OTL logfile created on: 12/18/2009 3:55:06 AM - Run 2
OTL by OldTimer - Version 3.1.18.0 Folder = C:\Documents and Settings\Terry D. Zelenitz\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.06 Gb Available Physical Memory | 52.94% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): [Binary data over 100 bytes]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 49.81 Gb Total Space | 18.89 Gb Free Space | 37.92% Space Free | Partition Type: NTFS
Drive D: | 233.76 Gb Total Space | 67.58 Gb Free Space | 28.91% Space Free | Partition Type: NTFS
Unable to calculate disk information.
Drive F: | 24.71 Gb Total Space | 4.11 Gb Free Space | 16.64% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
Drive I: | 2.83 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Computer Name: SCOOTER
Current User Name: Terry D. Zelenitz
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ========== PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\WINDOWS\system32\winupdate86.exe ()
PRC - C:\Program Files\Google\Update\1.2.183.13\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\WINDOWS\system32\PnkBstrB.exe ()
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\iTunes\iTunes.exe (Apple Inc.)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\Rosewill\Common\RaUI.exe (Rosewill Inc.)
PRC - C:\WINDOWS\system32\PnkBstrA.exe ()
PRC - C:\Program Files\Rosewill\Common\RaRegistry.exe (Ralink Technology, Corp.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\WINDOWS\system32\CtHelper.exe (Creative Technology Ltd)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe (Nero AG)
PRC - C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\Creative\DVDAudio\CTDVDDET.exe (Creative Technology Ltd)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgam.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgfws8.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Documents and Settings\Terry D. Zelenitz\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\WINDOWS\system32\CTSVCCDA.EXE (Creative Technology Ltd)
========== Modules (SafeList) ========== MOD - C:\Documents and Settings\Terry D. Zelenitz\Desktop\OTL.exe (OldTimer Tools)
========== Win32 Services (SafeList) ========== SRV - (RoxLiveShare9) -- File not found
SRV - (PnkBstrB) -- C:\WINDOWS\system32\PnkBstrB.exe ()
SRV - (JavaQuickStarterService) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (iPod Service) -- C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (DAUpdaterSvc) -- D:\Games\Dragon Age\bin_ship\daupdatersvc.service.exe (BioWare)
SRV - (gupdate1ca0774dbc1706e) Google Update Service (gupdate1ca0774dbc1706e) -- C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
SRV - (gusvc) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (PnkBstrA) -- C:\WINDOWS\system32\PnkBstrA.exe ()
SRV - (RalinkRegistryWriter) -- C:\Program Files\Rosewill\Common\RaRegistry.exe (Ralink Technology, Corp.)
SRV - (Adobe LM Service) -- C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe (Adobe Systems)
SRV - (Apple Mobile Device) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (NVSvc) -- C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (Bonjour Service) -- C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (odserv) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (Microsoft Office Groove Audit Service) -- C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)
SRV - (Pml Driver HPZ12) -- C:\WINDOWS\system32\HPZipm12.dll (Hewlett-Packard)
SRV - (Net Driver HPZ12) -- C:\WINDOWS\system32\HPZinw12.dll (Hewlett-Packard)
SRV - (Nero BackItUp Scheduler 3) -- C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe (Nero AG)
SRV - (NMIndexingService) -- C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe (Nero AG)
SRV - (hpqcxs08) -- C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll (Hewlett-Packard Co.)
SRV - (hpqddsvc) -- C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll (Hewlett-Packard Co.)
SRV - (MSCamSvc) -- C:\Program Files\Microsoft LifeCam\MSCamS32.exe (Microsoft Corporation)
SRV - (Viewpoint Manager Service) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (ose) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (IDriverT) -- C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (avg8emc) -- C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgfws8) -- C:\Program Files\AVG\AVG8\avgfws8.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Creative Service for CDROM Access) -- C:\WINDOWS\system32\CTSVCCDA.EXE (Creative Technology Ltd)
SRV - (Visual Studio Analyzer RPC bridge) -- C:\Program Files\Microsoft Visual Studio\COMMON\Tools\VS-Ent98\Vanalyzr\VARPC.EXE (Microsoft Corporation)
========== Driver Services (SafeList) ========== DRV - (RT80x86) -- C:\WINDOWS\system32\drivers\rt2860.sys (Ralink Technology, Corp.)
DRV - (USBAAPL) -- C:\WINDOWS\system32\drivers\usbaapl.sys (Apple, Inc.)
DRV - (atksgt) -- C:\WINDOWS\system32\drivers\atksgt.sys ()
DRV - (lirsgt) -- C:\WINDOWS\system32\drivers\lirsgt.sys ()
DRV - (GEARAspiWDM) -- C:\WINDOWS\system32\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (Avgfwfd) -- C:\WINDOWS\system32\drivers\avgfwdx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgfwdx) -- C:\WINDOWS\system32\drivers\avgfwdx.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX) -- C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgRkx86) -- C:\WINDOWS\System32\Drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Scutum50) -- C:\WINDOWS\system32\drivers\Scutum50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (nv) -- C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (mcdbus) -- C:\WINDOWS\system32\drivers\mcdbus.sys (MagicISO, Inc.)
