This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] I tihnk I am infected: "NTVDM CPU illegal instruc

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

1st off thanks for providing such a great service. You helped a friend of mine last week. I have never had spyware before so I was hoping to never need your services but here I am! I will try to be as thorough as possible.

I have been running AVG 8.0x ever since I got his computer several months ago and I have never been infected. The machine is running XP Media Center version 2002, SP3. My java version was one update behind, I was on update 12, I installed update 13 this morning. I am running IE 7.0.57x


Yesterday I noticed a random pop up box when I came to my computer ,it was titled MS DOS 16 bit error. It was similar to this:
The NTVDM CPU has encountered and illegal instruction.
CS:0543 IP:0106 OP:63 74 79 70 65 Choose ‘Close’ to terminate the application.

I would have to hit ignore or close several times for them to disappear.

I looked for help on google and came across some other forums and I was able to find these two files in my system32 directory and I deleted them:
regedit.com and cmd.com

A day later and most of the NTVDM CPU error messages have gone away but I was still getting one or two. I ran a malwarebytes scan and it found several problems and I had malwarebytes attempt to fix them for me. Here is that log:

Malwarebytes 1st pass

Malwarebytes' Anti-Malware 1.36
Database version: 1994
Windows 5.1.2600 Service Pack 3

4/17/2009 11:25:17 AM
mbam-log-2009-04-17 (11-25-17).txt

Scan type: Quick Scan
Objects scanned: 95975
Time elapsed: 13 minute(s), 56 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 1
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
C:\WINDOWS\system32\drivers\svchost.exe (Heuristics.Reserved.Word.Exploit) -> Failed to unload process.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\eeekp (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\drivers\svchost.exe (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\Sysvxd.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.



After reboot I ran another malwarebytes scan while I was running a hijackthis scan. This time malwarebytes found zero problems. And here is my hijackthis scan. I am not confident that my problems are over yet:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:30:06 PM, on 4/17/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\zHotkey.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\Windows Media Connect 2\WMCCFG.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DNA\btdna.exe
C:\WINDOWS\ehome\RMSysTry.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\ehome\RMSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\AVG\AVG8\aAvgApi.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [ShowWnd] ShowWnd.exe
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Windows Media Connect 2] "C:\Program Files\Windows Media Connect 2\WMCCFG.exe" /StartQuiet
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Extender Resource Monitor.lnk = C:\WINDOWS\ehome\RMSysTry.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Plugin Control) - http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1227679334344
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS

–
End of file - 8078 bytes


Thanks for the help!

Trent

It also appears all of my cookies have been removed. Every site I normally visit is not remembering me which means I have to put in my username and password. I don't feel comfortable doing this until I get the green light from you guys.

Thank you,
Trent
Hi Trentk,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

  • Download OTListIt2 to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.
Thanks for taking the time to help me. I ran the scan as advised and when I came back to my pc I had the attached AVG trojan warning, I have never seen it before.

Here are the results of the scans:

OTListIt logfile created on: 4/22/2009 12:58:42 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

894.48 Mb Total Physical Memory | 373.37 Mb Available Physical Memory | 41.74% Memory free
2.11 Gb Paging File | 1.46 Gb Available in Paging File | 69.10% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 182.10 Gb Total Space | 57.74 Gb Free Space | 31.71% Space Free | Partition Type: NTFS
Drive D: | 4.20 Gb Total Space | 0.99 Gb Free Space | 23.65% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
Drive F: | 647.77 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive G: | 232.89 Gb Total Space | 60.33 Gb Free Space | 25.91% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: TRENT-DESKTOP
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - [2005/03/14 18:49:00 | 00,352,256 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\system32\Ati2evxx.exe
PRC - [2005/03/14 18:49:00 | 00,352,256 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\system32\Ati2evxx.exe
PRC - [2008/04/13 17:12:19 | 01,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Explorer.EXE
PRC - [2009/02/01 09:59:02 | 00,298,264 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgwdsvc.exe
PRC - [2005/10/11 08:40:32 | 00,237,568 | —- | M] (Microsoft Corporation) – C:\WINDOWS\eHome\ehRecvr.exe
PRC - [2005/08/05 13:56:32 | 00,102,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\eHome\ehSched.exe
PRC - [2009/03/09 05:19:15 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2008/10/16 20:35:28 | 00,116,032 | —- | M] (LogMeIn, Inc.) – C:\Program Files\LogMeIn\x86\RaMaint.exe
PRC - [2005/08/05 13:56:34 | 00,064,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\ehome\ehtray.exe
PRC - [2004/05/17 19:30:04 | 00,543,232 | —- | M] () – C:\WINDOWS\zHotkey.exe
PRC - [2009/02/01 09:59:06 | 00,484,120 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgrsx.exe
PRC - [2008/07/24 18:46:10 | 00,063,040 | —- | M] (LogMeIn, Inc.) – C:\Program Files\LogMeIn\x86\LogMeIn.exe
PRC - [2004/11/15 16:04:32 | 00,135,168 | —- | M] (Alcor Micro, Corp.) – C:\Program Files\Digital Media Reader\shwiconem.exe
PRC - [2004/11/02 21:24:46 | 00,032,768 | —- | M] (Cyberlink Corp.) – C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
PRC - [2004/12/01 17:54:22 | 00,077,824 | —- | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\SOUNDMAN.EXE
PRC - [2008/10/16 20:35:24 | 00,087,360 | —- | M] (LogMeIn, Inc.) – C:\Program Files\LogMeIn\x86\LMIGuardian.exe
PRC - [2005/10/06 18:12:22 | 00,368,128 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Connect 2\WMCCFG.exe
PRC - [2007/05/08 16:24:20 | 00,054,840 | —- | M] (Hewlett-Packard) – C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
PRC - [2008/07/24 18:46:10 | 00,063,048 | —- | M] (LogMeIn, Inc.) – C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
PRC - [2008/12/05 16:11:54 | 00,935,208 | —- | M] (Nero AG) – C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
PRC - [2009/03/09 05:19:17 | 00,148,888 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2008/12/18 19:17:07 | 00,342,848 | —- | M] (BitTorrent, Inc.) – C:\Program Files\DNA\btdna.exe
PRC - [2005/10/20 19:55:40 | 00,018,432 | —- | M] (Microsoft Corporation) – C:\WINDOWS\ehome\RMSysTry.exe
PRC - [2006/02/19 04:21:22 | 00,288,472 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
PRC - [2008/10/16 20:35:24 | 00,087,360 | —- | M] (LogMeIn, Inc.) – C:\Program Files\LogMeIn\x86\LMIGuardian.exe
PRC - [2008/11/13 22:02:05 | 00,172,032 | —- | M] (New Boundary Technologies, Inc.) – C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
PRC - [2005/10/20 19:55:40 | 00,028,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\ehome\RMSvc.exe
PRC - [2009/02/01 09:58:59 | 00,903,960 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgemc.exe
PRC - [2005/10/20 19:55:50 | 00,096,256 | —- | M] (Microsoft Corporation) – C:\WINDOWS\ehome\mcrdsvc.exe
PRC - [2006/11/16 15:26:40 | 00,239,192 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
PRC - [2005/10/06 18:12:30 | 00,855,552 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Connect 2\wmccds.exe
PRC - [2009/02/01 09:59:06 | 00,687,896 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgcsrvx.exe
PRC - [2005/08/05 13:56:28 | 00,046,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\eHome\ehmsas.exe
PRC - [2008/10/13 11:25:02 | 12,310,864 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
PRC - [2009/02/01 09:59:06 | 00,687,896 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgcsrvx.exe
PRC - [2009/02/01 09:58:57 | 01,601,304 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgtray.exe
PRC - [2009/02/01 09:58:54 | 00,592,128 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgnsx.exe
PRC - [2008/12/08 18:08:04 | 00,637,232 | —- | M] (BitTorrent, Inc.) – C:\Program Files\BitTorrent\bittorrent.exe
PRC - [2008/07/24 18:46:10 | 00,063,040 | —- | M] (LogMeIn, Inc.) – C:\Program Files\LogMeIn\x86\LogMeIn.exe
PRC - [2008/10/16 20:35:24 | 00,087,360 | —- | M] (LogMeIn, Inc.) – C:\Program Files\LogMeIn\x86\LMIGuardian.exe
PRC - [2009/04/22 12:57:35 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTListIt2.exe

========== Win32 Services (SafeList) ==========

SRV - [2007/10/24 01:47:22 | 00,033,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe – (aspnet_state [On_Demand | Stopped])
SRV - [2005/03/14 18:49:00 | 00,352,256 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\system32\Ati2evxx.exe – (Ati HotKey Poller [Auto | Running])
SRV - [2009/02/01 09:58:59 | 00,903,960 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgemc.exe – (avg8emc [Auto | Running])
SRV - [2009/02/01 09:59:02 | 00,298,264 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgwdsvc.exe – (avg8wd [Auto | Running])
SRV - [2007/10/24 01:47:40 | 00,070,144 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2005/10/11 08:40:32 | 00,237,568 | —- | M] (Microsoft Corporation) – C:\WINDOWS\eHome\ehRecvr.exe – (ehRecvr [Auto | Running])
SRV - [2005/08/05 13:56:32 | 00,102,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\eHome\ehSched.exe – (ehSched [Auto | Running])
SRV - [2009/03/24 15:03:28 | 00,183,280 | —- | M] (Google) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe – (gusvc [Auto | Stopped])
SRV - [2008/04/13 17:12:02 | 00,038,400 | —- | M] (Microsoft Corporation) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll – (helpsvc [Auto | Running])
SRV - [2009/03/09 05:19:15 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe – (JavaQuickStarterService [Auto | Running])
SRV - [2008/10/16 20:35:28 | 00,116,032 | —- | M] (LogMeIn, Inc.) – C:\Program Files\LogMeIn\x86\RaMaint.exe – (LMIMaint [Auto | Running])
SRV - [2008/07/24 18:46:10 | 00,063,040 | —- | M] (LogMeIn, Inc.) – C:\Program Files\LogMeIn\x86\LogMeIn.exe – (LogMeIn [Auto | Running])
SRV - [2005/10/20 19:55:50 | 00,096,256 | —- | M] (Microsoft Corporation) – C:\WINDOWS\ehome\mcrdsvc.exe – (McrdSvc [Auto | Running])
SRV - [2004/08/10 11:11:50 | 00,085,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mhn.dll – (MHN [On_Demand | Stopped])
SRV - [2008/12/05 16:11:54 | 00,935,208 | —- | M] (Nero AG) – C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe – (Nero BackItUp Scheduler 4.0 [Auto | Running])
SRV - [2006/05/09 16:03:30 | 00,043,520 | —- | M] (Hewlett-Packard) – C:\WINDOWS\system32\HPZinw12.dll – (Net Driver HPZ12 [Auto | Running])
SRV - [2003/07/28 12:28:22 | 00,089,136 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose [On_Demand | Stopped])
SRV - [2006/05/09 16:03:32 | 00,052,736 | —- | M] (Hewlett-Packard) – C:\WINDOWS\system32\HPZipm12.dll – (Pml Driver HPZ12 [Auto | Running])
SRV - [2008/11/13 22:02:05 | 00,172,032 | —- | M] (New Boundary Technologies, Inc.) – C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS – (PrismXL [Auto | Running])
SRV - [2005/10/20 19:55:40 | 00,028,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\ehome\RMSvc.exe – (RMSvc [Auto | Running])
SRV - [2005/08/03 18:29:52 | 00,038,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\wdfmgr.exe – (UMWdf [On_Demand | Stopped])
SRV - [2005/10/06 18:12:30 | 00,855,552 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Connect 2\wmccds.exe – (WMConnectCDS [Auto | Running])

