OT View IT
OTViewIt logfile created on: 2008-08-30 17:19:07 - Run 1
OTViewIt by OldTimer - Version 1.0.1.7 Folder = C:\Documents and Settings\michele\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: yyyy-MM-dd
511.48 Mb Total Physical Memory | 342.65 Mb Available Physical Memory | 66.99% Memory free
1.22 Gb Paging File | 1.08 Gb Available in Paging File | 88.27% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 64.85 Gb Free Space | 87.02% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: MICHELE
Current User Name: michele
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Whitelist: On
===== Processes - Non-Microsoft Only =====
[06-25-2004 02:05 PM | 00,045,056 | ---- | M] () - C:\WINDOWS\system32\WLTRYSVC.EXE
[08-23-2001 05:52 PM | 00,331,830 | ---- | M] (Microsoft® Corporation) - C:\Program Files\Microsoft Works\wkssb.exe
[08-17-2001 12:41 AM | 00,028,738 | ---- | M] (Microsoft® Corporation) - C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
[09-12-2002 01:13 PM | 01,101,824 | ---- | M] (Copyright (C) ahead software gmbh and its licensors) - C:\Program Files\Ahead\InCD\InCD.exe
[07-20-2005 12:19 PM | 00,385,024 | ---- | M] (Motive Communications, Inc.) - C:\Program Files\Verizon Online\SmartBridge\MotiveSB.exe
[08-07-2001 07:06 PM | 00,024,633 | ---- | M] (Microsoft® Corporation) - C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
[08-09-2002 06:00 PM | 00,221,184 | ---- | M] (Motive Communications, Inc.) - C:\Program Files\Verizon Online\bin\mpbtn.exe
===== Win32 Services - Non-Microsoft Only =====
(Autocomplete) AutoComplete Service [On_Demand | Stopped]
File not found - C:\PROGRA~1\SYSTEM~1\autocomp.exe
(WLTRYSVC) WLTRYSVC [Auto | Running]
[06-25-2004 02:05 PM | 00,045,056 | ---- | M] () - C:\WINDOWS\system32\WLTRYSVC.EXE
===== Driver Services - Non-Microsoft Only =====
(BsStor) InCD Storage Helper Driver [Boot | Running]
[06-05-2002 07:07 PM | 00,009,344 | ---- | M] (B.H.A Co.,Ltd.) - C:\WINDOWS\system32\drivers\bsstor.sys
(BsUDF) InCD UDF Driver [Auto | Running]
[09-13-2002 08:35 AM | 00,448,640 | ---- | M] (ahead software) - C:\WINDOWS\System32\drivers\bsudf.sys
(catchme) catchme [On_Demand | Stopped]
File not found - C:\ComboFix\catchme.sys
(GMSIPCI) GMSIPCI [On_Demand | Stopped]
File not found - E:\INSTALL\GMSIPCI.SYS
(rtl8139) Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver [On_Demand | Stopped]
[08-04-2004 01:31 AM | 00,020,992 | ---- | M] (Realtek Semiconductor Corporation) - C:\WINDOWS\system32\drivers\RTL8139.sys
(USBNET_XP) Instant Wireless XP USB Network Adapter ver.2.6 Driver [On_Demand | Stopped]
[02-19-2002 02:34 PM | 00,072,576 | R--- | M] (The LinkSys Group, Inc.) - C:\WINDOWS\system32\drivers\netusbxp.sys
========== Run Keys ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"InCD" = C:\Program Files\Ahead\InCD\InCD.exe [09-12-2002 01:13 PM | 01,101,824 | ---- | M] (Copyright (C) ahead software gmbh and its licensors)
"Microsoft Works Portfolio" = C:\Program Files\Microsoft Works\WksSb.exe /AllUsers [08-23-2001 05:52 PM | 00,331,830 | ---- | M] (Microsoft® Corporation)
"Microsoft Works Update Detection" = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe [08-17-2001 12:41 AM | 00,028,738 | ---- | M] (Microsoft® Corporation)
"Motive SmartBridge" = C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe [07-20-2005 12:19 PM | 00,385,024 | ---- | M] (Motive Communications, Inc.)
"NeroCheck" = C:\WINDOWS\system32\NeroCheck.exe [07-09-2001 04:50 AM | 00,155,648 | ---- | M] (Ahead Software Gmbh)
"NvCplDaemon" = RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup [03-20-2003 08:13 AM | 04,616,192 | ---- | M] (NVIDIA Corporation)
"vptray" = C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe [05-21-2003 02:21 AM | 00,090,112 | ---- | M] (Symantec Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" = Reg Error: Key does not exist or could not be opened.