DRV - (Si3114r5) -- C:\WINDOWS\system32\DRIVERS\Si3114r5.sys (Silicon Image, Inc)
DRV - (SiFilter) -- C:\WINDOWS\system32\DRIVERS\SiWinAcc.sys (Silicon Image, Inc.)
DRV - (SiRemFil) -- C:\WINDOWS\system32\DRIVERS\SiRemFil.sys (Silicon Image, Inc.)
DRV - (sptd) -- C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (ENTECH) -- C:\WINDOWS\system32\drivers\Entech.sys (EnTech Taiwan)
DRV - (nvnetbus) -- C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) -- C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (hap17v2k) -- C:\WINDOWS\system32\drivers\haP17v2k.sys (Creative Technology Ltd)
DRV - (CTERFXFX.SYS) -- C:\WINDOWS\System32\drivers\CTERFXFX.SYS (Creative Technology Ltd)
DRV - (CTERFXFX) -- C:\WINDOWS\system32\drivers\CTERFXFX.sys (Creative Technology Ltd)
DRV - (CTSBLFX.SYS) -- C:\WINDOWS\System32\drivers\CTSBLFX.SYS (Creative Technology Ltd)
DRV - (CTSBLFX) -- C:\WINDOWS\system32\drivers\CTSBLFX.sys (Creative Technology Ltd)
DRV - (CTAUDFX.SYS) -- C:\WINDOWS\System32\drivers\CTAUDFX.SYS (Creative Technology Ltd)
DRV - (CTAUDFX) -- C:\WINDOWS\system32\drivers\CTAUDFX.sys (Creative Technology Ltd)
DRV - (COMMONFX.SYS) -- C:\WINDOWS\System32\drivers\COMMONFX.SYS (Creative Technology Ltd)
DRV - (COMMONFX) -- C:\WINDOWS\system32\drivers\COMMONFX.sys (Creative Technology Ltd)
DRV - (usbaudio) USB Audio Driver (WDM) -- C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (atapi) -- C:\WINDOWS\system32\DRIVERS\atapi.sys ()
DRV - (gameenum) -- C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (Secdrv) -- C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (yukonwxp) -- C:\WINDOWS\system32\drivers\yk51x86.sys (Marvell)
DRV - (AmdPPM) -- C:\WINDOWS\system32\drivers\AmdPPM.sys (Advanced Micro Devices)
DRV - (CT20XUT.DLL) -- C:\WINDOWS\system32\CT20XUT.DLL (Creative Technology Ltd.)
DRV - (CTHWIUT.DLL) -- C:\WINDOWS\system32\CTHWIUT.DLL (Creative Technology Ltd.)
DRV - (CTEXFIFX.DLL) -- C:\WINDOWS\system32\CTEXFIFX.DLL (Creative Technology Ltd.)
DRV - (CTEDSPSY.DLL) -- C:\WINDOWS\system32\CTEDSPSY.DLL (Creative Technology Ltd)
DRV - (CTEDSPIO.DLL) -- C:\WINDOWS\system32\CTEDSPIO.DLL (Creative Technology Ltd)
DRV - (CTEDSPFX.DLL) -- C:\WINDOWS\system32\CTEDSPFX.DLL (Creative Technology Ltd)
DRV - (CTEAPSFX.DLL) -- C:\WINDOWS\system32\CTEAPSFX.DLL (Creative Technology Ltd)
DRV - (VX3000) -- C:\WINDOWS\system32\drivers\VX3000.sys (Microsoft Corporation)
DRV - (HPZius12) -- C:\WINDOWS\system32\drivers\HPZius12.sys (HP)
DRV - (HPZipr12) -- C:\WINDOWS\system32\drivers\HPZipr12.sys (HP)
DRV - (HPZid412) -- C:\WINDOWS\system32\drivers\HPZid412.sys (HP)
DRV - (RimVSerPort) -- C:\WINDOWS\system32\drivers\RimSerial.sys (Research in Motion Ltd)
DRV - (W8335XP) NETGEAR WG311v3 802.11g Wireless PCI Adapter for Windows XP (8335) -- C:\WINDOWS\system32\drivers\WG311v3XP.sys (Marvell Semiconductor, Inc)
DRV - (nvnforce) Service for NVIDIA® nForce -- C:\WINDOWS\system32\drivers\nvapu.sys (NVIDIA Corporation)
DRV - (nvax) Service for NVIDIA® nForce -- C:\WINDOWS\system32\drivers\nvax.sys (NVIDIA Corporation)
DRV - (ctaud2k) Creative Audio Driver (WDM) -- C:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (Ptilink) -- C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (ROOTMODEM) -- C:\WINDOWS\system32\drivers\rootmdm.sys (Microsoft Corporation)
DRV - (a347bus) -- C:\WINDOWS\system32\DRIVERS\a347bus.sys ( )
DRV - (a347scsi) -- C:\WINDOWS\System32\Drivers\a347scsi.sys ( )
DRV - (ha10kx2k) -- C:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (ctac32k) -- C:\WINDOWS\system32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (CTAUDFX.DLL) -- C:\WINDOWS\system32\ctaudfx.dll (Creative Technology Ltd)
DRV - (hap16v2k) -- C:\WINDOWS\system32\drivers\haP16v2k.sys (Creative Technology Ltd)
DRV - (ctdvda2k) -- C:\WINDOWS\system32\drivers\ctdvda2k.sys (Creative Technology Ltd)
