | ---- | M] (Windows (R) Server 2003 DDK provider)
(HDAudBus) Microsoft UAA Bus Driver for High Definition Audio [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\HDAudBus.sys -> [2008/04/13 11:36:05 | 00,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider)
(HSFHWBS2) HSFHWBS2 [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\HSFHWBS2.sys -> [2004/06/17 17:56:22 | 00,220,032 | ---- | M] (Conexant Systems, Inc.)
(HSF_DP) HSF_DP [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\HSF_DP.sys -> [2004/06/17 17:55:04 | 01,041,536 | ---- | M] (Conexant Systems, Inc.)
(ialm) ialm [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\ialmnt5.sys -> [2004/08/20 19:26:00 | 00,737,874 | ---- | M] (Intel Corporation)
(IntcAzAudAddService) Service for Realtek HD Audio (WDM) [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\drivers\RtkHDAud.sys -> [2004/09/24 21:14:40 | 02,276,672 | ---- | M] (Realtek Semiconductor Corp.)
(L8042Kbd) Logitech SetPoint Keyboard Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\L8042Kbd.sys -> [2007/04/11 15:32:30 | 00,020,496 | ---- | M] (Logitech Inc.)
(L8042mou) SetPoint PS/2 Mouse Filter Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\L8042mou.Sys -> [2008/12/18 23:43:12 | 00,063,248 | ---- | M] (Logitech, Inc.)
(LHidFilt) Logitech SetPoint KMDF HID Filter Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\LHidFilt.Sys -> [2008/12/18 23:43:40 | 00,035,472 | ---- | M] (Logitech, Inc.)
(LMouKE) SetPoint Mouse Filter Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\LMouKE.Sys -> [2008/12/18 23:43:54 | 00,079,248 | ---- | M] (Logitech, Inc.)
(mdmxsdk) mdmxsdk [Kernel | Auto | Running] -> C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys -> [2004/03/17 14:04:14 | 00,013,059 | ---- | M] (Conexant)
(mfeavfk) McAfee Inc. mfeavfk [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\drivers\mfeavfk.sys -> [2009/03/25 11:06:28 | 00,079,880 | ---- | M] (McAfee, Inc.)
(mfebopk) McAfee Inc. mfebopk [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\drivers\mfebopk.sys -> [2009/03/25 11:06:28 | 00,035,272 | ---- | M] (McAfee, Inc.)
(mfehidk) McAfee Inc. mfehidk [Kernel | System | Running] -> C:\WINDOWS\System32\drivers\mfehidk.sys -> [2009/03/25 11:06:28 | 00,214,024 | ---- | M] (McAfee, Inc.)
(mferkdk) McAfee Inc. mferkdk [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\drivers\mferkdk.sys -> [2009/03/25 11:05:54 | 00,034,216 | ---- | M] (McAfee, Inc.)
(mfesmfk) McAfee Inc. mfesmfk [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\drivers\mfesmfk.sys -> [2009/03/25 11:06:30 | 00,040,552 | ---- | M] (McAfee, Inc.)
(MPFP) MPFP [Kernel | System | Running] -> C:\WINDOWS\System32\Drivers\Mpfp.sys -> [2008/10/23 14:08:54 | 00,120,136 | ---- | M] (McAfee, Inc.)
(mraid35x) mraid35x [Kernel | Boot | Running] -> C:\WINDOWS\system32\DRIVERS\mraid35x.sys -> [2001/08/17 22:52:12 | 00,017,280 | ---- | M] (American Megatrends Inc.)
(mxnic) Macronix MX987xx Family Fast Ethernet NT Driver [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\mxnic.sys -> [2001/08/17 15:49:32 | 00,019,968 | ---- | M] (Macronix International Co., Ltd. )
(nv) nv [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\nv4_mini.sys -> [2004/08/04 00:29:56 | 01,897,408 | ---- | M] (NVIDIA Corporation)
(Ptilink) Direct Parallel Link Driver [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\ptilink.sys -> [2004/08/04 14:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.)
(ql1080) ql1080 [Kernel | Boot | Running] -> C:\WINDOWS\system32\DRIVERS\ql1080.sys -> [2001/08/17 22:52:20 | 00,040,320 | ---- | M] (QLogic Corporation)
(ql12160) ql12160 [Kernel | Boot | Running] -> C:\WINDOWS\system32\DRIVERS\ql12160.sys -> [2001/08/17 22:52:20 | 00,045,312 | ---- | M] (QLogic Corporation)
(ql1280) ql1280 [Kernel | Boot | Running] -> C:\WINDOWS\system32\DRIVERS\ql1280.sys -> [2001/08/17 22:52:18 | 00,049,024 | ---- | M] (QLogic Corporation)
(Secdrv) Secdrv [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\DRIVERS\secdrv.sys -> [2007/11/13 05:25:53 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
(sisagp) SIS AGP Bus Filter [Kernel | Boot | Running] -> C:\WINDOWS\system32\DRIVERS\sisagp.sys -> [2008/04/13 13:36:39 | 00,040,960 | ---- | M] (Silicon Integrated Systems Corporation)
(Sparrow) Sparrow [Kernel | Boot | Running] -> C:\WINDOWS\system32\DRIVERS\sparrow.sys -> [2001/08/17 23:07:44 | 00,019,072 | ---- | M] (Adaptec, Inc.)
(SunkFilt) Alcor Micro Corp - 9360 [Kernel | On_Demand | Stopped] -> C:\WINDOWS\System32\Drivers\sunkfilt.sys -> [2004/10/20 14:39:32 | 00,040,724 | ---- | M] (Alcor Micro Corp.)
(SunkFilt39) Alcor Micro Corp - 3239 [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\Drivers\sunkfilt39.sys -> [2004/10/18 17:05:12 | 00,042,968 | ---- | M] (Alcor Micro Corp.)
(symc810) symc810 [Kernel | Boot | Running] -> C:\WINDOWS\system32\DRIVERS\symc810.sys -> [2001/08/17 23:07:34 | 00,016,256 | ---- | M] (Symbios Logic Inc.)
(symc8xx) symc8xx [Kernel | Boot | Running] -> C:\WINDOWS\system32\DRIVERS\symc8xx.sys -> [2001/08/17 23:07:36 | 00,032,640 | ---- | M] (LSI Logic)
(sym_hi) sym_hi [Kernel | Boot | Running] -> C:\WINDOWS\system32\DRIVERS\sym_hi.sys -> [2001/08/17 23:07:40 | 00,028,384 | ---- | M] (LSI Logic)
(sym_u3) sym_u3 [Kernel | Boot | Running] -> C:\WINDOWS\system32\DRIVERS\sym_u3.sys -> [2001/08/17 23:07:42 | 00,030,688 | ---- | M] (LSI Logic)
(ultra) ultra [Kernel | Boot | Running] -> C:\WINDOWS\system32\DRIVERS\ultra.sys -> [2001/08/17 22:52:22 | 00,036,736 | ---- | M] (Promise Technology, Inc.)
(winachsf) winachsf [Kernel | On_Demand | Running] -> C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys -> [2004/06/17 17:55:38 | 00,685,056 | ---- | M] (Conexant Systems, Inc.)
