From looking at other posts I've downloaded OTL and please see my attached log from the scan. Hope this helps!!
OTL logfile created on: 12/10/2009 21:51:50 - Run 2
OTL by OldTimer - Version 3.0.20.0 Folder = C:\Documents and Settings\IBM USER\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
1022.92 Mb Total Physical Memory | 260.31 Mb Available Physical Memory | 25.45% Memory free
2.40 Gb Paging File | 1.72 Gb Available in Paging File | 71.54% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.25 Gb Total Space | 6.71 Gb Free Space | 18.02% Space Free | Partition Type: NTFS
Drive D: | 330.61 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: OWAIN
Current User Name: IBM USER
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ========== PRC - [2009/10/12 21:49:28 | 00,520,704 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\IBM USER\Desktop\OTL.exe
PRC - [2009/06/10 23:28:26 | 12,973,336 | ---- | M] () -- C:\Program Files\RegCure\RegCure.exe
PRC - [2009/03/08 14:09:26 | 00,638,816 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Internet Explorer\iexplore.exe
PRC - [2009/02/16 09:55:38 | 00,087,336 | ---- | M] (CyberLink Corp.) -- C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe
PRC - [2009/02/06 18:51:28 | 03,885,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe
PRC - [2008/12/07 16:02:43 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2008/04/14 01:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2007/08/24 08:00:48 | 00,033,648 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
PRC - [2007/02/22 20:50:00 | 00,144,960 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
PRC - [2007/02/22 20:50:00 | 00,112,216 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
PRC - [2007/02/22 20:50:00 | 00,054,872 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
PRC - [2006/12/19 15:06:00 | 00,086,016 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\McTray.exe
PRC - [2006/12/19 11:27:54 | 00,136,768 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
PRC - [2006/12/19 11:27:00 | 00,136,768 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\UdaterUI.exe
PRC - [2006/12/19 11:24:50 | 00,104,000 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\FrameworkService.exe
PRC - [2006/10/02 18:19:48 | 00,094,208 | ---- | M] () -- C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
PRC - [2006/09/13 10:23:00 | 00,237,568 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\ThinkPad\Utilities\EZEJMNAP.EXE
PRC - [2006/07/04 11:05:00 | 00,225,280 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\ThinkPad\UltraNav Wizard\UNavTray.EXE
PRC - [2006/06/16 23:58:42 | 00,426,051 | ---- | M] (Intel Corporation ) -- C:\WINDOWS\System32\S24EvMon.exe
PRC - [2006/06/16 23:55:14 | 00,122,880 | ---- | M] (Intel Corporation) -- C:\WINDOWS\System32\RegSrvc.exe
PRC - [2006/05/30 23:05:42 | 00,086,016 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
PRC - [2006/04/17 21:13:00 | 00,094,208 | ---- | M] (Lenovo) -- C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
PRC - [2006/04/17 21:12:28 | 00,151,552 | ---- | M] (Lenovo) -- C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
PRC - [2006/04/17 21:12:26 | 00,040,960 | ---- | M] () -- C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
PRC - [2006/04/17 20:59:10 | 00,098,304 | ---- | M] (Lenovo) -- C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
PRC - [2006/02/14 22:17:28 | 00,110,592 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
PRC - [2006/02/14 22:16:28 | 00,512,000 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
PRC - [2005/11/11 09:33:00 | 00,073,782 | ---- | M] () -- C:\WINDOWS\System32\ibmpmsvc.exe
PRC - [2005/11/09 00:07:02 | 00,036,864 | ---- | M] () -- C:\WINDOWS\System32\acs.exe
PRC - [2005/11/07 19:14:16 | 00,106,496 | ---- | M] (Lenovo, Ltd. and IBM Corporation.) -- C:\WINDOWS\System32\TpShocks.exe
PRC - [2005/10/29 03:04:30 | 00,045,056 | ---- | M] () -- C:\Program Files\ThinkPad\Utilities\TpKmapMn.exe
PRC - [2005/07/05 22:57:12 | 00,077,824 | ---- | M] () -- C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
PRC - [2005/06/20 20:15:00 | 00,077,824 | ---- | M] (Lenovo.) -- C:\WINDOWS\System32\TPHDEXLG.EXE