"run" = Reg Error: Key does not exist or could not be opened.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AIM" = C:\Program Files\AIM\aim.exe -cnetwait.odl File not found
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" = Reg Error: Value load does not exist or could not be read.
"run" = Reg Error: Value run does not exist or could not be read.
========== Startup Folders ==========
[All Users Startup Folder - C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
[04-23-2008 03:38 AM | 00,029,696 | ---- | M] (Adobe Systems Incorporated) - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
[01-27-1998 02:10 AM | 00,055,296 | ---- | M] (Micrografx, Inc.) - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\CreataCard Gold 2 Forget Me Not Reminders.lnk = C:\Program Files\CreataCard\Gold\fmrmd32.exe
[08-07-2001 07:06 PM | 00,024,633 | ---- | M] (Microsoft® Corporation) - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
[08-06-2002 11:07 AM | 00,204,800 | ---- | M] (Motive Communications, Inc.) - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\bin\matcli.exe
[michele Startup Folder - C:\Documents and Settings\michele\Start Menu\Programs\Startup]
========== BHO's ==========
========== Toolbars ==========
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
HKLM CLSID: (Reg Error: Key does not exist or could not be opened.) - File not found Reg Error: Key does not exist or could not be opened.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}"
HKLM CLSID: (Yahoo! Toolbar) - File not found Reg Error: Key does not exist or could not be opened.
========== AppInit_Dlls ==========
========== HKLM Security Providers ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders]
"msapsspc.dllschannel.dlldigest.dllmsnsspc.dll" - File not found
========== HKLM Winlogon Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell]
"Explorer.exe" - [06-13-2007 06:23 AM | 01,033,216 | ---- | M] (Microsoft Corporation) C:\WINDOWS\explorer.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit]
"C:\WINDOWS\system32\userinit.exe" - [08-04-2004 03:56 AM | 00,024,576 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\userinit.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UIHost]
"logonui.exe" - [08-04-2004 03:56 AM | 00,514,560 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\logonui.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet]
"rundll32 shell32" - [10-25-2007 11:34 PM | 08,460,288 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
"Control_RunDLL "sysdm.cpl"" - [08-04-2004 03:56 AM | 00,298,496 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\sysdm.cpl
========== User's Winlogon Settings ==========
========== Winlogon Notify Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
"DllName" = C:\WINDOWS\system32\NavLogon.dll [05-21-2003 02:19 AM | 00,045,056 | ---- | M] ()
========== Policies ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveAutoRun" = 67108863
"NoDriveTypeAutoRun" = 255
"NoDrives" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"dontdisplaylastusername" = 0
"legalnoticecaption" =
"legalnoticetext" =
"shutdownwithoutlogon" = 1
"undockwithoutlogon" = 1
"DisableRegistryTools" = 0
"HideLegacyLogonScripts" = 0
"HideLogoffScripts" = 0
"RunLogonScriptSync" = 1
"RunStartupScriptSync" = 0
"HideStartupScripts" = 0
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun" = 145
"NoDrives" = 0
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"HideLegacyLogonScripts" = 0
"HideLogoffScripts" = 0
"RunLogonScriptSync" = 1
"RunStartupScriptSync" = 0
"HideStartupScripts" = 0
========== Lsa Authentication Packages ==========
========== Lsa Security Packages ==========
========== Desktop Components ==========
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"FriendlyName" = "My Current Home Page"
"Source" = "About:Home"
"SubscribedURL" = "About:Home"
========== Safeboot Options ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot]
"AlternateShell" = cmd.exe
========== Disabled MsConfig Items ==========
Unable to open key or key not present!
