So far, I have run Adaware, Spybot S&D, SuperAntiSpyware, Malwarebytes, and Avast. A couple things were found but seemed inactive/benign and removed fine. Still have the problem.
I have gone through the guide:
cleaned temp files
system restore, backed up registry
scanned with MBAM, nothing found.
scanned with avast, nothing found.
updated windows critical updates
rebooted
Here are the rootrepeal and OTL logs:
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/10/14 20:47
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: dump_atapi.sys
Image Path: D:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xAAD00000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: D:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF7AEE000 Size: 8192 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: D:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xA9B8D000 Size: 49152 File Visible: No Signed: -
Status: -
SSDT
-------------------
#: 041 Function Name: NtCreateKey
Status: Hooked by "D:\WINDOWS\system32\DRIVERS\pamondrv.sys" at address 0xaa646620
#: 063 Function Name: NtDeleteKey
Status: Hooked by "D:\WINDOWS\system32\DRIVERS\pamondrv.sys" at address 0xaa646990
#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "D:\WINDOWS\system32\DRIVERS\pamondrv.sys" at address 0xaa646a70
#: 247 Function Name: NtSetValueKey
Status: Hooked by "D:\WINDOWS\system32\DRIVERS\pamondrv.sys" at address 0xaa646b60
==EOF==
--------------------------------------------------------------------------------------
OTL logfile created on: 10/14/2009 8:53:11 PM - Run 1
OTL by OldTimer - Version 3.0.21.0 Folder = D:\Documents and Settings\personal\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
758.42 Mb Total Physical Memory | 423.66 Mb Available Physical Memory | 55.86% Memory free
1.44 Gb Paging File | 1.18 Gb Available in Paging File | 82.37% Paging File free
Paging file location(s): D:\pagefile.sys 756 1512 [binary data]
%SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files
Drive C: | 7.45 Gb Total Space | 0.29 Gb Free Space | 3.88% Space Free | Partition Type: FAT32
Drive D: | 29.78 Gb Total Space | 6.17 Gb Free Space | 20.72% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: LAP
Current User Name: personal
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2009/10/14 20:34:31 | 00,521,216 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\personal\Desktop\OTL.exe
PRC - [2009/08/27 11:02:42 | 01,237,224 | ---- | M] (InternetSafety.com, Inc.) -- D:\Program Files\Internet Content Filter\SafeEyes.exe
PRC - [2009/04/03 14:37:22 | 00,145,408 | ---- | M] (Monsoon Multimedia Inc.) -- D:\Program Files\Monsoon Multimedia\HAVA\Common\havasvc.exe
PRC - [2009/03/01 22:28:53 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- D:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2008/11/07 15:28:16 | 00,132,424 | ---- | M] (Apple Inc.) -- D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2008/10/05 10:29:24 | 00,676,053 | ---- | M] () -- D:\Program Files\Common Files\Acronis\ProcessActivityMonitor\paamsrv.exe
PRC - [2008/08/29 11:18:44 | 00,238,888 | ---- | M] (Apple Inc.) -- D:\Program Files\Bonjour\mDNSResponder.exe
PRC - [2008/07/25 11:17:02 | 00,069,632 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
PRC - [2008/04/13 20:12:22 | 00,093,184 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Internet Explorer\iexplore.exe
PRC - [2008/04/13 20:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\Explorer.EXE
PRC - [2007/12/06 17:20:56 | 01,024,000 | ---- | M] (Synaptics, Inc.) -- D:\Program Files\Synaptics\SynTP\SynTPEnh.exe
PRC - [2005/08/24 15:00:28 | 00,258,103 | ---- | M] (Broadcom Corporation.) -- D:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe
PRC - [2005/07/19 10:10:06 | 00,114,688 | ---- | M] (Intel Corporation) -- D:\WINDOWS\System32\igfxpers.exe
PRC - [2005/07/19 10:06:12 | 00,077,824 | ---- | M] (Intel Corporation) -- D:\WINDOWS\System32\hkcmd.exe
PRC - [2004/01/06 11:47:06 | 00,327,792 | ---- | M] (Executive Software International, Inc.) -- D:\Program Files\Executive Software\Diskeeper\DkService.exe
PRC - [2003/07/28 12:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
PRC - [2003/06/19 23:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
========== Win32 Services (SafeList) ==========
SRV - [2009/04/03 14:37:22 | 00,145,408 | ---- | M] (Monsoon Multimedia Inc.) -- D:\Program Files\Monsoon Multimedia\HAVA\Common\havasvc.exe -- (havasvc [Auto | Running])
SRV - [2009/03/01 22:28:53 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- D:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
SRV - [2009/01/06 14:06:24 | 00,536,872 | ---- | M] (Apple Inc.) -- D:\Program Files\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Stopped])
SRV - [2008/11/07 15:28:16 | 00,132,424 | ---- | M] (Apple Inc.) -- D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running])
SRV - [2008/10/15 17:13:58 | 00,439,632 | ---- | M] (RealVNC Ltd.) -- D:\Program Files\RealVNC\VNC4\WinVNC4.exe -- (WinVNC4 [On_Demand | Stopped])
SRV - [2008/10/05 10:29:24 | 00,676,053 | ---- | M] () -- D:\Program Files\Common Files\Acronis\ProcessActivityMonitor\paamsrv.exe -- (paamsrv [Auto | Running])
SRV - [2008/10/05 10:29:24 | 00,155,648 | ---- | M] (Acronis) -- D:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc [On_Demand | Stopped])
SRV - [2008/08/29 11:18:44 | 00,238,888 | ---- | M] (Apple Inc.) -- D:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service [Auto | Running])
SRV - [2008/07/29 21:10:04 | 00,046,104 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008/07/29 19:24:50 | 00,881,664 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
SRV - [2008/07/29 19:16:38 | 00,132,096 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
SRV - [2008/07/25 11:17:02 | 00,069,632 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [Auto | Running])
SRV - [2008/07/25 11:16:40 | 00,034,312 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2008/06/24 19:56:38 | 00,431,384 | ---- | M] (Seagate) -- D:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe -- (SgtSch2Svc [On_Demand | Stopped])
SRV - [2008/04/13 20:12:02 | 00,038,400 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2007/07/06 14:24:54 | 05,730,304 | ---- | M] () -- D:\Program Files\PIM Xtreme\MySQL\bin\mysqld.exe -- (MySQL [Auto | Stopped])
SRV - [2005/08/24 15:00:28 | 00,258,103 | ---- | M] (Broadcom Corporation.) -- D:\Program Files\Belkin\Bluetooth Software\bin\btwdins.exe -- (btwdins [Auto | Running])
