OT's done
OT3:
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
Service vsmon stopped successfully.
Service vsmon deleted successfully.
========== FILES ==========
C:\WINDOWS\system32\ZoneLabs\vsmon.exe moved successfully.
========== COMMANDS ==========
File delete failed.
C:\DOCUME~1\Alan\LOCALS~1\Temp\etilqs_GaJs5esHOUXduTYLcRac scheduled to
be deleted on reboot.
File delete failed.
C:\DOCUME~1\Alan\LOCALS~1\Temp\Perflib_Perfdata_d28.dat scheduled to be
deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_7d4.dat scheduled
to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\Alan\Local
Settings\Application Data\Mozilla\Firefox\Profiles\8a5knr8q.ALAN
NEW\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Alan\Local
Settings\Application Data\Mozilla\Firefox\Profiles\8a5knr8q.ALAN
NEW\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Alan\Local
Settings\Application Data\Mozilla\Firefox\Profiles\8a5knr8q.ALAN
NEW\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Alan\Local
Settings\Application Data\Mozilla\Firefox\Profiles\8a5knr8q.ALAN
NEW\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Alan\Local
Settings\Application Data\Mozilla\Firefox\Profiles\8a5knr8q.ALAN
NEW\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Alan\Local
Settings\Application Data\Mozilla\Firefox\Profiles\8a5knr8q.ALAN
NEW\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully
OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02152009_011315
OT2:
OTListIt logfile created on: 2/15/2009 1:37:56 AM - Run
OTListIt2 by OldTimer - Version 2.0.0.12 Folder = F:\Firefox\downloads
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1023.01 Mb Total Physical Memory | 687.13 Mb Available Physical Memory | 67.17% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): E:\pagefile.sys 1500 2000;F:\pagefile.sys 0 0;S:\pagefile.sys 0 0;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 9.32 Gb Total Space | 2.37 Gb Free Space | 25.42% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 9.31 Gb Total Space | 2.72 Gb Free Space | 29.21% Space Free | Partition Type: FAT32
Drive F: | 27.93 Gb Total Space | 15.12 Gb Free Space | 54.12% Space Free | Partition Type: FAT32
Drive G: | 27.93 Gb Total Space | 25.17 Gb Free Space | 90.11% Space Free | Partition Type: FAT32
Drive H: | 27.94 Gb Total Space | 19.05 Gb Free Space | 68.19% Space Free | Partition Type: FAT32
I: Drive not present or media not loaded
Drive J: | 3.77 Gb Total Space | 1.49 Gb Free Space | 39.51% Space Free | Partition Type: FAT
Drive S: | 27.93 Gb Total Space | 21.52 Gb Free Space | 77.05% Space Free | Partition Type: FAT32
Computer Name: SUNRISE-RAP
Current User Name: Alan
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ========== PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\WINDOWS\system32\snmp.exe (Microsoft Corporation)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - E:\Program Files\Clipomatic\Clipomatic.exe ( )
PRC - E:\Program Files\pita210\Pitaschio.exe ( )
PRC - C:\Program Files\SpamPal\spampal.exe (SpamPal.org)
PRC - E:\PROGRA~1\Webshots\webshots.scr (Webshots.com)
PRC - F:\Firefox\downloads\OTListIt2.exe (OldTimer Tools)
========== Win32 Services (SafeList) ========== SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (AVG Anti-Spyware Guard [Auto | Stopped]) -- File not found
SRV - (avg8emc [Auto | Running]) -- C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd [Auto | Running]) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Creative Service for CDROM Access [Auto | Stopped]) -- File not found
SRV - (gusvc [On_Demand | Stopped]) -- File not found
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll (Microsoft Corporation)
SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (SNMP [Auto | Running]) -- C:\WINDOWS\system32\snmp.exe (Microsoft Corporation)
SRV - (SNMPTRAP [On_Demand | Stopped]) -- C:\WINDOWS\system32\snmptrap.exe (Microsoft Corporation)
SRV - (vsmon [Auto | Stopped]) -- File not found
SRV - (WMPNetworkSvc [Disabled | Stopped]) -- C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (WudfSvc [Auto | Running]) -- C:\WINDOWS\system32\WudfSvc.dll (Microsoft Corporation)
========== Driver Services (SafeList) ========== DRV - (ac97intc [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\ac97intc.sys (Intel Corporation)
DRV - (Afc [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (AvgLdx86 [System | Running]) -- C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) -- C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) -- C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (FETNDISB [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\dxe1015b.sys (Best Buy Corporation )
DRV - (giveio [Boot | Running]) -- C:\WINDOWS\system32\giveio.sys ()
DRV - (itchfltr [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\itchfltr.sys (Logitech, Inc.)