========== CDRom AutoRun Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1
========== Autorun Files on Drives ==========
AUTOEXEC.BAT []
[07-11-2003 01:27 AM | 00,000,000 | ---- | M] () C:\AUTOEXEC.BAT [ NTFS ]
========== MountPoints2 ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{06eb2976-d4b1-11d7-93b9-000c410c8bb4}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{200abfe4-c03a-11da-945e-000e2e216509}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{32754293-d6d6-11d9-9428-000e2e216509}\Shell]
"" = Open
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4131139c-2877-11dd-94bf-000e2e216509}\Shell]
"" = Open
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{565e4c3a-79b4-11db-947a-000f661bb2bb}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{565e4c46-79b4-11db-947a-000f661bb2bb}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6007a5f8-5b4a-11dc-94a1-000e2e216509}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{936fda1e-6cd0-11d9-9411-000f661bb2bb}\Shell]
"" = Open
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9d356454-8aeb-11db-947b-000e2e216509}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b8a45af1-9592-11dc-94a6-000e2e216509}\Shell]
"" = AutoRun
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b8a45af2-9592-11dc-94a6-000e2e216509}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d1c6be90-b839-11d9-941d-000f661bb2bb}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{efd0c32a-b37e-11d7-93a8-b0c80decdf80}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F\Shell]
"" = AutoRun
========== DNS Name Servers ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{7C48A721-0A35-4753-BE40-E80EBE593471}]
Servers: | Description: Instant Wireless USB Network Adapter ver.2.6
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{836D4178-AA3D-4AEA-8210-609376CBBB7A}]
Servers: | Description: Linksys LNE100TX Fast Ethernet Adapter(LNE100TX v4)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{A6A5C012-00A3-4209-A6B7-1E6CA2BA5C11}]
Servers: | Description: Linksys Wireless-G PCI Adapter with SpeedBooster
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{AB0DBDA3-DFDA-495C-A2E7-A88BC5504E89}]
Servers: | Description: Realtek RTL8139 Family PCI Fast Ethernet NIC
========== Hosts File ==========
HOSTS File = (686 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
First 25 entries...
127.0.0.1 localhost
========== Files/Folders - Created Within 30 days ==========
[1 C:\*.tmp files]
[08-28-2008 03:04 AM | 01,417,602 | ---- | C] () - C:\SDFix.exe
[08-28-2008 03:07 AM | ---D | C] - C:\SDFix
[08-30-2008 04:26 PM | ---D | C] - C:\ComboFix
[08-30-2008 04:26 PM | ---D | C] - C:\QooBox
[08-30-2008 05:09 PM | ---D | C] - C:\Avenger
[2 C:\WINDOWS\System32\*.tmp files]
[08-01-2008 05:29 PM | ---D | C] - C:\WINDOWS\System32\CatRoot_bak
[08-13-2008 01:02 AM | 00,588,800 | ---- | C] () - C:\WINDOWS\System32\Psetup.exe
[08-16-2008 03:04 AM | 00,000,206 | ---- | C] () - C:\WINDOWS\System32\MRT.INI
[08-17-2008 01:08 PM | ---D | C] - C:\WINDOWS\System32\inf
[08-20-2008 11:23 PM | 00,125,804 | ---- | C] () - C:\WINDOWS\System32\newcool.exe
[08-23-2008 04:51 PM | ---D | C] - C:\WINDOWS\System32\1024
[08-24-2008 02:35 PM | 00,029,764 | ---- | C] () - C:\WINDOWS\System32\mf0824.exe
[08-28-2008 02:17 PM | 00,062,464 | ---- | C] () - C:\WINDOWS\System32\dwbins.exe
[3 C:\WINDOWS\*.tmp files]
[08-25-2008 11:13 AM | 00,001,409 | ---- | C] () - C:\WINDOWS\QTFont.for
[08-25-2008 11:13 AM | 00,054,156 | -H-- | C] () - C:\WINDOWS\QTFont.qfn
[08-28-2008 03:11 AM | ---D | C] - C:\WINDOWS\ERUNT
[08-29-2008 05:57 AM | 00,002,560 | ---- | C] () - C:\WINDOWS\_MSRSTRT.EXE
[08-30-2008 04:26 PM | 00,028,672 | ---- | C] (NirSoft) - C:\WINDOWS\Nircmd.exe