DRV - (emupia) -- C:\WINDOWS\system32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k) -- C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) -- C:\WINDOWS\system32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ossrv) -- C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (CTSBLFX.DLL) -- C:\WINDOWS\system32\ctsblfx.dll (Creative Technology Ltd)
DRV - (COMMONFX.DLL) -- C:\WINDOWS\system32\commonfx.dll (Creative Technology Ltd)
DRV - (PfModNT) -- C:\WINDOWS\system32\drivers\pfmodnt.sys (Creative Technology Ltd.)
DRV - (AvgLdx86) -- C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) -- C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (ms_mpu401) -- C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.espn.go.com/IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "AIM Search"
FF - prefs.js..browser.search.defaulturl: "
http://slirsredirect...fftrie7&query="FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "espn.com"
FF - prefs.js..extensions.enabledItems:
[email protected]:4.0.27.0
FF - prefs.js..extensions.enabledItems:
[email protected]:1.11.5
FF - prefs.js..extensions.enabledItems: {74714d77-1695-4e73-a98e-25cb374f46b4}:2.4.0.4
FF - prefs.js..extensions.enabledItems:
[email protected]:1.0
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/12/17 15:44:16 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/12/17 15:44:16 | 00,000,000 | ---D | M]
[2009/05/14 10:11:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Terry D. Zelenitz\Application Data\Mozilla\Extensions
[2009/05/14 10:11:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Terry D. Zelenitz\Application Data\Mozilla\Extensions\
[email protected][2009/12/17 13:58:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Terry D. Zelenitz\Application Data\Mozilla\Firefox\Profiles\tupbhve6.default\extensions
[2009/11/10 11:14:58 | 00,000,000 | ---D | M] (iPhone OS 3 Toolbar) -- C:\Documents and Settings\Terry D. Zelenitz\Application Data\Mozilla\Firefox\Profiles\tupbhve6.default\extensions\{74714d77-1695-4e73-a98e-25cb374f46b4}
[2009/11/06 18:55:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Terry D. Zelenitz\Application Data\Mozilla\Firefox\Profiles\tupbhve6.default\extensions\
[email protected][2009/10/30 09:55:19 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Terry D. Zelenitz\Application Data\Mozilla\Firefox\Profiles\tupbhve6.default\extensions\
[email protected][2009/10/30 09:55:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Terry D. Zelenitz\Application Data\Mozilla\Firefox\Profiles\tupbhve6.default\extensions\
[email protected][2009/12/17 13:58:44 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2007/04/16 12:07:12 | 00,180,293 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
O1 HOSTS File: (616485 bytes) - C:\WINDOWS\system32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 ad.a8.net
O1 - Hosts: 127.0.0.1 asy.a8ww.net
O1 - Hosts: 127.0.0.1 a9rhiwa.cn #[Google.Warning]
O1 - Hosts: 127.0.0.1 www.a9rhiwa.cn
O1 - Hosts: 127.0.0.1 acezip.net #[SiteAdvisor.acezip.net]
O1 - Hosts: 127.0.0.1 www.acezip.net #[Win32/Adware.180Solutions]
O1 - Hosts: 127.0.0.1 phpadsnew.abac.com
O1 - Hosts: 127.0.0.1 a.abnad.net
O1 - Hosts: 127.0.0.1 b.abnad.net
O1 - Hosts: 127.0.0.1 c.abnad.net #[eTrust.Tracking.Cookie]
O1 - Hosts: 127.0.0.1 d.abnad.net
O1 - Hosts: 127.0.0.1 e.abnad.net
O1 - Hosts: 127.0.0.1 t.abnad.net
O1 - Hosts: 127.0.0.1 z.abnad.net
O1 - Hosts: 127.0.0.1 banners.absolpublisher.com
O1 - Hosts: 127.0.0.1 tracking.absolstats.com
O1 - Hosts: 127.0.0.1 adv.abv.bg
O1 - Hosts: 127.0.0.1 bimg.abv.bg
O1 - Hosts: 127.0.0.1 www2.a-counter.kiev.ua
O1 - Hosts: 127.0.0.1 track.acclaimnetwork.com
O1 - Hosts: 127.0.0.1 accuserveadsystem.com
O1 - Hosts: 127.0.0.1 www.accuserveadsystem.com
O1 - Hosts: 127.0.0.1 gtb5.acecounter.com
O1 - Hosts: 127.0.0.1 gtcc1.acecounter.com
O1 - Hosts: 16263 more lines...