PRC - [2005/06/07 05:26:22 | 00,032,768 | ---- | M] () -- C:\WINDOWS\System32\TpKmpSVC.exe
PRC - [2005/05/26 05:56:48 | 00,364,544 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\Ati2evxx.exe
PRC - [2004/10/14 17:11:10 | 01,388,544 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
PRC - [2003/10/29 11:06:00 | 00,024,576 | ---- | M] (BVRP Software) -- C:\Program Files\Digital Line Detect\DLG.exe
PRC - [2003/08/07 00:08:00 | 00,086,016 | ---- | M] (Intel® Corporation) -- C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
PRC - [2003/06/27 16:53:32 | 00,088,363 | ---- | M] (Agere Systems) -- C:\WINDOWS\AGRSMMSG.exe
PRC - [2003/06/19 23:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
PRC - [2003/01/07 22:52:16 | 00,495,616 | ---- | M] (IBM) -- C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
PRC - [2002/10/09 06:28:42 | 00,040,960 | ---- | M] () -- C:\WINDOWS\System32\TpScrLk.exe
PRC - [2002/09/20 22:50:10 | 00,045,056 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
========== Win32 Services (SafeList) ========== SRV - [2008/12/07 16:02:43 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
SRV - [2008/07/29 21:10:04 | 00,046,104 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008/07/29 19:24:50 | 00,881,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
SRV - [2008/07/29 19:16:38 | 00,132,096 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
SRV - [2008/07/25 11:17:02 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008/07/25 11:16:40 | 00,034,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2008/04/14 01:12:02 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2008/04/14 01:11:55 | 00,028,160 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\irmon.dll -- (Irmon [Auto | Running])
SRV - [2008/04/07 09:17:30 | 00,430,592 | ---- | M] (Nokia.) -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer [On_Demand | Stopped])
SRV - [2007/10/25 16:27:54 | 00,266,240 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\installer\WLSetupSvc.exe -- (WLSetupSvc [On_Demand | Stopped])
SRV - [2007/08/24 07:59:20 | 00,068,464 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service [On_Demand | Stopped])
SRV - [2007/08/24 04:19:12 | 00,443,776 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])
SRV - [2007/02/22 20:50:00 | 00,144,960 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe -- (McShield [Unknown | Running])
SRV - [2007/02/22 20:50:00 | 00,054,872 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe -- (McTaskManager [Unknown | Running])
SRV - [2006/12/19 11:24:50 | 00,104,000 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\FrameworkService.exe -- (McAfeeFramework [Unknown | Running])
SRV - [2006/10/26 15:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2006/10/18 20:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])
SRV - [2006/06/16 23:58:42 | 00,426,051 | ---- | M] (Intel Corporation ) -- C:\WINDOWS\System32\S24EvMon.exe -- (S24EventMonitor [Auto | Running])
SRV - [2006/06/16 23:55:14 | 00,122,880 | ---- | M] (Intel Corporation) -- C:\WINDOWS\System32\RegSrvc.exe -- (RegSrvc [Auto | Running])
SRV - [2006/04/17 21:12:28 | 00,151,552 | ---- | M] (Lenovo) -- C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe -- (AcSvc [Auto | Running])
SRV - [2006/04/17 21:12:26 | 00,040,960 | ---- | M] () -- C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe -- (AcPrfMgrSvc [Auto | Running])
SRV - [2005/11/11 09:33:00 | 00,073,782 | ---- | M] () -- C:\WINDOWS\System32\ibmpmsvc.exe -- (IBMPMSVC [Auto | Running])
SRV - [2005/11/09 00:07:02 | 00,036,864 | ---- | M] () -- C:\WINDOWS\System32\acs.exe -- (ACS [On_Demand | Running])
SRV - [2005/06/20 20:15:00 | 00,077,824 | ---- | M] (Lenovo.) -- C:\WINDOWS\System32\TPHDEXLG.EXE -- (TPHDEXLGSVC [Auto | Running])
SRV - [2005/06/07 05:26:22 | 00,032,768 | ---- | M] () -- C:\WINDOWS\System32\TpKmpSVC.exe -- (TpKmpSVC [Auto | Running])
SRV - [2005/05/26 05:56:48 | 00,364,544 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\Ati2evxx.exe -- (Ati HotKey Poller [Auto | Running])
SRV - [2004/10/22 11:24:18 | 00,073,728 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped])
SRV - [2003/07/16 20:37:58 | 00,143,360 | ---- | M] (Intel® Corporation) -- C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe -- (NetSvc [On_Demand | Stopped])