[08-30-2008 04:26 PM | 00,049,152 | ---- | C] () - C:\WINDOWS\VFind.exe
[08-30-2008 04:26 PM | 00,068,096 | ---- | C] () - C:\WINDOWS\zip.exe
[08-30-2008 04:26 PM | 00,080,412 | ---- | C] () - C:\WINDOWS\grep.exe
[08-30-2008 04:26 PM | 00,089,504 | ---- | C] (Smallfrogs Studio) - C:\WINDOWS\fdsv.exe
[08-30-2008 04:26 PM | 00,098,816 | ---- | C] () - C:\WINDOWS\sed.exe
[08-30-2008 04:26 PM | 00,136,704 | ---- | C] (SteelWerX) - C:\WINDOWS\swsc.exe
[08-30-2008 04:26 PM | 00,161,792 | ---- | C] (SteelWerX) - C:\WINDOWS\swreg.exe
[08-30-2008 04:26 PM | 00,212,480 | ---- | C] (SteelWerX) - C:\WINDOWS\swxcacls.exe
[08-30-2008 04:26 PM | ---D | C] - C:\WINDOWS\erdnt
[08-28-2008 03:05 AM | ---D | C] - C:\Documents and Settings\All Users\Application Data\Malwarebytes
[08-27-2008 12:30 AM | ---D | C] - C:\Documents and Settings\michele\Application Data\Help
[08-28-2008 03:05 AM | ---D | C] - C:\Documents and Settings\michele\Application Data\Malwarebytes
[08-30-2008 05:18 PM | ---D | C] - C:\Documents and Settings\michele\Application Data\InterVideo
[08-16-2008 10:50 PM | 00,000,793 | ---- | C] () - C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[08-28-2008 03:05 AM | 00,000,696 | ---- | C] () - C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[08-27-2008 12:48 PM | 00,001,734 | ---- | C] () - C:\Documents and Settings\michele\Desktop\HijackThis.lnk
[08-16-2008 10:49 PM | ---D | C] - C:\Program Files\Common Files\Wise Installation Wizard
[08-28-2008 03:05 AM | ---D | C] - C:\Program Files\Malwarebytes' Anti-Malware
========== Files - Modified Within 30 days ==========
[1 C:\*.tmp files]
[08-28-2008 03:04 AM | 01,417,602 | ---- | M] () - C:\SDFix.exe
[08-23-2008 10:51 AM | 00,091,136 | ---- | M] () - C:\WINDOWS\System32\dllcache\msgsvc.dll
[08-29-2008 11:39 PM | 00,000,686 | ---- | M] () - C:\WINDOWS\System32\drivers\etc\HOSTS
[2 C:\WINDOWS\System32\*.tmp files]
[08-13-2008 01:02 AM | 00,588,800 | ---- | M] () - C:\WINDOWS\System32\Psetup.exe
[08-16-2008 03:04 AM | 00,000,206 | ---- | M] () - C:\WINDOWS\System32\MRT.INI
[08-26-2008 01:09 PM | 00,029,764 | ---- | M] () - C:\WINDOWS\System32\mf0824.exe
[08-29-2008 02:10 PM | 00,062,464 | ---- | M] () - C:\WINDOWS\System32\dwbins.exe
[08-29-2008 02:10 PM | 00,125,804 | ---- | M] () - C:\WINDOWS\System32\newcool.exe
[08-30-2008 05:12 PM | 00,002,206 | ---- | M] () - C:\WINDOWS\System32\wpa.dbl
[3 C:\WINDOWS\*.tmp files]
[08-16-2008 03:05 AM | 00,001,374 | ---- | M] () - C:\WINDOWS\imsins.BAK
[08-23-2008 01:34 PM | 00,000,049 | ---- | M] () - C:\WINDOWS\wpd99.drv
[08-25-2008 11:13 AM | 00,001,409 | ---- | M] () - C:\WINDOWS\QTFont.for
[08-25-2008 11:13 AM | 00,054,156 | -H-- | M] () - C:\WINDOWS\QTFont.qfn
[08-28-2008 03:01 AM | 00,000,139 | ---- | M] () - C:\WINDOWS\msicpl.ini
[08-29-2008 05:57 AM | 00,002,560 | ---- | M] () - C:\WINDOWS\_MSRSTRT.EXE
[08-30-2008 05:09 PM | 00,002,048 | --S- | M] () - C:\WINDOWS\bootstat.dat
[08-30-2008 05:10 PM | 00,000,006 | -H-- | M] () - C:\WINDOWS\tasks\SA.DAT
[1 C:\Documents and Settings\michele\My Documents\*.tmp files]
[08-11-2008 12:59 PM | 00,027,136 | ---- | M] () - C:\Documents and Settings\michele\My Documents\INFO.doc
[08-16-2008 10:50 PM | 00,000,793 | ---- | M] () - C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[08-28-2008 03:05 AM | 00,000,696 | ---- | M] () - C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[08-27-2008 01:19 PM | 00,002,483 | ---- | M] () - C:\Documents and Settings\michele\Desktop\Microsoft Word.lnk
[08-27-2008 12:48 PM | 00,001,734 | ---- | M] () - C:\Documents and Settings\michele\Desktop\HijackThis.lnk
< End of report >
OTViewIt logfile created on: 2008-08-30 17:19:07 - Run 1
OTViewIt by OldTimer - Version 1.0.1.7 Folder = C:\Documents and Settings\michele\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: yyyy-MM-dd