========== Driver Services (SafeList) ==========

DRV - [2008/04/13 11:46:20 | 00,048,128 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\DRIVERS\61883.sys – (61883 [On_Demand | Stopped])
DRV - [2004/12/01 22:40:08 | 02,300,928 | —- | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS – (ALCXWDM [On_Demand | Running])
DRV - [2001/08/17 20:51:56 | 00,005,248 | —- | M] (Acer Laboratories Inc.) – C:\WINDOWS\system32\DRIVERS\aliide.sys – (AliIde [Boot | Stopped])
DRV - [2008/04/13 11:36:39 | 00,043,008 | —- | M] (Advanced Micro Devices, Inc.) – C:\WINDOWS\system32\DRIVERS\amdagp.sys – (amdagp [Boot | Stopped])
DRV - [2001/08/17 20:52:00 | 00,026,496 | —- | M] (Advanced System Products, Inc.) – C:\WINDOWS\system32\DRIVERS\asc.sys – (asc [Boot | Stopped])
DRV - [2001/08/17 20:51:58 | 00,014,848 | —- | M] (Advanced System Products, Inc.) – C:\WINDOWS\system32\DRIVERS\asc3550.sys – (asc3550 [Boot | Stopped])
DRV - [2008/11/13 22:16:33 | 00,008,552 | —- | M] (Windows ® 2000 DDK provider) – C:\WINDOWS\System32\drivers\asctrm.sys – (ASCTRM [Auto | Running])
DRV - [2005/03/14 18:54:00 | 01,032,192 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\system32\DRIVERS\ati2mtag.sys – (ati2mtag [On_Demand | Running])
DRV - [2008/04/13 11:46:20 | 00,038,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\DRIVERS\avc.sys – (Avc [On_Demand | Stopped])
DRV - [2009/02/01 09:59:06 | 00,325,128 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\Drivers\avgldx86.sys – (AvgLdx86 [System | Running])
DRV - [2009/02/01 09:59:06 | 00,027,656 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\Drivers\avgmfx86.sys – (AvgMfx86 [System | Running])
DRV - [2009/02/01 09:59:05 | 00,107,272 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\Drivers\avgtdix.sys – (AvgTdiX [System | Running])
DRV - [2007/03/07 16:51:00 | 00,009,336 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\drivers\cdr4_xp.sys – (Cdr4_xp [System | Running])
DRV - [2007/03/07 16:51:00 | 00,009,464 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\drivers\cdralw2k.sys – (Cdralw2k [System | Running])
DRV - [2001/08/17 20:51:54 | 00,006,656 | —- | M] (CMD Technology, Inc.) – C:\WINDOWS\system32\DRIVERS\cmdide.sys – (CmdIde [Boot | Stopped])
DRV - [2001/08/17 20:52:16 | 00,179,584 | —- | M] (Mylex Corporation) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys – (dac2w2k [Boot | Stopped])
DRV - [2005/10/20 20:58:52 | 00,049,920 | R— | M] (HP) – C:\WINDOWS\system32\DRIVERS\HPZid412.sys – (HPZid412 [On_Demand | Running])
DRV - [2005/10/20 20:58:58 | 00,016,496 | R— | M] (HP) – C:\WINDOWS\system32\DRIVERS\HPZipr12.sys – (HPZipr12 [On_Demand | Running])
DRV - [2005/10/20 20:52:48 | 00,021,568 | R— | M] (HP) – C:\WINDOWS\system32\DRIVERS\HPZius12.sys – (HPZius12 [On_Demand | Running])
DRV - [2004/06/17 15:56:22 | 00,220,032 | —- | M] (Conexant Systems, Inc.) – C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys – (HSFHWBS2 [On_Demand | Running])
DRV - [2004/06/17 15:55:04 | 01,041,536 | —- | M] (Conexant Systems, Inc.) – C:\WINDOWS\system32\DRIVERS\HSF_DP.sys – (HSF_DP [On_Demand | Running])
DRV - [2008/07/24 18:46:12 | 00,012,856 | —- | M] (LogMeIn, Inc.) – C:\Program Files\LogMeIn\x86\RaInfo.sys – (LMIInfo [Auto | Running])
DRV - [2008/07/24 18:45:20 | 00,010,144 | —- | M] (LogMeIn, Inc.) – C:\WINDOWS\system32\DRIVERS\lmimirr.sys – (lmimirr [On_Demand | Running])
DRV - [2008/10/16 20:35:58 | 00,083,288 | —- | M] (LogMeIn, Inc.) – C:\WINDOWS\System32\LMIRfsClientNP.dll – (LMIRfsClientNP [Disabled | Stopped])
DRV - [2008/07/24 18:46:10 | 00,047,640 | —- | M] (LogMeIn, Inc.) – C:\WINDOWS\system32\drivers\LMIRfsDriver.sys – (LMIRfsDriver [Auto | Running])
DRV - [2004/03/17 12:04:14 | 00,013,059 | —- | M] (Conexant) – C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys – (mdmxsdk [Auto | Running])
DRV - [2001/08/17 20:52:12 | 00,017,280 | —- | M] (American Megatrends Inc.) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys – (mraid35x [Boot | Stopped])
DRV - [2008/04/13 11:46:10 | 00,051,200 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\DRIVERS\msdv.sys – (MSDV [On_Demand | Stopped])
DRV - [2001/08/17 13:49:32 | 00,019,968 | —- | M] (Macronix International Co., Ltd. ) – C:\WINDOWS\system32\DRIVERS\mxnic.sys – (mxnic [On_Demand | Stopped])
DRV - [2004/08/03 22:29:56 | 01,897,408 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\system32\DRIVERS\nv4_mini.sys – (nv [On_Demand | Stopped])
DRV - [2004/08/10 12:00:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.) – C:\WINDOWS\system32\DRIVERS\ptilink.sys – (Ptilink [On_Demand | Running])
DRV - [2007/03/07 16:51:00 | 00,043,528 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\Drivers\PxHelp20.sys – (PxHelp20 [Boot | Running])
DRV - [2001/08/17 20:52:20 | 00,040,320 | —- | M] (QLogic Corporation) – C:\WINDOWS\system32\DRIVERS\ql1080.sys – (ql1080 [Boot | Stopped])
DRV - [2001/08/17 20:52:20 | 00,045,312 | —- | M] (QLogic Corporation) – C:\WINDOWS\system32\DRIVERS\ql12160.sys – (ql12160 [Boot | Stopped])
DRV - [2001/08/17 20:52:18 | 00,049,024 | —- | M] (QLogic Corporation) – C:\WINDOWS\system32\DRIVERS\ql1280.sys – (ql1280 [Boot | Stopped])
DRV - [2004/04/13 21:14:12 | 00,070,144 | —- | M] (Realtek Semiconductor Corporation ) – C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys – (RTL8023xp [On_Demand | Running])
DRV - [2007/11/13 03:25:53 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) – C:\WINDOWS\system32\DRIVERS\secdrv.sys – (Secdrv [On_Demand | Stopped])
DRV - [2008/04/13 11:36:39 | 00,040,960 | —- | M] (Silicon Integrated Systems Corporation) – C:\WINDOWS\system32\DRIVERS\sisagp.sys – (sisagp [Boot | Stopped])
DRV - [2001/08/17 21:07:44 | 00,019,072 | —- | M] (Adaptec, Inc.) – C:\WINDOWS\system32\DRIVERS\sparrow.sys – (Sparrow [Boot | Stopped])
DRV - [2004/11/15 18:41:54 | 00,036,804 | —- | M] (Alcor Micro Corp.) – C:\WINDOWS\System32\Drivers\sunkfilt.sys – (SunkFilt [On_Demand | Running])
DRV - [2001/08/17 21:07:34 | 00,016,256 | —- | M] (Symbios Logic Inc.) – C:\WINDOWS\system32\DRIVERS\symc810.sys – (symc810 [Boot | Stopped])
DRV - [2001/08/17 21:07:36 | 00,032,640 | —- | M] (LSI Logic) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys – (symc8xx [Boot | Stopped])
DRV - [2001/08/17 21:07:40 | 00,028,384 | —- | M] (LSI Logic) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys – (sym_hi [Boot | Stopped])
DRV - [2001/08/17 21:07:42 | 00,030,688 | —- | M] (LSI Logic) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys – (sym_u3 [Boot | Stopped])
DRV - [2001/08/17 20:52:22 | 00,036,736 | —- | M] (Promise Technology, Inc.) – C:\WINDOWS\system32\DRIVERS\ultra.sys – (ultra [Boot | Stopped])
DRV - [2004/06/17 15:55:38 | 00,685,056 | —- | M] (Conexant Systems, Inc.) – C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys – (winachsf [On_Demand | Running])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.5

FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/03/26 17:16:25 | 00,000,000 | —D | M]