SRV - [2004/12/13 04:34:32 | 00,049,152 | ---- | M] (Ulead Systems, Inc.) -- D:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe -- (UleadBurningHelper [On_Demand | Stopped])
SRV - [2004/11/18 00:32:56 | 00,098,304 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- D:\Program Files\HPQ\SHARED\HPQWMI.exe -- (hpqwmi [On_Demand | Stopped])
SRV - [2004/01/06 11:47:06 | 00,327,792 | ---- | M] (Executive Software International, Inc.) -- D:\Program Files\Executive Software\Diskeeper\DkService.exe -- (Diskeeper [Auto | Running])
SRV - [2003/07/28 12:28:22 | 00,089,136 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Running])
SRV - [2003/06/19 23:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- D:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE -- (MDM [Auto | Running])
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft...p...&ar=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft...amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft...p...ER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn...st/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = D:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.startup.homepage: ""
FF - prefs.js..network.proxy.type: 4
FF - HKLM\software\mozilla\Firefox\extensions\\[email protected]: D:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/03/01 22:28:53 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{20a82645-c095-46ed-80e3-08825760534b}: d:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/10/14 17:40:18 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.17\extensions\\Components: D:\Program Files\Mozilla Firefox\components [2009/06/29 18:36:52 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 2.0.0.17\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins [2009/10/14 17:17:26 | 00,000,000 | ---D | M]
[2009/10/14 20:50:49 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\mozilla\Firefox\Profiles\vz2g438j.default\extensions
[2009/10/14 20:50:49 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\mozilla\Firefox\Profiles\vz2g438j.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/09/24 12:38:53 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\mozilla\Firefox\Profiles\vz2g438j.default\extensions\{455D905A-D37C-4643-A9E2-F6FEFAA0424A}
[2008/12/06 12:16:04 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\mozilla\Firefox\Profiles\vz2g438j.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/08/26 12:48:06 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\mozilla\Firefox\Profiles\vz2g438j.default\extensions\[email protected]
[2008/12/26 02:15:51 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\mozilla\Firefox\Profiles\vz2g438j.default\extensions\[email protected]
[2008/12/03 23:53:22 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\mozilla\Sunbird\Profiles\1qhp2gtv.default\extensions
[2008/12/03 23:47:35 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\mozilla\Sunbird\Profiles\1qhp2gtv.default\extensions\{4014fd56-67cb-4dd9-8d89-1021a2d759d9}
[2009/10/07 23:51:00 | 00,000,000 | ---D | M] -- D:\Program Files\mozilla firefox\extensions
[2008/10/18 02:06:09 | 00,000,000 | ---D | M] -- D:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/03/01 22:29:09 | 00,000,000 | ---D | M] -- D:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
[2008/10/18 02:06:09 | 00,000,000 | ---D | M] -- D:\Program Files\mozilla firefox\extensions\[email protected]
[2008/10/18 02:05:49 | 00,067,696 | ---- | M] (Mozilla Foundation) -- D:\Program Files\mozilla firefox\components\jar50.dll
[2008/10/18 02:05:50 | 00,054,376 | ---- | M] (Mozilla Foundation) -- D:\Program Files\mozilla firefox\components\jsd3250.dll
[2008/10/18 02:05:50 | 00,034,952 | ---- | M] (Mozilla Foundation) -- D:\Program Files\mozilla firefox\components\myspell.dll
[2008/10/18 02:05:54 | 00,046,720 | ---- | M] (Mozilla Foundation) -- D:\Program Files\mozilla firefox\components\spellchk.dll
[2008/10/18 02:05:54 | 00,172,144 | ---- | M] (Mozilla Foundation) -- D:\Program Files\mozilla firefox\components\xpinstal.dll
[2009/03/01 22:28:53 | 00,410,984 | ---- | M] (Sun Microsystems, Inc.) -- D:\Program Files\mozilla firefox\plugins\npdeploytk.dll
[2009/02/06 12:44:28 | 01,447,296 | ---- | M] (Microsoft Corporation) -- D:\Program Files\mozilla firefox\plugins\npLegitCheckPlugin.dll
[2008/10/18 02:06:04 | 00,022,664 | ---- | M] (mozilla.org) -- D:\Program Files\mozilla firefox\plugins\npnul32.dll
[2007/03/22 19:23:30 | 00,017,248 | ---- | M] (Microsoft Corporation) -- D:\Program Files\mozilla firefox\plugins\NPOFFICE.DLL
[2009/01/26 19:43:02 | 00,143,360 | ---- | M] (Apple Inc.) -- D:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2009/01/26 19:43:03 | 00,143,360 | ---- | M] (Apple Inc.) -- D:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2009/01/26 19:43:03 | 00,143,360 | ---- | M] (Apple Inc.) -- D:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2009/01/26 19:43:03 | 00,143,360 | ---- | M] (Apple Inc.) -- D:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2009/01/26 19:43:03 | 00,143,360 | ---- | M] (Apple Inc.) -- D:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2009/01/26 19:43:03 | 00,143,360 | ---- | M] (Apple Inc.) -- D:\Program Files\mozilla firefox\plugins\npqtplugin6.dll
[2009/01/26 19:43:03 | 00,143,360 | ---- | M] (Apple Inc.) -- D:\Program Files\mozilla firefox\plugins\npqtplugin7.dll
[2008/10/18 02:06:08 | 00,001,514 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2008/10/18 02:06:08 | 00,002,193 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\answers.xml
[2008/10/18 02:06:08 | 00,001,038 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2008/10/18 02:06:08 | 00,001,046 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2008/10/18 02:06:08 | 00,002,351 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\google.xml
[2008/10/18 02:06:08 | 00,000,792 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (734 bytes) - D:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (CAdBlocker Object) - {E24AD748-155E-4254-B674-4EDF86E7E1DF} - D:\Program Files\Acronis\PrivacyExpert\Blocker.dll (Acronis)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Safe &Eyes Toolbar) - {430DDB4F-38CC-4E91-AF33-4157334EC937} - D:\Program Files\Internet Content Filter\setoolbar.dll (InternetSafety.com, Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Safe &Eyes Toolbar) - {430DDB4F-38CC-4E91-AF33-4157334EC937} - D:\Program Files\Internet Content Filter\setoolbar.dll (InternetSafety.com, Inc.)
O4 - HKLM..\Run: [ICF] D:\Program Files\Internet Content Filter\SafeEyes.exe (InternetSafety.com, Inc.)