SRV - [2003/06/19 23:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe -- (MDM [Auto | Running])
SRV - [2002/09/20 22:50:10 | 00,045,056 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe -- (SoundMAX Agent Service (default) [Auto | Running])
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://ie.search.msn...st/srchcust.htmIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://ie.search.msn...st/srchasst.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://uk.yahoo.com/?fr=fp-yie8IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft...amp;ar=iesearchIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = AC 6B B6 01 46 1A D1 45 B7 18 8A 90 AF 15 90 43 [binary data]
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..browser.startup.homepage: "
http://www.google.co.uk/" FF - HKLM\software\mozilla\Firefox\Extensions\\
[email protected]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2008/12/07 16:02:49 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/09/03 00:18:15 | 00,000,000 | ---D | M]
[2009/06/29 22:08:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\IBM USER\Application Data\mozilla\Extensions
[2009/06/29 22:08:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\IBM USER\Application Data\mozilla\Extensions\
[email protected][2009/10/11 23:45:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\IBM USER\Application Data\mozilla\Firefox\Profiles\xyqptzep.default\extensions
[2008/01/08 23:15:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\IBM USER\Application Data\mozilla\Firefox\Profiles\xyqptzep.default\extensions\{2c7bf5d2-2002-4912-95b2-7c2ee8a9ce7c}
[2009/10/12 21:45:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\IBM USER\Application Data\mozilla\Firefox\Profiles\xyqptzep.default\extensions\{68614531-b168-49fd-ba5c-00fc33d1c1f5}
[2008/01/08 23:06:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\IBM USER\Application Data\mozilla\Firefox\Profiles\xyqptzep.default\extensions\
[email protected] O1 HOSTS File: (686 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {01B66BAC-1A46-45D1-B718-8A90AF159043} - C:\WINDOWS\System32\d3dx9_3232.dll ()
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\Scriptcl.dll (McAfee, Inc.)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {724D43A0-0D85-11D4-9908-00400523E39A} - No CLSID value found.
O4 - HKLM..\Run: [ACWLIcon] C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe (Lenovo)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AGRSMMSG] C:\WINDOWS\AGRSMMSG.exe (Agere Systems)
O4 - HKLM..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\irprops.CPL (Microsoft Corporation)
O4 - HKLM..\Run: [BMMGAG] C:\Program Files\ThinkPad\Utilities\PWRMONIT.DLL (IBM Corp.)
O4 - HKLM..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE ()
O4 - HKLM..\Run: [BMMMONWND] C:\Program Files\ThinkPad\Utilities\BATINFEX.DLL ()
O4 - HKLM..\Run: [EZEJMNAP] C:\Program Files\ThinkPad\Utilities\EZEJMNAP.EXE (Lenovo Group Limited)
O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe (IBM)
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\McAfee\Common Framework\UdaterUI.exe (McAfee, Inc.)
O4 - HKLM..\Run: [PDVD9LanguageShortcut] C:\Program Files\CyberLink\PowerDVD9\Language\Language.exe (CyberLink Corp.)
O4 - HKLM..\Run: [PRONoMgrWired] C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe (Intel® Corporation)
O4 - HKLM..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE (FUJI PHOTO FILM CO., LTD.)
O4 - HKLM..\Run: [RemoteControl9] C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [S3TRAY2] C:\WINDOWS\System32\S3Tray2.exe (S3 Graphics, Inc.)
O4 - HKLM..\Run: [ShStatEXE] C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [TP4EX] C:\WINDOWS\System32\tp4ex.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [TPHOTKEY] C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe ()
O4 - HKLM..\Run: [TPKBDLED] C:\WINDOWS\System32\TpScrLk.exe ()
O4 - HKLM..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe (Lenovo)
O4 - HKLM..\Run: [TPKMAPMN] C:\Program Files\ThinkPad\Utilities\TpKmapMn.exe ()
O4 - HKLM..\Run: [TpShocks] C:\WINDOWS\System32\TpShocks.exe (Lenovo, Ltd. and IBM Corporation.)