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (HP Print Clips) - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll (Hewlett-Packard Co.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [CTDVDDET] C:\Program Files\Creative\DVDAudio\CTDVDDET.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [CTHelper] C:\WINDOWS\System32\CtHelper.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [CTxfiHlp] C:\WINDOWS\System32\Ctxfihlp.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [winupdate86.exe] C:\WINDOWS\system32\winupdate86.exe ()
O4 - HKCU..\Run: [SetDefaultMIDI] C:\WINDOWS\System32\MIDIDEF.EXE (Creative Technology Ltd)
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\NPSWF32_FlashUtil.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Rosewill Wireless Utility.lnk = C:\Program Files\Rosewill\Common\RaUI.exe (Rosewill Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Terry D. Zelenitz\Start Menu\Programs\Startup\DesktopVideoPlayer.LNK = C:\Program Files\vghd\vghd.exe File not found
O4 - Startup: C:\Documents and Settings\Terry D. Zelenitz\Start Menu\Programs\Startup\LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe (Lime Wire, LLC)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetActiveDesktop = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 302 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.micros...b?1232033200921 (WUWebControl Class)
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884}
http://www.creative....101/CTSUEng.cab (Creative Software AutoUpdate)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.micros...b?1232033190984 (MUWebControl Class)
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48}
http://chat.yahoo.com/cab/yuplapp.cab (Yahoo! Webcam Upload Wrapper)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29}
http://www.creative....15106/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\winlogon86.exe) - C:\WINDOWS\system32\winlogon86.exe ()
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/11/14 19:29:56 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2009/08/27 08:56:38 | 01,702,136 | R--- | M] () - I:\AutoRun.exe -- [ UDF ]
O32 - AutoRun File - [2009/08/12 03:12:43 | 00,000,063 | R--- | M] () - I:\autorun.inf -- [ UDF ]
O33 - MountPoints2\{28efd2fe-b2ad-11dd-8410-9854771729d0}\Shell\AutoRun\command - "" = H:\d1vmq.exe -- File not found
O33 - MountPoints2\{28efd2fe-b2ad-11dd-8410-9854771729d0}\Shell\open\Command - "" = H:\d1vmq.exe -- File not found
O33 - MountPoints2\{d3d45f20-b38b-11dd-8421-0013d48a62cc}\Shell\AutoRun\command - "" = K:\d1vmq.exe -- File not found
O33 - MountPoints2\{d3d45f20-b38b-11dd-8421-0013d48a62cc}\Shell\open\Command - "" = K:\d1vmq.exe -- File not found
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\LaunchU3.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2009/03/11 23:27:08 | 00,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16891947461378048)
========== Files/Folders - Created Within 30 Days ========== [2009/12/18 13:31:21 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Terry D. Zelenitz\Desktop\SmitfraudFix
[2009/12/18 13:05:49 | 00,000,000 | ---D | C] -- C:\Qoobox
[2009/12/18 13:05:29 | 00,000,000 | ---D | C] -- C:\32788R22FWJFW
[2009/12/04 12:04:35 | 00,757,852 | ---- | C] (Ralink Technology, Corp.) -- C:\WINDOWS\System32\Scutum.dll
[2009/12/04 12:04:35 | 00,200,704 | ---- | C] (The OpenSSL Project,
http://www.openssl.org/) -- C:\WINDOWS\System32\ssleay32.dll
[2009/12/04 12:04:35 | 00,180,224 | ---- | C] (Printing Communications Assoc., Inc. (PCAUSA)) -- C:\WINDOWS\System32\W32N55.dll
[2009/12/04 12:04:35 | 00,143,459 | ---- | C] (Ralink Tech) -- C:\WINDOWS\System32\RalinkGina.dll
[2009/12/04 12:04:34 | 01,085,440 | ---- | C] (The OpenSSL Project,
http://www.openssl.org/) -- C:\WINDOWS\System32\libeay32.dll
[2009/12/04 12:04:34 | 00,019,072 | ---- | C] (Printing Communications Assoc., Inc. (PCAUSA)) -- C:\WINDOWS\System32\drivers\Scutum50.sys
[2009/12/04 12:04:16 | 01,069,824 | ---- | C] (Ralink Technology, Corp.) -- C:\WINDOWS\System32\drivers\rt2860.sys
[2009/12/04 12:04:16 | 00,221,184 | ---- | C] (Ralink Technology, Inc.) -- C:\WINDOWS\System32\RaCoInst.dll
[2009/12/04 12:04:01 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Rosewill Driver
[2009/12/04 12:04:01 | 00,000,000 | ---D | C] -- C:\Program Files\Rosewill
[2009/12/04 12:03:31 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Terry D. Zelenitz\Application Data\InstallShield
[2009/12/04 11:58:59 | 00,015,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuapi.dll.mui
[2009/11/01 14:11:58 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2009/10/28 08:24:41 | 00,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2009/08/14 13:17:46 | 00,065,536 | ---- | C] ( ) -- C:\WINDOWS\System32\a3d.dll