O4 - HKLM..\Run: [igfxhkcmd] D:\WINDOWS\System32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxpers] D:\WINDOWS\System32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxtray] D:\WINDOWS\System32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [SynTPEnh] D:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [SynTPLpr] D:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [SynTPStart] D:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
O4 - Startup: D:\Documents and Settings\personal\Start Menu\Programs\Startup\PowerReg Scheduler.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 04 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 01 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsMenu = 01 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 01 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsHistory = 01 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyDocs = 01 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyPictures = 01 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoUserNameInStartMenu = 01 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ClearRecentDocsOnExit = 01 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRecentDocsNetHood = 01 00 00 00 [binary data]
O8 - Extra context menu item: E&xport to Microsoft Excel - D:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Send To &Bluetooth - D:\Program Files\Belkin\Bluetooth Software\btsendto_ie_ctx.htm ()
O9 - Extra Button: Acronis Pop-up Blocker - {2E071ADC-ADF8-4b4b-8ACB-EDC49E6D45A2} - D:\Program Files\Acronis\PrivacyExpert\Blocker.dll (Acronis)
O9 - Extra 'Tools' menuitem : Acronis Pop-up Blocker - {2E071ADC-ADF8-4b4b-8ACB-EDC49E6D45A2} - D:\Program Files\Acronis\PrivacyExpert\Blocker.dll (Acronis)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - D:\Program Files\Belkin\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - D:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - D:\WINDOWS\System32\wshbth.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - File not found
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.micr...78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.micros...b?1255533120796 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.micros...b?1255533036546 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_12)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - D:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - D:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - D:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - D:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\x-atng {7e8717b0-d862-11d5-8c9e-00010304f989} - D:\Program Files\Fidelity Investments\Fidelity Active Trader\System\atngprot.dll (Fidelity Investments)
O18 - Protocol\Filter: - text/xml - D:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (D:\DOCUME~1\ALLUSE~1\APPLIC~1\MACROM~1\SwUpdate\swupdate.dll) - D:\Documents and Settings\All Users\Application Data\Macromedia\SwUpdate\swupdate.dll ()
O20 - AppInit_DLLs: (一䠻႞䌀䵏位繎1 ̀Ѐಾ鰵侁ᐂ) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - D:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - D:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - D:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - D:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - D:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O30 - LSA: Authentication Packages - (relog_ap) - D:\WINDOWS\System32\relog_ap.dll (Acronis)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/07/27 23:07:38 | 00,000,000 | -HS- | M] () - C:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2004/04/30 15:01:14 | 00,000,053 | -HS- | M] () - C:\Autorun.inf -- [ FAT32 ]
O33 - MountPoints2\{2f5e409a-d311-11dd-8a7a-00166f61418d}\Shell - "" = AutoRun
O33 - MountPoints2\{2f5e409a-d311-11dd-8a7a-00166f61418d}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{2f5e409a-d311-11dd-8a7a-00166f61418d}\Shell\AutoRun\command - "" = F:\USBAutoRun.exe -- File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - D:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found
NetSvcs: 6to4 - Service key not found. File not found
NetSvcs: Ias - Service key not found. File not found
NetSvcs: Iprip - Service key not found. File not found
NetSvcs: Irmon - Service key not found. File not found
NetSvcs: NWCWorkstation - Service key not found. File not found
NetSvcs: Nwsapagent - Service key not found. File not found
NetSvcs: WmdmPmSp - Service key not found. File not found
NetSvcs: helpsvc - D:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
========== Files/Folders - Created Within 14 Days ==========
[1 D:\WINDOWS\System32\*.tmp files]
[4 D:\WINDOWS\*.tmp files]
[2009/10/13 17:05:23 | 00,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\Lavasoft
[2009/10/13 20:34:48 | 00,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/10/13 14:52:17 | 00,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/10/13 20:34:54 | 00,000,000 | ---D | C] -- D:\Documents and Settings\personal\Application Data\Malwarebytes
[2009/10/14 10:59:00 | 00,000,000 | ---D | C] -- D:\Program Files\Alwil Software
[2009/10/13 20:32:29 | 00,000,000 | ---D | C] -- D:\Program Files\ERUNT
[2009/10/13 20:34:48 | 00,000,000 | ---D | C] -- D:\Program Files\Malwarebytes' Anti-Malware
[2009/10/14 17:42:53 | 00,000,000 | ---D | C] -- D:\Program Files\Microsoft Silverlight
[2009/10/13 14:52:17 | 00,000,000 | ---D | C] -- D:\Program Files\Spybot - Search & Destroy
[2009/10/13 14:47:55 | 00,000,000 | ---D | C] -- D:\Program Files\Trend Micro
[2009/10/14 16:39:41 | 00,000,000 | ---D | C] -- D:\Program Files\WinDirStat
[2009/10/14 20:34:29 | 00,521,216 | ---- | C] (OldTimer Tools) -- D:\Documents and Settings\personal\Desktop\OTL.exe
[2009/10/14 16:07:55 | 00,000,000 | ---D | C] -- D:\Documents and Settings\personal\Desktop\notes & misc
[2009/10/14 15:23:30 | 00,000,000 | ---D | C] -- D:\WINDOWS\Prefetch
[2009/10/14 15:11:47 | 00,000,000 | ---D | C] -- D:\WINDOWS\System32\scripting
[2009/10/14 15:11:45 | 00,000,000 | ---D | C] -- D:\WINDOWS\l2schemas
[2009/10/14 15:11:44 | 00,000,000 | ---D | C] -- D:\WINDOWS\System32\en
[2009/10/14 15:11:44 | 00,000,000 | ---D | C] -- D:\WINDOWS\System32\bits
[2009/10/14 15:04:56 | 00,000,000 | ---D | C] -- D:\WINDOWS\network diagnostic