[2009/01/07 11:54:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Extensions
[2009/01/07 11:54:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/01/07 11:54:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\hdnzonsa.default\extensions

O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (&Google;) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [CHotkey] zHotkey.exe ()
O4 - HKLM..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe (Microsoft Corporation)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe" (LogMeIn, Inc.)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime File not found
O4 - HKLM..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE ()
O4 - HKLM..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe (SoftThinks)
O4 - HKLM..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" (Cyberlink Corp.)
O4 - HKLM..\Run: [ShowWnd] ShowWnd.exe ()
O4 - HKLM..\Run: [SoundMan] SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe (Alcor Micro, Corp.)
O4 - HKLM..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" File not found
O4 - HKLM..\Run: [Windows Media Connect 2] "C:\Program Files\Windows Media Connect 2\WMCCFG.exe" /StartQuiet (Microsoft Corporation)
O4 - HKCU..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe" (BitTorrent, Inc.)
O4 - HKCU..\Run: [nah_Shell] C:\Documents and Settings\Owner\nah_giwq.exe [FILE handle not seen by OS]
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Extender Resource Monitor.lnk = C:\WINDOWS\ehome\RMSysTry.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Development Company, L.P.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 95 00 00 00 [binary data]
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Plugin Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1227679334344 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\LMIinit: DllName - LMIinit.dll - C:\WINDOWS\system32\LMIinit.dll (LogMeIn, Inc.)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O27 - HKLM IFEO\ehshell.exe: Debugger - C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/04/13 10:20:25 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2004/09/13 12:15:24 | 00,000,053 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2 C:\WINDOWS\*.tmp files]
[2009/04/22 12:57:27 | 00,501,248 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTListIt2.exe
[2009/04/17 12:29:35 | 00,001,734 | —- | C] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk
[2009/04/17 12:29:33 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/04/17 10:23:00 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Malwarebytes
[2009/04/17 10:22:55 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/04/17 10:22:55 | 00,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/04/17 10:22:52 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/04/17 10:22:51 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/04/17 10:22:51 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/04/15 14:59:21 | 00,284,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pdh.dll
[2009/04/15 14:59:20 | 00,473,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fastprox.dll
[2009/04/15 14:59:20 | 00,401,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rpcss.dll
[2009/04/15 14:59:20 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\services.exe
[2009/04/15 14:59:20 | 00,035,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sc.exe
[2009/04/15 14:59:19 | 00,453,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvsd.dll
[2009/04/15 14:59:19 | 00,227,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvse.exe
[2009/04/15 14:59:18 | 00,729,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\lsasrv.dll
[2009/04/15 14:59:18 | 00,617,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\advapi32.dll
[2009/04/15 14:59:17 | 00,714,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntdll.dll
[2009/04/15 14:58:25 | 00,002,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpsp4res.dll
[2009/04/15 14:58:22 | 01,203,922 | —- | C] () – C:\WINDOWS\System32\dllcache\sysmain.sdb
[2009/04/15 14:58:20 | 00,215,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wordpad.exe
[2009/04/03 22:52:23 | 00,000,000 | —D | C] – C:\XBOX
[2009/04/03 22:16:48 | 00,130,100 | —- | C] () – C:\Documents and Settings\Owner\My Documents\2009_AVN_NOMINATIONS_11_25_08.pdf
[2009/04/03 11:10:58 | 00,000,000 | -H-D | C] – C:\WINDOWS\PIF
[2009/03/27 14:47:39 | 00,000,701 | —- | C] () – C:\Documents and Settings\All Users\Desktop\FLV Player.lnk
[2009/03/27 14:47:30 | 00,000,000 | —D | C] – C:\Program Files\FLV Player
[2009/03/27 14:30:41 | 00,001,636 | —- | C] () – C:\Documents and Settings\Owner\Desktop\CinemaForge.lnk
[2009/03/27 14:30:25 | 00,000,000 | —D | C] – C:\CFdownloads
[2009/03/27 14:30:19 | 00,000,000 | —D | C] – C:\Program Files\CinemaForge
[2009/03/27 14:30:04 | 04,691,208 | —- | C] (XMLAuthor Inc.) – C:\WINDOWS\screengenie.scr
[2009/03/27 12:03:22 | 00,721,248 | —- | C] () – C:\Documents and Settings\Owner\My Documents\2008 baja 500 Map.pdf
[2009/03/27 10:30:46 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\HandBrake
[2009/03/27 10:28:16 | 00,000,694 | —- | C] () – C:\Documents and Settings\Owner\Desktop\HandBrake.lnk
[2009/03/27 10:28:15 | 00,000,000 | —D | C] – C:\Program Files\HandBrake
[2009/03/27 10:10:46 | 00,050,777 | —- | C] () – C:\WINDOWS\System32\wdh.bin
[2009/03/07 19:25:06 | 00,765,952 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2009/03/07 19:25:05 | 00,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2009/01/08 10:38:32 | 00,004,767 | —- | C] () – C:\WINDOWS\Irremote.ini
[2008/11/21 20:51:02 | 00,000,287 | —- | C] () – C:\WINDOWS\Sierra.ini
[2008/11/15 11:19:32 | 00,077,824 | R— | C] () – C:\WINDOWS\System32\hpzids01.dll
[2008/11/15 11:15:31 | 00,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2008/11/14 12:42:53 | 00,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2008/11/13 22:26:57 | 00,156,672 | —- | C] () – C:\WINDOWS\System32\RTLCPAPI.dll
[2008/11/13 22:22:39 | 00,000,492 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/11/13 22:04:08 | 00,532,544 | —- | C] () – C:\WINDOWS\PIC.dll
[2008/11/13 22:04:08 | 00,024,576 | —- | C] () – C:\WINDOWS\HKNTDLL.dll
[2006/07/30 22:59:36 | 00,000,338 | —- | C] () – C:\WINDOWS\scrub2k.ini
[2005/08/05 14:01:54 | 00,239,104 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/04/13 12:02:03 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/04/13 09:57:05 | 00,001,436 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2005/04/13 09:57:05 | 00,000,495 | —- | C] () – C:\WINDOWS\System32\emver.ini
[2005/04/13 09:56:11 | 00,000,680 | —- | C] () – C:\WINDOWS\win.ini
[2005/04/13 09:56:08 | 00,000,231 | —- | C] () – C:\WINDOWS\system.ini
[2003/01/07 15:05:08 | 00,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[1996/02/23 14:34:48 | 00,014,629 | —- | C] () – C:\WINDOWS\System32\Declw.dll
[1996/02/22 12:09:20 | 00,032,256 | —- | C] () – C:\WINDOWS\System32\Decln.dll

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[2 C:\WINDOWS\*.tmp files]
[2 C:\Documents and Settings\Owner\My Documents\*.tmp files]
[2009/04/22 12:57:35 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTListIt2.exe
[2009/04/22 12:11:11 | 00,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2009/04/22 08:38:46 | 35,309,745 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/04/22 03:27:15 | 00,017,763 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/04/21 20:45:06 | 00,086,016 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/21 15:32:17 | 00,013,030 | —- | M] () – C:\PDOXUSRS.NET
[2009/04/18 03:28:21 | 00,434,673 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/04/17 21:18:38 | 00,409,562 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/04/17 21:18:38 | 00,064,576 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/04/17 21:18:37 | 00,478,838 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/04/17 16:38:07 | 00,001,924 | -H– | M] () – C:\Documents and Settings\Owner\My Documents\Default.rdp
[2009/04/17 12:29:35 | 00,001,734 | —- | M] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk
[2009/04/17 11:34:56 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/04/17 11:34:44 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/04/17 11:34:38 | 93,800,4480 | -HS- | M] () – C:\hiberfil.sys
[2009/04/17 10:22:55 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/04/16 03:11:52 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/04/16 03:04:08 | 00,000,680 | —- | M] () – C:\WINDOWS\win.ini
[2009/04/06 15:32:54 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/04/06 15:32:46 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/04/06 07:57:24 | 24,921,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/04/03 22:16:48 | 00,130,100 | —- | M] () – C:\Documents and Settings\Owner\My Documents\2009_AVN_NOMINATIONS_11_25_08.pdf
[2009/03/31 16:50:52 | 00,097,280 | -HS- | M] () – C:\Documents and Settings\Owner\My Documents\Thumbs.db
[2009/03/27 14:47:39 | 00,000,701 | —- | M] () – C:\Documents and Settings\All Users\Desktop\FLV Player.lnk
[2009/03/27 14:30:41 | 00,001,636 | —- | M] () – C:\Documents and Settings\Owner\Desktop\CinemaForge.lnk
[2009/03/27 12:03:28 | 00,721,248 | —- | M] () – C:\Documents and Settings\Owner\My Documents\2008 baja 500 Map.pdf
[2009/03/27 11:35:42 | 00,001,170 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/03/27 10:28:16 | 00,000,694 | —- | M] () – C:\Documents and Settings\Owner\Desktop\HandBrake.lnk
[2009/03/27 10:10:46 | 00,050,777 | —- | M] () – C:\WINDOWS\System32\wdh.bin
[2009/03/26 23:58:38 | 01,203,922 | —- | M] () – C:\WINDOWS\System32\dllcache\sysmain.sdb
[2009/03/26 17:21:40 | 02,638,260 | -H– | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\IconCache.db