[2009/07/23 02:39:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2009/07/18 01:56:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2009/07/18 01:56:25 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2009/03/13 00:36:47 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Roxio
[2009/01/13 15:48:31 | 00,090,112 | R--- | C] ( ) -- C:\WINDOWS\System32\SCCD3X02.DLL
[2008/11/20 21:03:00 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2008/11/15 21:02:07 | 00,160,640 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\a347bus.sys
[2008/11/15 21:02:07 | 00,005,248 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\a347scsi.sys
[2008/11/14 19:29:48 | 00,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[8 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2009/12/18 13:32:52 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\1869.exe
[2009/12/18 13:31:51 | 09,699,328 | ---- | M] () -- C:\Documents and Settings\Terry D. Zelenitz\NTUSER.DAT
[2009/12/18 13:30:59 | 01,872,472 | ---- | M] () -- C:\Documents and Settings\Terry D. Zelenitz\Desktop\SmitfraudFix.exe
[2009/12/18 13:12:34 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\11538.exe
[2009/12/18 13:04:54 | 00,025,088 | ---- | M] () -- C:\Documents and Settings\Terry D. Zelenitz\Desktop\Terry_resume_2009.doc
[2009/12/18 13:03:59 | 03,857,212 | ---- | M] () -- C:\Documents and Settings\Terry D. Zelenitz\Desktop\KittyFix.exe
[2009/12/18 12:52:34 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\14771.exe
[2009/12/18 12:32:34 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\21726.exe
[2009/12/18 12:12:34 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\5447.exe
[2009/12/18 11:52:34 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\19895.exe
[2009/12/18 02:54:43 | 00,029,544 | ---- | M] () -- C:\WINDOWS\System32\BMXStateBkp-{00000005-00000000-00000008-00001102-00000004-20021102}.rfx
[2009/12/18 02:54:43 | 00,029,544 | ---- | M] () -- C:\WINDOWS\System32\BMXState-{00000005-00000000-00000008-00001102-00000004-20021102}.rfx
[2009/12/18 02:54:43 | 00,026,424 | ---- | M] () -- C:\WINDOWS\System32\BMXCtrlState-{00000005-00000000-00000008-00001102-00000004-20021102}.rfx
[2009/12/18 02:54:43 | 00,026,424 | ---- | M] () -- C:\WINDOWS\System32\BMXBkpCtrlState-{00000005-00000000-00000008-00001102-00000004-20021102}.rfx
[2009/12/18 02:54:43 | 00,001,080 | ---- | M] () -- C:\WINDOWS\System32\settingsbkup.sfm
[2009/12/18 02:54:43 | 00,001,080 | ---- | M] () -- C:\WINDOWS\System32\settings.sfm
[2009/12/18 02:54:43 | 00,000,384 | ---- | M] () -- C:\WINDOWS\System32\DVCStateBkp-{00000005-00000000-00000008-00001102-00000004-20021102}.dat
[2009/12/18 02:54:43 | 00,000,384 | ---- | M] () -- C:\WINDOWS\System32\DVCState-{00000005-00000000-00000008-00001102-00000004-20021102}.dat
[2009/12/18 02:43:32 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\19718.exe
[2009/12/17 22:13:45 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\18716.exe
[2009/12/17 21:53:45 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\17421.exe
[2009/12/17 21:33:45 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\12382.exe
[2009/12/17 21:13:45 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\292.exe
[2009/12/17 20:53:45 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\153.exe
[2009/12/17 20:33:45 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\3902.exe
[2009/12/17 20:13:45 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\14604.exe
[2009/12/17 19:53:45 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\32391.exe
[2009/12/17 19:33:45 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\5436.exe
[2009/12/17 19:13:45 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\4827.exe
[2009/12/17 16:53:05 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\11942.exe
[2009/12/17 15:43:09 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\2995.exe
[2009/12/17 15:23:09 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\491.exe
[2009/12/17 15:03:09 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\9961.exe
[2009/12/17 14:43:09 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\16827.exe
[2009/12/17 14:23:09 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\23281.exe
[2009/12/17 14:17:00 | 00,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2009/12/17 14:03:09 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\28145.exe
[2009/12/17 13:43:09 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\5705.exe
[2009/12/17 13:23:09 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\24464.exe
[2009/12/17 13:03:09 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\26962.exe
[2009/12/17 12:43:09 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\29358.exe