[2009/10/14 10:56:55 | 00,472,064 | ---- | C] ( ) -- D:\Documents and Settings\personal\Desktop\RootRepeal.exe
[2009/10/13 20:34:49 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- D:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/10/13 20:34:48 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- D:\WINDOWS\System32\drivers\mbam.sys
[2009/10/13 20:32:49 | 00,000,000 | ---D | C] -- D:\WINDOWS\ERDNT
[2009/10/13 20:31:23 | 00,021,504 | ---- | C] (Doug Knox) -- D:\Documents and Settings\personal\Desktop\SysRestorePoint.exe
[2009/10/13 18:40:38 | 00,271,872 | ---- | C] (OldTimer Tools) -- D:\Documents and Settings\personal\Desktop\TFC.exe
========== Files - Modified Within 14 Days ==========
[1 D:\WINDOWS\System32\*.tmp files]
[4 D:\WINDOWS\*.tmp files]
[2009/10/14 20:53:00 | 00,000,418 | ---- | M] () -- D:\WINDOWS\tasks\Symantec NetDetect.job
[2009/10/14 20:42:20 | 00,002,206 | ---- | M] () -- D:\WINDOWS\System32\wpa.dbl
[2009/10/14 20:37:33 | 00,000,630 | ---- | M] () -- D:\WINDOWS\win.ini
[2009/10/14 20:34:31 | 00,521,216 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\personal\Desktop\OTL.exe
[2009/10/14 20:30:39 | 00,065,640 | ---- | M] () -- D:\Documents and Settings\personal\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/10/14 20:26:51 | 00,000,006 | -H-- | M] () -- D:\WINDOWS\tasks\SA.DAT
[2009/10/14 20:26:35 | 00,002,048 | --S- | M] () -- D:\WINDOWS\bootstat.dat
[2009/10/14 20:26:28 | 79,533,2608 | -HS- | M] () -- D:\hiberfil.sys
[2009/10/14 18:12:33 | 00,441,252 | ---- | M] () -- D:\WINDOWS\System32\perfh009.dat
[2009/10/14 18:12:33 | 00,071,404 | ---- | M] () -- D:\WINDOWS\System32\perfc009.dat
[2009/10/14 18:12:31 | 00,521,444 | ---- | M] () -- D:\WINDOWS\System32\PerfStringBackup.INI
[2009/10/14 18:06:19 | 00,247,904 | ---- | M] () -- D:\WINDOWS\System32\FNTCACHE.DAT
[2009/10/14 17:54:50 | 00,001,393 | ---- | M] () -- D:\WINDOWS\imsins.BAK
[2009/10/14 16:39:42 | 00,000,706 | ---- | M] () -- D:\Documents and Settings\personal\Desktop\WinDirStat.lnk
[2009/10/14 16:17:53 | 00,000,659 | ---- | M] () -- D:\Documents and Settings\personal\Application Data\freenote.ini
[2009/10/14 15:49:04 | 00,002,577 | ---- | M] () -- D:\WINDOWS\System32\CONFIG.NT
[2009/10/14 15:47:45 | 00,000,472 | ---- | M] () -- D:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/10/14 15:43:42 | 00,000,227 | ---- | M] () -- D:\WINDOWS\system.ini
[2009/10/14 15:37:12 | 00,000,786 | ---- | M] () -- D:\Documents and Settings\personal\Desktop\Windows Media Player.lnk
[2009/10/14 15:36:56 | 00,035,840 | ---- | M] () -- D:\Documents and Settings\personal\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/10/14 15:27:18 | 00,316,640 | ---- | M] () -- D:\WINDOWS\WMSysPr9.prx
[2009/10/14 10:56:46 | 00,472,064 | ---- | M] ( ) -- D:\Documents and Settings\personal\Desktop\RootRepeal.exe
[2009/10/13 20:34:52 | 00,000,696 | ---- | M] () -- D:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/10/13 20:32:30 | 00,000,611 | ---- | M] () -- D:\Documents and Settings\personal\Desktop\NTREGOPT.lnk
[2009/10/13 20:32:30 | 00,000,592 | ---- | M] () -- D:\Documents and Settings\personal\Desktop\ERUNT.lnk
[2009/10/13 20:29:51 | 00,021,504 | ---- | M] (Doug Knox) -- D:\Documents and Settings\personal\Desktop\SysRestorePoint.exe
[2009/10/13 18:40:38 | 00,271,872 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\personal\Desktop\TFC.exe
[2009/10/13 14:52:24 | 00,000,933 | ---- | M] () -- D:\Documents and Settings\personal\Desktop\Spybot - Search & Destroy.lnk
[2009/10/13 14:47:55 | 00,001,734 | ---- | M] () -- D:\Documents and Settings\personal\Desktop\HijackThis.lnk
[2009/10/12 16:30:06 | 00,000,284 | ---- | M] () -- D:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/10/10 08:01:32 | 56,536,684 | ---- | M] () -- D:\Documents and Settings\personal\Desktop\ofpdr_musicpack_mp3.zip
========== Files - No Company Name ==========
[2009/10/14 16:59:16 | 01,203,922 | ---- | C] () -- D:\WINDOWS\System32\dllcache\sysmain.sdb
[2009/10/14 16:58:45 | 01,089,593 | ---- | C] () -- D:\WINDOWS\System32\dllcache\ntprint.cat
[2009/10/14 16:39:42 | 00,000,706 | ---- | C] () -- D:\Documents and Settings\personal\Desktop\WinDirStat.lnk
[2009/10/14 12:45:16 | 00,613,334 | ---- | C] () -- D:\WINDOWS\System32\dllcache\wmplayer.chm
[2009/10/14 12:45:16 | 00,067,374 | ---- | C] () -- D:\WINDOWS\System32\dllcache\wmplayer.adm
[2009/10/14 12:45:16 | 00,023,195 | ---- | C] () -- D:\WINDOWS\System32\dllcache\wmplay.chm
[2009/10/14 12:45:16 | 00,010,457 | ---- | C] () -- D:\WINDOWS\System32\dllcache\wmptour.hta
[2009/10/14 12:45:16 | 00,001,771 | ---- | C] () -- D:\WINDOWS\System32\dllcache\wmptour.css
[2009/10/14 12:45:16 | 00,000,855 | ---- | C] () -- D:\WINDOWS\System32\dllcache\wmpocm.inf
[2009/10/14 12:45:16 | 00,000,420 | ---- | C] () -- D:\WINDOWS\System32\dllcache\wmploc.js
[2009/10/14 12:45:13 | 00,172,196 | ---- | C] () -- D:\WINDOWS\System32\dllcache\wmpaud9.wav
[2009/10/14 12:45:12 | 00,343,204 | ---- | C] () -- D:\WINDOWS\System32\dllcache\wmpaud7.wav
[2009/10/14 12:45:12 | 00,343,204 | ---- | C] () -- D:\WINDOWS\System32\dllcache\wmpaud6.wav
[2009/10/14 12:45:12 | 00,172,196 | ---- | C] () -- D:\WINDOWS\System32\dllcache\wmpaud8.wav
[2009/10/14 12:45:12 | 00,172,196 | ---- | C] () -- D:\WINDOWS\System32\dllcache\wmpaud3.wav
[2009/10/14 12:45:12 | 00,086,196 | ---- | C] () -- D:\WINDOWS\System32\dllcache\wmpaud5.wav
[2009/10/14 12:45:12 | 00,086,180 | ---- | C] () -- D:\WINDOWS\System32\dllcache\wmpaud4.wav
[2009/10/14 12:45:12 | 00,086,180 | ---- | C] () -- D:\WINDOWS\System32\dllcache\wmpaud2.wav
[2009/10/14 12:45:11 | 00,354,468 | ---- | C] () -- D:\WINDOWS\System32\dllcache\wmpaud1.wav
[2009/10/14 12:45:11 | 00,029,070 | ---- | C] () -- D:\WINDOWS\System32\dllcache\wmp.inf
[2009/10/14 12:45:09 | 00,017,272 | ---- | C] () -- D:\WINDOWS\System32\dllcache\wmdm.inf
[2009/10/14 12:45:09 | 00,008,677 | ---- | C] () -- D:\WINDOWS\System32\dllcache\wm7.gif
[2009/10/14 12:45:09 | 00,007,892 | ---- | C] () -- D:\WINDOWS\System32\dllcache\wm9.gif
[2009/10/14 12:45:09 | 00,007,369 | ---- | C] () -- D:\WINDOWS\System32\dllcache\wm4.gif
[2009/10/14 12:45:09 | 00,006,769 | ---- | C] () -- D:\WINDOWS\System32\dllcache\wmfsdk.inf
[2009/10/14 12:45:09 | 00,006,241 | ---- | C] () -- D:\WINDOWS\System32\dllcache\wm3.gif