========== LOP Check ==========

[2009/04/17 10:22:51 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2005/04/13 10:27:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2008/11/14 12:42:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2009/02/15 19:35:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2009/02/15 19:36:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/01/29 02:38:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg8
[2008/11/15 11:22:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2009/03/07 21:47:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2009/04/21 19:31:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google Updater
[2008/11/18 17:39:28 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HP
[2008/11/23 00:09:37 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HP Product Assistant
[2008/11/19 02:15:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LogMeIn
[2009/04/17 10:22:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2008/11/13 22:27:49 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee
[2008/11/13 22:27:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com
[2008/11/25 22:57:20 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2008/11/14 12:51:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2009/01/08 10:30:46 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nero
[2008/11/13 22:00:02 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Prism Deploy
[2008/11/13 22:18:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pure Networks
[2008/11/14 21:50:54 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2008/11/14 12:44:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2008/11/13 22:18:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/12/28 01:04:54 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2009/04/17 10:23:00 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Owner\Application Data
[2008/12/23 22:21:01 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Adobe
[2008/12/05 18:58:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AdobeUM
[2009/02/15 19:46:12 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Apple Computer
[2008/11/29 21:59:47 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AVGTOOLBAR
[2009/04/22 12:58:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\BitTorrent
[2008/11/15 11:22:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\CyberLink
[2009/04/22 12:57:47 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\DNA
[2009/04/10 11:18:55 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\FileZilla
[2009/03/27 10:30:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\HandBrake
[2008/12/08 10:54:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\HP
[2005/04/13 10:20:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Identities
[2008/12/12 13:50:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Macromedia
[2009/04/17 10:23:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Malwarebytes
[2008/11/13 22:27:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\McAfee
[2009/02/28 11:12:56 | 00,000,000 | –SD | M] – C:\Documents and Settings\Owner\Application Data\Microsoft
[2009/02/19 11:13:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Move Networks
[2009/01/07 11:54:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla
[2009/01/16 20:50:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Nero
[2008/11/13 22:27:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SampleView
[2005/04/13 10:43:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Sun
[2008/11/17 10:12:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Viewpoint
[2008/12/12 12:30:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Winamp
[2004/08/10 12:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/04/22 12:11:11 | 00,000,868 | —- | M] () – C:\WINDOWS\Tasks\Google Software Updater.job
[2009/04/17 11:34:56 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========

< End of report >


2ND FILE

OTListIt Extras logfile created on: 4/22/2009 12:58:42 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

894.48 Mb Total Physical Memory | 373.37 Mb Available Physical Memory | 41.74% Memory free
2.11 Gb Paging File | 1.46 Gb Available in Paging File | 69.10% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 182.10 Gb Total Space | 57.74 Gb Free Space | 31.71% Space Free | Partition Type: NTFS
Drive D: | 4.20 Gb Total Space | 0.99 Gb Free Space | 23.65% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
Drive F: | 647.77 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive G: | 232.89 Gb Total Space | 60.33 Gb Free Space | 25.91% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: TRENT-DESKTOP
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.js [@ = JSFile] – C:\Program Files\Macromedia\Dreamweaver MX\Dreamweaver.exe (Macromedia, Inc.)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"3776:UDP" = 3776:UDP:*:Enabled:Media Center Extender Service
"3390:TCP" = 3390:TCP:*:Enabled:Remote Media Center Experience
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Connect
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Connect
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Connect
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Connect
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Connect
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Connect
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
File not found – C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL
File not found – C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL
File not found – C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL
[2008/04/13 11:53:32 | 00,558,080 | —- | M] (Microsoft Corporation) – %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
File not found – C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL
File not found – C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL
File not found – C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL
[2008/04/13 17:12:28 | 01,695,232 | -HS- | M] (Microsoft Corporation) – C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger
[2005/10/26 14:43:00 | 03,219,456 | —- | M] (Microsoft Corporation) – C:\WINDOWS\ehome\ehshell.exe:LocalSubNet:Enabled:Media Center
[2009/02/01 09:58:59 | 00,903,960 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe
[2009/01/28 08:34:36 | 01,032,984 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe
[2006/08/13 13:36:06 | 00,118,784 | —- | M] (Push-A-Button) – C:\Program Files\Push-A-Button\BounceParse\ODWS.exe:*:Enabled:OnDemandWebServer
[2002/05/22 00:13:20 | 09,797,632 | —- | M] (Macromedia, Inc.) – C:\Program Files\Macromedia\Dreamweaver MX\Dreamweaver.exe:*:Enabled:Dreamweaver MX
[2008/12/18 19:17:07 | 00,342,848 | —- | M] (BitTorrent, Inc.) – C:\Program Files\DNA\btdna.exe:*:Enabled:DNA
[2008/12/08 18:08:04 | 00,637,232 | —- | M] (BitTorrent, Inc.) – C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
[2008/04/13 11:53:32 | 00,558,080 | —- | M] (Microsoft Corporation) – %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
File not found – C:\WINDOWS\system32\drivers\svchost.exe:*:Disabled:???????

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02627ee5-eaca-4742-a9cc-e687631773e4}" = Nero ShowTime
"{02C91E12-74A4-45E1-9D3F-C3DD7D6FECAE}" = 5700_Help
"{086a7d8c-0a38-4c7f-819a-620275550d5c}" = Nero Burning ROM Help
"{0A55CDBB-0566-4AA2-A15B-24C7F27C6FF4}" = BPD_Scan
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{0E92A5AC-05AB-48c2-9227-9AD504EAF4EA}" = J5700
"{11655C91-EF58-4aab-BF09-E8F205324FBF}" = BPDSoftware
"{15377C3E-9655-400F-B441-E69F0A6BEAFE}" = Recovery Software Suite eMachines
"{1c00c7c5-e615-4139-b817-7f4003de68c0}" = Nero PhotoSnap Help
"{20400dbd-e6db-45b8-9b6b-1dd7033818ec}" = Nero InfoTool
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{2348b586-c9ae-46ce-936c-a68e9426e214}" = Nero StartSmart Help
"{23FE964A-853B-4176-86D7-9E18B5CA1FC0}" = Media Center Extender
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java™ 6 Update 13
"{3248F0A8-6813-11D6-A77B-00B0D0150020}" = J2SE Runtime Environment 5.0 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{33cf58f5-48d8-4575-83d6-96f574e4d83a}" = Nero DriveSpeed
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{359cfc0a-beb1-440d-95ba-cf63a86da34f}" = Nero Recode
"{368ba326-73ad-4351-84ed-3c0a7a52cc53}" = Nero Rescue Agent
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{3D30BAC1-C250-4F10-9C78-C379D05A445E}" = BPDSoftware_Ini
"{3F262ADC-5AD2-48E5-A586-44315E04A9E2}" = Microsoft Picture It! Library 10
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{42756145-9997-4D28-809B-8756BFD00106}" = Microsoft Picture It! Premium 10
"{43e39830-1826-415d-8bae-86845787b54b}" = Nero Vision
"{45B8A76B-57EC-4242-B019-066400CD8428}" = BufferChm
"{4EA684E9-5C81-4033-A696-3019EC57AC3A}" = HPProductAssistant
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{585F72FF-7F0D-47D3-9686-20B1159992E5}" = Yougle
"{595a3116-40bb-4e0f-a2e8-d7951da56270}" = NeroExpress
"{5d9be3c1-8ba4-4e7e-82fd-9f74fa6815d1}" = Nero Vision
"{5e08ecd1-c98e-4711-bf65-8fd736b3f969}" = Nero RescueAgent Help
"{60c731fb-c951-41ce-ad41-8e54c8594609}" = Nero Disc Copy Gadget Help
"{62ac81f6-bdd3-4110-9d36-3e9eaab40999}" = Nero CoverDesigner
"{66910000-8B30-4973-A159-6371345AFFA5}" = WebReg
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6909F917-5499-482e-9AA1-FAD06A99F231}" = Toolbox
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6994491D-D491-48F1-AE1F-E179C1FFFC2F}" = HP Photosmart Essential
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7748ac8c-18e3-43bb-959b-088faea16fb2}" = Nero StartSmart
"{77e33d87-255e-413e-9c8d-eed2a7f9bebf}" = Nero Live Help
"{7829db6f-a066-4e40-8912-cb07887c20bb}" = Nero BurnRights
"{7F831576-6246-42C7-B523-55B3F96509CC}" = LogMeIn
"{81EED1A1-AE78-4B11-BE47-C6AE9F5E87F1}" = Digital Media Reader
"{83202942-84b3-4c50-8622-b8c0aa2d2885}" = Nero Express Help
"{8331C3EA-0C91-43AA-A4D4-27221C631139}" = Status
"{85243696-5e58-4357-9cf8-3498c609941d}" = NeroLiveGadget Help
"{869200db-287a-4dc0-b02b-2b6787fbcd4c}" = Nero DiscSpeed
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8A4CE7FD-9657-4B06-9943-E1819F3D5D67}" = DocProc
"{8B4AB829-DFD3-436D-B808-D9733D76C590}" = Macromedia Dreamweaver MX
"{8DCE550C-CA43-4E82-92DF-FFC4A48F5BE1}" = Napster Burn Engine
"{91110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{912da275-d895-4a53-bcd4-f7f76571a154}" = Nero 9 Trial
"{98a67610-a3b5-4098-a423-3708040026d3}" = "Nero SoundTrax Help
"{9941F0AA-B903-4AF4-A055-83A9815CC011}" = Sonic Encoders
"{9e82b934-9a25-445b-b8df-8012808074ac}" = Nero PhotoSnap
"{9e9fdde6-2c26-492a-85a0-05646b3f2795}" = NeroLiveGadget
"{9F7FC79B-3059-4264-9450-39EB368E3225}" = Microsoft Digital Image Library 9 - Blocker
"{a209525b-3377-43f4-b886-32f6b6e7356f}" = Nero WaveEditor
"{A5BA14E0-7384-11D4-BAE7-00409631A2C8}" = Macromedia Extension Manager
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7646-A70000000000}" = Adobe Reader 7.0
"{AC76BA86-7AD7-EF45-47A7-7E8A45000002}" = Adobe Reader Multimedia Package
"{ad6bc5cc-2ef0-49c4-b33d-cdc8b2c4dc80}" = Nero Recode Help
"{b1adf008-e898-4fe2-8a1f-690d9a06acaf}" = DolbyFiles
"{b2ec4a38-b545-4a00-8214-13fe0e915e6d}" = Advertising Center
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{b78120a0-cf84-4366-a393-4d0a59bc546c}" = Menu Templates - Starter Kit
"{B929776E-7527-4F98-AE4D-BEBCF0BEA669}" = BPD_HPSU
"{bd5ca0da-71ad-43da-b19e-6eee0c9adc9a}" = Nero ControlCenter
"{c5a7cb6c-e76d-408f-ba0e-85605420fe9d}" = SoundTrax
"{C7F54CF8-D6FB-4E0A-93A3-E68AE0D6C476}" = SolutionCenter
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{cc019e3f-59d2-4486-8d4b-878105b62a71}" = Nero DiscSpeed
"{CE24344F-DFD8-40C8-8FD8-C9740B5F25AC}" = BPDfax
"{ce96f5a5-584d-4f8f-aa3e-9baed413db72}" = Nero CoverDesigner Help
"{d025a639-b9c9-417d-8531-208859000af8}" = NeroBurningROM
"{d9dcf92e-72eb-412d-ac71-3b01276e5f8b}" = Nero ShowTime
"{DBC20735-34E6-4E97-A9E5-2066B66B243D}" = TrayApp
"{df6a95f5-adc1-406a-bdc6-2aa7cc0182aa}" = Nero Live
"{E1B80DEE-A795-4258-8445-074C06AE3AB8}" = MarketResearch
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{e498385e-1c51-459a-b45f-1721e37aa1a0}" = Movie Templates - Starter Kit
"{e5c7d048-f9b4-4219-b323-8bdb01a2563d}" = Nero DriveSpeed
"{e8631efb-6b9a-426c-b1ce-e7173ca26bf8}" = Nero WaveEditor Help
"{e8a80433-302b-4ff1-815d-fcc8eac482ff}" = Nero Installer
"{f1861f30-3419-44db-b2a1-c274825698b3}" = Nero Disc Copy Gadget
"{F2CA5A0D-5F2F-4d99-89F0-2D1358218A7A}" = ProductContext
"{F3760724-B29D-465B-BC53-E5D72095BCC4}" = Scan
"{f4041dce-3fe1-4e18-8a9e-9de65231ee36}" = Nero ControlCenter
"{f6bdd7c5-89ed-4569-9318-469aa9732572}" = Nero BurnRights
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FB15E224-67C3-491F-9F5C-F257BC418412}" = Destinations
"{fbcdfd61-7dcf-4e71-9226-873ba0053139}" = Nero InfoTool
"{FE57DE70-95DE-4B64-9266-84DA811053DB}" = HP Update
"{FF262740-C85A-11D5-BBEC-00D0B740900A}" = Multimedia Keyboard Driver
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Photoshop 6.0" = Adobe Photoshop 6.0
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"All ATI Software" = ATI - Software Uninstall Utility
"ATI Display Driver" = ATI Display Driver
"AVG8Uninstall" = AVG Free 8.0
"Black Dahlia" = Black Dahlia
"CinemaForge" = CinemaForge
"CNXT_MODEM_PCI_VEN_14F1&DEV;_2F20&SUBSYS;_200014F1" = SoftV92 Data Fax Modem with SmartCP
"EHome Devices" = Media Center Extender
"FileZilla Client" = FileZilla Client 3.2.1
"FLV Player" = FLV Player 2.0 (build 25)
"Google Updater" = Google Updater
"HandBrake" = HandBrake 0.9.3
"HijackThis" = HijackThis 2.0.2
"HP Imaging Device Functions" = HP Imaging Device Functions 7.0
"HP Officejet All-In-One Series" = HP Officejet All-In-One Series
"HP Solution Center & Imaging Support Tools" = HP Solution Center 7.0
"HPExtendedCapabilities" = HP Customer Participation Program 7.0
"HPOCR" = OCR Software by I.R.I.S 7.0
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{81EED1A1-AE78-4B11-BE47-C6AE9F5E87F1}" = Digital Media Reader
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Nero BurnRights!UninstallKey" = Nero BurnRights
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"P5 Manager" = P5 Manager
"P5 Operator" = P5 Operator
"PictureItPrem_v10" = Microsoft Picture It! Premium 10
"Premier Jeweler Software" = Premier Jeweler Software
"Print Artist 12.0" = SierraHome Print Artist 12.0
"RADVideo" = RAD Video Tools
"RealPlayer 6.0" = RealPlayer Basic
"StreetPlugin" = Learn2 Player (Uninstall Only)
"ViewpointMediaPlayer" = Viewpoint Media Player
"Winamp" = Winamp
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMCSetup" = Windows Media Connect
"Xvid_is1" = Xvid 1.1.3 final uninstall