[Registry - Safe List]
< Internet Explorer Settings [HKEY_LOCAL_MACHINE\] > -> ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Page_URL" -> http://go.microsoft.com/fwlink/?LinkId=69157 ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Search_URL" -> http://go.microsoft.com/fwlink/?LinkId=54896 ->
HKEY_LOCAL_MACHINE\: Main\\"Default_Secondary_Page_URL" -> [binary data] ->
HKEY_LOCAL_MACHINE\: Main\\"Extensions Off Page" -> about:NoAdd-ons ->
HKEY_LOCAL_MACHINE\: Main\\"Local Page" -> C:\WINDOWS\system32\blank.htm ->
HKEY_LOCAL_MACHINE\: Main\\"Search Page" -> http://go.microsoft.com/fwlink/?LinkId=54896 ->
HKEY_LOCAL_MACHINE\: Main\\"Security Risk Page" -> about:SecurityRisk ->
HKEY_LOCAL_MACHINE\: Main\\"Start Page" -> http://go.microsoft.com/fwlink/?LinkId=69157 ->
HKEY_LOCAL_MACHINE\: Search\\"CustomizeSearch" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm ->
HKEY_LOCAL_MACHINE\: Search\\"SearchAssistant" -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm ->
< Internet Explorer Settings [HKEY_CURRENT_USER\] > -> ->
HKEY_CURRENT_USER\: Main\\"Default_Search_URL" -> http://www.earthlink.net/partner/more/msie/button/search.html ->
HKEY_CURRENT_USER\: Main\\"Local Page" -> C:\WINDOWS\system32\blank.htm ->
HKEY_CURRENT_USER\: Main\\"Page_Transitions" -> 1 ->
HKEY_CURRENT_USER\: Main\\"Search Page" -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch ->
HKEY_CURRENT_USER\: Main\\"Start Page" -> http://start.earthlink.net/ ->
HKEY_CURRENT_USER\: URLSearchHooks\\"{44F9B173-041C-4825-A9B9-D914BD9DCBB3}" [HKLM] -> C:\Program Files\EarthLink TotalAccess\ElnIE.dll [SrchHook Class] -> [2005/09/20 16:09:10 | 00,069,632 | ---- | M] (EarthLink, Inc.)
HKEY_CURRENT_USER\: "ProxyEnable" -> 0 ->
< FireFox Settings [Prefs.js] > -> C:\Documents and Settings\Owner\Application Data\Mozilla\FireFox\Profiles\dj6fmni2.default\prefs.js ->
browser.search.selectedEngine -> "Live Search" ->
browser.search.useDBForOrder -> true ->
browser.startup.homepage -> "http://start.earthlink.net/" ->
extensions.enabledItems -> {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.3 ->
network.proxy.type -> 1 ->
< FireFox Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla
HKLM\software\mozilla\Firefox\Extensions -> ->
HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions -> ->
HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Components -> C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS] -> [2009/09/10 18:46:23 | 00,000,000 | ---D | M]
HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Plugins -> C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS] -> [2009/09/18 14:44:04 | 00,000,000 | ---D | M]
< FireFox Extensions [User Folders] > ->
-> C:\Documents and Settings\Owner\Application Data\mozilla\Extensions -> [2008/08/30 10:08:25 | 00,000,000 | ---D | M]
-> C:\Documents and Settings\Owner\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} -> [2008/08/30 10:08:25 | 00,000,000 | ---D | M]
-> C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\dj6fmni2.default\extensions -> [2009/09/10 18:46:35 | 00,101,869 | ---- | M] ()
< FireFox SearchPlugins [User Folders] > ->
C:\Documents and Settings\Owner\Application Data\Mozilla\FireFox\Profiles\dj6fmni2.default\searchplugins\ -> C:\Documents and Settings\Owner\Application Data\Mozilla\FireFox\Profiles\dj6fmni2.default\searchplugins -> [2008/05/30 07:29:48 | 00,000,000 | ---D | M]
live-search.xml -> C:\Documents and Settings\Owner\Application Data\Mozilla\FireFox\Profiles\dj6fmni2.default\searchplugins\live-search.xml -> [2008/05/30 07:29:48 | 00,001,944 | ---- | M] ()
< FireFox Extensions [Program Folders] > ->
-> C:\PROGRAM FILES\MOZILLA FIREFOX\extensions -> [2009/09/10 18:46:23 | 10,776,568 | ---- | M] (Mozilla Foundation)
-> C:\PROGRAM FILES\MOZILLA FIREFOX\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} -> [2009/09/10 18:46:23 | 10,776,568 | ---- | M] (Mozilla Foundation)
< FireFox Components [Program Folders] > ->
C:\PROGRAM FILES\MOZILLA FIREFOX\components\ -> C:\PROGRAM FILES\MOZILLA FIREFOX\components -> [2009/09/10 18:46:23 | 00,000,000 | ---D | M]
browserdirprovider.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\components\browserdirprovider.dll -> [2009/09/10 18:46:17 | 00,023,544 | ---- | M] (Mozilla Foundation)
brwsrcmp.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\components\brwsrcmp.dll -> [2009/09/10 18:46:17 | 00,137,208 | ---- | M] (Mozilla Foundation)
< FireFox Plugins [Program Folders] > ->
C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\ -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins -> [2009/09/18 14:44:04 | 00,000,000 | ---D | M]
flashplayer.xpt -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\flashplayer.xpt -> [2007/11/20 16:51:00 | 00,000,856 | ---- | M] ()
npnul32.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\npnul32.dll -> [2009/09/10 18:46:18 | 00,065,016 | ---- | M] (mozilla.org)
nppdf32.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\nppdf32.dll -> [2008/10/14 21:33:30 | 00,095,600 | ---- | M] (Adobe Systems Inc.)
NPSWF32.dll -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\NPSWF32.dll -> [2007/11/20 17:52:00 | 02,884,992 | ---- | M] ()
NPSWF32_FlashUtil.exe -> C:\PROGRAM FILES\MOZILLA FIREFOX\plugins\NPSWF32_FlashUtil.exe -> [2007/11/20 17:52:00 | 00,218,496 | ---- | M] (Adobe Systems, Inc.)
< FireFox SearchPlugins [Program Folders] > ->
C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\ -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins -> [2009/09/05 12:16:39 | 00,000,000 | ---D | M]
amazondotcom.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\amazondotcom.xml -> [2009/09/05 12:16:35 | 00,001,394 | ---- | M] ()
answers.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\answers.xml -> [2009/09/05 12:16:35 | 00,002,193 | ---- | M] ()
creativecommons.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\creativecommons.xml -> [2009/09/05 12:16:35 | 00,001,534 | ---- | M] ()
eBay.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\eBay.xml -> [2009/09/05 12:16:35 | 00,002,344 | ---- | M] ()
google.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\google.xml -> [2009/09/05 12:16:35 | 00,002,371 | ---- | M] ()
wikipedia.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\wikipedia.xml -> [2009/09/05 12:16:35 | 00,001,178 | ---- | M] ()
yahoo.xml -> C:\PROGRAM FILES\MOZILLA FIREFOX\searchplugins\yahoo.xml -> [2009/09/05 12:16:35 | 00,000,792 | ---- | M] ()
< HOSTS File > (27 bytes and 1 lines) -> C:\WINDOWS\System32\drivers\etc\Hosts ->
Reset Hosts
127.0.0.1 localhost
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} [HKLM] -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [Adobe PDF Reader Link Helper] -> [2006/10/22 23:08:42 | 00,062,080 | ---- | M] (Adobe Systems Incorporated)
{512ACF1B-64D9-4928-B382-A80556F28DB4} [HKLM] -> C:\Program Files\EarthLink TotalAccess\Toolbar\ElnkPub.dll [ElnkPubBHO Class] -> [2009/09/25 07:26:14 | 00,255,296 | ---- | M] (EarthLink, Inc.)