O4 - HKCU..\Run: [A00F1A180A3.exe] C:\Documents and Settings\IBM USER\Local Settings\temp\_A00F1A180A3.exe ()
O4 - HKCU..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe (IBM)
O4 - HKCU..\Run: [msnmsgr] C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - Reg Error: Value error. File not found
O9 - Extra Button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\ThinkPad\PkgMgr\PkgMgr.exe (Lenovo Group Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 26 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {0972B098-DEE9-4279-AC7E-4BAAA029102D}
http://assets.photob...?20090507063008 (PhotoboxPhotowaysUploader5 Control)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83}
http://upload.facebo...toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files/Fish%20Tycoon/Images/stg_drm.ocx (SpinTop DRM Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://fpdownload.ma...director/sw.cab (Reg Error: Key error.)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper200711281.dll (Installation Support)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0}
http://www3.snapfish...shUKActivia.cab (Snapfish Activia)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967}
http://dlm.tools.aka...vex-2.2.4.8.cab (DLM Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.micros...b?1160964812199 (WUWebControl Class)
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862}
https://webdl.symant...ex/symdlmgr.cab (Symantec Download Manager)
O16 - DPF: {741747F6-83B4-4FB9-A268-8CA4010762C8}
http://www3.snapfish...ishActivia2.cab (Snapfish Activia2)
O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084}
http://www-307.ibm.c...rt/IbmEgath.cab (IBM Access Support)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968}
http://upload.facebo...oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.ma...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/Fish%20Tycoon/Images/armhelper.ocx (ArmHelper Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF}
http://upload.facebo...Uploader4_5.cab (Facebook Photo Uploader 4)
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2}
https://signin3.valu...OCX/flashax.cab (FlashXControl Object)
O16 - DPF: {EB6D7E70-AAA9-40D9-BA05-F214089F2275}
http://www.theclickt...e4/vitalize.cab (Vitalize Class)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\WINDOWS\System32\FINFCHECK32.dll) - C:\WINDOWS\System32\FINFCHECK32.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\__c0073A6C: DllName - C:\WINDOWS\system32\__c0073A6C.dat - C:\WINDOWS\System32\__c0073A6C.dat File not found
O20 - Winlogon\Notify\ACNotify: DllName - ACNotify.dll - C:\Program Files\ThinkPad\ConnectUtilities\ACNotify.dll (Lenovo)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\Ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\cc979ab4687: DllName - C:\WINDOWS\System32\FINFCHECK32.dll - C:\WINDOWS\System32\FINFCHECK32.dll ()
O20 - Winlogon\Notify\tpfnf2: DllName - notifyf2.dll - C:\WINDOWS\System32\notifyf2.dll ()
O20 - Winlogon\Notify\tphotkey: DllName - tphklock.dll - C:\WINDOWS\System32\tphklock.dll ()
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/10/16 00:49:39 | 00,000,000 | -H-- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2003/03/13 14:11:46 | 00,000,049 | R--- | M] () - D:\Autorun.inf -- [ CDFS ]
O32 - AutoRun File - [2001/09/10 15:06:52 | 00,050,176 | R--- | M] () - D:\autorun.exe -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found
NetSvcs: 6to4 - Service key not found. File not found
NetSvcs: Ias - Service key not found. File not found
NetSvcs: Iprip - Service key not found. File not found
NetSvcs: Irmon - C:\WINDOWS\System32\irmon.dll (Microsoft Corporation)
NetSvcs: NWCWorkstation - Service key not found. File not found
NetSvcs: Nwsapagent - Service key not found. File not found
NetSvcs: WmdmPmSp - Service key not found. File not found
NetSvcs: helpsvc - C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
========== Files/Folders - Created Within 14 Days ========== [5 C:\WINDOWS\System32\*.tmp files]