DRV - (kbdhid [System | Running]) -- C:\WINDOWS\system32\drivers\kbdhid.sys (Microsoft Corporation)
DRV - (LCcfltr [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\LCcfltr.sys (Logitech, Inc.)
DRV - (LHidFilt [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (LHidKe [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\LHidKE.Sys (Logitech, Inc.)
DRV - (LHidUsb [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\LHidUsb.Sys (Logitech, Inc.)
DRV - (LHidUsbK [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\LHidUsbK.sys (Logitech, Inc.)
DRV - (LMouFilt [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LUsbFilt [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\LUsbFilt.sys (Logitech, Inc.)
DRV - (mxInsMon [On_Demand | Stopped]) -- E:\PROGRA~1\ALADDI~1\SPRING~1\mxInsMon.sys ()
DRV - (nv [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\system32\drivers\pxhelp20.sys (Sonic Solutions)
DRV - (Rcfilter [Auto | Running]) -- C:\WINDOWS\system32\drivers\Rcfilter.sys (FarStone Technology Inc.,)
DRV - (RITFSD [Boot | Running]) -- C:\WINDOWS\system32\drivers\RITFSD.sys ()
DRV - (rtl8139 [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (SBKUPNT [Auto | Running]) -- C:\WINDOWS\system32\drivers\SBKUPNT.SYS ()
DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (speedfan [Boot | Running]) -- C:\WINDOWS\system32\speedfan.sys (Windows ® 2000 DDK provider)
DRV - (srescan [Boot | Running]) -- C:\WINDOWS\system32\ZoneLabs\srescan.sys (Check Point Software Technologies LTD)
DRV - (symlcbrd [Auto | Running]) -- C:\WINDOWS\system32\drivers\symlcbrd.sys (Symantec Corporation)
DRV - (vsdatant [System | Running]) -- C:\WINDOWS\system32\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (Wdf01000 [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\wdf01000.sys (Microsoft Corporation)
DRV - (Wdm1 [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\usbbc.sys ()
DRV - (WS2IFSL [System | Running]) -- C:\WINDOWS\system32\drivers\ws2ifsl.sys (Microsoft Corporation)
========== Standard Registry (All) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://ie.search.msn...st/srchcust.htmIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch =
http://us.rd.yahoo.c...rch/search.htmlIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ieIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://ie.search.msn...st/srchasst.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft...amp;ar=iesearchIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://www.google.co...m...tf8&oe=utf8IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.webshots.com/IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
O1 HOSTS File: (253869 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.1001-search.info
O1 - Hosts: 127.0.0.1 1001-search.info
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 8842 more lines...
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - Reg Error: Key error. File not found
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll File not found
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - Reg Error: Key error. File not found
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {01E04581-4EEE-11D0-BFE9-00AA005B4383} - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0E5CBF21-D15F-11D0-8301-00AA005B4383} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [Clipomatic] E:\Program Files\Clipomatic\Clipomatic.exe ( )
O4 - Startup: C:\Documents and Settings\Alan\Start Menu\Programs\Startup\procexp (2).lnk = E:\processes\nwProcessExplorer\procexp.exe (Sysinternals - www.sysinternals.com)
O4 - Startup: C:\Documents and Settings\Alan\Start Menu\Programs\Startup\Shortcut to Pitaschio.exe.lnk = E:\Program Files\pita210\Pitaschio.exe ( )
O4 - Startup: C:\Documents and Settings\Alan\Start Menu\Programs\Startup\SpamPl.lnk = C:\Program Files\SpamPal\spampal.exe (SpamPal.org)
O4 - Startup: C:\Documents and Settings\Alan\Start Menu\Programs\Startup\Webshots.lnk = E:\Program Files\Webshots\Launcher.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O8 - Extra context menu item: &Search - ?p=ZRxdm529YYUS
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [Tcpip] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [NTDS] - C:\WINDOWS\system32\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [Network Location Awareness (NLA) Namespace] - C:\WINDOWS\system32\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\SpamPal\spampalLSP.dll (SpamPal.org)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\SpamPal\spampalLSP.dll (SpamPal.org)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\SpamPal\spampalLSP.dll (SpamPal.org)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\SpamPal\spampalLSP.dll (SpamPal.org)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\SpamPal\spampalLSP.dll (SpamPal.org)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\SpamPal\spampalLSP.dll (SpamPal.org)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\SpamPal\spampalLSP.dll (SpamPal.org)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\SpamPal\spampalLSP.dll (SpamPal.org)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\SpamPal\spampalLSP.dll (SpamPal.org)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\SpamPal\spampalLSP.dll (SpamPal.org)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\SpamPal\spampalLSP.dll (SpamPal.org)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\SpamPal\spampalLSP.dll (SpamPal.org)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\SpamPal\spampalLSP.dll (SpamPal.org)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\SpamPal\spampalLSP.dll (SpamPal.org)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\SpamPal\spampalLSP.dll (SpamPal.org)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\SpamPal\spampalLSP.dll (SpamPal.org)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\SpamPal\spampalLSP.dll (SpamPal.org)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\SpamPal\spampalLSP.dll (SpamPal.org)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\SpamPal\spampalLSP.dll (SpamPal.org)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Program Files\SpamPal\spampalLSP.dll (SpamPal.org)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files\SpamPal\spampalLSP.dll (SpamPal.org)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Program Files\SpamPal\spampalLSP.dll (SpamPal.org)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Program Files\SpamPal\spampalLSP.dll (SpamPal.org)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {01010200-5E80-11D8-9E86-0007E96C65AE}
http://supportcenter...ad/tgctlins.cab (Reg Error: Key error.)
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE}
http://supportcenter...oad/tgctlsi.cab (SupportSoft SmartIssue)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://go.microsoft....k/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {2E12FB00-546B-4EE3-9CC2-057BF02E1C17}
http://community.web...wsaxcontrol.cab (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.micros...b?1139291678343 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.ma...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {99FE5072-78AA-4FEE-89BA-69A5FA55343F}
http://download.micr...44/igdtoolx.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078}
https://www-secure.s...rl/SymAData.cab (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload.ma...ent/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\gopher {79eac9e4-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\WINDOWS\system32\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\system32\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\sysimage {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wia {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\system32\wiascr.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/octet-stream - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-complus - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - application/x-msdownload - C:\WINDOWS\system32\mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter: - Class Install Handler - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - deflate - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - gzip - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - lzdhtml - C:\WINDOWS\system32\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/webviewhtml - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UIHost - (logonui.exe) - C:\WINDOWS\system32\logonui.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (rundll32 shell32) - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (Control_RunDLL "sysdm.cpl") - C:\WINDOWS\system32\sysdm.cpl (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\crypt32chain: DllName - crypt32.dll - C:\WINDOWS\system32\crypt32.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cryptnet: DllName - cryptnet.dll - C:\WINDOWS\system32\cryptnet.dll (Microsoft Corporation)
O20 - Winlogon\Notify\cscdll: DllName - cscdll.dll - C:\WINDOWS\system32\cscdll.dll (Microsoft Corporation)
O20 - Winlogon\Notify\ScCertProp: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\Schedule: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\sclgntfy: DllName - sclgntfy.dll - C:\WINDOWS\system32\sclgntfy.dll (Microsoft Corporation)
O20 - Winlogon\Notify\SensLogn: DllName - WlNotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\termsrv: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\system32\WgaLogon.dll (Microsoft Corporation)
O20 - Winlogon\Notify\wlballoon: DllName - wlnotify.dll - C:\WINDOWS\system32\wlnotify.dll (Microsoft Corporation)
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\system32\stobject.dll (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\WINDOWS\system32\webcheck.dll (Microsoft Corporation)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {438755C2-A8BA-11D1-B96B-00A0C90312E1} - Browseui preloader - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O22 - SharedTaskScheduler: {8C7461EF-2B13-11d2-BE35-3078302C2030} - Component Categories cache daemon - C:\WINDOWS\system32\browseui.dll (Microsoft Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O27 - HKLM IFEO\Your Image File Name Here without a path: Debugger - C:\WINDOWS\system32\ntsd.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {57B86673-276A-48B2-BAE7-C6DBB3020EB8} - Reg Error: Key error. File not found