{656EC4B7-072B-4698-B504-2A414C1F0037} [HKLM] -> C:\Program Files\EarthLink TotalAccess\Accelerator\prpl_IePopupBlocker.dll [IE_PopupBlocker Class] -> [2005/02/02 19:33:24 | 00,049,152 | R--- | M] (Propel Software Corporation)
{68F9551E-0411-48E4-9AAF-4BC42A6A46BE} [HKLM] -> C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll [EWPBrowseObject Class] -> [2005/10/20 21:16:26 | 00,034,304 | ---- | M] ()
{7DB2D5A0-7241-4E79-B68D-6309F01C5231} [HKLM] -> C:\Program Files\McAfee\VirusScan\scriptsn.dll [scriptproxy] -> [2009/03/25 11:05:56 | 00,062,784 | ---- | M] (McAfee, Inc.)
{9579D574-D4D8-4335-9560-FE8641A013BD} [HKLM] -> C:\Program Files\EarthLink TotalAccess\Toolbar\ProtctIE.dll [ElnkProtectionBHO Class] -> [2009/09/25 07:26:23 | 00,415,040 | ---- | M] (EarthLink, Inc.)
{E713904C-DF05-4C79-BBAD-02DB923253BE} [HKLM] -> C:\Program Files\EarthLink TotalAccess\Toolbar\uninsttb.dll [ElnkLegacyUninstBHO Class] -> [2009/09/25 07:26:30 | 00,279,872 | ---- | M] (EarthLink, Inc.)
{FDD3B846-8D59-4ffb-8758-209B6AD74ACC} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar ->
"{327C2873-E90D-4c37-AA9D-10AC9BABA46C}" [HKLM] -> C:\Program Files\Canon\Easy-WebPrint\Toolband.dll [Easy-WebPrint] -> [2005/10/20 21:18:00 | 00,552,960 | ---- | M] ()
"{C7768536-96F8-4001-B1A2-90EE21279187}" [HKLM] -> C:\Program Files\EarthLink TotalAccess\Toolbar\Toolbar.dll [EarthLink Toolbar] -> [2009/09/25 07:26:29 | 01,033,536 | ---- | M] (EarthLink, Inc.)
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ ->
ShellBrowser\\"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" [HKLM] -> Reg Error: Key error. [Reg Error: Key error.] -> File not found
WebBrowser\\"{C7768536-96F8-4001-B1A2-90EE21279187}" [HKLM] -> C:\Program Files\EarthLink TotalAccess\Toolbar\Toolbar.dll [EarthLink Toolbar] -> [2009/09/25 07:26:29 | 01,033,536 | ---- | M] (EarthLink, Inc.)
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"Adobe Reader Speed Launcher" -> C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe ["C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"] -> [2008/10/15 01:04:34 | 00,039,792 | ---- | M] (Adobe Systems Incorporated)
"AlcWzrd" -> C:\WINDOWS\ALCWZRD.EXE [ALCWZRD.EXE] -> [2004/09/24 21:06:46 | 02,559,488 | ---- | M] (RealTek Semicoductor Corp.)
"CHotkey" -> C:\WINDOWS\zHotkey.exe [zHotkey.exe] -> [2004/05/17 21:30:04 | 00,543,232 | ---- | M] ()
"High Definition Audio Property Page Shortcut" -> C:\WINDOWS\System32\Hdaudpropshortcut.exe [HDAudPropShortcut.exe] -> [2004/03/17 18:10:40 | 00,061,952 | ---- | M] (Windows (R) Server 2003 DDK provider)
"HotKeysCmds" -> C:\WINDOWS\System32\hkcmd.exe [C:\WINDOWS\system32\hkcmd.exe] -> [2004/08/20 18:51:14 | 00,118,784 | ---- | M] (Intel Corporation)
"IgfxTray" -> C:\WINDOWS\System32\igfxtray.exe [C:\WINDOWS\system32\igfxtray.exe] -> [2004/08/20 18:55:14 | 00,155,648 | ---- | M] (Intel Corporation)
"IPInSightLAN 01" -> C:\Program Files\EarthLink TotalAccess\FastLane2\IPClient.exe ["C:\Program Files\EarthLink TotalAccess\FastLane2\IPClient.exe" -l] -> [2005/08/10 22:10:36 | 00,380,928 | R--- | M] (Visual Networks)
"IPInSightMonitor 01" -> C:\Program Files\EarthLink TotalAccess\FastLane2\IPMon32.exe ["C:\Program Files\EarthLink TotalAccess\FastLane2\IPMon32.exe"] -> [2005/08/10 22:10:36 | 00,122,880 | R--- | M] (Visual Networks)
"Kernel and Hardware Abstraction Layer" -> C:\WINDOWS\KHALMNPR.Exe [KHALMNPR.EXE] -> [2008/12/18 23:42:58 | 00,076,304 | ---- | M] (Logitech, Inc.)
"Logitech Hardware Abstraction Layer" -> C:\WINDOWS\KHALMNPR.Exe [KHALMNPR.EXE] -> [2008/12/18 23:42:58 | 00,076,304 | ---- | M] (Logitech, Inc.)
"Malwarebytes Anti-Malware (reboot)" -> C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe ["C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript] -> [2009/09/10 14:53:56 | 01,312,080 | ---- | M] (Malwarebytes Corporation)
"mcagent_exe" -> C:\Program Files\McAfee.com\Agent\mcagent.exe ["C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey] -> [2009/01/08 21:30:26 | 00,645,328 | ---- | M] (McAfee, Inc.)
"Microsoft Works Update Detection" -> C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe [C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe] -> [2003/06/07 06:32:32 | 00,050,688 | ---- | M] (Microsoft® Corporation)
"NeroFilterCheck" -> C:\WINDOWS\System32\NeroCheck.exe [C:\WINDOWS\system32\NeroCheck.exe] -> [2001/07/09 14:50:42 | 00,155,648 | ---- | M] (Ahead Software Gmbh)
"OpwareSE2" -> C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe ["C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"] -> [2003/05/08 12:00:58 | 00,049,152 | ---- | M] (ScanSoft, Inc.)
"QuickTime Task" -> C:\Program Files\QuickTime\qttask.exe ["C:\Program Files\QuickTime\qttask.exe" -atboottime] -> [2004/11/17 09:17:35 | 00,098,304 | ---- | M] (Apple Computer, Inc.)
"Recguard" -> C:\WINDOWS\SMINST\RECGUARD.EXE [C:\WINDOWS\SMINST\RECGUARD.EXE] -> [2002/09/13 15:42:26 | 00,212,992 | ---- | M] ()
"RemoteControl" -> C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe ["C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"] -> [2003/10/31 22:42:40 | 00,032,768 | ---- | M] (Cyberlink Corp.)