[2009/12/17 10:40:19 | 00,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2009/12/17 10:22:53 | 00,018,944 | ---- | M] () -- C:\WINDOWS\System32\winupdate86.exe
[2009/12/17 10:22:53 | 00,018,944 | ---- | M] () -- C:\WINDOWS\System32\winlogon86.exe
[2009/12/11 12:55:12 | 00,011,237 | ---- | M] () -- C:\Documents and Settings\Terry D. Zelenitz\My Documents\Metabolic Syndrome Summary.docx
[2009/12/11 11:50:27 | 00,012,847 | ---- | M] () -- C:\Documents and Settings\Terry D. Zelenitz\My Documents\Reflection Paper 1.docx
[2009/12/05 21:58:47 | 00,000,178 | -HS- | M] () -- C:\Documents and Settings\Terry D. Zelenitz\ntuser.ini
[2009/12/04 12:05:28 | 00,555,168 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/12/04 12:05:28 | 00,465,072 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/12/04 12:05:28 | 00,078,958 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/12/04 12:04:32 | 00,001,641 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Rosewill Wireless Utility.lnk
[2009/12/03 16:14:06 | 00,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/12/03 16:13:56 | 00,019,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/12/03 12:14:32 | 00,021,293 | ---- | M] () -- C:\Documents and Settings\Terry D. Zelenitz\Desktop\Economics.docx
[2009/11/24 01:10:22 | 00,193,024 | ---- | M] () -- C:\Documents and Settings\Terry D. Zelenitz\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[8 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ========== [2009/12/18 13:32:52 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\1869.exe
[2009/12/18 13:30:38 | 01,872,472 | ---- | C] () -- C:\Documents and Settings\Terry D. Zelenitz\Desktop\SmitfraudFix.exe
[2009/12/18 13:12:34 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\11538.exe
[2009/12/18 13:03:41 | 03,857,212 | ---- | C] () -- C:\Documents and Settings\Terry D. Zelenitz\Desktop\KittyFix.exe
[2009/12/18 12:52:34 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\14771.exe
[2009/12/18 12:32:34 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\21726.exe
[2009/12/18 12:12:34 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\5447.exe
[2009/12/18 11:52:34 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\19895.exe
[2009/12/18 02:43:32 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\19718.exe
[2009/12/17 22:13:45 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\18716.exe
[2009/12/17 21:53:45 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\17421.exe
[2009/12/17 21:33:45 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\12382.exe
[2009/12/17 21:13:45 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\292.exe
[2009/12/17 20:53:45 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\153.exe
[2009/12/17 20:33:45 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\3902.exe
[2009/12/17 20:13:45 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\14604.exe
[2009/12/17 19:53:45 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\32391.exe
[2009/12/17 19:33:45 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\5436.exe
[2009/12/17 19:13:45 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\4827.exe
[2009/12/17 16:53:05 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\11942.exe
[2009/12/17 15:43:09 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\2995.exe
[2009/12/17 15:23:09 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\491.exe
[2009/12/17 15:03:09 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\9961.exe
[2009/12/17 14:43:09 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\16827.exe
[2009/12/17 14:23:09 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\23281.exe
[2009/12/17 14:03:09 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\28145.exe
[2009/12/17 13:43:09 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\5705.exe
[2009/12/17 13:23:09 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\24464.exe
[2009/12/17 13:03:09 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\26962.exe
[2009/12/17 12:43:09 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\29358.exe
[2009/12/17 12:23:09 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\11478.exe
[2009/12/17 12:03:09 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\15724.exe
[2009/12/17 11:43:09 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\19169.exe
[2009/12/17 11:23:09 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\26500.exe
[2009/12/17 11:03:09 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\6334.exe
[2009/12/17 10:43:09 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\18467.exe
[2009/12/17 10:23:09 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\AVR10.exe
[2009/12/17 10:23:09 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\41.exe
[2009/12/17 10:23:08 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\winhelper86.dll