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - C:\WINDOWS\system32\shell32.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msapsspc.dll) - C:\WINDOWS\system32\msapsspc.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - ( schannel.dll) - C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - ( digest.dll) - C:\WINDOWS\system32\digest.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - ( msnsspc.dll) - C:\WINDOWS\system32\msnsspc.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) - C:\WINDOWS\system32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (kerberos) - C:\WINDOWS\system32\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) - C:\WINDOWS\system32\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) - C:\WINDOWS\system32\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) - C:\WINDOWS\system32\wdigest.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O32 - Autorun File - C:\AutoSetup.log () - [ NTFS ]
O32 - Autorun File - E:\autorunsc [2007/07/12 15:36:26 00,000,000 | ---D | M] - [ FAT32 ]
O32 - Autorun File - E:\AutoUpd.txt () - [ FAT32 ]
O32 - Autorun File - E:\autoStreamer.exe (Antonis Kaladis) - [ FAT32 ]
O32 - Autorun File - J:\autoRunCD [2008/05/23 19:49:36 00,000,000 | ---D | M] - [ FAT ]
O32 - Autorun File - J:\autoStitch [2008/05/23 19:49:58 00,000,000 | ---D | M] - [ FAT ]
========== Files/Folders - Created Within 30 Days ========== [2009/02/14 23:04:14 | 00,000,515 | ---- | C] () -- C:\Documents and Settings\Alan\Desktop\Add-Remove Pro.lnk
[2009/02/14 16:32:03 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2009/02/14 02:16:44 | 00,000,000 | -HSD | C] -- C:\RECYCLER
[2009/02/14 00:41:45 | 00,000,211 | ---- | C] () -- C:\Boot.bak
[2009/02/14 00:41:42 | 00,260,272 | ---- | C] () -- C:\cmldr
[2009/02/14 00:41:36 | 00,000,000 | RHSD | C] -- C:\cmdcons
[2009/02/14 00:40:07 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2009/02/14 00:40:07 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2009/02/14 00:40:07 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2009/02/14 00:40:07 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2009/02/14 00:40:07 | 00,089,504 | ---- | C] (Smallfrogs Studio) -- C:\WINDOWS\fdsv.exe
[2009/02/14 00:40:07 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2009/02/14 00:40:07 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2009/02/14 00:40:07 | 00,049,152 | ---- | C] () -- C:\WINDOWS\VFIND.exe
[2009/02/14 00:40:07 | 00,029,696 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2009/02/14 00:40:01 | 00,000,000 | ---D | C] -- C:\Qoobox
[2009/02/11 16:15:52 | 16,409,960 | ---- | C] (Safer Networking Limited ) -- C:\Documents and Settings\Alan\Desktop\spybotsd162.exe
[2009/02/07 15:08:59 | 00,001,192 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1645522239-2052111302-725345543-1004.job
[2009/01/28 17:18:02 | 00,000,258 | ---- | C] () -- C:\Documents and Settings\Alan\Desktop\Shortcut to rips.lnk
[2009/01/27 18:38:23 | 00,001,507 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\AVG Free 8.0.lnk
[2009/01/27 18:38:22 | 00,010,520 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll
[2009/01/27 18:38:21 | 00,107,272 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/01/27 18:38:12 | 00,325,128 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/01/27 18:38:10 | 00,027,656 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/01/27 18:38:06 | 33,147,622 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/01/27 18:38:06 | 06,061,540 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/01/27 18:38:06 | 00,368,010 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/01/27 18:38:06 | 00,102,133 | ---- | C] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/01/27 18:38:06 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\Avg
[2009/01/24 17:42:38 | 00,002,211 | ---- | C] () -- C:\Documents and Settings\Alan\Desktop\e-Sword.lnk
[2009/01/20 14:18:28 | 00,331,451 | ---- | C] () -- C:\Documents and Settings\Alan\My Documents\FW_ Gender specific driving etiquette.eml
========== Files - Modified Within 30 Days ========== [5 C:\WINDOWS\System32\*.tmp files]
[3 C:\WINDOWS\*.tmp files]
[2009/02/15 01:27:51 | 00,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/02/15 01:26:49 | 00,000,310 | ---- | M] () -- C:\WINDOWS\tasks\GlaryInitialize.job
[2009/02/15 01:26:48 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/02/15 01:26:44 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/02/15 00:43:40 | 00,001,192 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1645522239-2052111302-725345543-1004.job
[2009/02/15 00:06:14 | 33,147,622 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/02/14 23:04:14 | 00,000,515 | ---- | M] () -- C:\Documents and Settings\Alan\Desktop\Add-Remove Pro.lnk
[2009/02/14 00:44:16 | 00,000,285 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/02/14 00:41:45 | 00,000,281 | RHS- | M] () -- C:\boot.ini
[2009/02/13 15:32:15 | 00,010,752 | ---- | M] () -- C:\Documents and Settings\Alan\My Documents\Condo09.xlr
[2009/02/11 21:50:04 | 00,108,544 | ---- | M] () -- C:\Documents and Settings\Alan\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/02/11 16:16:29 | 16,409,960 | ---- | M] (Safer Networking Limited ) -- C:\Documents and Settings\Alan\Desktop\spybotsd162.exe
[2009/02/11 16:07:52 | 00,102,133 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/02/10 11:48:08 | 00,079,432 | ---- | M] () -- C:\Documents and Settings\Alan\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/02/09 15:21:18 | 00,406,636 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/02/09 15:21:18 | 00,063,644 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/02/09 15:21:17 | 00,478,282 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/02/08 22:57:48 | 00,027,656 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/02/08 22:57:48 | 00,010,520 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\avgrsstx.dll