511.48 Mb Total Physical Memory | 342.65 Mb Available Physical Memory | 66.99% Memory free
1.22 Gb Paging File | 1.08 Gb Available in Paging File | 88.27% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 64.85 Gb Free Space | 87.02% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: MICHELE
Current User Name: michele
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Whitelist: On
===== Processes - Non-Microsoft Only =====
[06-25-2004 02:05 PM | 00,045,056 | ---- | M] () - C:\WINDOWS\system32\WLTRYSVC.EXE
[08-23-2001 05:52 PM | 00,331,830 | ---- | M] (Microsoft® Corporation) - C:\Program Files\Microsoft Works\wkssb.exe
[08-17-2001 12:41 AM | 00,028,738 | ---- | M] (Microsoft® Corporation) - C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
[09-12-2002 01:13 PM | 01,101,824 | ---- | M] (Copyright (C) ahead software gmbh and its licensors) - C:\Program Files\Ahead\InCD\InCD.exe
[07-20-2005 12:19 PM | 00,385,024 | ---- | M] (Motive Communications, Inc.) - C:\Program Files\Verizon Online\SmartBridge\MotiveSB.exe
[08-07-2001 07:06 PM | 00,024,633 | ---- | M] (Microsoft® Corporation) - C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
[08-09-2002 06:00 PM | 00,221,184 | ---- | M] (Motive Communications, Inc.) - C:\Program Files\Verizon Online\bin\mpbtn.exe
===== Win32 Services - Non-Microsoft Only =====
(Autocomplete) AutoComplete Service [On_Demand | Stopped]
File not found - C:\PROGRA~1\SYSTEM~1\autocomp.exe
(WLTRYSVC) WLTRYSVC [Auto | Running]
[06-25-2004 02:05 PM | 00,045,056 | ---- | M] () - C:\WINDOWS\system32\WLTRYSVC.EXE
===== Driver Services - Non-Microsoft Only =====
(BsStor) InCD Storage Helper Driver [Boot | Running]
[06-05-2002 07:07 PM | 00,009,344 | ---- | M] (B.H.A Co.,Ltd.) - C:\WINDOWS\system32\drivers\bsstor.sys
(BsUDF) InCD UDF Driver [Auto | Running]
[09-13-2002 08:35 AM | 00,448,640 | ---- | M] (ahead software) - C:\WINDOWS\System32\drivers\bsudf.sys
(catchme) catchme [On_Demand | Stopped]
File not found - C:\ComboFix\catchme.sys
(GMSIPCI) GMSIPCI [On_Demand | Stopped]
File not found - E:\INSTALL\GMSIPCI.SYS
(rtl8139) Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver [On_Demand | Stopped]
[08-04-2004 01:31 AM | 00,020,992 | ---- | M] (Realtek Semiconductor Corporation) - C:\WINDOWS\system32\drivers\RTL8139.sys
(USBNET_XP) Instant Wireless XP USB Network Adapter ver.2.6 Driver [On_Demand | Stopped]
[02-19-2002 02:34 PM | 00,072,576 | R--- | M] (The LinkSys Group, Inc.) - C:\WINDOWS\system32\drivers\netusbxp.sys
========== Run Keys ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"InCD" = C:\Program Files\Ahead\InCD\InCD.exe [09-12-2002 01:13 PM | 01,101,824 | ---- | M] (Copyright (C) ahead software gmbh and its licensors)
"Microsoft Works Portfolio" = C:\Program Files\Microsoft Works\WksSb.exe /AllUsers [08-23-2001 05:52 PM | 00,331,830 | ---- | M] (Microsoft® Corporation)
"Microsoft Works Update Detection" = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe [08-17-2001 12:41 AM | 00,028,738 | ---- | M] (Microsoft® Corporation)
"Motive SmartBridge" = C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe [07-20-2005 12:19 PM | 00,385,024 | ---- | M] (Motive Communications, Inc.)
"NeroCheck" = C:\WINDOWS\system32\NeroCheck.exe [07-09-2001 04:50 AM | 00,155,648 | ---- | M] (Ahead Software Gmbh)
"NvCplDaemon" = RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup [03-20-2003 08:13 AM | 04,616,192 | ---- | M] (NVIDIA Corporation)
"vptray" = C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe [05-21-2003 02:21 AM | 00,090,112 | ---- | M] (Symantec Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" = Reg Error: Key does not exist or could not be opened.