"ShowWnd" -> C:\WINDOWS\ShowWnd.exe [ShowWnd.exe] -> [2003/09/19 12:09:22 | 00,036,864 | ---- | M] ()
"SoundMan" -> C:\WINDOWS\SOUNDMAN.EXE [SOUNDMAN.EXE] -> [2004/09/23 22:27:18 | 00,077,824 | ---- | M] (Realtek Semiconductor Corp.)
"SunKistEM" -> C:\Program Files\Digital Media Reader\shwiconem.exe [C:\Program Files\Digital Media Reader\shwiconem.exe] -> [2004/10/18 17:05:12 | 00,135,168 | ---- | M] (Alcor Micro, Corp.)
< Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
"E6TaskPanel" -> C:\Program Files\EarthLink TotalAccess\TaskPanl.exe ["C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" -winstart] -> [2005/09/01 17:24:56 | 00,942,080 | ---- | M] (EarthLink, Inc.)
"MoneyAgent" -> C:\Program Files\Microsoft Money\System\mnyexpr.exe ["C:\Program Files\Microsoft Money\System\mnyexpr.exe"] -> [2003/06/18 15:00:00 | 00,200,704 | ---- | M] (Microsoft Corp.)
"MSMSGS" -> C:\Program Files\Messenger\msmsgs.exe ["C:\Program Files\Messenger\msmsgs.exe" /background] -> [2008/04/13 19:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)
< All Users Startup Folder > -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup ->
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk -> C:\Program Files\Logitech\SetPoint\SetPoint.exe -> [2009/02/19 00:33:08 | 00,809,488 | ---- | M] (Logitech, Inc.)
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk -> C:\Program Files\WinZip\WZQKPICK.EXE -> [2008/09/23 11:20:00 | 00,415,072 | R--- | M] (WinZip Computing, S.L.)
< Owner Startup Folder > -> C:\Documents and Settings\Owner\Start Menu\Programs\Startup ->
< Software Policy Settings [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Internet Explorer ->
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Internet Explorer\Control Panel
\Control Panel\\"Connwiz Admin Lock" -> [0] -> File not found
< CurrentVersion Policy Settings - Explorer [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"HonorAutoRunSetting" -> [1] -> File not found
\\"NoDriveAutoRun" -> [67108863] -> File not found
\\"NoDriveTypeAutoRun" -> [323] -> File not found
\\"NoDrives" -> [0] -> File not found
< CurrentVersion Policy Settings - System [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
\\"dontdisplaylastusername" -> [0] -> File not found
\\"legalnoticecaption" -> [] -> File not found
\\"legalnoticetext" -> [] -> File not found
\\"shutdownwithoutlogon" -> [1] -> File not found
\\"undockwithoutlogon" -> [1] -> File not found
\\"DisableRegistryTools" -> [0] -> File not found
< CurrentVersion Policy Settings - Explorer [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
\\"NoDriveTypeAutoRun" -> [323] -> File not found
\\"NoDriveAutoRun" -> [67108863] -> File not found
\\"NoDrives" -> [0] -> File not found
< CurrentVersion Policy Settings - System [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System ->
< Internet Explorer Menu Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ ->
E&xport to Microsoft Excel -> C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE [res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000] -> [2003/08/13 03:34:38 | 10,073,144 | ---- | M] (Microsoft Corporation)
EarthLink Google Search -> C:\Program Files\EarthLink TotalAccess\Toolbar\SearchUI.dll [res://C:\Program Files\EarthLink TotalAccess\Toolbar\SearchUI.dll/search.html] -> [2009/09/25 07:26:25 | 00,415,040 | ---- | M] (EarthLink, Inc.)
Easy-WebPrint Add To Print List -> C:\Program Files\Canon\Easy-WebPrint\Toolband.dll [res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html] -> [2005/10/20 21:18:00 | 00,552,960 | ---- | M] ()
Easy-WebPrint High Speed Print -> C:\Program Files\Canon\Easy-WebPrint\Toolband.dll [res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html] -> [2005/10/20 21:18:00 | 00,552,960 | ---- | M] ()
Easy-WebPrint Preview -> C:\Program Files\Canon\Easy-WebPrint\Toolband.dll [res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html] -> [2005/10/20 21:18:00 | 00,552,960 | ---- | M] ()
Easy-WebPrint Print -> C:\Program Files\Canon\Easy-WebPrint\Toolband.dll [res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html] -> [2005/10/20 21:18:00 | 00,552,960 | ---- | M] ()
< Internet Explorer Extensions [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ ->
{92780B25-18CC-41C8-B9BE-3C9C571A8263}:{FF059E31-CC5A-4E2E-BF3B-96E929D65503} [HKLM] -> C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL [Button: Research] -> [2003/07/14 23:57:08 | 00,040,512 | ---- | M] (Microsoft Corporation)
{e2e2dd38-d088-4134-82b7-f2ba38496583}:Exec [HKLM] -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [Menu: @xpsp3res.dll,-20001] -> [2008/04/13 13:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> C:\Program Files\Messenger\msmsgs.exe [Button: Messenger] -> [2008/04/13 19:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)
{FB5F1910-F110-11d2-BB9E-00C04F795683}:Exec [HKLM] -> C:\Program Files\Messenger\msmsgs.exe [Menu: Windows Messenger] -> [2008/04/13 19:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)
< Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\ ->
CmdMapping\\"{4982D40A-C53B-4615-B15B-B5B5E98D167C}" [HKLM] -> [Reg Error: Key error.] -> File not found
CmdMapping\\"{92780B25-18CC-41C8-B9BE-3C9C571A8263}" [HKLM] -> C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL [Research] -> [2003/07/14 23:57:08 | 00,040,512 | ---- | M] (Microsoft Corporation)
CmdMapping\\"{FB5F1910-F110-11d2-BB9E-00C04F795683}" [HKLM] -> C:\Program Files\Messenger\msmsgs.exe [Messenger] -> [2008/04/13 19:12:28 | 01,695,232 | ---- | M] (Microsoft Corporation)
< Internet Explorer Plugins [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\ ->
PluginsPageFriendlyName -> Microsoft ActiveX Gallery ->
PluginsPage -> http://activex.microsoft.com/controls/find.asp?ext=%s&mime=%s ->
< Default Prefix > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\DefaultPrefix
"" -> http://
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 1 domain(s) found. ->
1 domain(s) and sub-domain(s) not assigned to a zone.
< Trusted Sites Ranges [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 2 domain(s) found. ->
internet .[about] -> Trusted sites ->
mcafee.com .[http] -> Trusted sites ->
mcafee.com .[https] -> Trusted sites ->
< Trusted Sites Ranges [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ -> [Key] 0 range(s) found. ->
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} [HKLM] -> http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab [McAfee.com Operating System Class] ->
{BCC0FF27-31D9-4614-A68E-C18E1ADA4389} [HKLM] -> http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,23/mcgdmgr.cab [DwnldGroupMgr Class] ->
{D27CDB6E-AE6D-11CF-96B8-444553540000} [HKLM] -> http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab [Shockwave Flash Object] ->
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\ ->
DhcpNameServer -> 192.168.1.1 ->
< Name Servers [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->
{150DF96D-A5E8-4D01-90C0-C290CB1E2944}\\DhcpNameServer -> 192.168.1.1 (Intel(R) PRO/100 VE Network Connection) ->
< Winlogon settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
*Shell* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell ->
Explorer.exe -> C:\WINDOWS\explorer.exe -> [2008/04/13 19:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation)
*MultiFile Done* -> ->
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ ->
igfxcui -> C:\WINDOWS\System32\igfxsrvc.dll -> [2004/08/20 18:50:54 | 00,344,064 | ---- | M] (Intel Corporation)
LBTWlgn -> c:\program files\common files\logitech\bluetooth\LBTWlgn.dll -> [2009/02/19 00:30:52 | 00,072,208 | ---- | M] (Logitech, Inc.)