[2009/10/14 12:45:09 | 00,006,060 | ---- | C] () -- D:\WINDOWS\System32\dllcache\wm6.gif
[2009/10/14 12:45:09 | 00,004,193 | ---- | C] () -- D:\WINDOWS\System32\dllcache\wm8.gif
[2009/10/14 12:45:09 | 00,002,477 | ---- | C] () -- D:\WINDOWS\System32\dllcache\wm5.gif
[2009/10/14 12:45:08 | 00,007,636 | ---- | C] () -- D:\WINDOWS\System32\dllcache\wm2.gif
[2009/10/14 12:45:08 | 00,005,789 | ---- | C] () -- D:\WINDOWS\System32\dllcache\wm1.gif
[2009/10/14 12:45:03 | 00,300,969 | ---- | C] () -- D:\WINDOWS\System32\dllcache\viz.wmv
[2009/10/14 12:45:03 | 00,017,489 | ---- | C] () -- D:\WINDOWS\System32\dllcache\videobg.gif
[2009/10/14 12:45:03 | 00,005,290 | ---- | C] () -- D:\WINDOWS\System32\dllcache\vidsamp.gif
[2009/10/14 12:44:57 | 00,023,829 | ---- | C] () -- D:\WINDOWS\System32\dllcache\tourbg.gif
[2009/10/14 12:44:57 | 00,003,187 | ---- | C] () -- D:\WINDOWS\System32\dllcache\tour.js
[2009/10/14 12:44:57 | 00,002,469 | ---- | C] () -- D:\WINDOWS\System32\dllcache\tplay.gif
[2009/10/14 12:44:57 | 00,002,450 | ---- | C] () -- D:\WINDOWS\System32\dllcache\tpause.gif
[2009/10/14 12:44:57 | 00,002,375 | ---- | C] () -- D:\WINDOWS\System32\dllcache\tplayh.gif
[2009/10/14 12:44:57 | 00,002,371 | ---- | C] () -- D:\WINDOWS\System32\dllcache\tpauseh.gif
[2009/10/14 12:44:54 | 00,001,398 | ---- | C] () -- D:\WINDOWS\System32\dllcache\taon.gif
[2009/10/14 12:44:54 | 00,001,380 | ---- | C] () -- D:\WINDOWS\System32\dllcache\taonh.gif
[2009/10/14 12:44:54 | 00,001,380 | ---- | C] () -- D:\WINDOWS\System32\dllcache\taoff.gif
[2009/10/14 12:44:54 | 00,001,367 | ---- | C] () -- D:\WINDOWS\System32\dllcache\taoffh.gif
[2009/10/14 12:44:47 | 00,001,148 | ---- | C] () -- D:\WINDOWS\System32\dllcache\snd.htm
[2009/10/14 12:44:46 | 00,000,908 | ---- | C] () -- D:\WINDOWS\System32\dllcache\skins.inf
[2009/10/14 12:44:39 | 00,572,557 | ---- | C] () -- D:\WINDOWS\System32\dllcache\rtuner.wmv
[2009/10/14 12:44:38 | 00,066,725 | ---- | C] () -- D:\WINDOWS\System32\dllcache\revert.wmz
[2009/10/14 12:44:32 | 00,077,307 | ---- | C] () -- D:\WINDOWS\System32\dllcache\plyr_err.chm
[2009/10/14 12:44:32 | 00,001,477 | ---- | C] () -- D:\WINDOWS\System32\dllcache\plylst6.wpl
[2009/10/14 12:44:32 | 00,001,477 | ---- | C] () -- D:\WINDOWS\System32\dllcache\plylst5.wpl
[2009/10/14 12:44:32 | 00,001,474 | ---- | C] () -- D:\WINDOWS\System32\dllcache\plylst3.wpl
[2009/10/14 12:44:32 | 00,001,448 | ---- | C] () -- D:\WINDOWS\System32\dllcache\plylst4.wpl
[2009/10/14 12:44:32 | 00,001,046 | ---- | C] () -- D:\WINDOWS\System32\dllcache\plylst7.wpl
[2009/10/14 12:44:32 | 00,001,036 | ---- | C] () -- D:\WINDOWS\System32\dllcache\plylst8.wpl
[2009/10/14 12:44:32 | 00,000,784 | ---- | C] () -- D:\WINDOWS\System32\dllcache\plylst9.wpl
[2009/10/14 12:44:31 | 00,001,451 | ---- | C] () -- D:\WINDOWS\System32\dllcache\plylst12.wpl
[2009/10/14 12:44:31 | 00,001,250 | ---- | C] () -- D:\WINDOWS\System32\dllcache\plylst1.wpl
[2009/10/14 12:44:31 | 00,001,049 | ---- | C] () -- D:\WINDOWS\System32\dllcache\plylst2.wpl
[2009/10/14 12:44:31 | 00,000,789 | ---- | C] () -- D:\WINDOWS\System32\dllcache\plylst11.wpl
[2009/10/14 12:44:31 | 00,000,787 | ---- | C] () -- D:\WINDOWS\System32\dllcache\plylst10.wpl
[2009/10/14 12:44:31 | 00,000,783 | ---- | C] () -- D:\WINDOWS\System32\dllcache\plylst13.wpl
[2009/10/14 12:44:31 | 00,000,775 | ---- | C] () -- D:\WINDOWS\System32\dllcache\plylst14.wpl
[2009/10/14 12:44:31 | 00,000,733 | ---- | C] () -- D:\WINDOWS\System32\dllcache\plylst15.wpl
[2009/10/14 12:44:24 | 00,375,519 | ---- | C] () -- D:\WINDOWS\System32\dllcache\nuskin.wmv
[2009/10/14 12:44:20 | 00,022,060 | ---- | C] () -- D:\WINDOWS\System32\dllcache\npds.zip
[2009/10/14 12:44:20 | 00,000,403 | ---- | C] () -- D:\WINDOWS\System32\dllcache\npdrmv2.zip
[2009/10/14 12:44:02 | 00,844,314 | ---- | C] () -- D:\WINDOWS\System32\dllcache\msdxm.ocx
[2009/10/14 12:44:02 | 00,004,126 | ---- | C] () -- D:\WINDOWS\System32\dllcache\msdxmlc.dll
[2009/10/14 12:43:55 | 00,097,117 | ---- | C] () -- D:\WINDOWS\System32\dllcache\mplayer2.hlp
[2009/10/14 12:43:55 | 00,018,286 | ---- | C] () -- D:\WINDOWS\System32\dllcache\mplayer2.inf
[2009/10/14 12:43:55 | 00,002,778 | ---- | C] () -- D:\WINDOWS\System32\dllcache\mplogoh.gif
[2009/10/14 12:43:55 | 00,002,545 | ---- | C] () -- D:\WINDOWS\System32\dllcache\mplogo.gif
[2009/10/14 12:43:55 | 00,001,885 | ---- | C] () -- D:\WINDOWS\System32\dllcache\mplayer2.cnt
[2009/10/14 12:43:49 | 00,457,607 | ---- | C] () -- D:\WINDOWS\System32\dllcache\mdlib.wmv
[2009/10/14 12:43:26 | 00,000,974 | ---- | C] () -- D:\WINDOWS\System32\pid.inf
[2009/10/14 12:43:11 | 00,005,971 | ---- | C] () -- D:\WINDOWS\System32\dllcache\events.js
[2009/10/14 12:43:07 | 00,498,742 | ---- | C] () -- D:\WINDOWS\System32\dllcache\dxmasf.dll
[2009/10/14 12:42:57 | 00,381,425 | ---- | C] () -- D:\WINDOWS\System32\dllcache\copycd.wmv
[2009/10/14 12:42:57 | 00,009,585 | ---- | C] () -- D:\WINDOWS\System32\dllcache\controls.css
[2009/10/14 12:42:57 | 00,008,298 | ---- | C] () -- D:\WINDOWS\System32\dllcache\contents.htm
[2009/10/14 12:42:57 | 00,006,878 | ---- | C] () -- D:\WINDOWS\System32\dllcache\controls.js
[2009/10/14 12:42:56 | 00,184,959 | ---- | C] () -- D:\WINDOWS\System32\dllcache\compact.wmz
[2009/10/14 12:42:56 | 00,000,773 | ---- | C] () -- D:\WINDOWS\System32\dllcache\cnth.gif
[2009/10/14 12:42:56 | 00,000,773 | ---- | C] () -- D:\WINDOWS\System32\dllcache\cnt.gif
[2009/10/14 12:42:56 | 00,000,772 | ---- | C] () -- D:\WINDOWS\System32\dllcache\cntd.gif
[2009/10/14 12:42:55 | 00,000,760 | ---- | C] () -- D:\WINDOWS\System32\dllcache\cloapph.gif
[2009/10/14 12:42:55 | 00,000,717 | ---- | C] () -- D:\WINDOWS\System32\dllcache\cloapp.gif
[2009/10/14 12:42:51 | 00,000,999 | ---- | C] () -- D:\WINDOWS\System32\dllcache\bktrh.gif
[2009/10/13 20:34:52 | 00,000,696 | ---- | C] () -- D:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/10/13 20:32:30 | 00,000,611 | ---- | C] () -- D:\Documents and Settings\personal\Desktop\NTREGOPT.lnk
[2009/10/13 20:32:30 | 00,000,592 | ---- | C] () -- D:\Documents and Settings\personal\Desktop\ERUNT.lnk
[2009/10/13 17:07:59 | 00,000,472 | ---- | C] () -- D:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/10/13 14:52:24 | 00,000,933 | ---- | C] () -- D:\Documents and Settings\personal\Desktop\Spybot - Search & Destroy.lnk