"run" = Reg Error: Key does not exist or could not be opened.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AIM" = C:\Program Files\AIM\aim.exe -cnetwait.odl File not found
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"load" = Reg Error: Value load does not exist or could not be read.
"run" = Reg Error: Value run does not exist or could not be read.
========== Startup Folders ==========
[All Users Startup Folder - C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
[04-23-2008 03:38 AM | 00,029,696 | ---- | M] (Adobe Systems Incorporated) - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
[01-27-1998 02:10 AM | 00,055,296 | ---- | M] (Micrografx, Inc.) - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\CreataCard Gold 2 Forget Me Not Reminders.lnk = C:\Program Files\CreataCard\Gold\fmrmd32.exe
[08-07-2001 07:06 PM | 00,024,633 | ---- | M] (Microsoft® Corporation) - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
[08-06-2002 11:07 AM | 00,204,800 | ---- | M] (Motive Communications, Inc.) - C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Verizon Online Support Center.lnk = C:\Program Files\Verizon Online\bin\matcli.exe
[michele Startup Folder - C:\Documents and Settings\michele\Start Menu\Programs\Startup]
========== BHO's ==========
========== Toolbars ==========
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser]
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
HKLM CLSID: (Reg Error: Key does not exist or could not be opened.) - File not found Reg Error: Key does not exist or could not be opened.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}"
HKLM CLSID: (Yahoo! Toolbar) - File not found Reg Error: Key does not exist or could not be opened.
========== AppInit_Dlls ==========
========== HKLM Security Providers ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders]
"msapsspc.dllschannel.dlldigest.dllmsnsspc.dll" - File not found
========== HKLM Winlogon Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell]
"Explorer.exe" - [06-13-2007 06:23 AM | 01,033,216 | ---- | M] (Microsoft Corporation) C:\WINDOWS\explorer.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit]
"C:\WINDOWS\system32\userinit.exe" - [08-04-2004 03:56 AM | 00,024,576 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\userinit.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UIHost]
"logonui.exe" - [08-04-2004 03:56 AM | 00,514,560 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\logonui.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet]
"rundll32 shell32" - [10-25-2007 11:34 PM | 08,460,288 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
"Control_RunDLL "sysdm.cpl"" - [08-04-2004 03:56 AM | 00,298,496 | ---- | M] (Microsoft Corporation) C:\WINDOWS\system32\sysdm.cpl
========== User's Winlogon Settings ==========
========== Winlogon Notify Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
"DllName" = C:\WINDOWS\system32\NavLogon.dll [05-21-2003 02:19 AM | 00,045,056 | ---- | M] ()
========== Policies ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveAutoRun" = 67108863
"NoDriveTypeAutoRun" = 255
"NoDrives" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"dontdisplaylastusername" = 0
"legalnoticecaption" =
"legalnoticetext" =
"shutdownwithoutlogon" = 1
"undockwithoutlogon" = 1
"DisableRegistryTools" = 0
"HideLegacyLogonScripts" = 0
"HideLogoffScripts" = 0
"RunLogonScriptSync" = 1
"RunStartupScriptSync" = 0
"HideStartupScripts" = 0
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun" = 145
"NoDrives" = 0
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System]
"HideLegacyLogonScripts" = 0
"HideLogoffScripts" = 0
"RunLogonScriptSync" = 1
"RunStartupScriptSync" = 0
"HideStartupScripts" = 0
========== Lsa Authentication Packages ==========
========== Lsa Security Packages ==========
========== Desktop Components ==========
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"FriendlyName" = "My Current Home Page"
"Source" = "About:Home"
"SubscribedURL" = "About:Home"
========== Safeboot Options ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot]
"AlternateShell" = cmd.exe
========== Disabled MsConfig Items ==========
Unable to open key or key not present!