< Domain Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List ->
"%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2008/04/13 13:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" -> C:\WINDOWS\System32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008/04/13 19:12:34 | 00,141,312 | ---- | M] (Microsoft Corporation)
"C:\Program Files\America Online 9.0\waol.exe" -> C:\Program Files\America Online 9.0\waol.exe [C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL] -> File not found
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe" -> C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe [C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL] -> File not found
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" -> C:\Program Files\Common Files\AOL\ACS\AOLDial.exe [C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL] -> File not found
< Standard Profile Authorized Applications List > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List ->
"%windir%\Network Diagnostic\xpnetdiag.exe" -> C:\WINDOWS\Network Diagnostic\xpnetdiag.exe [%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000] -> [2008/04/13 13:53:32 | 00,558,080 | ---- | M] (Microsoft Corporation)
"%windir%\system32\sessmgr.exe" -> C:\WINDOWS\System32\sessmgr.exe [%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019] -> [2008/04/13 19:12:34 | 00,141,312 | ---- | M] (Microsoft Corporation)
"C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe" -> C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe [C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent] -> [2009/01/09 12:31:16 | 02,482,848 | ---- | M] (McAfee, Inc.)
"C:\Program Files\GlobalSCAPE\CuteSITE Builder\program\csb.exe" -> C:\Program Files\GlobalSCAPE\CuteSITE Builder\program\csb.exe [C:\Program Files\GlobalSCAPE\CuteSITE Builder\program\csb.exe:*:Enabled:CuteSITE Builder] -> [2003/06/05 13:53:36 | 00,046,864 | ---- | M] (GlobalSCAPE Texas, LP)
< SafeBoot AlternateShell [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot ->
"AlternateShell" -> cmd.exe ->
< CDROM Autorun Setting [HKEY_LOCAL_MACHINE]> -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom ->
"AutoRun" -> 1 ->
"DisplayName" -> CD-ROM Driver ->
"ImagePath" -> [system32\DRIVERS\cdrom.sys] -> File not found
< Drives with AutoRun files > -> ->
C:\AUTOEXEC.BAT [] -> C:\AUTOEXEC.BAT [ NTFS ] -> [2004/08/26 13:04:39 | 00,000,000 | ---- | M] ()
D:\autorun.inf.aug.8 [[AUTORUN] | OPEN=Info.exe folder.htt 480 480 | ] -> D:\autorun.inf [ FAT32 ] -> File not found
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2 ->
[Files/Folders - Created Within 30 Days]
JavaRa.zip -> C:\Documents and Settings\Owner\Desktop\JavaRa.zip -> [2009/09/27 18:07:18 | 00,071,798 | ---- | C] ()
RECYCLER -> C:\RECYCLER -> [2009/09/27 17:59:13 | 00,000,000 | -HSD | C]
TFC.exe -> C:\Documents and Settings\Owner\Desktop\TFC.exe -> [2009/09/27 17:57:52 | 00,271,872 | ---- | C] (OldTimer Tools)
spring.zip -> C:\Documents and Settings\Owner\My Documents\spring.zip -> [2009/09/26 20:03:18 | 03,692,120 | ---- | C] ()
summersun.zip -> C:\Documents and Settings\Owner\My Documents\summersun.zip -> [2009/09/26 20:02:16 | 01,981,405 | ---- | C] ()
polar.zip -> C:\Documents and Settings\Owner\My Documents\polar.zip -> [2009/09/26 20:01:14 | 02,088,015 | ---- | C] ()
purple.zip -> C:\Documents and Settings\Owner\My Documents\purple.zip -> [2009/09/26 20:00:16 | 01,586,447 | ---- | C] ()
patterns.zip -> C:\Documents and Settings\Owner\My Documents\patterns.zip -> [2009/09/26 19:59:10 | 02,197,969 | ---- | C] ()
oxfordgrey.zip -> C:\Documents and Settings\Owner\My Documents\oxfordgrey.zip -> [2009/09/26 19:58:07 | 01,652,189 | ---- | C] ()
mauve.zip -> C:\Documents and Settings\Owner\My Documents\mauve.zip -> [2009/09/26 19:57:10 | 01,650,644 | ---- | C] ()
lines.zip -> C:\Documents and Settings\Owner\My Documents\lines.zip -> [2009/09/26 19:55:40 | 00,975,323 | ---- | C] ()
pinkblue.zip -> C:\Documents and Settings\Owner\My Documents\pinkblue.zip -> [2009/09/26 19:54:42 | 01,460,908 | ---- | C] ()
gas.zip -> C:\Documents and Settings\Owner\My Documents\gas.zip -> [2009/09/26 19:53:44 | 00,546,373 | ---- | C] ()
heat.zip -> C:\Documents and Settings\Owner\My Documents\heat.zip -> [2009/09/26 19:52:43 | 01,042,490 | ---- | C] ()
darker.zip -> C:\Documents and Settings\Owner\My Documents\darker.zip -> [2009/09/26 19:51:24 | 01,876,611 | ---- | C] ()
blackwhite.zip -> C:\Documents and Settings\Owner\My Documents\blackwhite.zip -> [2009/09/26 19:49:37 | 01,384,858 | ---- | C] ()
greige.zip -> C:\Documents and Settings\Owner\My Documents\greige.zip -> [2009/09/26 19:46:42 | 00,994,883 | ---- | C] ()
Boot.bak -> C:\Boot.bak -> [2009/09/26 10:39:12 | 00,000,211 | ---- | C] ()
cmldr -> C:\cmldr -> [2009/09/26 10:39:09 | 00,260,272 | ---- | C] ()
cmdcons -> C:\cmdcons -> [2009/09/26 10:39:08 | 00,000,000 | RHSD | C]
PEV.exe -> C:\WINDOWS\PEV.exe -> [2009/09/26 10:37:32 | 00,229,888 | ---- | C] ()
SWXCACLS.exe -> C:\WINDOWS\SWXCACLS.exe -> [2009/09/26 10:37:32 | 00,212,480 | ---- | C] (SteelWerX)
SWREG.exe -> C:\WINDOWS\SWREG.exe -> [2009/09/26 10:37:32 | 00,161,792 | ---- | C] (SteelWerX)