[2009/10/03 11:33:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2009/10/03 11:35:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\IBM USER\Local Settings\Application Data\PC_Drivers_Headquarters
[2009/10/03 11:33:15 | 00,000,000 | ---D | C] -- C:\Program Files\PC Drivers HeadQuarters
[2009/10/03 11:46:54 | 00,000,000 | ---D | C] -- C:\Program Files\REGSHAVE
[2009/10/12 21:49:24 | 00,520,704 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\IBM USER\Desktop\OTL.exe
[2009/10/12 20:32:47 | 00,000,000 | ---D | C] -- C:\SDFix
[2009/10/12 20:19:50 | 00,000,000 | ---D | C] -- C:\Documents and Settings\IBM USER\Desktop\avz4
[2009/10/11 23:45:10 | 00,000,000 | -HSD | C] -- C:\WINDOWS\System32\LocalService
[2009/10/03 11:46:59 | 00,081,924 | ---- | C] (FUJI PHOTO FILM CO.,LTD.) -- C:\WINDOWS\System32\drivers\VC4CB104.SYS
[2009/10/03 11:46:54 | 00,045,056 | ---- | C] (FUJIFILM) -- C:\WINDOWS\System32\FINFCOPY.dll
[2009/10/03 11:46:53 | 00,065,536 | ---- | C] (FUJIFILM) -- C:\WINDOWS\System32\FINFCHECK.dll
[2009/10/03 11:46:51 | 00,069,632 | ---- | C] (FUJIFILM) -- C:\WINDOWS\System32\FREGSHEX.DLL
[2009/10/03 11:46:51 | 00,045,056 | ---- | C] (FUJIFILM) -- C:\WINDOWS\System32\FCLKBTN.DLL
[2009/10/03 11:46:01 | 00,000,000 | ---D | C] -- C:\Documents and Settings\IBM USER\Desktop\FinePix_USB
========== Files - Modified Within 14 Days ========== [5 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009/10/12 21:59:03 | 00,003,011 | -HS- | M] () -- C:\Documents and Settings\IBM USER\Application Data\020000009b1187e3687P.manifest
[2009/10/12 21:49:28 | 00,520,704 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\IBM USER\Desktop\OTL.exe
[2009/10/12 21:29:45 | 00,001,745 | ---- | M] () -- C:\Documents and Settings\IBM USER\Desktop\HijackThis.lnk
[2009/10/12 21:21:23 | 00,005,609 | -HS- | M] () -- C:\Documents and Settings\IBM USER\Application Data\020000009b1187e3687C.manifest
[2009/10/12 21:21:22 | 00,000,011 | -HS- | M] () -- C:\Documents and Settings\IBM USER\Application Data\020000009b1187e3687S.manifest
[2009/10/12 21:21:21 | 00,000,617 | -HS- | M] () -- C:\Documents and Settings\IBM USER\Application Data\020000009b1187e3687O.manifest
[2009/10/12 21:11:30 | 00,000,444 | ---- | M] () -- C:\WINDOWS\tasks\RegCure Program Check.job
[2009/10/12 21:11:28 | 00,001,170 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/10/12 21:11:06 | 00,000,384 | ---- | M] () -- C:\WINDOWS\tasks\RegCure Startup.job
[2009/10/12 21:09:51 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/10/12 21:09:47 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/10/12 21:09:44 | 10,726,80960 | -HS- | M] () -- C:\hiberfil.sys
[2009/10/12 21:01:38 | 00,000,686 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\HOSTS
[2009/10/12 20:24:05 | 00,007,168 | ---- | M] () -- C:\WINDOWS\System32\drivers\uteznja4.sys
[2009/10/12 00:06:00 | 00,000,806 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/10/11 23:53:06 | 00,018,692 | ---- | M] () -- C:\WINDOWS\GnuHashes.ini
[2009/10/11 23:49:00 | 00,116,736 | ---- | M] () -- C:\WINDOWS\System32\d3dx9_3232.dll
[2009/10/11 23:49:00 | 00,000,615 | ---- | M] () -- C:\WINDOWS\System32\peL21Ap9dYXKU.vbs
[2009/10/11 23:45:10 | 00,001,849 | -HS- | M] () -- C:\WINDOWS\System32\GroupPolicy000.dat
[2009/10/11 23:45:06 | 00,122,368 | ---- | M] () -- C:\WINDOWS\System32\danim32.dll
[2009/10/11 23:44:57 | 00,122,368 | ---- | M] () -- C:\WINDOWS\System32\FINFCHECK32.dll
[2009/10/11 23:44:56 | 00,000,615 | ---- | M] () -- C:\WINDOWS\System32\cx0Yu.vbs
[2009/10/11 22:28:48 | 00,164,522 | ---- | M] () -- C:\Documents and Settings\IBM USER\My Documents\dollar.jpg
[2009/10/11 22:27:04 | 00,149,457 | ---- | M] () -- C:\Documents and Settings\IBM USER\My Documents\modelpic.jpg
[2009/10/11 22:25:28 | 00,145,923 | ---- | M] () -- C:\Documents and Settings\IBM USER\My Documents\6pack.jpg
[2009/10/11 22:22:45 | 00,064,544 | ---- | M] () -- C:\Documents and Settings\IBM USER\My Documents\piggy-bank.jpg
[2009/10/07 20:53:33 | 00,030,305 | ---- | M] () -- C:\Documents and Settings\IBM USER\My Documents\mmoney.jpg
[2009/10/05 21:52:40 | 00,075,008 | ---- | M] () -- C:\Documents and Settings\IBM USER\My Documents\bman.jpg
[2009/10/03 11:34:05 | 00,002,209 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Driver Detective.lnk
[2009/10/01 20:53:18 | 09,819,586 | ---- | M] () -- C:\Documents and Settings\IBM USER\Desktop\September_2009_Data_Update.rar
========== Files - No Company Name ==========[2009/10/12 21:29:45 | 00,001,745 | ---- | C] () -- C:\Documents and Settings\IBM USER\Desktop\HijackThis.lnk
[2009/10/12 21:09:44 | 10,726,80960 | -HS- | C] () -- C:\hiberfil.sys
[2009/10/12 20:23:36 | 00,007,168 | ---- | C] () -- C:\WINDOWS\System32\drivers\uteznja4.sys
[2009/10/11 23:53:06 | 00,018,692 | ---- | C] () -- C:\WINDOWS\GnuHashes.ini
[2009/10/11 23:49:00 | 00,116,736 | ---- | C] () -- C:\WINDOWS\System32\d3dx9_3232.dll
[2009/10/11 23:49:00 | 00,000,615 | ---- | C] () -- C:\WINDOWS\System32\peL21Ap9dYXKU.vbs
[2009/10/11 23:45:10 | 00,001,849 | -HS- | C] () -- C:\WINDOWS\System32\GroupPolicy000.dat
[2009/10/11 23:45:06 | 00,122,368 | ---- | C] () -- C:\WINDOWS\System32\danim32.dll
[2009/10/11 23:45:05 | 00,005,609 | -HS- | C] () -- C:\Documents and Settings\IBM USER\Application Data\020000009b1187e3687C.manifest
[2009/10/11 23:45:05 | 00,003,011 | -HS- | C] () -- C:\Documents and Settings\IBM USER\Application Data\020000009b1187e3687P.manifest
[2009/10/11 23:45:05 | 00,000,617 | -HS- | C] () -- C:\Documents and Settings\IBM USER\Application Data\020000009b1187e3687O.manifest
[2009/10/11 23:45:05 | 00,000,011 | -HS- | C] () -- C:\Documents and Settings\IBM USER\Application Data\020000009b1187e3687S.manifest
[2009/10/11 23:44:57 | 00,122,368 | ---- | C] () -- C:\WINDOWS\System32\FINFCHECK32.dll
[2009/10/11 23:44:56 | 00,000,615 | ---- | C] () -- C:\WINDOWS\System32\cx0Yu.vbs
[2009/10/07 21:01:07 | 00,164,522 | ---- | C] () -- C:\Documents and Settings\IBM USER\My Documents\dollar.jpg
[2009/10/07 20:53:43 | 00,030,305 | ---- | C] () -- C:\Documents and Settings\IBM USER\My Documents\mmoney.jpg
[2009/10/07 19:58:23 | 00,149,457 | ---- | C] () -- C:\Documents and Settings\IBM USER\My Documents\modelpic.jpg
[2009/10/07 18:01:31 | 00,145,923 | ---- | C] () -- C:\Documents and Settings\IBM USER\My Documents\6pack.jpg
[2009/10/05 21:52:52 | 00,075,008 | ---- | C] () -- C:\Documents and Settings\IBM USER\My Documents\bman.jpg
[2009/10/05 21:16:12 | 00,064,544 | ---- | C] () -- C:\Documents and Settings\IBM USER\My Documents\piggy-bank.jpg
[2009/10/03 11:34:05 | 00,002,209 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Driver Detective.lnk
[2009/10/01 20:53:17 | 09,819,586 | ---- | C] () -- C:\Documents and Settings\IBM USER\Desktop\September_2009_Data_Update.rar
[2009/08/03 15:07:42 | 00,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2009/01/21 19:57:26 | 00,000,280 | ---- | C] () -- C:\WINDOWS\System32\epoPGPsdk.dll.sig
[2008/10/26 21:41:35 | 00,761,856 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2008/10/26 21:41:35 | 00,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2008/10/26 21:41:34 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2008/10/26 21:24:49 | 00,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2008/10/26 21:24:49 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2008/09/03 17:27:47 | 00,051,736 | ---- | C] () -- C:\Documents and Settings\IBM USER\Application Data\GDIPFONTCACHEV1.DAT
[2008/08/27 11:31:21 | 02,463,976 | ---- | C] () -- C:\WINDOWS\System32\NPSWF32.dll
[2008/08/21 21:34:06 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008/01/08 19:18:44 | 00,037,376 | ---- | C] () -- C:\Documents and Settings\IBM USER\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/12/03 21:18:06 | 00,000,220 | ---- | C] () -- C:\WINDOWS\ANS2000.INI
[2007/12/03 21:18:06 | 00,000,020 | -H-- | C] () -- C:\WINDOWS\akebook.ini
[2007/12/03 21:18:06 | 00,000,004 | -H-- | C] () -- C:\WINDOWS\a3kebook.ini
[2007/11/23 19:43:58 | 00,000,032 | ---- | C] () -- C:\WINDOWS\CD_Start.INI
[2007/11/14 18:42:27 | 00,237,568 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
[2007/11/09 12:01:59 | 00,000,164 | ---- | C] () -- C:\WINDOWS\System32\psyswin32.dll
[2007/09/27 11:51:02 | 00,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 11:48:48 | 00,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 11:48:28 | 00,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2006/10/16 05:46:35 | 00,095,528 | ---- | C] () -- C:\Documents and Settings\IBM USER\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2006/10/16 03:24:47 | 00,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2006/10/16 00:49:29 | 02,538,746 | -H-- | C] () -- C:\Documents and Settings\IBM USER\Local Settings\Application Data\IconCache.db
[2006/10/16 00:49:29 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\IBM USER\Application Data\desktop.ini
[2006/10/15 23:57:48 | 00,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/10/15 23:51:52 | 00,000,222 | ---- | C] () -- C:\WINDOWS\Welcome.ini
[2006/10/15 23:46:41 | 00,007,168 | ---- | C] () -- C:\WINDOWS\System32\drivers\TSMAPIP.SYS
[2006/10/15 23:46:18 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\FPCALL.dll
[2006/10/15 23:46:01 | 00,006,016 | ---- | C] () -- C:\WINDOWS\System32\drivers\IBMBLDID.sys
[2006/10/15 23:45:33 | 00,009,343 | ---- | C] () -- C:\WINDOWS\System32\drivers\TDSMAPI.SYS
[2006/10/15 23:36:38 | 00,002,481 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2006/06/17 00:09:52 | 00,045,124 | ---- | C] () -- C:\WINDOWS\System32\LsaWrApi.dll
[2006/06/16 23:57:32 | 00,528,453 | ---- | C] () -- C:\WINDOWS\System32\C1XStngs.dll
[2006/06/16 23:56:10 | 00,069,632 | ---- | C] () -- C:\WINDOWS\System32\D8021Xps.dll
[2006/06/12 20:27:00 | 00,073,728 | ---- | C] () -- C:\WINDOWS\System32\DEVMAN.DLL
[2005/12/01 04:16:02 | 00,024,576 | ---- | C] () -- C:\WINDOWS\System32\tphklock.dll
[2005/07/06 07:45:08 | 00,028,672 | ---- | C] () -- C:\WINDOWS\System32\notifyf2.dll
[2005/01/13 11:00:14 | 00,147,456 | ---- | C] () -- C:\WINDOWS\System32\ssleay32.dll
[2005/01/13 11:00:10 | 00,651,264 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll
[2002/11/15 09:14:28 | 00,143,360 | ---- | C] () -- C:\WINDOWS\System32\AIBMRUNL.dll
[2002/09/27 01:26:59 | 00,000,791 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2002/09/27 01:06:26 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\desktop.ini
[2002/07/09 16:49:25 | 00,286,208 | ---- | C] () -- C:\WINDOWS\System32\cncs232.dll
[1980/01/01 08:00:00 | 00,077,824 | ---- | C] () -- C:\WINDOWS\System32\SynTPCoI.dll
[1980/01/01 08:00:00 | 00,000,806 | ---- | C] () -- C:\WINDOWS\win.ini
[1980/01/01 08:00:00 | 00,000,284 | ---- | C] () -- C:\WINDOWS\system.ini
========== LOP Check ========== [2009/10/03 11:33:51 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data
[2008/10/07 16:20:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2009/04/21 12:37:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CyberLink
[2009/02/26 22:32:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Downloaded Installations
[2007/12/03 22:22:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\eBay
[2008/08/26 16:08:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FLEXnet
[2006/10/15 23:52:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ibm
[2008/09/04 17:58:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Installations
[2007/12/30 15:58:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MGS
[2008/11/20 18:23:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Micro Niche Finder
[2009/02/26 22:33:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2009/10/03 11:33:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2008/09/04 18:03:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite
[2009/06/17 20:13:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RegCure
[2008/01/02 20:38:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RoboForm
[2002/09/27 01:27:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SBSI
[2009/04/06 22:58:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2009/08/03 17:50:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2009/10/11 23:45:05 | 00,000,000 | -H-D | M] -- C:\Documents and Settings\IBM USER\Application Data
[2009/03/24 00:00:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\IBM USER\Application Data\Auslogics
[2009/04/21 16:56:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\IBM USER\Application Data\BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1