[2009/02/08 22:57:47 | 00,325,128 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/02/08 22:57:42 | 00,107,272 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/02/08 22:54:12 | 00,368,010 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/02/07 17:31:17 | 00,258,248 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/02/06 19:12:41 | 00,000,863 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/02/06 12:06:50 | 00,348,370 | ---- | M] () -- C:\WINDOWS\System32\vsconfig.xml
[2009/01/29 01:39:00 | 00,000,563 | ---- | M] () -- C:\Documents and Settings\Alan\Desktop\ccleaner.lnk
[2009/01/28 17:17:56 | 00,000,258 | ---- | M] () -- C:\Documents and Settings\Alan\Desktop\Shortcut to rips.lnk
[2009/01/28 17:06:40 | 04,071,826 | -H-- | M] () -- C:\Documents and Settings\Alan\Local Settings\Application Data\IconCache.db
[2009/01/27 18:38:23 | 00,001,507 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AVG Free 8.0.lnk
[2009/01/27 18:38:06 | 06,061,540 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/01/27 17:45:19 | 00,002,473 | ---- | M] () -- C:\Documents and Settings\Alan\Desktop\MS Word.lnk
[2009/01/27 17:00:02 | 00,013,588 | ---- | M] () -- C:\WINDOWS\System32\wpa.bak
[2009/01/25 13:07:38 | 00,000,467 | ---- | M] () -- C:\Documents and Settings\Alan\Start Menu\Programs\Startup\Webshots.lnk
[2009/01/20 14:18:28 | 00,331,451 | ---- | M] () -- C:\Documents and Settings\Alan\My Documents\FW_ Gender specific driving etiquette.eml
========== LOP Check ========== [2009/01/27 18:15:29 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\Alan\Application Data
[2008/10/31 11:16:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\.clamwin
[2008/01/16 16:18:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\Adobe
[2006/06/07 22:01:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\AdobeUM
[2007/02/11 22:42:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\Aim
[2007/06/18 19:36:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\Apple Computer
[2006/02/15 17:28:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\ArcSoft
[2008/01/26 21:18:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\Creative
[2007/07/22 12:12:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\Desktop Sidebar
[2008/10/11 20:31:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\DisplayTune
[2006/03/15 19:36:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\EBookSys
[2007/02/02 22:44:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\EPSON
[2007/05/23 15:21:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\FastStone
[2008/07/27 23:29:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\FireShot
[2007/12/27 22:01:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\FUJIFILM
[2007/01/12 17:11:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\Google
[2006/05/08 13:01:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\Help
[2006/06/27 20:17:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\HP
[2008/11/04 14:40:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\Hyperionics
[2008/06/01 00:51:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\Identities
[2006/01/28 19:48:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\Intuit
[2007/03/24 22:05:33 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\iPodder
[2008/10/25 11:43:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\JAM Software
[2008/07/16 21:30:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\Lavasoft
[2006/01/27 18:50:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\Leadertech
[2006/01/28 12:41:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\Macromedia
[2008/10/08 14:37:40 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\Malwarebytes
[2007/01/17 02:21:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\Media Player Classic
[2009/02/08 22:50:28 | 00,000,000 | --SD | M] -- C:\Documents and Settings\Alan\Application Data\Microsoft
[2006/01/28 16:58:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\Microsoft Web Folders
[2008/11/05 19:42:05 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\minimem
[2008/07/09 15:00:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\Move Networks
[2008/07/05 15:38:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\Mozilla
[2007/09/10 13:15:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\MxBoost
[2007/09/10 00:06:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\Netscape
[2007/03/20 23:17:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\OpenOffice.org2
[2007/08/21 21:14:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\Opera
[2006/05/20 21:59:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\PC Magazine Utilities
[2007/12/09 16:44:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\Real
[2008/01/01 22:27:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\Screenshot Studio Files
[2007/04/11 20:35:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\SiteAdvisor
[2007/12/04 23:15:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\Snapfish