SWSC.exe -> C:\WINDOWS\SWSC.exe -> [2009/09/26 10:37:32 | 00,136,704 | ---- | C] (SteelWerX)
sed.exe -> C:\WINDOWS\sed.exe -> [2009/09/26 10:37:32 | 00,098,816 | ---- | C] ()
grep.exe -> C:\WINDOWS\grep.exe -> [2009/09/26 10:37:32 | 00,080,412 | ---- | C] ()
zip.exe -> C:\WINDOWS\zip.exe -> [2009/09/26 10:37:32 | 00,068,096 | ---- | C] ()
NIRCMD.exe -> C:\WINDOWS\NIRCMD.exe -> [2009/09/26 10:37:32 | 00,031,232 | ---- | C] (NirSoft)
ERDNT -> C:\WINDOWS\ERDNT -> [2009/09/26 10:37:26 | 00,000,000 | ---D | C]
Qoobox -> C:\Qoobox -> [2009/09/26 10:36:56 | 00,000,000 | ---D | C]
Combo-Fix.exe -> C:\Documents and Settings\Owner\Desktop\Combo-Fix.exe -> [2009/09/26 10:23:29 | 03,321,356 | R--- | C] ()
Unzipped -> C:\Documents and Settings\Owner\My Documents\Unzipped -> [2009/09/24 22:39:14 | 00,000,000 | ---D | C]
SysProt -> C:\Documents and Settings\Owner\Desktop\SysProt -> [2009/09/24 22:36:24 | 00,000,000 | ---D | C]
OTS.exe -> C:\Documents and Settings\Owner\Desktop\OTS.exe -> [2009/09/24 22:22:54 | 00,514,560 | ---- | C] (OldTimer Tools)
OTS.exe -> C:\Program Files\OTS.exe -> [2009/09/24 22:20:29 | 00,514,560 | ---- | C] (OldTimer Tools)
frosty.zip -> C:\Documents and Settings\Owner\My Documents\frosty.zip -> [2009/09/21 21:50:59 | 02,831,128 | ---- | C] ()
WinZip.lnk -> C:\Documents and Settings\All Users\Desktop\WinZip.lnk -> [2009/09/21 21:14:18 | 00,001,732 | ---- | C] ()
WinZip Quick Pick.lnk -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk -> [2009/09/21 21:14:18 | 00,001,660 | ---- | C] ()
ApplicationHistory -> C:\Documents and Settings\Owner\Local Settings\Application Data\ApplicationHistory -> [2009/09/20 14:19:56 | 00,000,000 | ---D | C]
Malwarebytes -> C:\Documents and Settings\Owner\Application Data\Malwarebytes -> [2009/09/18 21:23:25 | 00,000,000 | ---D | C]
Malwarebytes' Anti-Malware.lnk -> C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk -> [2009/09/18 21:23:21 | 00,000,696 | ---- | C] ()
mbamswissarmy.sys -> C:\WINDOWS\System32\drivers\mbamswissarmy.sys -> [2009/09/18 21:23:01 | 00,038,224 | ---- | C] (Malwarebytes Corporation)
mbam.sys -> C:\WINDOWS\System32\drivers\mbam.sys -> [2009/09/18 21:22:59 | 00,019,160 | ---- | C] (Malwarebytes Corporation)
Malwarebytes' Anti-Malware -> C:\Program Files\Malwarebytes' Anti-Malware -> [2009/09/18 21:22:59 | 00,000,000 | ---D | C]
Malwarebytes -> C:\Documents and Settings\All Users\Application Data\Malwarebytes -> [2009/09/18 21:22:59 | 00,000,000 | ---D | C]
mbam-setup.exe -> C:\Program Files\mbam-setup.exe -> [2009/09/18 21:18:40 | 04,045,536 | ---- | C] (Malwarebytes Corporation )
erunt_setup.exe -> C:\Program Files\erunt_setup.exe -> [2009/09/18 21:17:41 | 00,791,393 | ---- | C] (Lars Hederer )
SysRestorePoint.exe -> C:\Program Files\SysRestorePoint.exe -> [2009/09/18 21:15:10 | 00,021,504 | ---- | C] (Doug Knox)
settings.dat -> C:\Program Files\settings.dat -> [2009/09/18 21:11:32 | 00,000,000 | ---- | C] ()
RootRepeal.exe -> C:\Program Files\RootRepeal.exe -> [2009/09/18 20:51:38 | 00,472,064 | ---- | C] ( )
ISO1.nri -> C:\Documents and Settings\Owner\My Documents\ISO1.nri -> [2009/09/18 19:48:57 | 00,504,793 | ---- | C] ()
Adobe Reader 8.lnk -> C:\Documents and Settings\All Users\Desktop\Adobe Reader 8.lnk -> [2009/09/18 14:44:54 | 00,001,729 | ---- | C] ()
SxsCaPendDel -> C:\WINDOWS\SxsCaPendDel -> [2009/09/18 14:44:27 | 00,000,000 | ---D | C]
fxsclntR.dll -> C:\WINDOWS\System32\fxsclntR.dll -> [2009/09/18 14:13:55 | 00,132,608 | ---- | C] (Microsoft Corporation)
fxsclntr.dll -> C:\WINDOWS\System32\dllcache\fxsclntr.dll -> [2009/09/18 14:13:55 | 00,132,608 | ---- | C] ()
fxscfgwz.dll -> C:\WINDOWS\System32\fxscfgwz.dll -> [2009/09/18 14:13:55 | 00,111,104 | ---- | C] (Microsoft Corporation)
fxscfgwz.dll -> C:\WINDOWS\System32\dllcache\fxscfgwz.dll -> [2009/09/18 14:13:55 | 00,111,104 | ---- | C] ()
fxsroute.dll -> C:\WINDOWS\System32\fxsroute.dll -> [2009/09/18 14:13:55 | 00,031,744 | ---- | C] (Microsoft Corporation)
fxsroute.dll -> C:\WINDOWS\System32\dllcache\fxsroute.dll -> [2009/09/18 14:13:55 | 00,031,744 | ---- | C] ()
fxssend.exe -> C:\WINDOWS\System32\fxssend.exe -> [2009/09/18 14:13:55 | 00,011,264 | ---- | C] (Microsoft Corporation)
fxssend.exe -> C:\WINDOWS\System32\dllcache\fxssend.exe -> [2009/09/18 14:13:55 | 00,011,264 | ---- | C] ()
fxsperf.ini -> C:\WINDOWS\System32\fxsperf.ini -> [2009/09/18 14:13:55 | 00,001,793 | ---- | C] ()
fxscount.h -> C:\WINDOWS\System32\fxscount.h -> [2009/09/18 14:13:55 | 00,001,361 | ---- | C] ()
mapisvc.inf -> C:\WINDOWS\System32\mapisvc.inf -> [2009/09/18 14:13:55 | 00,000,535 | ---- | C] ()
MRT.INI -> C:\WINDOWS\System32\MRT.INI -> [2009/09/09 03:02:37 | 00,000,129 | ---- | C] ()
triedit.dll -> C:\WINDOWS\System32\dllcache\triedit.dll -> [2009/09/08 22:40:32 | 00,153,088 | ---- | C] (Microsoft Corporation)
JascCmdPrint.INI -> C:\WINDOWS\JascCmdPrint.INI -> [2009/09/06 13:27:01 | 00,000,072 | ---- | C] ()
Minidump -> C:\WINDOWS\Minidump -> [2009/09/05 18:31:23 | 00,000,000 | ---D | C]
JascCmdFile.INI -> C:\WINDOWS\JascCmdFile.INI -> [2009/05/14 14:35:50 | 00,000,054 | ---- | C] ()