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"BitTorrent" = BitTorrent
"BitTorrent DNA" = DNA
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/9/2009 1:46:06 PM | Computer Name = TRENT-DESKTOP | Source = Media Center Extender Services | ID = 36866
Description = ERROR: Device Service Listener - The listener loop unexpectedly ended.
Error code 0x00000000.

Error - 2/10/2009 9:17:31 PM | Computer Name = TRENT-DESKTOP | Source = Media Center Extender Services | ID = 36866
Description = ERROR: Device Service Listener - The listener loop unexpectedly ended.
Error code 0x00000000.

Error - 2/11/2009 1:45:58 PM | Computer Name = TRENT-DESKTOP | Source = Media Center Extender Services | ID = 36866
Description = ERROR: Device Service Listener - The listener loop unexpectedly ended.
Error code 0x00000000.

Error - 2/12/2009 9:04:39 PM | Computer Name = TRENT-DESKTOP | Source = Media Center Extender Services | ID = 36866
Description = ERROR: Device Service Listener - The listener loop unexpectedly ended.
Error code 0x00000000.

Error - 2/13/2009 11:39:00 AM | Computer Name = TRENT-DESKTOP | Source = Media Center Extender Services | ID = 36866
Description = ERROR: Device Service Listener - The listener loop unexpectedly ended.
Error code 0x00000000.

Error - 2/13/2009 12:09:11 PM | Computer Name = TRENT-DESKTOP | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16791, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2/13/2009 3:34:58 PM | Computer Name = TRENT-DESKTOP | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16791, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2/14/2009 12:42:54 PM | Computer Name = TRENT-DESKTOP | Source = Media Center Extender Services | ID = 36866
Description = ERROR: Device Service Listener - The listener loop unexpectedly ended.
Error code 0x00000000.

Error - 2/15/2009 2:39:48 AM | Computer Name = TRENT-DESKTOP | Source = Media Center Extender Services | ID = 36866
Description = ERROR: Device Service Listener - The listener loop unexpectedly ended.
Error code 0x00000000.

Error - 2/15/2009 11:03:13 PM | Computer Name = TRENT-DESKTOP | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16791, faulting
module avgssie.dll, version 8.0.0.223, fault address 0x0000992b.

[ System Events ]
Error - 12/26/2008 4:02:30 PM | Computer Name = TRENT-DESKTOP | Source = Service Control Manager | ID = 7031
Description = The AVG Free8 WatchDog service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 0 milliseconds:
Restart the service.

Error - 1/8/2009 2:04:52 AM | Computer Name = TRENT-DESKTOP | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service COMSysApp with
arguments "" in order to run the server: {ECABAFBC-7F19-11D2-978E-0000F8757E2A}

Error - 1/8/2009 2:04:53 AM | Computer Name = TRENT-DESKTOP | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the COM+ System Application
service to connect.

Error - 1/8/2009 2:04:53 AM | Computer Name = TRENT-DESKTOP | Source = Service Control Manager | ID = 7000
Description = The COM+ System Application service failed to start due to the following
error: %%1053

Error - 1/14/2009 2:09:00 PM | Computer Name = TRENT-DESKTOP | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)

Error - 1/14/2009 2:09:00 PM | Computer Name = TRENT-DESKTOP | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.

Error - 1/16/2009 12:56:50 PM | Computer Name = TRENT-DESKTOP | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.1.2 for the Network Card with network
address 0013D3256874 has been denied by the DHCP server 0.0.0.0 (The DHCP Server
sent a DHCPNACK message).

Error - 2/14/2009 12:42:46 PM | Computer Name = TRENT-DESKTOP | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.1.2 on
the Network Card with network address 0013D3256874.

Error - 2/23/2009 4:01:18 PM | Computer Name = TRENT-DESKTOP | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.1.2 on
the Network Card with network address 0013D3256874.

Error - 2/26/2009 11:32:27 PM | Computer Name = TRENT-DESKTOP | Source = DCOM | ID = 10016
Description = The application-specific permission settings do not grant Local Activation
permission for the COM Server application with CLSID {BA126AD1-2166-11D1-B1D0-00805FC1270E}

to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission
can be modified using the Component Services administrative tool.


< End of report >

Attachments:

Trentk,

  • Click Start, then Settings, then click Control Panel.
  • In Control Panel, double-click Add or Remove Programs.
  • In Add or Remove Programs, Remove J2SE Runtime Environment 5.0 Update 2
  • Do the same for Java™ 6 Update 7.

Double click on OTList2.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:OTLI
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [] File not found
O4 - HKCU..\Run: [nah_Shell] C:\Documents and Settings\Owner\nah_giwq.exe [FILE handle not seen by OS]

:Files

:Commands
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer
Please post the OTL2 log and a new HJT log.

Then


Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Trentk,

It should take 5 minutes or less. See if you can get out of it. Then please try again but with this modified script.

:Processes
explorer.exe

:OTLI
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [] File not found
O4 - HKCU..\Run: [nah_Shell] C:\Documents and Settings\Owner\nah_giwq.exe [FILE handle not seen by OS]

:Files

:Commands
[emptytemp]
[start explorer]
[Reboot]
Tom, this code is also non responsive after 15 minutes. Maybe AVG already "fixed" that nah_giwq.exe file? I don't see that file in that directory.

Here are updated scan results, I am only getting one text file log now even though LOP and purity check are both checked.