[2009/10/13 14:47:55 | 00,001,734 | ---- | C] () -- D:\Documents and Settings\personal\Desktop\HijackThis.lnk
[2009/10/10 07:55:44 | 56,536,684 | ---- | C] () -- D:\Documents and Settings\personal\Desktop\ofpdr_musicpack_mp3.zip
[2009/06/23 21:22:00 | 00,020,112 | ---- | C] () -- D:\WINDOWS\System32\drivers\hdiavd.sys
[2008/12/04 20:05:08 | 00,000,586 | ---- | C] () -- D:\WINDOWS\Calendar.INI
[2008/12/04 19:47:28 | 00,000,131 | ---- | C] () -- D:\Documents and Settings\personal\Local Settings\Application Data\fusioncache.dat
[2008/12/04 19:46:35 | 00,000,032 | ---- | C] () -- D:\WINDOWS\JPIMBKP.INI
[2008/12/04 16:24:23 | 00,000,032 | ---- | C] () -- D:\WINDOWS\jpimupg.INI
[2008/12/03 23:07:58 | 00,000,073 | ---- | C] () -- D:\WINDOWS\EurekaLog.ini
[2008/12/03 00:52:09 | 00,000,659 | ---- | C] () -- D:\Documents and Settings\personal\Application Data\freenote.ini
[2008/12/03 00:42:21 | 00,000,051 | ---- | C] () -- D:\WINDOWS\GEORGES.INI
[2008/10/05 10:29:29 | 00,043,648 | ---- | C] () -- D:\WINDOWS\System32\drivers\pamondrv.sys
[2008/03/16 15:31:08 | 00,739,748 | ---- | C] () -- D:\Documents and Settings\personal\Application Data\Ken.zip
[2008/01/11 13:37:09 | 00,698,962 | ---- | C] () -- D:\Documents and Settings\personal\Application Data\Ciga.zip
[2006/10/20 13:40:45 | 00,002,716 | ---- | C] () -- D:\Documents and Settings\personal\Application Data\evpro32.prf
[2006/08/19 14:43:27 | 00,000,156 | ---- | C] () -- D:\WINDOWS\Kpcms.ini
[2006/08/19 14:42:55 | 00,210,944 | ---- | C] () -- D:\WINDOWS\System32\Msvcrt10.dll
[2006/08/13 10:56:36 | 00,077,824 | ---- | C] () -- D:\WINDOWS\System32\setupnt.dll
[2006/08/13 09:07:01 | 00,000,376 | ---- | C] () -- D:\WINDOWS\ODBC.INI
[2006/08/12 18:06:11 | 00,035,840 | ---- | C] () -- D:\Documents and Settings\personal\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/08/12 16:56:00 | 00,065,640 | ---- | C] () -- D:\Documents and Settings\personal\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2006/08/12 16:53:48 | 06,951,520 | -H-- | C] () -- D:\Documents and Settings\personal\Local Settings\Application Data\IconCache.db
[2006/08/12 16:29:09 | 00,000,062 | -HS- | C] () -- D:\Documents and Settings\personal\Application Data\desktop.ini
[2006/08/12 12:12:33 | 00,000,062 | -HS- | C] () -- D:\Documents and Settings\All Users\Application Data\desktop.ini
[2005/08/24 14:56:04 | 00,090,112 | ---- | C] () -- D:\WINDOWS\System32\btprn2k.dll
[2004/10/26 18:39:05 | 03,375,104 | ---- | C] () -- D:\WINDOWS\System32\qt-mt331.dll
[2004/10/12 02:42:45 | 00,047,616 | ---- | C] () -- D:\WINDOWS\System32\ff_tremor.dll
[2004/10/12 02:42:42 | 00,151,552 | ---- | C] () -- D:\WINDOWS\System32\ff_libdts.dll
[2004/10/12 02:42:40 | 00,122,880 | ---- | C] () -- D:\WINDOWS\System32\ff_samplerate.dll
[2004/10/12 02:42:39 | 00,249,856 | ---- | C] () -- D:\WINDOWS\System32\ff_libfaad2.dll
[2004/10/12 02:42:30 | 00,034,816 | ---- | C] () -- D:\WINDOWS\System32\ff_liba52.dll
[2004/10/12 02:42:29 | 00,262,144 | ---- | C] () -- D:\WINDOWS\System32\TomsMoComp_ff.dll
[2004/10/12 02:40:56 | 02,255,360 | ---- | C] () -- D:\WINDOWS\System32\libavcodec.dll
[2004/10/12 02:39:47 | 00,028,160 | ---- | C] () -- D:\WINDOWS\System32\ff_wmv9.dll
[2004/10/12 02:39:06 | 00,110,592 | ---- | C] () -- D:\WINDOWS\System32\ff_theora.dll
[2004/10/12 02:38:47 | 00,122,880 | ---- | C] () -- D:\WINDOWS\System32\ff_libmad.dll
[2004/10/05 04:16:07 | 00,395,776 | ---- | C] () -- D:\WINDOWS\System32\libmplayer.dll
[2004/10/03 13:59:29 | 00,228,352 | ---- | C] () -- D:\WINDOWS\System32\ff_x264.dll
[2004/10/03 13:50:53 | 00,129,024 | ---- | C] () -- D:\WINDOWS\System32\ff_mpeg2enc.dll
[2004/10/03 13:50:25 | 00,112,640 | ---- | C] () -- D:\WINDOWS\System32\libmpeg2_ff.dll
[2004/09/24 05:09:42 | 00,077,824 | ---- | C] () -- D:\WINDOWS\System32\vorbisfile.dll
[2004/07/26 07:12:52 | 00,166,912 | ---- | C] () -- D:\WINDOWS\System32\lame_enc.dll
[2004/01/27 08:13:14 | 00,061,440 | ---- | C] () -- D:\WINDOWS\System32\libfaac.dll
[2003/11/18 08:50:24 | 00,421,888 | ---- | C] () -- D:\WINDOWS\System32\OpenQuicktimeLib.dll
[2003/05/25 20:41:30 | 00,704,512 | ---- | C] () -- D:\WINDOWS\System32\FreeImage.dll
[2003/01/07 15:05:08 | 00,002,695 | ---- | C] () -- D:\WINDOWS\System32\OUTLPERF.INI
[2002/05/17 18:18:30 | 00,124,928 | ---- | C] () -- D:\WINDOWS\System32\mp4fil32.dll
[2002/05/16 00:29:04 | 00,000,607 | ---- | C] () -- D:\WINDOWS\System32\BTNeighborhood.dll.manifest
[2001/11/23 19:18:00 | 00,000,597 | ---- | C] () -- D:\WINDOWS\System32\btcss.dll.manifest
[2001/11/14 14:56:00 | 01,802,240 | ---- | C] () -- D:\WINDOWS\System32\lcppn21.dll
[2001/08/23 08:00:00 | 00,000,630 | ---- | C] () -- D:\WINDOWS\win.ini
[2001/08/23 08:00:00 | 00,000,227 | ---- | C] () -- D:\WINDOWS\system.ini
========== LOP Check ==========
[2009/10/14 16:32:05 | 00,000,000 | RH-D | M] -- D:\Documents and Settings\All Users\Application Data
[2009/09/07 02:07:56 | 00,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[2008/10/05 10:29:24 | 00,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Acronis
[2008/12/04 16:42:08 | 00,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Agenda At Once
[2008/12/04 18:00:24 | 00,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Chaos Software
[2008/12/04 19:47:34 | 00,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Effexis Software
[2008/01/10 17:08:48 | 00,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Fidelity Investments
[2008/12/04 13:38:42 | 00,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\M8 Software
[2009/06/23 21:15:52 | 00,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Seagate
[2009/08/26 12:48:27 | 00,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\TVU Networks
[2009/10/14 15:52:26 | 00,000,000 | RH-D | M] -- D:\Documents and Settings\personal\Application Data
[2008/12/03 02:42:43 | 00,000,000 | -HSD | M] -- D:\Documents and Settings\personal\Application Data\.#
[2008/12/02 22:15:16 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\3M
[2008/12/04 17:48:19 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\AcePlanner
[2008/10/05 10:29:51 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\Acronis
[2008/12/04 16:58:43 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\Agenda At Once
[2008/12/03 21:07:24 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\Blumentals