WSYS049.SYS -> C:\WINDOWS\WSYS049.SYS -> [2007/07/22 21:03:24 | 00,000,104 | -HS- | C] ()
CNMVS7O.DLL -> C:\WINDOWS\System32\CNMVS7O.DLL -> [2007/01/01 23:02:13 | 00,008,704 | ---- | C] ()
MAXLINK.INI -> C:\WINDOWS\MAXLINK.INI -> [2007/01/01 22:55:17 | 00,000,532 | ---- | C] ()
OpPrintServer.INI -> C:\WINDOWS\OpPrintServer.INI -> [2006/10/29 23:14:06 | 00,000,000 | ---- | C] ()
NeroDigital.ini -> C:\WINDOWS\NeroDigital.ini -> [2005/12/28 09:49:35 | 00,000,049 | ---- | C] ()
ODBC.INI -> C:\WINDOWS\ODBC.INI -> [2005/12/10 15:55:48 | 00,000,376 | ---- | C] ()
AuthMgr.INI -> C:\WINDOWS\AuthMgr.INI -> [2005/05/15 14:10:44 | 00,000,034 | ---- | C] ()
SIERRA.INI -> C:\WINDOWS\SIERRA.INI -> [2005/03/12 20:08:10 | 00,000,334 | ---- | C] ()
lexstat.ini -> C:\WINDOWS\lexstat.ini -> [2005/03/06 22:05:49 | 00,000,332 | ---- | C] ()
lxblvs.dll -> C:\WINDOWS\System32\lxblvs.dll -> [2005/03/06 22:05:27 | 00,040,960 | ---- | C] ()
LXBLLCNP.DLL -> C:\WINDOWS\System32\LXBLLCNP.DLL -> [2005/03/06 22:05:11 | 00,077,824 | ---- | C] ()
msoffice.ini -> C:\WINDOWS\msoffice.ini -> [2005/03/06 09:10:23 | 00,000,002 | ---- | C] ()
PIC.dll -> C:\WINDOWS\PIC.dll -> [2004/11/17 09:22:21 | 00,532,544 | ---- | C] ()
HKNTDLL.dll -> C:\WINDOWS\HKNTDLL.dll -> [2004/11/17 09:22:21 | 00,024,576 | ---- | C] ()
RTCOMDLL.dll -> C:\WINDOWS\System32\RTCOMDLL.dll -> [2004/11/17 09:14:28 | 00,192,512 | ---- | C] ()
RTLCPAPI.dll -> C:\WINDOWS\System32\RTLCPAPI.dll -> [2004/11/17 09:14:28 | 00,156,160 | ---- | C] ()
e100bmsg.dll -> C:\WINDOWS\System32\e100bmsg.dll -> [2004/11/17 09:01:41 | 00,012,288 | ---- | C] ()
smscfg.ini -> C:\WINDOWS\smscfg.ini -> [2004/08/27 05:50:59 | 00,000,061 | ---- | C] ()
emver.ini -> C:\WINDOWS\System32\emver.ini -> [2004/08/26 11:12:43 | 00,000,462 | ---- | C] ()
OEMINFO.INI -> C:\WINDOWS\System32\OEMINFO.INI -> [2004/08/26 11:12:43 | 00,000,437 | ---- | C] ()
win.ini -> C:\WINDOWS\win.ini -> [2004/08/26 11:12:21 | 00,000,598 | ---- | C] ()
system.ini -> C:\WINDOWS\system.ini -> [2004/08/26 11:12:17 | 00,000,227 | ---- | C] ()
OUTLPERF.INI -> C:\WINDOWS\System32\OUTLPERF.INI -> [2003/01/07 16:05:08 | 00,002,695 | ---- | C] ()
zlib.dll -> C:\WINDOWS\System32\zlib.dll -> [2002/03/13 15:46:46 | 00,053,248 | R--- | C] ()
[Files/Folders - Modified Within 30 Days]
wpa.dbl -> C:\WINDOWS\System32\wpa.dbl -> [2009/09/27 19:39:27 | 00,001,170 | ---- | M] ()
SA.DAT -> C:\WINDOWS\tasks\SA.DAT -> [2009/09/27 19:38:55 | 00,000,006 | -H-- | M] ()
bootstat.dat -> C:\WINDOWS\bootstat.dat -> [2009/09/27 19:38:53 | 00,002,048 | --S- | M] ()
hiberfil.sys -> C:\hiberfil.sys -> [2009/09/27 19:38:52 | 52,615,9872 | -HS- | M] ()
NTUSER.DAT -> C:\Documents and Settings\Owner\NTUSER.DAT -> [2009/09/27 19:37:40 | 07,864,320 | ---- | M] ()
ntuser.ini -> C:\Documents and Settings\Owner\ntuser.ini -> [2009/09/27 19:37:40 | 00,000,178 | -HS- | M] ()
JavaRa.zip -> C:\Documents and Settings\Owner\Desktop\JavaRa.zip -> [2009/09/27 18:07:21 | 00,071,798 | ---- | M] ()
TFC.exe -> C:\Documents and Settings\Owner\Desktop\TFC.exe -> [2009/09/27 17:57:53 | 00,271,872 | ---- | M] (OldTimer Tools)
spring.zip -> C:\Documents and Settings\Owner\My Documents\spring.zip -> [2009/09/26 20:03:19 | 03,692,120 | ---- | M] ()
summersun.zip -> C:\Documents and Settings\Owner\My Documents\summersun.zip -> [2009/09/26 20:02:17 | 01,981,405 | ---- | M] ()
polar.zip -> C:\Documents and Settings\Owner\My Documents\polar.zip -> [2009/09/26 20:01:15 | 02,088,015 | ---- | M] ()
purple.zip -> C:\Documents and Settings\Owner\My Documents\purple.zip -> [2009/09/26 20:00:17 | 01,586,447 | ---- | M] ()
patterns.zip -> C:\Documents and Settings\Owner\My Documents\patterns.zip -> [2009/09/26 19:59:11 | 02,197,969 | ---- | M] ()
oxfordgrey.zip -> C:\Documents and Settings\Owner\My Documents\oxfordgrey.zip -> [2009/09/26 19:58:07 | 01,652,189 | ---- | M] ()
mauve.zip -> C:\Documents and Settings\Owner\My Documents\mauve.zip -> [2009/09/26 19:57:10 | 01,650,644 | ---- | M] ()
lines.zip -> C:\Documents and Settings\Owner\My Documents\lines.zip -> [2009/09/26 19:55:40 | 00,975,323 | ---- | M] ()
pinkblue.zip -> C:\Documents and Settings\Owner\My Documents\pinkblue.zip -> [2009/09/26 19:54:42 | 01,460,908 | ---- | M] ()
gas.zip -> C:\Documents and Settings\Owner\My Documents\gas.zip -> [2009/09/26 19:53:44 | 00,546,373 | ---- | M] ()
heat.zip -> C:\Documents and Settings\Owner\My Documents\heat.zip -> [2009/09/26 19:52:43 | 01,042,490 | ---- | M] ()
darker.zip -> C:\Documents and Settings\Owner\My Documents\darker.zip -> [2009/09/26 19:51:24 | 01,876,611 | ---- | M] ()
blackwhite.zip -> C:\Documents and Settings\Owner\My Documents\blackwhite.zip -> [2009/09/26 19:49:37 | 01,384,858 | ---- | M] ()
greige.zip -> C:\Documents and Settings\Owner\My Documents\greige.zip -> [2009/09/26 19:46:42 | 00,994,883 | ---- | M] ()
system.ini -> C:\WINDOWS\system.ini -> [2009/09/26 11:00:19 | 00,000,227 | ---- | M] ()
hosts -> C:\WINDOWS\System32\drivers\etc\hosts -> [2009/09/26 10:59:55 | 00,000,027 | ---- | M] ()
boot.ini -> C:\boot.ini -> [2009/09/26 10:39:12 | 00,000,281 | RHS- | M] ()
Combo-Fix.exe -> C:\Documents and Settings\Owner\Desktop\Combo-Fix.exe -> [2009/09/26 10:23:29 | 03,321,356 | R--- | M] ()
OTS.exe -> C:\Documents and Settings\Owner\Desktop\OTS.exe -> [2009/09/24 22:22:54 | 00,514,560 | ---- | M] (OldTimer Tools)
OTS.exe -> C:\Program Files\OTS.exe -> [2009/09/24 22:20:31 | 00,514,560 | ---- | M] (OldTimer Tools)
wklnhst.dat -> C:\Documents and Settings\Owner\Application Data\wklnhst.dat -> [2009/09/23 06:55:28 | 00,004,632 | ---- | M] ()
frosty.zip -> C:\Documents and Settings\Owner\My Documents\frosty.zip -> [2009/09/21 21:51:01 | 02,831,128 | ---- | M] ()
WinZip.lnk -> C:\Documents and Settings\All Users\Desktop\WinZip.lnk -> [2009/09/21 21:14:18 | 00,001,732 | ---- | M] ()
WinZip Quick Pick.lnk -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk -> [2009/09/21 21:14:18 | 00,001,660 | ---- | M] ()
Malwarebytes' Anti-Malware.lnk -> C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk -> [2009/09/18 21:23:21 | 00,000,696 | ---- | M] ()
mbam-setup.exe -> C:\Program Files\mbam-setup.exe -> [2009/09/18 21:18:54 | 04,045,536 | ---- | M] (Malwarebytes Corporation )
erunt_setup.exe -> C:\Program Files\erunt_setup.exe -> [2009/09/18 21:17:41 | 00,791,393 | ---- | M] (Lars Hederer )
SysRestorePoint.exe -> C:\Program Files\SysRestorePoint.exe -> [2009/09/18 21:15:11 | 00,021,504 | ---- | M] (Doug Knox)
settings.dat -> C:\Program Files\settings.dat -> [2009/09/18 21:11:32 | 00,000,000 | ---- | M] ()
RootRepeal.exe -> C:\Program Files\RootRepeal.exe -> [2009/09/18 20:51:38 | 00,472,064 | ---- | M] ( )
ISO1.nri -> C:\Documents and Settings\Owner\My Documents\ISO1.nri -> [2009/09/18 20:05:53 | 00,504,793 | ---- | M] ()
Adobe Reader 8.lnk -> C:\Documents and Settings\All Users\Desktop\Adobe Reader 8.lnk -> [2009/09/18 14:51:51 | 00,001,729 | ---- | M] ()
PerfStringBackup.INI -> C:\WINDOWS\System32\PerfStringBackup.INI -> [2009/09/18 14:13:57 | 00,440,176 | ---- | M] ()
perfh009.dat -> C:\WINDOWS\System32\perfh009.dat -> [2009/09/18 14:13:57 | 00,381,692 | ---- | M] ()
perfc009.dat -> C:\WINDOWS\System32\perfc009.dat -> [2009/09/18 14:13:57 | 00,053,436 | ---- | M] ()
mapisvc.inf -> C:\WINDOWS\System32\mapisvc.inf -> [2009/09/18 14:13:55 | 00,000,535 | ---- | M] ()
spider.sav -> C:\Documents and Settings\Owner\My Documents\spider.sav -> [2009/09/17 22:11:33 | 00,000,572 | ---- | M] ()
McDefragTask.job -> C:\WINDOWS\tasks\McDefragTask.job -> [2009/09/15 01:00:04 | 00,000,350 | ---- | M] ()
PEV.exe -> C:\WINDOWS\PEV.exe -> [2009/09/14 02:12:36 | 00,229,888 | ---- | M] ()
CuteSITEBuilder.tlex -> C:\Documents and Settings\Owner\My Documents\CuteSITEBuilder.tlex -> [2009/09/13 08:32:52 | 00,002,525 | ---- | M] ()
mbamswissarmy.sys -> C:\WINDOWS\System32\drivers\mbamswissarmy.sys -> [2009/09/10 14:54:06 | 00,038,224 | ---- | M] (Malwarebytes Corporation)
mbam.sys -> C:\WINDOWS\System32\drivers\mbam.sys -> [2009/09/10 14:53:50 | 00,019,160 | ---- | M] (Malwarebytes Corporation)
MRT.INI -> C:\WINDOWS\System32\MRT.INI -> [2009/09/09 03:02:37 | 00,000,129 | ---- | M] ()
imsins.BAK -> C:\WINDOWS\imsins.BAK -> [2009/09/09 03:00:43 | 00,001,355 | ---- | M] ()
qmgr0.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat -> [2009/09/08 22:41:16 | 00,005,543 | ---- | M] ()
qmgr1.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat -> [2009/09/08 22:41:16 | 00,004,232 | ---- | M] ()
JascCmdPrint.INI -> C:\WINDOWS\JascCmdPrint.INI -> [2009/09/06 13:27:01 | 00,000,072 | ---- | M] ()
McQcTask.job -> C:\WINDOWS\tasks\McQcTask.job -> [2009/09/01 01:01:03 | 00,000,352 | ---- | M] ()
CalMRU.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Works\CalMRU.dat -> [2009/08/09 14:32:05 | 00,001,804 | ---- | M] ()
hhcolreg.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\HTML Help\hhcolreg.dat -> [2008/07/04 22:56:55 | 00,011,075 | ---- | M] ()
opa11.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\DATA\opa11.dat -> [2005/12/10 16:49:16 | 00,008,206 | ---- | M] ()
wklntsk1.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Works\wklntsk1.dat -> [2005/03/06 10:17:12 | 00,172,544 | ---- | M] ()
wkcalcat.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Works\wkcalcat.dat -> [2005/03/06 10:08:24 | 00,016,384 | ---- | M] ()
ylpgscat.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Money\12.0\Webcache\ylpgscat.dat -> [2003/06/18 15:00:00 | 12,283,223 | ---- | M] ()
college.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Money\12.0\Webcache\college.dat -> [2003/06/18 15:00:00 | 00,327,746 | ---- | M] ()
about.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Money\12.0\Webcache\about.dat -> [2003/06/18 15:00:00 | 00,001,528 | ---- | M] ()
moreinfo.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Money\12.0\Webcache\moreinfo.dat -> [2003/06/18 15:00:00 | 00,000,102 | ---- | M] ()
< End of report >
____________________________
As through all of this, my computer's working just fine. The only way I knew the virus was there was that it kept showing up on the McAfee scans. AFAIK it caused no problems. I'm waiting until I know it's clean before doing any business through it.
Edited by tgshaw, 27 September 2009 - 07:13 PM.