OTListIt logfile created on: 4/22/2009 4:29:41 PM - Run 4
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

894.48 Mb Total Physical Memory | 452.85 Mb Available Physical Memory | 50.63% Memory free
2.12 Gb Paging File | 1.60 Gb Available in Paging File | 75.84% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688;

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 182.10 Gb Total Space | 57.84 Gb Free Space | 31.76% Space Free | Partition Type: NTFS
Drive D: | 4.20 Gb Total Space | 0.99 Gb Free Space | 23.65% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
Drive F: | 647.77 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive G: | 232.89 Gb Total Space | 60.33 Gb Free Space | 25.91% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: TRENT-DESKTOP
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - [2005/03/14 18:49:00 | 00,352,256 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\system32\Ati2evxx.exe
PRC - [2005/03/14 18:49:00 | 00,352,256 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\system32\Ati2evxx.exe
PRC - [2008/04/13 17:12:19 | 01,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Explorer.EXE
PRC - [2005/08/05 13:56:34 | 00,064,512 | —- | M] (Microsoft Corporation) – C:\WINDOWS\ehome\ehtray.exe
PRC - [2009/02/01 09:59:02 | 00,298,264 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgwdsvc.exe
PRC - [2005/10/11 08:40:32 | 00,237,568 | —- | M] (Microsoft Corporation) – C:\WINDOWS\eHome\ehRecvr.exe
PRC - [2004/05/17 19:30:04 | 00,543,232 | —- | M] () – C:\WINDOWS\zHotkey.exe
PRC - [2004/11/15 16:04:32 | 00,135,168 | —- | M] (Alcor Micro, Corp.) – C:\Program Files\Digital Media Reader\shwiconem.exe
PRC - [2005/08/05 13:56:32 | 00,102,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\eHome\ehSched.exe
PRC - [2004/11/02 21:24:46 | 00,032,768 | —- | M] (Cyberlink Corp.) – C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
PRC - [2004/12/01 17:54:22 | 00,077,824 | —- | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\SOUNDMAN.EXE
PRC - [2005/10/06 18:12:22 | 00,368,128 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Connect 2\WMCCFG.exe
PRC - [2007/05/08 16:24:20 | 00,054,840 | —- | M] (Hewlett-Packard) – C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
PRC - [2008/07/24 18:46:10 | 00,063,048 | —- | M] (LogMeIn, Inc.) – C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
PRC - [2009/03/09 05:19:15 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2009/02/01 09:58:57 | 01,601,304 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgtray.exe
PRC - [2009/03/09 05:19:17 | 00,148,888 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2008/12/18 19:17:07 | 00,342,848 | —- | M] (BitTorrent, Inc.) – C:\Program Files\DNA\btdna.exe
PRC - [2009/02/01 09:59:06 | 00,484,120 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgrsx.exe
PRC - [2009/02/01 09:58:54 | 00,592,128 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgnsx.exe
PRC - [2008/10/16 20:35:28 | 00,116,032 | —- | M] (LogMeIn, Inc.) – C:\Program Files\LogMeIn\x86\RaMaint.exe
PRC - [2008/10/16 20:35:24 | 00,087,360 | —- | M] (LogMeIn, Inc.) – C:\Program Files\LogMeIn\x86\LMIGuardian.exe
PRC - [2005/10/20 19:55:40 | 00,018,432 | —- | M] (Microsoft Corporation) – C:\WINDOWS\ehome\RMSysTry.exe
PRC - [2006/02/19 04:21:22 | 00,288,472 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
PRC - [2008/07/24 18:46:10 | 00,063,040 | —- | M] (LogMeIn, Inc.) – C:\Program Files\LogMeIn\x86\LogMeIn.exe
PRC - [2008/10/16 20:35:24 | 00,087,360 | —- | M] (LogMeIn, Inc.) – C:\Program Files\LogMeIn\x86\LMIGuardian.exe
PRC - [2008/12/05 16:11:54 | 00,935,208 | —- | M] (Nero AG) – C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
PRC - [2006/11/16 15:26:40 | 00,239,192 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
PRC - [2008/11/13 22:02:05 | 00,172,032 | —- | M] (New Boundary Technologies, Inc.) – C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
PRC - [2005/10/20 19:55:40 | 00,028,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\ehome\RMSvc.exe
PRC - [2009/02/01 09:58:59 | 00,903,960 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgemc.exe
PRC - [2005/10/20 19:55:50 | 00,096,256 | —- | M] (Microsoft Corporation) – C:\WINDOWS\ehome\mcrdsvc.exe
PRC - [2005/10/06 18:12:30 | 00,855,552 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Connect 2\wmccds.exe
PRC - [2009/02/01 09:59:06 | 00,687,896 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgcsrvx.exe
PRC - [2005/08/05 13:56:28 | 00,046,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\eHome\ehmsas.exe
PRC - [2008/07/24 18:46:10 | 00,063,040 | —- | M] (LogMeIn, Inc.) – C:\Program Files\LogMeIn\x86\LogMeIn.exe
PRC - [2008/10/16 20:35:24 | 00,087,360 | —- | M] (LogMeIn, Inc.) – C:\Program Files\LogMeIn\x86\LMIGuardian.exe
PRC - [2009/04/22 12:57:35 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTListIt2.exe

========== Win32 Services (SafeList) ==========

SRV - [2007/10/24 01:47:22 | 00,033,800 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe – (aspnet_state [On_Demand | Stopped])
SRV - [2005/03/14 18:49:00 | 00,352,256 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\system32\Ati2evxx.exe – (Ati HotKey Poller [Auto | Running])
SRV - [2009/02/01 09:58:59 | 00,903,960 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgemc.exe – (avg8emc [Auto | Running])
SRV - [2009/02/01 09:59:02 | 00,298,264 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG8\avgwdsvc.exe – (avg8wd [Auto | Running])
SRV - [2007/10/24 01:47:40 | 00,070,144 | —- | M] (Microsoft Corporation) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2005/10/11 08:40:32 | 00,237,568 | —- | M] (Microsoft Corporation) – C:\WINDOWS\eHome\ehRecvr.exe – (ehRecvr [Auto | Running])
SRV - [2005/08/05 13:56:32 | 00,102,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\eHome\ehSched.exe – (ehSched [Auto | Running])
SRV - [2009/03/24 15:03:28 | 00,183,280 | —- | M] (Google) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe – (gusvc [Auto | Stopped])
SRV - [2008/04/13 17:12:02 | 00,038,400 | —- | M] (Microsoft Corporation) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll – (helpsvc [Auto | Running])
SRV - [2009/03/09 05:19:15 | 00,152,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Java\jre6\bin\jqs.exe – (JavaQuickStarterService [Auto | Running])
SRV - [2008/10/16 20:35:28 | 00,116,032 | —- | M] (LogMeIn, Inc.) – C:\Program Files\LogMeIn\x86\RaMaint.exe – (LMIMaint [Auto | Running])
SRV - [2008/07/24 18:46:10 | 00,063,040 | —- | M] (LogMeIn, Inc.) – C:\Program Files\LogMeIn\x86\LogMeIn.exe – (LogMeIn [Auto | Running])
SRV - [2005/10/20 19:55:50 | 00,096,256 | —- | M] (Microsoft Corporation) – C:\WINDOWS\ehome\mcrdsvc.exe – (McrdSvc [Auto | Running])
SRV - [2004/08/10 11:11:50 | 00,085,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\mhn.dll – (MHN [On_Demand | Stopped])
SRV - [2008/12/05 16:11:54 | 00,935,208 | —- | M] (Nero AG) – C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe – (Nero BackItUp Scheduler 4.0 [Auto | Running])
SRV - [2006/05/09 16:03:30 | 00,043,520 | —- | M] (Hewlett-Packard) – C:\WINDOWS\system32\HPZinw12.dll – (Net Driver HPZ12 [Auto | Running])
SRV - [2003/07/28 12:28:22 | 00,089,136 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE – (ose [On_Demand | Stopped])
SRV - [2006/05/09 16:03:32 | 00,052,736 | —- | M] (Hewlett-Packard) – C:\WINDOWS\system32\HPZipm12.dll – (Pml Driver HPZ12 [Auto | Running])
SRV - [2008/11/13 22:02:05 | 00,172,032 | —- | M] (New Boundary Technologies, Inc.) – C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS – (PrismXL [Auto | Running])
SRV - [2005/10/20 19:55:40 | 00,028,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\ehome\RMSvc.exe – (RMSvc [Auto | Running])
SRV - [2005/08/03 18:29:52 | 00,038,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\wdfmgr.exe – (UMWdf [On_Demand | Stopped])
SRV - [2005/10/06 18:12:30 | 00,855,552 | —- | M] (Microsoft Corporation) – C:\Program Files\Windows Media Connect 2\wmccds.exe – (WMConnectCDS [Auto | Running])