========== CDRom AutoRun Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom]
"AutoRun" = 1
========== Autorun Files on Drives ==========
AUTOEXEC.BAT []
[07-11-2003 01:27 AM | 00,000,000 | ---- | M] () C:\AUTOEXEC.BAT [ NTFS ]
========== MountPoints2 ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{06eb2976-d4b1-11d7-93b9-000c410c8bb4}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{200abfe4-c03a-11da-945e-000e2e216509}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{32754293-d6d6-11d9-9428-000e2e216509}\Shell]
"" = Open
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4131139c-2877-11dd-94bf-000e2e216509}\Shell]
"" = Open
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{565e4c3a-79b4-11db-947a-000f661bb2bb}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{565e4c46-79b4-11db-947a-000f661bb2bb}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6007a5f8-5b4a-11dc-94a1-000e2e216509}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{936fda1e-6cd0-11d9-9411-000f661bb2bb}\Shell]
"" = Open
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9d356454-8aeb-11db-947b-000e2e216509}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b8a45af1-9592-11dc-94a6-000e2e216509}\Shell]
"" = AutoRun
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b8a45af2-9592-11dc-94a6-000e2e216509}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d1c6be90-b839-11d9-941d-000f661bb2bb}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{efd0c32a-b37e-11d7-93a8-b0c80decdf80}\Shell]
"" = None
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F\Shell]
"" = AutoRun
========== DNS Name Servers ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{7C48A721-0A35-4753-BE40-E80EBE593471}]
Servers: | Description: Instant Wireless USB Network Adapter ver.2.6
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{836D4178-AA3D-4AEA-8210-609376CBBB7A}]
Servers: | Description: Linksys LNE100TX Fast Ethernet Adapter(LNE100TX v4)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{A6A5C012-00A3-4209-A6B7-1E6CA2BA5C11}]
Servers: | Description: Linksys Wireless-G PCI Adapter with SpeedBooster
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{AB0DBDA3-DFDA-495C-A2E7-A88BC5504E89}]
Servers: | Description: Realtek RTL8139 Family PCI Fast Ethernet NIC
========== Hosts File ==========
HOSTS File = (686 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
First 25 entries...
127.0.0.1 localhost
========== Files/Folders - Created Within 30 days ==========
[1 C:\*.tmp files]
[08-28-2008 03:04 AM | 01,417,602 | ---- | C] () - C:\SDFix.exe
[08-28-2008 03:07 AM | ---D | C] - C:\SDFix
[08-30-2008 04:26 PM | ---D | C] - C:\ComboFix
[08-30-2008 04:26 PM | ---D | C] - C:\QooBox
[08-30-2008 05:09 PM | ---D | C] - C:\Avenger
[2 C:\WINDOWS\System32\*.tmp files]
[08-01-2008 05:29 PM | ---D | C] - C:\WINDOWS\System32\CatRoot_bak
[08-13-2008 01:02 AM | 00,588,800 | ---- | C] () - C:\WINDOWS\System32\Psetup.exe
[08-16-2008 03:04 AM | 00,000,206 | ---- | C] () - C:\WINDOWS\System32\MRT.INI
[08-17-2008 01:08 PM | ---D | C] - C:\WINDOWS\System32\inf
[08-20-2008 11:23 PM | 00,125,804 | ---- | C] () - C:\WINDOWS\System32\newcool.exe
[08-23-2008 04:51 PM | ---D | C] - C:\WINDOWS\System32\1024
[08-24-2008 02:35 PM | 00,029,764 | ---- | C] () - C:\WINDOWS\System32\mf0824.exe
[08-28-2008 02:17 PM | 00,062,464 | ---- | C] () - C:\WINDOWS\System32\dwbins.exe
[3 C:\WINDOWS\*.tmp files]
[08-25-2008 11:13 AM | 00,001,409 | ---- | C] () - C:\WINDOWS\QTFont.for
[08-25-2008 11:13 AM | 00,054,156 | -H-- | C] () - C:\WINDOWS\QTFont.qfn
[08-28-2008 03:11 AM | ---D | C] - C:\WINDOWS\ERUNT
[08-29-2008 05:57 AM | 00,002,560 | ---- | C] () - C:\WINDOWS\_MSRSTRT.EXE
[08-30-2008 04:26 PM | 00,028,672 | ---- | C] (NirSoft) - C:\WINDOWS\Nircmd.exe
[08-30-2008 04:26 PM | 00,049,152 | ---- | C] () - C:\WINDOWS\VFind.exe
[08-30-2008 04:26 PM | 00,068,096 | ---- | C] () - C:\WINDOWS\zip.exe
[08-30-2008 04:26 PM | 00,080,412 | ---- | C] () - C:\WINDOWS\grep.exe
[08-30-2008 04:26 PM | 00,089,504 | ---- | C] (Smallfrogs Studio) - C:\WINDOWS\fdsv.exe
[08-30-2008 04:26 PM | 00,098,816 | ---- | C] () - C:\WINDOWS\sed.exe
[08-30-2008 04:26 PM | 00,136,704 | ---- | C] (SteelWerX) - C:\WINDOWS\swsc.exe
[08-30-2008 04:26 PM | 00,161,792 | ---- | C] (SteelWerX) - C:\WINDOWS\swreg.exe
[08-30-2008 04:26 PM | 00,212,480 | ---- | C] (SteelWerX) - C:\WINDOWS\swxcacls.exe
[08-30-2008 04:26 PM | ---D | C] - C:\WINDOWS\erdnt
[08-28-2008 03:05 AM | ---D | C] - C:\Documents and Settings\All Users\Application Data\Malwarebytes
[08-27-2008 12:30 AM | ---D | C] - C:\Documents and Settings\michele\Application Data\Help
[08-28-2008 03:05 AM | ---D | C] - C:\Documents and Settings\michele\Application Data\Malwarebytes
[08-30-2008 05:18 PM | ---D | C] - C:\Documents and Settings\michele\Application Data\InterVideo
[08-16-2008 10:50 PM | 00,000,793 | ---- | C] () - C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[08-28-2008 03:05 AM | 00,000,696 | ---- | C] () - C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[08-27-2008 12:48 PM | 00,001,734 | ---- | C] () - C:\Documents and Settings\michele\Desktop\HijackThis.lnk
[08-16-2008 10:49 PM | ---D | C] - C:\Program Files\Common Files\Wise Installation Wizard
[08-28-2008 03:05 AM | ---D | C] - C:\Program Files\Malwarebytes' Anti-Malware
========== Files - Modified Within 30 days ==========
[1 C:\*.tmp files]
[08-28-2008 03:04 AM | 01,417,602 | ---- | M] () - C:\SDFix.exe
[08-23-2008 10:51 AM | 00,091,136 | ---- | M] () - C:\WINDOWS\System32\dllcache\msgsvc.dll
[08-29-2008 11:39 PM | 00,000,686 | ---- | M] () - C:\WINDOWS\System32\drivers\etc\HOSTS
[2 C:\WINDOWS\System32\*.tmp files]
[08-13-2008 01:02 AM | 00,588,800 | ---- | M] () - C:\WINDOWS\System32\Psetup.exe
[08-16-2008 03:04 AM | 00,000,206 | ---- | M] () - C:\WINDOWS\System32\MRT.INI
[08-26-2008 01:09 PM | 00,029,764 | ---- | M] () - C:\WINDOWS\System32\mf0824.exe
[08-29-2008 02:10 PM | 00,062,464 | ---- | M] () - C:\WINDOWS\System32\dwbins.exe
[08-29-2008 02:10 PM | 00,125,804 | ---- | M] () - C:\WINDOWS\System32\newcool.exe
[08-30-2008 05:12 PM | 00,002,206 | ---- | M] () - C:\WINDOWS\System32\wpa.dbl
[3 C:\WINDOWS\*.tmp files]
[08-16-2008 03:05 AM | 00,001,374 | ---- | M] () - C:\WINDOWS\imsins.BAK
[08-23-2008 01:34 PM | 00,000,049 | ---- | M] () - C:\WINDOWS\wpd99.drv
[08-25-2008 11:13 AM | 00,001,409 | ---- | M] () - C:\WINDOWS\QTFont.for
[08-25-2008 11:13 AM | 00,054,156 | -H-- | M] () - C:\WINDOWS\QTFont.qfn
[08-28-2008 03:01 AM | 00,000,139 | ---- | M] () - C:\WINDOWS\msicpl.ini
[08-29-2008 05:57 AM | 00,002,560 | ---- | M] () - C:\WINDOWS\_MSRSTRT.EXE
[08-30-2008 05:09 PM | 00,002,048 | --S- | M] () - C:\WINDOWS\bootstat.dat
[08-30-2008 05:10 PM | 00,000,006 | -H-- | M] () - C:\WINDOWS\tasks\SA.DAT
[1 C:\Documents and Settings\michele\My Documents\*.tmp files]
[08-11-2008 12:59 PM | 00,027,136 | ---- | M] () - C:\Documents and Settings\michele\My Documents\INFO.doc
[08-16-2008 10:50 PM | 00,000,793 | ---- | M] () - C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[08-28-2008 03:05 AM | 00,000,696 | ---- | M] () - C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[08-27-2008 01:19 PM | 00,002,483 | ---- | M] () - C:\Documents and Settings\michele\Desktop\Microsoft Word.lnk
[08-27-2008 12:48 PM | 00,001,734 | ---- | M] () - C:\Documents and Settings\michele\Desktop\HijackThis.lnk
< End of report >