[2009/12/17 10:22:57 | 00,002,854 | ---- | C] () -- C:\WINDOWS\System32\critical_warning.html
[2009/12/17 10:22:56 | 00,018,944 | ---- | C] () -- C:\WINDOWS\System32\winupdate86.exe
[2009/12/17 10:22:56 | 00,018,944 | ---- | C] () -- C:\WINDOWS\System32\winlogon86.exe
[2009/12/13 13:10:24 | 00,025,088 | ---- | C] () -- C:\Documents and Settings\Terry D. Zelenitz\Desktop\Terry_resume_2009.doc
[2009/12/11 12:55:12 | 00,011,237 | ---- | C] () -- C:\Documents and Settings\Terry D. Zelenitz\My Documents\Metabolic Syndrome Summary.docx
[2009/12/11 11:50:27 | 00,012,847 | ---- | C] () -- C:\Documents and Settings\Terry D. Zelenitz\My Documents\Reflection Paper 1.docx
[2009/12/04 12:04:35 | 00,001,191 | ---- | C] () -- C:\WINDOWS\System32\W32N55.INI
[2009/12/04 12:04:35 | 00,000,480 | ---- | C] () -- C:\WINDOWS\System32\DiagFunc.ini
[2009/12/04 12:04:34 | 00,147,456 | ---- | C] () -- C:\WINDOWS\System32\DiagFunc.dll
[2009/12/04 12:04:32 | 00,001,641 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Rosewill Wireless Utility.lnk
[2009/12/04 12:04:01 | 00,013,931 | ---- | C] () -- C:\WINDOWS\System32\RaCoInst.dat
[2009/12/03 11:35:30 | 00,021,293 | ---- | C] () -- C:\Documents and Settings\Terry D. Zelenitz\Desktop\Economics.docx
[2009/09/26 00:53:58 | 00,165,320 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2009/08/07 18:51:34 | 00,178,430 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat
[2009/03/16 09:27:13 | 00,000,262 | ---- | C] () -- C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2009/01/26 22:46:27 | 00,002,215 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2009/01/22 23:04:05 | 00,000,273 | ---- | C] () -- C:\WINDOWS\game.ini
[2009/01/15 23:40:56 | 00,003,972 | ---- | C] () -- C:\WINDOWS\System32\drivers\PciBus.sys
[2009/01/15 14:26:38 | 00,138,808 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009/01/15 14:26:38 | 00,022,328 | ---- | C] () -- C:\Documents and Settings\Terry D. Zelenitz\Application Data\PnkBstrK.sys
[2009/01/13 15:48:27 | 00,131,072 | R--- | C] () -- C:\WINDOWS\System32\SCCD3X01.DLL
[2009/01/01 18:45:10 | 00,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2008/12/01 04:17:18 | 00,281,760 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys
[2008/12/01 04:17:17 | 00,025,888 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys
[2008/11/21 22:46:37 | 00,015,498 | R--- | C] () -- C:\WINDOWS\VX3000.ini
[2008/11/21 20:09:52 | 00,000,185 | ---- | C] () -- C:\WINDOWS\mdm.ini
[2008/11/21 20:09:46 | 00,000,288 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008/11/15 15:21:36 | 00,685,816 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2008/11/15 04:11:20 | 00,043,516 | ---- | C] () -- C:\WINDOWS\System32\e10kxwdm.ini
[2008/11/15 04:11:18 | 00,005,515 | ---- | C] () -- C:\WINDOWS\System32\ENSDEF.INI
[2008/11/15 04:09:03 | 00,765,952 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2008/11/15 04:09:03 | 00,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2008/11/14 23:48:08 | 00,000,118 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2008/11/14 19:35:19 | 00,193,024 | ---- | C] () -- C:\Documents and Settings\Terry D. Zelenitz\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/10/07 09:13:22 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2008/10/07 09:13:20 | 00,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2008/07/25 23:48:00 | 01,724,416 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2008/07/25 23:48:00 | 01,503,232 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2008/07/25 23:48:00 | 01,101,824 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2008/07/25 23:48:00 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2008/07/25 23:48:00 | 00,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2008/06/27 18:05:08 | 00,049,565 | ---- | C] () -- C:\WINDOWS\System32\instwdm.ini
[2008/06/27 18:05:06 | 00,000,175 | ---- | C] () -- C:\WINDOWS\System32\ctzapxx.ini
[2008/06/27 17:27:54 | 00,043,520 | ---- | C] () -- C:\WINDOWS\System32\CTBurst.dll
[2008/06/05 08:58:26 | 00,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll
[2007/09/27 09:51:02 | 00,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 09:48:48 | 00,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 09:48:28 | 00,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2007/08/13 20:45:02 | 00,077,824 | ---- | C] () -- C:\WINDOWS\System32\ctmmactl.dll
[2007/04/12 08:10:28 | 00,105,728 | ---- | C] () -- C:\WINDOWS\System32\APOMgrH.dll
[2006/10/02 17:25:18 | 00,000,307 | ---- | C] () -- C:\WINDOWS\System32\kill.ini
[2004/08/04 07:00:00 | 00,096,512 | ---- | C] () -- C:\WINDOWS\System32\drivers\atapi.sys
[2001/08/23 14:00:00 | 00,022,400 | ---- | C] () -- C:\WINDOWS\System32\drivers\SbcpHid.sys
[1998/06/10 00:00:00 | 00,015,120 | ---- | C] () -- C:\WINDOWS\System32\REPUTIL.DLL