[2008/12/04 19:06:32 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\Chaos Software
[2009/09/13 15:13:26 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\com.raptr.Raptr.848BBC53270CAC248E8FA0F339176201CDEB525F.1
[2008/12/04 02:44:20 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\desksware
[2008/12/04 13:52:30 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\DGtalize
[2008/12/04 19:47:34 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\Effexis Software
[2008/12/03 02:31:15 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\EssentialPIM
[2009/06/29 20:00:22 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\Fortora
[2009/09/13 14:24:57 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\gtk-2.0
[2008/12/02 23:45:36 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\Jarte
[2008/12/02 11:56:14 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\JGsoft
[2009/02/13 15:03:21 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\KomaMail
[2008/12/03 03:16:41 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\Konrad Papala
[2006/08/13 10:45:34 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\Leadertech
[2008/12/04 13:38:42 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\M8 Software
[2009/10/13 12:46:56 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\MechCAD
[2009/03/05 19:17:05 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\Miranda
[2008/12/02 12:31:08 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\NoteTab Light
[2008/12/03 22:59:09 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\Program.Files.Forte
[2009/10/14 16:30:24 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\stickies
[2008/12/04 16:24:11 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\StrategyOnline
[2009/02/14 16:25:35 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\Sylpheed
[2008/12/02 21:57:49 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\TaskCoach
[2008/10/18 10:56:08 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\The Labyrinth Plus! Edition
[2009/02/13 10:04:08 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\Thunderbird
[2009/02/14 13:52:53 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\tinySpell
[2008/12/03 03:25:00 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\TreeDBNotes 3
[2009/10/13 12:46:43 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\uTorrent
[2008/12/03 05:01:37 | 00,000,000 | ---D | M] -- D:\Documents and Settings\personal\Application Data\Vertikal Systems
[2009/10/14 15:47:45 | 00,000,472 | ---- | M] () -- D:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2009/10/12 16:30:06 | 00,000,284 | ---- | M] () -- D:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2001/08/23 08:00:00 | 00,000,065 | RH-- | M] () -- D:\WINDOWS\Tasks\desktop.ini
[2009/10/14 20:26:51 | 00,000,006 | -H-- | M] () -- D:\WINDOWS\Tasks\SA.DAT
[2009/10/14 20:53:00 | 00,000,418 | ---- | M] () -- D:\WINDOWS\Tasks\Symantec NetDetect.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< %systemroot%\system32\eventlog.dll >
[2008/04/13 20:11:53 | 00,056,320 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\system32\eventlog.dll
[1 D:\WINDOWS\system32\*.tmp files]
< %systemroot%\system32\scecli.dll >
[2008/04/13 20:12:05 | 00,181,248 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\system32\scecli.dll
[1 D:\WINDOWS\system32\*.tmp files]
< %systemroot%\netlogon.dll >
< %systemroot%\system32\cngaudit.dll >
< %systemroot%\system32\sceclt.dll >
< %systemroot%\ntelogon.dll >
< %systemroot%\system32\logevent.dll >
< End of report >
---------------------------------------------------------------------
OTL Extras logfile created on: 10/14/2009 8:53:11 PM - Run 1
OTL by OldTimer - Version 3.0.21.0 Folder = D:\Documents and Settings\personal\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
758.42 Mb Total Physical Memory | 423.66 Mb Available Physical Memory | 55.86% Memory free
1.44 Gb Paging File | 1.18 Gb Available in Paging File | 82.37% Paging File free
Paging file location(s): D:\pagefile.sys 756 1512 [binary data]
%SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files
Drive C: | 7.45 Gb Total Space | 0.29 Gb Free Space | 3.88% Space Free | Partition Type: FAT32
Drive D: | 29.78 Gb Total Space | 6.17 Gb Free Space | 20.72% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: LAP
Current User Name: personal
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm [@ = chm.file] -- D:\WINDOWS\hh.exe (Microsoft Corporation)
.html [@ = htmlfile] -- D:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %* File not found
chm.file [open] -- "D:\WINDOWS\hh.exe" %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %* File not found
comfile [open] -- "%1" %* File not found
exefile [open] -- "%1" %* File not found
htmlfile [edit] -- "D:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "D:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "D:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "D:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] -- "D:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] -- "D:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
piffile [open] -- "%1" %* File not found
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1" File not found
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S File not found
txtfile [edit] -- Reg Error: Key error.
Directory [AddToPlaylistVLC] -- D:\Program Files\VideoLAN\VLC\vlc.exe --started-from-file --playlist-enqueue "%1" ()
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- D:\Program Files\VideoLAN\VLC\vlc.exe --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "D:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "D:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1778:UDP" = 1778:UDP:*:Enabled:HAVA Service
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"D:\Program Files\Mozilla Firefox\alg.exe" = D:\Program Files\Mozilla Firefox\alg.exe:*:Enabled:SAM -- File not found
"D:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\vmmonitor.exe" = D:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\vmmonitor.exe:*:Enabled:SAM -- File not found
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"D:\Program Files\Bonjour\mDNSResponder.exe" = D:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour -- (Apple Inc.)
"D:\Program Files\iTunes\iTunes.exe" = D:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)
"D:\Program Files\Mozilla Firefox\alg.exe" = D:\Program Files\Mozilla Firefox\alg.exe:*:Enabled:SAM -- File not found
"D:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\vmmonitor.exe" = D:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\vmmonitor.exe:*:Enabled:SAM -- File not found
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{081E540C-1A6F-4C46-994B-6E3229222A10}" = HAVA Software
"{0CB3C535-1171-4A20-B549-E2CB5DEB9723}" = MySQL Connector/ODBC 3.51
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java 6 Update 12
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3F4EC965-28EF-45C3-B063-04B25D4E9679}" = Belkin Bluetooth Software
"{5511D34C-323F-42E0-8C82-0AEB3E920417}" = Diskeeper Professional Edition
"{5809E7CF-4DCF-11D4-9875-00105ACE7734}" = Logitech MouseWare 9.79.1
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}" = Bonjour
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver for Mobile
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{94FB906A-CF42-4128-A509-D353026A607E}" = REALTEK Gigabit and Fast Ethernet NIC Driver
"{97DBB946-E676-420E-A17E-FB41DE881C19}" = NSV VP62 Plug-In
"{A23866A0-738B-4091-9924-0B0DE3988A15}" = VP6 VFW Codec
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0
"{AE18DDA5-78BD-4A80-A7D9-53CE8450FD15}}_is1" = RSJ HD Image 3.06
"{B0C078CA-50AC-4C3D-B175-3B7B3A3F95F2}" = Fidelity Active Trader Pro®
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{BCB4C18A-ACA6-4383-8688-E19933A705DD}" = Microsoft SOAP Toolkit 3.0
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C3FA280D-3AE4-43F3-AFB5-D459B36A05B7}" = Safe Eyes
"{C43E4B9C-14C8-4EB0-998B-85211B6EDD61}" = Seagate DiscWizard
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CEB326EC-8F40-47B2-BA22-BB092565D66F}" = Quick Launch Buttons 5.10 B5
"{D641EA51-114A-4248-9FEE-A375CEF2F7D2}" = Acronis True Image Enterprise Server
"{EC4455AB-F155-4CC1-A4C5-88F3777F9886}" = Apple Mobile Device Support
"{EEC2DAFD-5558-40AC-8E9C-5005C8F810E8}" = Microsoft Plus! for Windows XP
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F5C63795-2708-4D15-BF18-5ABBFF7DFFC8}" = iTunes
"{FA02ACAC-9E14-4878-A257-92A22A647C2C}" = LG USB Modem Drivers
"{FA61D601-A0FC-48BD-AE7A-54946BCD7FB6}_is1" = BitPim 1.0.6
"{FA7621DC-7144-4A24-973C-B9BC0E945628}" = Ulead Straight-to-Disc SDK
"ACDSee 32" = ACDSee 32
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe PageMaker 7.0" = Adobe PageMaker 7.0
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"Automatic Wallpaper Changer_is1" = AWC 2.3.5
"CNXT_MODEM_PCI_VEN_8086&DEV_266D&SUBSYS_3080103C" = Soft Data Fax Modem with SmartCP
"Cole2k Media - Codec Pack" = Cole2k Media - Codec Pack (Advanced)
"Conexant PCI Audio" = Conexant AC-Link Audio
"DiskDirector" = Acronis Disk Director Suite
"ERUNT_is1" = ERUNT 1.1j
"EssentialPIM" = EssentialPIM
"Exact Audio Copy" = Exact Audio Copy 0.95b4
"ExamView Pro" = ExamView Pro
"FLAC" = FLAC 1.2.1b (remove only)
"FLV Player" = FLV Player 2.0, build 24
"Forte Agent" = Forté Agent
"HijackThis" = HijackThis 2.0.2
"InstallShield_{081E540C-1A6F-4C46-994B-6E3229222A10}" = HAVA Software
"Kcast_Beta_1.0" = Kcast Beta 1.1.3
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (2.0.0.17)" = Mozilla Firefox (2.0.0.17)
"NetObjects Fusion Essentials" = NetObjects Fusion Essentials
"NSV encoder interface for VP6 codec" = NSV encoder interface for VP6 codec 2.0
"Pigeonhole Free Organizer" = Pigeonhole Free Organizer
"PrivacyExpert" = Acronis Privacy Expert Suite
"PSPad editor_is1" = PSPad editor
"QuickPar" = QuickPar 0.9
"RealVNC_is1" = VNC Free Edition 4.1.3
"Stickies 6.7a" = Stickies 6.7a
"Sylpheed" = Sylpheed 2.6.0-win32
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"thinkorswim" = thinkorswim
"TreeDBNotes 3" = TreeDBNotes 3
"Tweak UI 2.10" = Tweak UI
"VLC media player" = VLC media player 0.9.8a
"WIC" = Windows Imaging Component
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WinZip" = WinZip
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"WinDirStat" = WinDirStat 1.1.2
"WindowSizer" = WindowSizer
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 4/22/2008 3:26:47 PM | Computer Name = LAP | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: This network connection does not exist.
Error - 4/22/2008 3:26:47 PM | Computer Name = LAP | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: This network connection does not exist.
Error - 4/22/2008 3:26:48 PM | Computer Name = LAP | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: This network connection does not exist.
Error - 4/22/2008 3:26:48 PM | Computer Name = LAP | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: This network connection does not exist.
Error - 4/22/2008 3:26:48 PM | Computer Name = LAP | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: This network connection does not exist.
Error - 4/22/2008 3:26:49 PM | Computer Name = LAP | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: This network connection does not exist.
Error - 4/22/2008 3:26:49 PM | Computer Name = LAP | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: This network connection does not exist.
Error - 4/22/2008 3:26:49 PM | Computer Name = LAP | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: This network connection does not exist.
Error - 4/22/2008 3:27:49 PM | Computer Name = LAP | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: This network connection does not exist.
Error - 4/22/2008 3:27:49 PM | Computer Name = LAP | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download....uthrootseq.txt>
with error: This network connection does not exist.
[ System Events ]
Error - 10/14/2009 8:24:19 PM | Computer Name = LAP | Source = Service Control Manager | ID = 7031
Description = The Apple Mobile Device service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.
Error - 10/14/2009 8:24:19 PM | Computer Name = LAP | Source = Service Control Manager | ID = 7034
Description = The Bonjour Service service terminated unexpectedly. It has done
this 1 time(s).
Error - 10/14/2009 8:24:20 PM | Computer Name = LAP | Source = Service Control Manager | ID = 7031
Description = The .NET Runtime Optimization Service v2.0.50727_X86 service terminated
unexpectedly. It has done this 1 time(s). The following corrective action will
be taken in 60000 milliseconds: Restart the service.
Error - 10/14/2009 8:24:20 PM | Computer Name = LAP | Source = Service Control Manager | ID = 7034
Description = The Diskeeper service terminated unexpectedly. It has done this 1
time(s).
Error - 10/14/2009 8:24:20 PM | Computer Name = LAP | Source = Service Control Manager | ID = 7031
Description = The Bluetooth Service service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.
Error - 10/14/2009 8:24:20 PM | Computer Name = LAP | Source = Service Control Manager | ID = 7034
Description = The Java Quick Starter service terminated unexpectedly. It has done
this 1 time(s).
Error - 10/14/2009 8:24:20 PM | Computer Name = LAP | Source = Service Control Manager | ID = 7034
Description = The HAVA Service service terminated unexpectedly. It has done this
1 time(s).
Error - 10/14/2009 8:24:20 PM | Computer Name = LAP | Source = Service Control Manager | ID = 7034
Description = The Machine Debug Manager service terminated unexpectedly. It has
done this 1 time(s).
Error - 10/14/2009 8:24:20 PM | Computer Name = LAP | Source = Service Control Manager | ID = 7034
Description = The Process Activity Monitor service terminated unexpectedly. It
has done this 1 time(s).
Error - 10/14/2009 8:28:13 PM | Computer Name = LAP | Source = Service Control Manager | ID = 7034
Description = The MySQL service terminated unexpectedly. It has done this 1 time(s).
< End of report >
Thanks for your help!