[2008/07/25 13:47:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\Snood
[2007/06/29 19:43:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\SpamPal
[2006/01/30 21:02:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\Sun
[2006/01/27 18:19:32 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\Talkback
[2007/01/20 18:27:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\Uniblue
[2006/01/28 12:44:24 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\Webshots
[2008/11/03 14:49:34 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\WinPatrol
[2007/02/07 20:22:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\WinRAR
[2007/10/16 22:08:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Alan\Application Data\wsInspector
[2009/02/14 21:33:25 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data
[2008/07/05 14:14:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Adobe
[2007/10/16 20:04:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/02/08 22:50:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg8
[2006/01/29 18:36:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Broderbund LLC
[2006/01/29 18:36:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Broderbund Software
[2007/12/15 00:18:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Google
[2008/05/07 14:29:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Grisoft
[2006/01/28 19:47:10 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Intuit
[2008/07/16 22:01:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Lavasoft
[2007/06/28 16:33:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LogiShrd
[2008/08/13 21:18:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LogMeIn
[2006/01/29 20:30:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Macromedia
[2007/09/23 23:39:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MailFrontier
[2008/10/08 14:37:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2007/04/11 20:35:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\McAfee
[2008/07/16 21:30:38 | 00,000,000 | --SD | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft
[2007/02/18 21:30:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Microsoft Corporation
[2009/02/14 16:32:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2006/07/04 21:50:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
[2006/01/27 19:14:22 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\QuickTime
[2007/01/17 02:17:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Real
[2007/04/11 20:35:43 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SiteAdvisor
[2006/06/27 20:04:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sonic
[2009/02/12 23:04:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2007/10/14 22:33:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2006/03/08 11:56:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Support.com
[2007/06/24 16:44:36 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SupportSoft
[2008/06/10 18:00:27 | 00,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Application Data\System Restore
[2007/07/27 20:05:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Tarma Installer
[2007/04/16 19:44:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Tenebril
[2007/03/24 22:01:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2006/07/29 21:41:51 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2006/01/29 21:18:04 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2007/02/05 01:27:45 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\YAHOO
[2007/10/26 21:02:17 | 00,000,000 | RH-D | M] -- C:\Documents and Settings\All Users\Application Data\yahoo!
[2004/08/04 03:00:00 | 00,000,065 | RH-- | M] () -- C:\WINDOWS\Tasks\desktop.ini
[2009/02/15 01:26:49 | 00,000,310 | ---- | M] () -- C:\WINDOWS\Tasks\GlaryInitialize.job
[2009/02/15 00:43:40 | 00,001,192 | ---- | M] () -- C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1645522239-2052111302-725345543-1004.job
[2009/02/15 01:26:48 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ========== < End of report >
Ext:
OTListIt Extras logfile created on: 2/15/2009 1:37:57 AM - Run
OTListIt2 by OldTimer - Version 2.0.0.12 Folder = F:\Firefox\downloads
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1023.01 Mb Total Physical Memory | 687.13 Mb Available Physical Memory | 67.17% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): E:\pagefile.sys 1500 2000;F:\pagefile.sys 0 0;S:\pagefile.sys 0 0;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 9.32 Gb Total Space | 2.37 Gb Free Space | 25.42% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 9.31 Gb Total Space | 2.72 Gb Free Space | 29.21% Space Free | Partition Type: FAT32
Drive F: | 27.93 Gb Total Space | 15.12 Gb Free Space | 54.12% Space Free | Partition Type: FAT32
Drive G: | 27.93 Gb Total Space | 25.17 Gb Free Space | 90.11% Space Free | Partition Type: FAT32
Drive H: | 27.94 Gb Total Space | 19.05 Gb Free Space | 68.19% Space Free | Partition Type: FAT32
I: Drive not present or media not loaded
Drive J: | 3.77 Gb Total Space | 1.49 Gb Free Space | 39.51% Space Free | Partition Type: FAT
Drive S: | 27.93 Gb Total Space | 21.52 Gb Free Space | 77.05% Space Free | Partition Type: FAT32
Computer Name: SUNRISE-RAP
Current User Name: Alan
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Moni