========== Driver Services (SafeList) ==========

DRV - [2008/04/13 11:46:20 | 00,048,128 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\DRIVERS\61883.sys – (61883 [On_Demand | Stopped])
DRV - [2004/12/01 22:40:08 | 02,300,928 | —- | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS – (ALCXWDM [On_Demand | Running])
DRV - [2001/08/17 20:51:56 | 00,005,248 | —- | M] (Acer Laboratories Inc.) – C:\WINDOWS\system32\DRIVERS\aliide.sys – (AliIde [Boot | Running])
DRV - [2008/04/13 11:36:39 | 00,043,008 | —- | M] (Advanced Micro Devices, Inc.) – C:\WINDOWS\system32\DRIVERS\amdagp.sys – (amdagp [Boot | Running])
DRV - [2001/08/17 20:52:00 | 00,026,496 | —- | M] (Advanced System Products, Inc.) – C:\WINDOWS\system32\DRIVERS\asc.sys – (asc [Boot | Running])
DRV - [2001/08/17 20:51:58 | 00,014,848 | —- | M] (Advanced System Products, Inc.) – C:\WINDOWS\system32\DRIVERS\asc3550.sys – (asc3550 [Boot | Running])
DRV - [2008/11/13 22:16:33 | 00,008,552 | —- | M] (Windows ® 2000 DDK provider) – C:\WINDOWS\System32\drivers\asctrm.sys – (ASCTRM [Auto | Running])
DRV - [2005/03/14 18:54:00 | 01,032,192 | —- | M] (ATI Technologies Inc.) – C:\WINDOWS\system32\DRIVERS\ati2mtag.sys – (ati2mtag [On_Demand | Running])
DRV - [2008/04/13 11:46:20 | 00,038,912 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\DRIVERS\avc.sys – (Avc [On_Demand | Stopped])
DRV - [2009/02/01 09:59:06 | 00,325,128 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\Drivers\avgldx86.sys – (AvgLdx86 [System | Running])
DRV - [2009/02/01 09:59:06 | 00,027,656 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\Drivers\avgmfx86.sys – (AvgMfx86 [System | Running])
DRV - [2009/02/01 09:59:05 | 00,107,272 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\Drivers\avgtdix.sys – (AvgTdiX [System | Running])
DRV - [2007/03/07 16:51:00 | 00,009,336 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\drivers\cdr4_xp.sys – (Cdr4_xp [System | Running])
DRV - [2007/03/07 16:51:00 | 00,009,464 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\drivers\cdralw2k.sys – (Cdralw2k [System | Running])
DRV - [2001/08/17 20:51:54 | 00,006,656 | —- | M] (CMD Technology, Inc.) – C:\WINDOWS\system32\DRIVERS\cmdide.sys – (CmdIde [Boot | Running])
DRV - [2001/08/17 20:52:16 | 00,179,584 | —- | M] (Mylex Corporation) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys – (dac2w2k [Boot | Running])
DRV - [2005/10/20 20:58:52 | 00,049,920 | R— | M] (HP) – C:\WINDOWS\system32\DRIVERS\HPZid412.sys – (HPZid412 [On_Demand | Running])
DRV - [2005/10/20 20:58:58 | 00,016,496 | R— | M] (HP) – C:\WINDOWS\system32\DRIVERS\HPZipr12.sys – (HPZipr12 [On_Demand | Running])
DRV - [2005/10/20 20:52:48 | 00,021,568 | R— | M] (HP) – C:\WINDOWS\system32\DRIVERS\HPZius12.sys – (HPZius12 [On_Demand | Running])
DRV - [2004/06/17 15:56:22 | 00,220,032 | —- | M] (Conexant Systems, Inc.) – C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys – (HSFHWBS2 [On_Demand | Running])
DRV - [2004/06/17 15:55:04 | 01,041,536 | —- | M] (Conexant Systems, Inc.) – C:\WINDOWS\system32\DRIVERS\HSF_DP.sys – (HSF_DP [On_Demand | Running])
DRV - [2008/07/24 18:46:12 | 00,012,856 | —- | M] (LogMeIn, Inc.) – C:\Program Files\LogMeIn\x86\RaInfo.sys – (LMIInfo [Auto | Running])
DRV - [2008/07/24 18:45:20 | 00,010,144 | —- | M] (LogMeIn, Inc.) – C:\WINDOWS\system32\DRIVERS\lmimirr.sys – (lmimirr [On_Demand | Running])
DRV - [2008/10/16 20:35:58 | 00,083,288 | —- | M] (LogMeIn, Inc.) – C:\WINDOWS\System32\LMIRfsClientNP.dll – (LMIRfsClientNP [Disabled | Stopped])
DRV - [2008/07/24 18:46:10 | 00,047,640 | —- | M] (LogMeIn, Inc.) – C:\WINDOWS\system32\drivers\LMIRfsDriver.sys – (LMIRfsDriver [Auto | Running])
DRV - [2004/03/17 12:04:14 | 00,013,059 | —- | M] (Conexant) – C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys – (mdmxsdk [Auto | Running])
DRV - [2001/08/17 20:52:12 | 00,017,280 | —- | M] (American Megatrends Inc.) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys – (mraid35x [Boot | Running])
DRV - [2008/04/13 11:46:10 | 00,051,200 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\DRIVERS\msdv.sys – (MSDV [On_Demand | Stopped])
DRV - [2001/08/17 13:49:32 | 00,019,968 | —- | M] (Macronix International Co., Ltd. ) – C:\WINDOWS\system32\DRIVERS\mxnic.sys – (mxnic [On_Demand | Stopped])
DRV - [2004/08/03 22:29:56 | 01,897,408 | —- | M] (NVIDIA Corporation) – C:\WINDOWS\system32\DRIVERS\nv4_mini.sys – (nv [On_Demand | Stopped])
DRV - [2004/08/10 12:00:00 | 00,017,792 | —- | M] (Parallel Technologies, Inc.) – C:\WINDOWS\system32\DRIVERS\ptilink.sys – (Ptilink [On_Demand | Running])
DRV - [2007/03/07 16:51:00 | 00,043,528 | —- | M] (Sonic Solutions) – C:\WINDOWS\System32\Drivers\PxHelp20.sys – (PxHelp20 [Boot | Running])
DRV - [2001/08/17 20:52:20 | 00,040,320 | —- | M] (QLogic Corporation) – C:\WINDOWS\system32\DRIVERS\ql1080.sys – (ql1080 [Boot | Running])
DRV - [2001/08/17 20:52:20 | 00,045,312 | —- | M] (QLogic Corporation) – C:\WINDOWS\system32\DRIVERS\ql12160.sys – (ql12160 [Boot | Running])
DRV - [2001/08/17 20:52:18 | 00,049,024 | —- | M] (QLogic Corporation) – C:\WINDOWS\system32\DRIVERS\ql1280.sys – (ql1280 [Boot | Running])
DRV - [2004/04/13 21:14:12 | 00,070,144 | —- | M] (Realtek Semiconductor Corporation ) – C:\WINDOWS\system32\DRIVERS\Rtlnicxp.sys – (RTL8023xp [On_Demand | Running])
DRV - [2007/11/13 03:25:53 | 00,020,480 | —- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) – C:\WINDOWS\system32\DRIVERS\secdrv.sys – (Secdrv [On_Demand | Stopped])
DRV - [2008/04/13 11:36:39 | 00,040,960 | —- | M] (Silicon Integrated Systems Corporation) – C:\WINDOWS\system32\DRIVERS\sisagp.sys – (sisagp [Boot | Running])
DRV - [2001/08/17 21:07:44 | 00,019,072 | —- | M] (Adaptec, Inc.) – C:\WINDOWS\system32\DRIVERS\sparrow.sys – (Sparrow [Boot | Running])
DRV - [2004/11/15 18:41:54 | 00,036,804 | —- | M] (Alcor Micro Corp.) – C:\WINDOWS\System32\Drivers\sunkfilt.sys – (SunkFilt [On_Demand | Running])
DRV - [2001/08/17 21:07:34 | 00,016,256 | —- | M] (Symbios Logic Inc.) – C:\WINDOWS\system32\DRIVERS\symc810.sys – (symc810 [Boot | Running])
DRV - [2001/08/17 21:07:36 | 00,032,640 | —- | M] (LSI Logic) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys – (symc8xx [Boot | Running])
DRV - [2001/08/17 21:07:40 | 00,028,384 | —- | M] (LSI Logic) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys – (sym_hi [Boot | Running])
DRV - [2001/08/17 21:07:42 | 00,030,688 | —- | M] (LSI Logic) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys – (sym_u3 [Boot | Running])
DRV - [2001/08/17 20:52:22 | 00,036,736 | —- | M] (Promise Technology, Inc.) – C:\WINDOWS\system32\DRIVERS\ultra.sys – (ultra [Boot | Running])
DRV - [2004/06/17 15:55:38 | 00,685,056 | —- | M] (Conexant Systems, Inc.) – C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys – (winachsf [On_Demand | Running])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.5

FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/03/26 17:16:25 | 00,000,000 | —D | M]

[2009/01/07 11:54:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Extensions
[2009/01/07 11:54:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/01/07 11:54:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\mozilla\Firefox\Profiles\hdnzonsa.default\extensions

O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]—————————-)
O4 - HKLM..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [CHotkey] zHotkey.exe ()
O4 - HKLM..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe (Microsoft Corporation)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe" (LogMeIn, Inc.)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime File not found
O4 - HKLM..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE ()
O4 - HKLM..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe (SoftThinks)
O4 - HKLM..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" (Cyberlink Corp.)
O4 - HKLM..\Run: [ShowWnd] ShowWnd.exe ()
O4 - HKLM..\Run: [SoundMan] SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe (Alcor Micro, Corp.)
O4 - HKLM..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" File not found
O4 - HKLM..\Run: [Windows Media Connect 2] "C:\Program Files\Windows Media Connect 2\WMCCFG.exe" /StartQuiet (Microsoft Corporation)
O4 - HKCU..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe" (BitTorrent, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Extender Resource Monitor.lnk = C:\WINDOWS\ehome\RMSysTry.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Development Company, L.P.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 95 00 00 00 [binary data]
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_13.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Plugin Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/C/0…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1227679334344 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\LMIinit: DllName - LMIinit.dll - C:\WINDOWS\system32\LMIinit.dll (LogMeIn, Inc.)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O27 - HKLM IFEO\ehshell.exe: Debugger - C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/04/13 10:20:25 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2004/09/13 12:15:24 | 00,000,053 | -HS- | M] () - D:\Autorun.inf – [ FAT32 ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2 C:\WINDOWS\*.tmp files]
[2009/04/22 14:22:06 | 00,104,971 | —- | C] () – C:\Documents and Settings\Owner\My Documents\otlist.jpg
[2009/04/22 13:44:10 | 00,000,000 | —D | C] – C:\_OTListIt
[2009/04/22 12:57:27 | 00,501,248 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTListIt2.exe
[2009/04/17 12:29:35 | 00,001,734 | —- | C] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk
[2009/04/17 12:29:33 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/04/17 10:23:00 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Malwarebytes
[2009/04/17 10:22:55 | 00,015,504 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/04/17 10:22:55 | 00,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/04/17 10:22:52 | 00,038,496 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/04/17 10:22:51 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/04/17 10:22:51 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/04/15 14:59:21 | 00,284,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pdh.dll
[2009/04/15 14:59:20 | 00,473,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fastprox.dll
[2009/04/15 14:59:20 | 00,401,408 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rpcss.dll
[2009/04/15 14:59:20 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\services.exe
[2009/04/15 14:59:20 | 00,035,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sc.exe
[2009/04/15 14:59:19 | 00,453,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvsd.dll
[2009/04/15 14:59:19 | 00,227,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvse.exe
[2009/04/15 14:59:18 | 00,729,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\lsasrv.dll
[2009/04/15 14:59:18 | 00,617,472 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\advapi32.dll
[2009/04/15 14:59:17 | 00,714,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntdll.dll
[2009/04/15 14:58:25 | 00,002,560 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpsp4res.dll
[2009/04/15 14:58:22 | 01,203,922 | —- | C] () – C:\WINDOWS\System32\dllcache\sysmain.sdb
[2009/04/15 14:58:20 | 00,215,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wordpad.exe
[2009/04/03 22:52:23 | 00,000,000 | —D | C] – C:\XBOX
[2009/04/03 22:16:48 | 00,130,100 | —- | C] () – C:\Documents and Settings\Owner\My Documents\2009_AVN_NOMINATIONS_11_25_08.pdf
[2009/04/03 11:10:58 | 00,000,000 | -H-D | C] – C:\WINDOWS\PIF
[2009/03/27 14:47:39 | 00,000,701 | —- | C] () – C:\Documents and Settings\All Users\Desktop\FLV Player.lnk
[2009/03/27 14:47:30 | 00,000,000 | —D | C] – C:\Program Files\FLV Player
[2009/03/27 14:30:41 | 00,001,636 | —- | C] () – C:\Documents and Settings\Owner\Desktop\CinemaForge.lnk
[2009/03/27 14:30:25 | 00,000,000 | —D | C] – C:\CFdownloads
[2009/03/27 14:30:19 | 00,000,000 | —D | C] – C:\Program Files\CinemaForge
[2009/03/27 14:30:04 | 04,691,208 | —- | C] (XMLAuthor Inc.) – C:\WINDOWS\screengenie.scr
[2009/03/27 12:03:22 | 00,721,248 | —- | C] () – C:\Documents and Settings\Owner\My Documents\2008 baja 500 Map.pdf
[2009/03/27 10:30:46 | 00,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\HandBrake
[2009/03/27 10:28:16 | 00,000,694 | —- | C] () – C:\Documents and Settings\Owner\Desktop\HandBrake.lnk
[2009/03/27 10:28:15 | 00,000,000 | —D | C] – C:\Program Files\HandBrake
[2009/03/27 10:10:46 | 00,050,777 | —- | C] () – C:\WINDOWS\System32\wdh.bin
[2009/03/07 19:25:06 | 00,765,952 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2009/03/07 19:25:05 | 00,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2009/01/08 10:38:32 | 00,004,767 | —- | C] () – C:\WINDOWS\Irremote.ini
[2008/11/21 20:51:02 | 00,000,287 | —- | C] () – C:\WINDOWS\Sierra.ini
[2008/11/15 11:19:32 | 00,077,824 | R— | C] () – C:\WINDOWS\System32\hpzids01.dll
[2008/11/15 11:15:31 | 00,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2008/11/14 12:42:53 | 00,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2008/11/13 22:26:57 | 00,156,672 | —- | C] () – C:\WINDOWS\System32\RTLCPAPI.dll
[2008/11/13 22:22:39 | 00,000,492 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/11/13 22:04:08 | 00,532,544 | —- | C] () – C:\WINDOWS\PIC.dll
[2008/11/13 22:04:08 | 00,024,576 | —- | C] () – C:\WINDOWS\HKNTDLL.dll
[2006/07/30 22:59:36 | 00,000,338 | —- | C] () – C:\WINDOWS\scrub2k.ini
[2005/08/05 14:01:54 | 00,239,104 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/04/13 12:02:03 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/04/13 09:57:05 | 00,001,436 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2005/04/13 09:57:05 | 00,000,495 | —- | C] () – C:\WINDOWS\System32\emver.ini
[2005/04/13 09:56:11 | 00,000,680 | —- | C] () – C:\WINDOWS\win.ini
[2005/04/13 09:56:08 | 00,000,231 | —- | C] () – C:\WINDOWS\system.ini
[2003/01/07 15:05:08 | 00,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[1996/02/23 14:34:48 | 00,014,629 | —- | C] () – C:\WINDOWS\System32\Declw.dll
[1996/02/22 12:09:20 | 00,032,256 | —- | C] () – C:\WINDOWS\System32\Decln.dll