[1998/05/18 00:00:00 | 00,014,017 | ---- | C] () -- C:\WINDOWS\JAUTOEXP.INI
[1998/04/24 00:00:00 | 00,000,218 | ---- | C] () -- C:\WINDOWS\FRONTPG.INI
========== LOP Check ========== [2009/11/04 11:24:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BioWare
[2008/11/15 15:33:18 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
[2008/11/17 13:47:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Fallout3
[2009/12/04 12:04:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Rosewill Driver
[2009/07/12 23:59:59 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Tages
[2008/11/21 15:09:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ubisoft
[2009/04/30 23:19:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/10/07 22:18:20 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/05/21 00:12:52 | 00,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2008/11/15 15:37:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Terry D. Zelenitz\Application Data\.BitTornado
[2008/11/15 15:32:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Terry D. Zelenitz\Application Data\DAEMON Tools Pro
[2009/07/18 01:26:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Terry D. Zelenitz\Application Data\GetRightToGo
[2008/11/28 17:48:17 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Terry D. Zelenitz\Application Data\HTSK
[2003/01/01 00:07:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Terry D. Zelenitz\Application Data\LimeWire
[2008/11/16 16:11:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Terry D. Zelenitz\Application Data\OpenOffice.org
[2009/06/23 10:19:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Terry D. Zelenitz\Application Data\Opera
[2008/11/30 13:32:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Terry D. Zelenitz\Application Data\Red Alert 3
[2009/03/13 18:03:14 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Terry D. Zelenitz\Application Data\The Creative Assembly
[2009/10/27 23:39:35 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Terry D. Zelenitz\Application Data\Tropico 3
[2009/07/13 00:01:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Terry D. Zelenitz\Application Data\Ubisoft
[2009/08/04 00:41:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Terry D. Zelenitz\Application Data\vghd
[2009/10/28 08:21:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Terry D. Zelenitz\Application Data\Windows Desktop Search
========== Purity Check ========== ========== Custom Scans ========== < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs > < %SYSTEMDRIVE%\*.exe > < MD5 for: AGP440.SYS >[2008/04/13 13:36:38 | 00,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 13:36:38 | 00,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
< MD5 for: ATAPI.SYS >[2008/04/13 13:40:30 | 00,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2004/08/04 07:00:00 | 00,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2008/04/13 13:40:30 | 00,096,512 | ---- | M] ()
Unable to obtain MD5 -- C:\WINDOWS\system32\drivers\atapi.sys
< MD5 for: EVENTLOG.DLL >[2008/04/13 19:11:53 | 00,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 19:11:53 | 00,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll
[2004/08/04 07:00:00 | 00,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: NETLOGON.DLL >[2008/04/13 19:12:01 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 19:12:01 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll
[2004/08/04 07:00:00 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: NVATA.SYS >[2006/04/24 17:52:28 | 00,100,736 | ---- | M] (NVIDIA Corporation) MD5=C03E15101F6D9E82CD9B0E7D715F5DE3 -- C:\NVIDIA\nForceWin2KXP\6.86\IDE\Win2K\sata_ide\nvata.sys
[2006/04/24 17:52:28 | 00,100,736 | ---- | M] (NVIDIA Corporation) MD5=C03E15101F6D9E82CD9B0E7D715F5DE3 -- C:\NVIDIA\nForceWin2KXP\6.86\IDE\WinXP\sata_ide\nvata.sys
< MD5 for: NVATABUS.SYS >[2006/04/24 17:52:28 | 00,100,736 | ---- | M] (NVIDIA Corporation) MD5=C03E15101F6D9E82CD9B0E7D715F5DE3 -- C:\NVIDIA\nForceWin2KXP\6.86\IDE\Win2K\legacy\nvatabus.sys
[2006/04/24 17:52:28 | 00,100,736 | ---- | M] (NVIDIA Corporation) MD5=C03E15101F6D9E82CD9B0E7D715F5DE3 -- C:\NVIDIA\nForceWin2KXP\6.86\IDE\Win2K\sataraid\nvatabus.sys
[2006/04/24 17:52:28 | 00,100,736 | ---- | M] (NVIDIA Corporation) MD5=C03E15101F6D9E82CD9B0E7D715F5DE3 -- C:\NVIDIA\nForceWin2KXP\6.86\IDE\WinXP\legacy\nvatabus.sys
[2006/04/24 17:52:28 | 00,100,736 | ---- | M] (NVIDIA Corporation) MD5=C03E15101F6D9E82CD9B0E7D715F5DE3 -- C:\NVIDIA\nForceWin2KXP\6.86\IDE\WinXP\sataraid\nvatabus.sys
< MD5 for: SCECLI.DLL >[2004/08/04 07:00:00 | 00,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 19:12:05 | 00,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 19:12:05 | 00,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll
< End of report >