[2009/04/27 22:25:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\IBM USER\Application Data\Clickteam
[2009/04/21 12:37:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\IBM USER\Application Data\CyberLink
[2009/06/12 21:27:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\IBM USER\Application Data\Download Manager
[2007/12/10 23:59:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\IBM USER\Application Data\EbkReader
[2008/06/10 21:36:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\IBM USER\Application Data\eBookPro6
[2007/11/22 22:23:55 | 00,000,000 | ---D | M] -- C:\Documents and Settings\IBM USER\Application Data\IBM
[2007/12/03 20:26:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\IBM USER\Application Data\InterVideo
[2009/05/14 22:10:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\IBM USER\Application Data\LegalSounds
[2009/10/11 23:47:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\IBM USER\Application Data\LimeWire
[2009/09/18 21:02:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\IBM USER\Application Data\Multimedia Player
[2008/01/17 21:53:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\IBM USER\Application Data\Nvu
[2008/08/21 21:24:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\IBM USER\Application Data\OpenOffice.org2
[2009/02/26 22:33:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\IBM USER\Application Data\ParetoLogic
[2008/09/04 18:00:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\IBM USER\Application Data\PC Suite
[2007/12/30 15:47:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\IBM USER\Application Data\Rbet
[2009/07/19 11:45:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\IBM USER\Application Data\Reg Tool
[2009/05/14 21:33:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\IBM USER\Application Data\Samsung
[2008/02/01 21:59:57 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\IBM USER\Application Data\SecuROM
[2008/01/07 21:30:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\IBM USER\Application Data\SmartFTP
[2008/07/08 19:42:49 | 00,000,000 | ---D | M] -- C:\Documents and Settings\IBM USER\Application Data\Snapfish
[2009/01/08 23:22:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\IBM USER\Application Data\SpinTop
[2008/02/01 22:00:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\IBM USER\Application Data\Sports Interactive
[2008/03/09 14:32:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\IBM USER\Application Data\ubi.com
[2008/10/30 15:20:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\IBM USER\Application Data\Windows Desktop Search
[2008/10/30 15:21:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\IBM USER\Application Data\Windows Search
[2009/06/01 08:48:06 | 00,000,284 | ---- | M] () -- C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2006/10/16 02:38:40 | 00,000,304 | ---- | M] () -- C:\WINDOWS\Tasks\BMMTask.job
[2002/08/29 13:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2009/10/12 21:11:30 | 00,000,444 | ---- | M] () -- C:\WINDOWS\Tasks\RegCure Program Check.job
[2009/10/12 21:11:06 | 00,000,384 | ---- | M] () -- C:\WINDOWS\Tasks\RegCure Startup.job
[2009/06/28 03:04:02 | 00,000,378 | ---- | M] () -- C:\WINDOWS\Tasks\RegCure.job
[2009/10/12 21:09:51 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.exe > < %systemroot%\system32\eventlog.dll >[2008/04/14 01:11:53 | 00,056,320 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\eventlog.dll
[5 C:\WINDOWS\system32\*.tmp files]
< %systemroot%\system32\scecli.dll >[2008/04/14 01:12:05 | 00,181,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\scecli.dll
[5 C:\WINDOWS\system32\*.tmp files]
< %systemroot%\netlogon.dll > < %systemroot%\system32\cngaudit.dll > < %systemroot%\system32\sceclt.dll > < %systemroot%\ntelogon.dll > < %systemroot%\system32\logevent.dll > ========== Alternate Data Streams ========== @Alternate Data Stream - 97 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:6FA8AF63
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0F8F5844
< End of report >