========== Files - Modified Within 30 Days ==========

[1 C:\WINDOWS\System32\*.tmp files]
[2 C:\WINDOWS\*.tmp files]
[2 C:\Documents and Settings\Owner\My Documents\*.tmp files]
[2009/04/22 16:02:03 | 00,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2009/04/22 16:01:36 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/04/22 16:01:25 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/04/22 16:01:19 | 93,800,4480 | -HS- | M] () – C:\hiberfil.sys
[2009/04/22 14:22:07 | 00,104,971 | —- | M] () – C:\Documents and Settings\Owner\My Documents\otlist.jpg
[2009/04/22 13:31:38 | 00,086,016 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/22 12:57:35 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTListIt2.exe
[2009/04/22 08:38:46 | 35,309,745 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/04/22 03:27:15 | 00,017,763 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/04/21 15:32:17 | 00,013,030 | —- | M] () – C:\PDOXUSRS.NET
[2009/04/18 03:28:21 | 00,434,673 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/04/17 21:18:38 | 00,409,562 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/04/17 21:18:38 | 00,064,576 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/04/17 21:18:37 | 00,478,838 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/04/17 16:38:07 | 00,001,924 | -H– | M] () – C:\Documents and Settings\Owner\My Documents\Default.rdp
[2009/04/17 12:29:35 | 00,001,734 | —- | M] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk
[2009/04/17 10:22:55 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/04/16 03:11:52 | 00,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/04/16 03:04:08 | 00,000,680 | —- | M] () – C:\WINDOWS\win.ini
[2009/04/06 15:32:54 | 00,038,496 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/04/06 15:32:46 | 00,015,504 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/04/06 07:57:24 | 24,921,544 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\MRT.exe
[2009/04/03 22:16:48 | 00,130,100 | —- | M] () – C:\Documents and Settings\Owner\My Documents\2009_AVN_NOMINATIONS_11_25_08.pdf
[2009/03/31 16:50:52 | 00,097,280 | -HS- | M] () – C:\Documents and Settings\Owner\My Documents\Thumbs.db
[2009/03/27 14:47:39 | 00,000,701 | —- | M] () – C:\Documents and Settings\All Users\Desktop\FLV Player.lnk
[2009/03/27 14:30:41 | 00,001,636 | —- | M] () – C:\Documents and Settings\Owner\Desktop\CinemaForge.lnk
[2009/03/27 12:03:28 | 00,721,248 | —- | M] () – C:\Documents and Settings\Owner\My Documents\2008 baja 500 Map.pdf
[2009/03/27 11:35:42 | 00,001,170 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/03/27 10:28:16 | 00,000,694 | —- | M] () – C:\Documents and Settings\Owner\Desktop\HandBrake.lnk
[2009/03/27 10:10:46 | 00,050,777 | —- | M] () – C:\WINDOWS\System32\wdh.bin
[2009/03/26 23:58:38 | 01,203,922 | —- | M] () – C:\WINDOWS\System32\dllcache\sysmain.sdb
[2009/03/26 17:21:40 | 02,638,260 | -H– | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\IconCache.db

========== LOP Check ==========

[2009/04/17 10:22:51 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2005/04/13 10:27:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2008/11/14 12:42:53 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AOL
[2009/02/15 19:35:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2009/02/15 19:36:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/01/29 02:38:04 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg8
[2008/11/15 11:22:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2009/03/07 21:47:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2009/04/21 19:31:15 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google Updater
[2008/11/18 17:39:28 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HP
[2008/11/23 00:09:37 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HP Product Assistant
[2008/11/19 02:15:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\LogMeIn
[2009/04/17 10:22:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2008/11/13 22:27:49 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee
[2008/11/13 22:27:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\McAfee.com
[2008/11/25 22:57:20 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2008/11/14 12:51:48 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2009/01/08 10:30:46 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nero
[2008/11/13 22:00:02 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Prism Deploy
[2008/11/13 22:18:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Pure Networks
[2008/11/14 21:50:54 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\QuickTime
[2008/11/14 12:44:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Symantec
[2008/11/13 22:18:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2008/12/28 01:04:54 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2009/04/17 10:23:00 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Owner\Application Data
[2008/12/23 22:21:01 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Adobe
[2008/12/05 18:58:56 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AdobeUM
[2009/02/15 19:46:12 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Apple Computer
[2008/11/29 21:59:47 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AVGTOOLBAR
[2009/04/22 12:58:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\BitTorrent
[2008/11/15 11:22:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\CyberLink
[2009/04/22 16:22:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\DNA
[2009/04/10 11:18:55 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\FileZilla
[2009/03/27 10:30:46 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\HandBrake
[2008/12/08 10:54:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\HP
[2005/04/13 10:20:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Identities
[2008/12/12 13:50:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Macromedia
[2009/04/17 10:23:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Malwarebytes
[2008/11/13 22:27:48 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\McAfee
[2009/02/28 11:12:56 | 00,000,000 | –SD | M] – C:\Documents and Settings\Owner\Application Data\Microsoft
[2009/02/19 11:13:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Move Networks
[2009/01/07 11:54:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Mozilla
[2009/01/16 20:50:20 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Nero
[2008/11/13 22:27:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SampleView
[2005/04/13 10:43:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Sun
[2008/11/17 10:12:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Viewpoint
[2008/12/12 12:30:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Winamp
[2004/08/10 12:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/04/22 16:02:03 | 00,000,868 | —- | M] () – C:\WINDOWS\Tasks\Google Software Updater.job
[2009/04/22 16:01:36 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========

< End of report >
Trentk,

I need you to run the following scan: Eset Online Scanner

  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
Hi Tom. I ran the scan last night, here is the log: # version=4 # OnlineScanner.ocx=1.0.0.635 # OnlineScannerDLLA.dll=1, 0, 0, 79 # OnlineScannerDLLW.dll=1, 0, 0, 78 # OnlineScannerUninstaller.exe=1, 0, 0, 49 # vers_standard_module=4029 (20090422) # vers_arch_module=1.064 (20080214) # vers_adv_heur_module=1.066 (20070917) # EOSSerial=20a63c877062c147812c4c57bd864158 # end=finished # remove_checked=false # unwanted_checked=false # utc_time=2009-04-23 04:44:14 # local_time=2009-04-22 09:44:14 (-0700, US Mountain Standard Time) # country="United States" # osver=5.1.2600 NT Service Pack 3 # scanned=699570 # found=0 # scan_time=8720
Trentk,

Log looks good :D

Cleanup

  • Double click on OTListIt2 to run it.
  • Click on CleanUp!
  • When done, you will be prompted to restart your computer. Please restart your computer.



You need to create a new Clean restore point:

Click Start Menu > Run > copy and paste

%SystemRoot%\System32\restore\rstrui.exe

Press OK. Choose Create a Restore Point then click Next. Name it (something you'll remember) and click Create, when the confirmation screen shows the restore point has been created click Close.

Remove all previous Restore Points
Click Start Menu > Run > copy and paste

cleanmgr

You may be asked to choose drive. Choose C: At top, click on More Options tab. Click Clean up… button in the System Restore box. Click on Yes button. When finished, click on Cancel button to exit.

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Check "Hide file extensions for known file types."
Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
Check "Hide protected operating system files."
Click Apply, and then click OK.


The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI