This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Win32/Gaelicum.A

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I done a malwarebytes scan…nothing found, scan log is attached.

Also attached is the HJT log…

AVG is constantly (and i mean CONSTANTLY) coming up with different exe files "infected" with this Gaelicum.A virus. Good old AVG has alread apparently deleted half the exe files from my nvidia folder and a bunch of game files exe's which i will need to reinstall. Now and again files called kht and khq (no file type endings at all on them, and 0kb in size) will appear on the desktop. I've had this problem before, and it was fixed in an earlier post in this forum however AVG didnt go nuts last time, now it is…constant pop ups.

Here is a screenshot to the last AVG pop up…

http://www.startrek-gamers.com/avg.jpg

I have went through the whole "self help" section as well for XP users.

Anyone got any ideas? Or is it just AVG going nuts on me?
Hi Victor1st, welcome to the forum.


To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.


Download OTListIt2 to your desktop.
  • Double click on OTList2.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

No need for a Hijackthis log this time.

Please decribe your computer's behavior at the moment.

Thanks
Hi :) Heres the results of the scan…

Contents of Extras.txt

OTListIt Extras logfile created on: 22/05/2009 06:27:26 - Run 1
OTListIt2 by OldTimer - Version 2.0.15.8 Folder = C:\Documents and Settings\Victor\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1023.48 Mb Total Physical Memory | 690.32 Mb Available Physical Memory | 67.45% Memory free
2.86 Gb Paging File | 2.29 Gb Available in Paging File | 80.21% Paging File free
Paging file location(s): C:\pagefile.sys 2000 2000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 77.34 Gb Free Space | 51.89% Space Free | Partition Type: NTFS
Drive D: | 298.02 Gb Total Space | 1.25 Gb Free Space | 0.42% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: VICTOR-3C104101
Current User Name: Victor
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"86:TCP" = 86:TCP:*:Enabled:BroadCam Web Server

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call (Microsoft Corporation)
C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent (BitTorrent, Inc.)
C:\Program Files\SecondLife\SLVoice.exe:*:Enabled:SLVoice ()
C:\Program Files\SecondLife\SecondLife.exe:*:Enabled:Second Life (Linden Lab)
C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\Curious Labs\Poser 6\Poser.exe:*:Enabled:Poser executable file (Curious Labs, Inc.)
C:\Program Files\Google\Google Talk\googletalk.exe:*:Enabled:Google Talk (Google)
C:\Program Files\Paltalk Messenger\paltalk.exe:*:Enabled:PaltalkScene (AVM Software Inc.)
C:\Program Files\SpacialAudio\SAMBC\SAMBC.exe:*:Enabled:SAMBC ()
C:\Program Files\GlobalSCAPE\CuteFTP 8 Professional\ftpte.exe:*:Enabled:FTP Transfer Engine (GlobalSCAPE Texas, LP.)
C:\Program Files\Mass Effect\Binaries\MassEffect.exe:*:Enabled:Mass Effect Game (BioWare)
C:\Program Files\Mass Effect\MassEffectLauncher.exe:*:Enabled:Mass Effect Launcher (BioWare)
C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call (Microsoft Corporation)
C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync (Microsoft Corporation)
C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger (Microsoft Corporation)
C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire (Lime Wire, LLC)
C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes (Apple Inc.)
C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath (Skype Technologies S.A.)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{0711500B-9912-4D60-9A49-C577B4503D42}" = Nero Recode Help
"{07FF7593-9DEA-40B5-9F87-F557E65BBF60}" = Nero Recode
"{0965D484-1777-4BA5-8C3A-095A6B0D2696}_is1" = Driver Sweeper 1.5.5
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{1122AAC4-AAAA-43BF-B2D4-3C8C12378952}" = Nero InfoTool
"{11A84FCA-C3C7-4AFD-A797-111DB8569DBC}" = Nero BurningROM
"{12345674-DE9A-677A-CCEE-666356D89777}" = Nero BurnRights
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR
"{1B040683-C390-4711-ABC7-DA8D85E470E7}" = NeroBurningROM
"{1B0FBB9A-995D-47cd-87CD-13E68B676E4F}" = Mass Effect
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk" = Google Talk (remove only)
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 11
"{297190A1-4B0D-4CD6-8B9F-3907F15C3FD8}" = Adobe CS4 American English Speech Analysis Models
"{2B6EC03E-6FA0-4D7C-9CCE-1B03819AB613}" = PerfectDisk 2008 Professional
"{2D3455A8-3B15-41A8-99F8-0D4215746463}" = Nero StartSmart
"{307F566E-3DCF-4A6C-A149-FE47F39A1BA4}_is1" = Power CD+G Player Pro
"{3097B151-1F61-4211-A4CC-D70127B226AE}" = SoundTrax
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3A4BEF94-179B-43DC-8380-76EEC6DB5EF4}" = TubeHunter Ultra
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3C52E7DA-C431-4239-B66B-1BF703D5B194}" = Windows Live Photo Gallery
"{3F30CC51-0788-487B-AA83-7214A239C0C0}" = Nero Disc Copy Gadget Help
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{4A5A427F-BA39-4BF0-9A47-9999FBE60C9F}" = Visual C++ Runtime for Dragon NaturallySpeaking
"{4AA3D64E-9EC3-4B0F-AB91-5885AC55641F}" = Microsoft Games for Windows - LIVE
"{4BC14A37-586A-4AB3-A458-874AAE29337C}" = Adobe Setup
"{4D42353B-533F-4306-AD0B-7FEF292ADE04}" = Nero CoverDesigner Help
"{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}" = Junk Mail filter update
"{4E8C27C2-D727-4C00-A90E-C3F6376EEE70}" = Nero ControlCenter
"{5285007a-039a-4e44-aa40-520829c28827}" = Nero 9
"{548F99E0-14CC-4D53-A7D6-4A62A5F2C748}" = Nero PhotoSnap
"{561968FD-56A1-49FD-9ED0-F55482C7C5BC}" = Adobe Media Encoder CS4 Exporter
"{566BB41D-F006-4956-A5D3-94D8DFFA7F51}" = Adobe Setup
"{56BE5CC9-95E6-4128-ABEA-968414CA9C80}" = DolbyFiles
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{5A62A775-A29A-4CE1-BBC2-4A9CD0B211EF}" = Nero Live Help
"{5AE12194-3EAA-40DF-B2BF-FE1D6B78BBF4}" = Nero Vision
"{5C2E8A0F-80E2-4C68-8CC0-D8D16E7196BF}" = Nero RescueAgent Help
"{5C42EAB8-54F9-423A-948C-1CBEF25F8DB4}" = Nero PhotoSnap Help
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.8
"{5C9BB0B3-E830-4814-BBA4-D93535E1C7B9}" = Nero Live
"{5EAD5443-7194-46CC-A055-428E6ABB1BAF}" = Adobe Encore CS4
"{5EFCBB42-36AB-4FF9-B90C-E78C7B9EE7B3}" = iTunes
"{60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}" = Adobe Dynamiclink Support
"{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail
"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7406DF60-016D-476B-A2C7-55D997592047}" = Adobe OnLocation CS4
"{75321954-2589-11DC-DDCC-E98356D81493}" = Nero DriveSpeed
"{753973C4-B961-43BF-B2D4-3C8C92F7216E}" = Nero DriveSpeed
"{7589edaa-b302-4d55-8c34-f3dabdd3b744}" = Nero 9 Trial
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{78523651-D8B1-11DC-CCEE-741589645873}" = Nero DiscSpeed
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA nTune
"{7D2370AC-D8E6-4996-986A-19824F8A167C}" = Logitech QuickCam
"{8186FF34-D389-4B7E-9A2F-C197585BCFBD}" = Adobe Media Encoder CS4 Importer
"{819E24AA-DB15-4BA8-8D76-92BDF710610B}" = Adobe Setup
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8C654BD0-1949-43DE-84F2-EC2A1ABB0CB4}" = Nero ShowTime
"{8EDBA74D-0686-4C99-BFDD-F894678E5102}" = Adobe Common File Installer
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{8FFC924C-ED06-44CB-8867-3CA778ECE903}" = Adobe Help Center 2.0
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90170409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office FrontPage 2003
"{91F34319-08DE-457a-99C0-0BCDFAC145B9}" = CuteFTP 8 Professional
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{943CC0C0-2253-4FE0-9493-DD386F7857FD}" = Nero Express
"{948FFAAE-C57F-447B-9B07-3721E950BFDC}" = Nero ShowTime
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{961D53EA-40DC-4156-AD74-25684CE05F81}" = Nero Installer
"{974C4B12-4D02-4879-85E0-61C95CC63E9E}" = Fallout 3
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{9A875B56-A35C-46BA-A3AA-DF8D03EE9F2F}" = Nero ControlCenter
"{9C48DCA4-00C2-449C-88D8-B1EE1692B44F}" = Safari
"{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}" = Microsoft Search Enhancement Pack
"{9F3523F8-DAD7-AE52-6DA7-45CDDDF33726}" = Advertising Center
"{9F8FDE1A-FA91-43F2-887B-CF080156D57E}" = Adobe Setup
"{A1BF9950-8CDB-468E-83FA-EACFB00EA7D5}" = Windows Live Sync
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A73BEC3C-40A0-480E-87EF-EFCD33629088}" = NeroExpress
"{A8399F58-234A-48C6-BA55-30C15738BF3C}" = Nero CoverDesigner
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AAA12554-2589-11DC-92EF-E98356D81493}" = Nero InfoTool
"{AABBCC54-D8B1-11DC-92EF-E98356D81493}" = Nero DiscSpeed
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{AE3D38A6-13B1-40B3-9423-D1FA9982FB6A}" = Adobe Bridge 1.0
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{AFA20D47-69C3-4030-8DF8-D37466E70F13}" = Apple Mobile Device Support
"{B095B0A4-50A5-46D7-9988-D038FEB040C0}" = Adobe Encore CS4 Library
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B169BC97-B8AA-4ACA-9CF2-9D0FF5BABDF7}" = Adobe Premiere Pro CS4 Functional Content
"{B21BDC7C-49A1-4155-9425-2F9DED3CD5ED}" = Adobe Setup
"{B2C12C8D-65DC-40BD-B309-5ADB0C6C8D8F}" = Nero WaveEditor
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B6F0BE9B-41D7-45A2-9A76-D3DB1A89EC6A}" = SnagIt 8
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B96C2601-52F5-4D5D-816A-63469EA311EF}" = "Nero SoundTrax Help
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{BCD82AB5-670D-4242-90FA-1F97103C16CD}" = Movie Templates - Starter Kit
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{BE9CEAAA-F069-4331-BF2F-8D350F6504F4}" = Adobe Media Encoder CS4 Additional Exporter
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{C6CA8874-5F22-4AF0-9BE3-016BF299C536}" = Windows Live Essentials
"{C938BE91-3BB5-4B84-9EF6-88F0505D0038}" = Adobe Premiere Pro CS4 Third Party Content
"{C99C89A3-119A-45E6-B26E-DD5643CAA0C5}" = Menu Templates - Starter Kit
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CD1826A5-CFCC-4C6E-9F9D-E181876162EA}" = Nero Rescue Agent
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}" = getPlus®
"{D499F8DE-3F31-4900-9157-61061613704B}" = Adobe Premiere Pro CS4
"{D642E38E-0D24-486C-9A2D-E316DD696F4B}" = Microsoft XML Parser
"{D7C206B6-1A63-4389-A8B1-8F607D0BFF1F}" = Nero StartSmart Help
"{DE3BB35E-C0CE-4CA1-9CB4-CD9E69364BD9}" = Adobe Premiere Pro CS4
"{DEB90B8E-0DCB-48CE-B90E-8842A2BD643E}" = Adobe Media Encoder CS4
"{E4A8DD87-A746-4443-BF25-CAF99CED6767}" = Nero Disc Copy Gadget
"{E86156E5-9859-440D-8876-26CED1349802}" = Nero WaveEditor Help
"{EA9FFE54-D8B1-11DC-92EF-E98356D81493}" = Nero BurnRights
"{EC68232E-C74E-4F1A-B296-DFD2E1944E10}" = Adobe Setup
"{EE353798-E875-42E0-B58D-7E6696182EA8}" = Adobe Media Encoder CS4 Dolby
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F53F6769-AC46-49E3-ABE3-2C8AFD39D0DD}" = Nero Vision
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FA17A726-B229-4116-B793-A2AB1A4EAE2E}" = Adobe Premiere Pro 2.0
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"{FB2A5FCC-B81B-48C2-A009-7804694D83E9}" = Adobe Encore CS4 Codecs
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"{FD052FB9-FE90-4438-B355-15EDC89D8FB1}" = Microsoft Games for Windows - LIVE Redistributable
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop 7.0.1" = Adobe Photoshop 7.0.1
"Adobe Premiere Pro 2.0" = Adobe Premiere Pro 2.0
"Adobe Shockwave Player" = Adobe Shockwave Player
"Adobe_0b36ff97a89684768f1da4defc9f237" = Adobe Encore CS4 Codecs
"Adobe_1f3d5fcc5fe78dc374b6ccbd2d399ba" = Adobe Encore CS4 Library
"Adobe_26b63376f4efc354dae41af6b5e3343" = Adobe Premiere Pro CS4
"Adobe_5eba9bbdf1514a06b1a4c79a2920188" = Adobe Media Encoder CS4 Exporter
"Adobe_6e02d32c7e5a9d9fc86bc91618cafda" = Adobe Premiere Pro CS4 Third Party Content
"Adobe_7774cb1e022c49962995a9014500066" = Adobe Media Encoder CS4 Importer
"Ask Toolbar_is1" = Ask Toolbar
"Audacity_is1" = Audacity 1.2.6
"AudioConSole" = Creative Audio Console
"AudioCS" = Creative Audio Console
"AVG8Uninstall" = AVG 8.5
"CCleaner" = CCleaner (remove only)
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"DAEMON Tools Toolbar" = DAEMON Tools Toolbar
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"Driver Genius Professional Edition 2007_is1" = Driver Genius Professional Edition 2007
"EPSON Printer and Utilities" = EPSON Printer Software
"exPressit S.E. 2.1" = exPressit S.E. 2.1
"Eye Candy 4000" = Eye Candy 4000
"Fallout 3 - The Pitt" = Fallout 3 - The Pitt
"Fallout 3: Operation Anchorage™" = Fallout 3: Operation Anchorage™
"Fraps" = Fraps (remove only)
"Google Updater" = Google Updater
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA nTune
"Karaoke Song List Creator" = Karaoke Song List Creator
"KLiteCodecPack_is1" = K-Lite Codec Pack 4.1.4 (Full)
"LimeWire" = LimeWire 5.1.2
"Magic Video Converter_is1" = Magic Video Converter Trial Version (English) 8.0.2.18
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.0.10)" = Mozilla Firefox (3.0.10)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"PalTalk8.2" = PaltalkScene
"Poser 6" = Poser 6
"RealPlayer 6.0" = RealPlayer
"RivaTuner" = RivaTuner v2.11
"SecondLife" = SecondLife (remove only)
"SecondLifeReleaseCandidate" = SecondLifeReleaseCandidate (remove only)
"SystemRequirementsLab" = System Requirements Lab
"Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2
"Tomb Raider: Underworld" = Tomb Raider: Underworld 1.0
"Trust Direct Webscan 19200 v1.0" = Trust Direct Webscan 19200 v1.0
"Tweak UI 2.10" = Tweak UI
"VLC media player" = VideoLAN VLC media player 0.8.6e
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Xvid_is1" = Xvid 1.2.1 final uninstall

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"bd3ec1dff3db8dd8" = SLBot
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 17/05/2009 04:10:26 | Computer Name = VICTOR-3C104101 | Source = nview_info | ID = 11141121
Description =

Error - 17/05/2009 04:10:26 | Computer Name = VICTOR-3C104101 | Source = nview_info | ID = 11141121
Description =

Error - 17/05/2009 04:10:26 | Computer Name = VICTOR-3C104101 | Source = nview_info | ID = 11141121
Description =

Error - 17/05/2009 17:52:38 | Computer Name = VICTOR-3C104101 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16791, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 17/05/2009 17:52:40 | Computer Name = VICTOR-3C104101 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16791, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 17/05/2009 18:22:41 | Computer Name = VICTOR-3C104101 | Source = Application Error | ID = 1000
Description = Faulting application paltalk.exe, version 9.93.3135.1004, faulting
module paltalk.exe, version 9.93.3135.1004, fault address 0x0020a6e2.

Error - 18/05/2009 03:03:00 | Computer Name = VICTOR-3C104101 | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16791, faulting
module unknown, version 0.0.0.0, fault address 0x03ce16cc.

Error - 18/05/2009 13:28:36 | Computer Name = VICTOR-3C104101 | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16791, faulting
module unknown, version 0.0.0.0, fault address 0x03c016cc.

Error - 18/05/2009 16:03:01 | Computer Name = VICTOR-3C104101 | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16791, faulting
module flash10b.ocx, version 10.0.22.87, fault address 0x001fe5eb.

Error - 21/05/2009 23:45:34 | Computer Name = VICTOR-3C104101 | Source = Application Error | ID = 1000
Description = Faulting application iexplore.exe, version 7.0.6000.16791, faulting
module sdhelper.dll, version 1.6.2.14, fault address 0x000051a0.

[ System Events ]
Error - 17/05/2009 21:08:38 | Computer Name = VICTOR-3C104101 | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\D.

Error - 17/05/2009 21:08:39 | Computer Name = VICTOR-3C104101 | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\D.

Error - 17/05/2009 21:08:40 | Computer Name = VICTOR-3C104101 | Source = atapi | ID = 262149
Description = A parity error was detected on \Device\Ide\IdePort0.

Error - 17/05/2009 21:08:40 | Computer Name = VICTOR-3C104101 | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\D.

Error - 18/05/2009 14:50:48 | Computer Name = VICTOR-3C104101 | Source = Service Control Manager | ID = 7000
Description = The NVR0FLASHDev service failed to start due to the following error:
%%2

Error - 18/05/2009 14:50:48 | Computer Name = VICTOR-3C104101 | Source = Service Control Manager | ID = 7000
Description = The PostgreSQL Database Server service failed to start due to the
following error: %%3

Error - 18/05/2009 14:55:52 | Computer Name = VICTOR-3C104101 | Source = Service Control Manager | ID = 7000
Description = The NVR0FLASHDev service failed to start due to the following error:
%%2

Error - 18/05/2009 14:55:52 | Computer Name = VICTOR-3C104101 | Source = Service Control Manager | ID = 7000
Description = The PostgreSQL Database Server service failed to start due to the
following error: %%3

Error - 21/05/2009 02:34:24 | Computer Name = VICTOR-3C104101 | Source = Service Control Manager | ID = 7000
Description = The NVR0FLASHDev service failed to start due to the following error:
%%2

Error - 21/05/2009 02:34:24 | Computer Name = VICTOR-3C104101 | Source = Service Control Manager | ID = 7000
Description = The PostgreSQL Database Server service failed to start due to the
following error: %%3


< End of report >




Contents of OTListIt.txt…

OTListIt logfile created on: 22/05/2009 06:27:26 - Run 1
OTListIt2 by OldTimer - Version 2.0.15.8 Folder = C:\Documents and Settings\Victor\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1023.48 Mb Total Physical Memory | 690.32 Mb Available Physical Memory | 67.45% Memory free
2.86 Gb Paging File | 2.29 Gb Available in Paging File | 80.21% Paging File free
Paging file location(s): C:\pagefile.sys 2000 2000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 77.34 Gb Free Space | 51.89% Space Free | Partition Type: NTFS
Drive D: | 298.02 Gb Total Space | 1.25 Gb Free Space | 0.42% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: VICTOR-3C104101
Current User Name: Victor
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
PRC - C:\Program Files\AVG\AVG8\avgam.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe (NVIDIA)
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe (Raxco Software, Inc.)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.)
PRC - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\WINDOWS\system32\CTHELPER.EXE (Creative Technology Ltd)
PRC - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Documents and Settings\Victor\Desktop\OTListIt2.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Adobe LM Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe (Adobe Systems)
SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (avg8emc [Auto | Running]) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd [Auto | Running]) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Creative Audio Engine Licensing Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (CTAudSvcService [Auto | Running]) – C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
SRV - (FLEXnet Licensing Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (getPlus® Helper [On_Demand | Stopped]) – C:\Program Files\NOS\bin\getPlus_HelperSvc.exe (NOS Microsystems Ltd.)
SRV - (gusvc [Auto | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (LVPrcSrv [Auto | Running]) – c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe (Logitech Inc.)
SRV - (LVSrvLauncher [Auto | Stopped]) – C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe (Logitech Inc.)
SRV - (MDM [Auto | Running]) – C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (Nero BackItUp Scheduler 4.0 [Auto | Running]) – C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (nTuneService [Auto | Running]) – C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe (NVIDIA)
SRV - (NVSvc [Auto | Running]) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (PD91Agent [Auto | Running]) – C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe (Raxco Software, Inc.)
SRV - (PD91Engine [On_Demand | Stopped]) – C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe (Raxco Software, Inc.)
SRV - (PD91VMDefrag [On_Demand | Stopped]) – C:\Program Files\Raxco\PerfectDisk2008\PD91VMDefrag.exe (Raxco Software, Inc.)
SRV - (PostgreSQL [Auto | Stopped]) – File not found
SRV - (SeaPort [Auto | Running]) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.)
SRV - (StarWindServiceAE [Auto | Running]) – C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (Rocket Division Software)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (61883 [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\61883.sys (Microsoft Corporation)
DRV - (ALCXWDM [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (AmdPPM [System | Running]) – C:\WINDOWS\system32\DRIVERS\AmdPPM.sys (Advanced Micro Devices)
DRV - (Avc [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\avc.sys (Microsoft Corporation)
DRV - (AvgLdx86 [System | Running]) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgRkx86 [Boot | Running]) – C:\WINDOWS\System32\Drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (CamDrL [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\Camdrl.sys (Logitech Inc.)
DRV - (COMMONFX [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\COMMONFX.SYS (Creative Technology Ltd)
DRV - (COMMONFX.SYS [On_Demand | Running]) – C:\WINDOWS\System32\drivers\COMMONFX.SYS (Creative Technology Ltd)
DRV - (ctac32k [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (ctaud2k [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (CTAUDFX [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\CTAUDFX.SYS (Creative Technology Ltd)
DRV - (CTAUDFX.SYS [On_Demand | Running]) – C:\WINDOWS\System32\drivers\CTAUDFX.SYS (Creative Technology Ltd)
DRV - (ctdvda2k [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\ctdvda2k.sys (Creative Technology Ltd)
DRV - (CTERFXFX [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\CTERFXFX.SYS (Creative Technology Ltd)
DRV - (CTERFXFX.SYS [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\CTERFXFX.SYS (Creative Technology Ltd)
DRV - (ctprxy2k [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (CTSBLFX [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\CTSBLFX.SYS (Creative Technology Ltd)
DRV - (CTSBLFX.SYS [On_Demand | Running]) – C:\WINDOWS\System32\drivers\CTSBLFX.SYS (Creative Technology Ltd)
DRV - (ctsfm2k [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (DefragFS [Boot | Running]) – C:\WINDOWS\System32\drivers\DefragFS.sys (Raxco Software, Inc.)
DRV - (emupia [On_Demand | Running]) – C:\WINDOWS\system32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (gameenum [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (GT680x [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\gt680x.sys ( )
DRV - (ha10kx2k [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (hap16v2k [On_Demand | Running]) – C:\WINDOWS\system32\drivers\hap16v2k.sys (Creative Technology Ltd)
DRV - (hap17v2k [On_Demand | Stopped]) – C:\WINDOWS\system32\drivers\hap17v2k.sys (Creative Technology Ltd)
DRV - (LVcKap [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\LVcKap.sys ()
DRV - (LVMVDrv [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\LVMVDrv.sys (Logitech Inc.)
DRV - (LVPr2Mon [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\LVPr2Mon.sys ()
DRV - (LVUSBSta [On_Demand | Running]) – C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (MSDV [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\msdv.sys (Microsoft Corporation)
DRV - (ms_mpu401 [On_Demand | Running]) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (nv [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (NVENETFD [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\NVENETFD.sys (NVIDIA Corporation)
DRV - (nvgts [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\nvgts.sys (NVIDIA Corporation)
DRV - (nvnetbus [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVR0Dev [On_Demand | Running]) – C:\WINDOWS\nvoclock.sys (NVidia Corp.)
DRV - (ossrv [On_Demand | Running]) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\PxHelp20.sys (Sonic Solutions)
DRV - (RivaTuner32 [On_Demand | Stopped]) – C:\Program Files\RivaTuner v2.11\RivaTuner32.sys ()
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sptd [Boot | Running]) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (SSHDRV76 [System | Running]) – C:\WINDOWS\system32\drivers\SSHDRV76.sys ()
DRV - (SVKP [Auto | Running]) – C:\WINDOWS\system32\SVKP.sys (AntiCracking)
DRV - (usbaudio [On_Demand | Running]) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.startrek-gamers.com/
IE - URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Ask"
FF - prefs.js..browser.search.order.1: "Ask"
FF - prefs.js..browser.search.selectedEngine: "Ask"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.startrek-gamers.com/"
FF - prefs.js..extensions.enabledItems: [removed]:1.3.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0
FF - prefs.js..extensions.enabledItems: {E9A1DEE0-C623-4439-8932-001E7D17607D}:[removed]
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10
FF - prefs.js..keyword.URL: "http://toolbar.ask.com/toolbarv/askRedirect?o=10591&gct;=&gc;=1&q;="

FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/02/01 03:23:04 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/02/01 03:48:10 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/04/29 23:48:41 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/04/29 23:48:41 | 00,000,000 | —D | M]

[2009/04/23 09:03:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor\Application Data\mozilla\Extensions
[2008/12/05 12:27:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/04/23 09:03:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor\Application Data\mozilla\Extensions\[removed]
[2009/05/21 17:22:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor\Application Data\mozilla\Firefox\Profiles\fhw30t2e.default\extensions
[2009/05/17 23:09:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor\Application Data\mozilla\Firefox\Profiles\fhw30t2e.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
[2009/02/24 12:24:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor\Application Data\mozilla\Firefox\Profiles\fhw30t2e.default\extensions\[removed]
[2009/05/17 23:23:18 | 00,000,681 | —- | M] () – C:\Documents and Settings\Victor\Application Data\Mozilla\FireFox\Profiles\fhw30t2e.default\searchplugins\ask.xml
[2009/05/21 17:22:32 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/04/29 23:48:41 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/07/30 19:53:30 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
[2009/02/01 03:23:17 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
[2009/04/29 23:48:22 | 00,023,032 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/04/29 23:48:22 | 00,134,648 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/04/29 23:48:35 | 00,001,538 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2009/04/29 23:48:36 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/04/29 23:48:36 | 00,000,947 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2009/04/29 23:48:36 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/04/29 23:48:36 | 00,000,759 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2009/04/29 23:48:36 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/04/29 23:48:36 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/04/29 23:48:36 | 00,000,831 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: (306008 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 127.0.0.1 www.163ns.com
O1 - Hosts: 127.0.0.1 163ns.com
O1 - Hosts: 10537 more lines…
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll (TechSmith Corporation)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - Reg Error: Key error. File not found
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (SnagIt) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll (TechSmith Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [CTHelper] CTHELPER.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start (InstallShield Software Corporation)
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install File not found
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SoundMan] SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKCU..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear (NVIDIA)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1100465 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; GTB6; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; OfficeLiveConnector.1.3; OfficeLivePatch.0.0)" -"http://homepages.paradise.net.nz/~trekker/policeboxes/tv1.html" (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\Victor\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 48 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} http://www.srtest.com/srl_bin/sysreqlab_srl.cab (System Requirements Lab Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/microsoftupdat…b?1231443949578 (WUWebControl Class)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx.com/player/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1231443937531 (MUWebControl Class)
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} http://www.nvidia.com/content/DriverDownlo…iaSmartScan.cab (NVIDIA Smart Scan)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} http://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab (get_atlcom Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - x-sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (Google Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/03/14 03:33:40 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (PDBoot.exe) - C:\WINDOWS\system32\PDBoot.exe (Raxco Software, Inc.)
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009/05/22 06:26:41 | 00,000,000 | —D | M]

========== Files/Folders - Created Within 30 Days ==========

[4 C:\WINDOWS\*.tmp files]
[2009/05/22 06:26:36 | 00,501,248 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Victor\Desktop\OTListIt2.exe
[2009/05/22 05:55:34 | 00,652,795 | —- | C] () – C:\Documents and Settings\Victor\Desktop\Snapshot_014.png
[2009/05/22 05:53:35 | 00,682,915 | —- | C] () – C:\Documents and Settings\Victor\Desktop\Snapshot_013.png
[2009/05/22 05:53:19 | 00,752,070 | —- | C] () – C:\Documents and Settings\Victor\Desktop\Snapshot_012.png
[2009/05/22 05:46:53 | 01,651,965 | —- | C] () – C:\Documents and Settings\Victor\Desktop\Snapshot_011.png
[2009/05/22 05:46:25 | 01,561,092 | —- | C] () – C:\Documents and Settings\Victor\Desktop\Snapshot_010.png
[2009/05/22 05:45:20 | 01,693,730 | —- | C] () – C:\Documents and Settings\Victor\Desktop\Snapshot_009.png
[2009/05/22 04:04:32 | 00,806,288 | —- | C] () – C:\Documents and Settings\Victor\Desktop\2628678624_6ea336b57c_o.png
[2009/05/22 04:01:35 | 00,907,179 | —- | C] () – C:\Documents and Settings\Victor\Desktop\2986484085_8ea8fc6a98_o.png
[2009/05/22 04:00:45 | 00,905,734 | —- | C] () – C:\Documents and Settings\Victor\Desktop\3045654259_f4b999f48e_o.png
[2009/05/22 03:48:30 | 00,306,139 | —- | C] () – C:\Documents and Settings\Victor\Desktop\rei_ayanami_plug_suit_by_Pixel_Reborn_1280x1024.jpg
[2009/05/22 03:45:15 | 00,911,494 | —- | C] () – C:\Documents and Settings\Victor\Desktop\2986483551_a7db5a4b39_o.png
[2009/05/22 02:40:14 | 06,629,814 | —- | C] () – C:\Documents and Settings\Victor\Desktop\untitledkk.bmp
[2009/05/22 02:18:23 | 03,235,254 | —- | C] () – C:\Documents and Settings\Victor\Desktop\untitled.bmp
[2009/05/22 01:38:46 | 00,739,869 | —- | C] () – C:\Documents and Settings\Victor\Desktop\Snapshot_008.png
[2009/05/22 01:36:10 | 01,142,373 | —- | C] () – C:\Documents and Settings\Victor\Desktop\Snapshot_007.png
[2009/05/22 01:35:39 | 01,163,418 | —- | C] () – C:\Documents and Settings\Victor\Desktop\Snapshot_006.png
[2009/05/22 01:34:54 | 00,726,963 | —- | C] () – C:\Documents and Settings\Victor\Desktop\Snapshot_005.png
[2009/05/22 01:26:41 | 00,746,117 | —- | C] () – C:\Documents and Settings\Victor\Desktop\Snapshot_004.png
[2009/05/22 01:26:02 | 01,104,499 | —- | C] () – C:\Documents and Settings\Victor\Desktop\Snapshot_003.png
[2009/05/22 01:25:57 | 01,155,337 | —- | C] () – C:\Documents and Settings\Victor\Desktop\Snapshot_002.png
[2009/05/22 01:24:42 | 00,814,919 | —- | C] () – C:\Documents and Settings\Victor\Desktop\Snapshot_001.png
[2009/05/21 19:45:16 | 00,248,452 | —- | C] () – C:\Documents and Settings\Victor\Desktop\cerulean.png
[2009/05/21 19:00:28 | 00,206,097 | —- | C] () – C:\Documents and Settings\Victor\Desktop\Untitled-1.psd
[2009/05/21 18:59:45 | 00,197,654 | —- | C] () – C:\Documents and Settings\Victor\Desktop\Celestial_Forms_Brushes_PS_by_Coby17_ps7.zip
[2009/05/21 08:08:35 | 01,578,616 | —- | C] () – C:\Documents and Settings\Victor\Desktop\2.wav
[2009/05/21 08:05:35 | 01,578,616 | —- | C] () – C:\Documents and Settings\Victor\Desktop\1.wav
[2009/05/21 08:00:05 | 00,789,344 | —- | C] () – C:\Documents and Settings\Victor\Desktop\take-off.wav
[2009/05/21 07:34:43 | 00,000,280 | —- | C] () – C:\WINDOWS\System32\PDBootState
[2009/05/21 05:59:02 | 00,388,908 | —- | C] () – C:\Documents and Settings\Victor\Desktop\Snapshot_046.png
[2009/05/21 04:33:41 | 00,682,727 | —- | C] () – C:\Documents and Settings\Victor\Desktop\Snapshot_045.png
[2009/05/20 23:00:18 | 01,578,616 | —- | C] () – C:\Documents and Settings\Victor\Desktop\03 - TARDIS take-off.wav
[2009/05/20 22:42:22 | 00,000,000 | —D | C] – C:\Documents and Settings\Victor\Desktop\DW30
[2009/05/20 22:36:05 | 88,579,340 | —- | C] () – C:\Documents and Settings\Victor\Desktop\DW30.rar
[2009/05/20 22:21:19 | 00,000,000 | —D | C] – C:\Documents and Settings\Victor\Desktop\Kinky Boots 2000
[2009/05/20 22:16:55 | 26,516,796 | —- | C] () – C:\Documents and Settings\Victor\Desktop\KB2000(2).rar
[2009/05/20 22:15:54 | 00,013,491 | —- | C] () – C:\Documents and Settings\Victor\Desktop\KB2000.rar
[2009/05/20 05:41:51 | 01,601,922 | —- | C] () – C:\Documents and Settings\Victor\Desktop\Snapshot_043.png
[2009/05/20 05:41:44 | 01,594,764 | —- | C] () – C:\Documents and Settings\Victor\Desktop\Snapshot_042.png
[2009/05/19 23:56:37 | 00,000,000 | —D | C] – C:\Documents and Settings\Victor\Desktop\Angels & Demons 2009 CAMRip AAC-SecretMyth (Kingdom-Release)
[2009/05/19 16:09:43 | 00,001,854 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2009/05/18 19:45:32 | 04,932,558 | —- | C] () – C:\WINDOWS\{00000005-00000000-00000008-00001102-00000004-20021102}.BAK
[2009/05/18 19:32:27 | 00,031,744 | -HS- | C] () – C:\Documents and Settings\Victor\My Documents\Thumbs.db
[2009/05/18 18:33:51 | 00,000,000 | —D | C] – C:\Documents and Settings\Victor\My Documents\SL Snaps
[2009/05/17 23:09:36 | 00,000,000 | —D | C] – C:\Program Files\AskBarDis
[2009/05/16 17:12:15 | 00,001,076 | —- | C] () – C:\WINDOWS\System32\settingsbkup.sfm
[2009/05/16 17:12:15 | 00,001,076 | —- | C] () – C:\WINDOWS\System32\settings.sfm
[2009/05/15 21:56:57 | 00,001,777 | —- | C] () – C:\Documents and Settings\Victor\Desktop\HijackThis.lnk
[2009/05/15 18:43:44 | 03,194,693 | —- | C] () – C:\Documents and Settings\Victor\My Documents\Fraps 2.9.4 Build 7037.rar
[2009/05/13 22:08:58 | 00,266,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\TweakUI.exe
[2009/05/13 22:08:58 | 00,160,217 | —- | C] () – C:\WINDOWS\System32\PowerToysLicense.rtf
[2009/05/13 07:34:45 | 00,000,000 | —D | C] – C:\Documents and Settings\Victor\My Documents\Stargate
[2009/05/04 02:44:17 | 00,476,517 | —- | C] () – C:\Documents and Settings\Victor\My Documents\aaa.mp3
[2009/04/30 07:58:23 | 00,030,528 | —- | C] () – C:\WINDOWS\System32\BMXCtrlState-{00000005-00000000-00000008-00001102-00000004-20021102}.rfx
[2009/04/30 07:58:23 | 00,030,528 | —- | C] () – C:\WINDOWS\System32\BMXBkpCtrlState-{00000005-00000000-00000008-00001102-00000004-20021102}.rfx
[2009/04/30 07:58:23 | 00,011,564 | —- | C] () – C:\WINDOWS\System32\DVCState-{00000005-00000000-00000008-00001102-00000004-20021102}.rfx
[2009/04/30 07:55:55 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Creative Labs Shared
[2009/04/30 07:55:26 | 04,932,558 | —- | C] () – C:\WINDOWS\{00000005-00000000-00000008-00001102-00000004-20021102}.CDF
[2009/04/30 07:20:53 | 00,000,000 | —D | C] – C:\Program Files\Realtek AC97
[2009/04/30 07:20:51 | 00,147,456 | —- | C] () – C:\WINDOWS\System32\RtlCPAPI.dll
[2009/04/30 06:27:38 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\nView_Profiles
[2009/04/28 20:59:24 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Games for Windows - LIVE
[2009/04/28 20:49:14 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Fallout3
[2009/04/28 20:49:11 | 00,000,000 | —D | C] – C:\Program Files\Bethesda Softworks
[2009/04/24 18:46:01 | 00,053,543 | —- | C] () – C:\Documents and Settings\Victor\My Documents\1.mp3
[2009/04/24 18:42:01 | 00,211,949 | —- | C] () – C:\Documents and Settings\Victor\My Documents\1111.mp3
[2009/04/23 00:11:31 | 00,031,056 | —- | C] () – C:\WINDOWS\System32\BMXStateBkp-{00000005-00000000-00000008-00001102-00000004-20021102}.rfx
[2009/04/23 00:11:31 | 00,031,056 | —- | C] () – C:\WINDOWS\System32\BMXState-{00000005-00000000-00000008-00001102-00000004-20021102}.rfx
[2009/04/23 00:10:36 | 00,215,383 | —- | C] () – C:\WINDOWS\System32\nvapps.xml
[2009/04/23 00:10:36 | 00,019,054 | —- | C] () – C:\WINDOWS\System32\nvdisp.nvu
[2009/04/23 00:10:36 | 00,000,000 | —D | C] – C:\WINDOWS\nview
[2009/04/23 00:01:56 | 00,109,080 | —- | C] (Portions © Creative Labs Inc. and NVIDIA Corp.) – C:\WINDOWS\System32\OpenAL32.dll
[2009/04/22 23:47:30 | 00,007,143 | —- | C] () – C:\WINDOWS\System32\nvide.nvu
[2009/04/22 23:46:24 | 00,004,984 | —- | C] () – C:\WINDOWS\System32\drivers\nvphy.bin
[2009/04/22 23:46:23 | 00,006,045 | —- | C] () – C:\WINDOWS\System32\nvnrm.nvu
[2009/04/22 23:45:32 | 00,000,000 | —D | C] – C:\NVIDIA
[2009/04/22 23:28:51 | 00,000,728 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Driver Sweeper.lnk
[2009/04/22 23:28:46 | 00,000,000 | —D | C] – C:\Program Files\Driver Sweeper
[2009/03/27 10:03:00 | 01,724,416 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2009/03/27 10:03:00 | 01,503,232 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2009/03/27 10:03:00 | 01,101,824 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2009/03/27 10:03:00 | 00,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2009/03/13 20:37:50 | 00,000,021 | —- | C] () – C:\WINDOWS\SurCode.INI
[2009/03/04 13:15:26 | 00,049,697 | —- | C] () – C:\WINDOWS\System32\instwdm.ini
[2009/03/04 13:15:24 | 00,000,054 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2009/03/04 12:47:28 | 00,043,520 | —- | C] () – C:\WINDOWS\System32\CTBurst.dll
[2009/03/04 12:46:18 | 00,010,752 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll
[2009/02/23 08:33:51 | 00,001,025 | —- | C] () – C:\WINDOWS\System32\sysprs7.dll
[2009/02/23 08:33:51 | 00,001,025 | —- | C] () – C:\WINDOWS\System32\clauth2.dll
[2009/02/23 08:33:51 | 00,001,025 | —- | C] () – C:\WINDOWS\System32\clauth1.dll
[2009/02/23 08:33:51 | 00,000,205 | —- | C] () – C:\WINDOWS\System32\lsprst7.dll
[2009/02/23 08:33:51 | 00,000,073 | —- | C] () – C:\WINDOWS\System32\ssprs.dll
[2009/01/08 20:53:46 | 00,000,346 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2008/12/27 02:59:59 | 00,053,760 | —- | C] () – C:\WINDOWS\System32\drivers\SSHDRV76.sys
[2008/12/16 18:24:59 | 00,000,000 | —- | C] () – C:\WINDOWS\ui.INI
[2008/12/16 18:21:49 | 00,017,504 | R— | C] ( ) – C:\WINDOWS\System32\drivers\gt680x.sys
[2008/12/16 18:03:43 | 00,000,000 | —- | C] () – C:\WINDOWS\WATCH.INI
[2008/11/16 09:58:53 | 00,004,757 | —- | C] () – C:\WINDOWS\Irremote.ini
[2008/10/28 17:40:48 | 00,173,552 | —- | C] () – C:\WINDOWS\System32\xlive.dll.cat
[2008/08/17 20:20:22 | 00,164,352 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2008/08/17 20:20:21 | 02,041,363 | —- | C] () – C:\WINDOWS\System32\x264vfw.dll
[2008/08/17 20:20:21 | 00,815,104 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2008/08/17 20:20:20 | 00,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2008/08/17 20:20:20 | 00,007,680 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2008/08/17 20:20:20 | 00,000,547 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll.manifest
[2008/07/30 18:37:47 | 00,000,221 | —- | C] () – C:\WINDOWS\NetViewer8ch.INI
[2008/07/05 22:50:20 | 00,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2008/06/14 19:09:05 | 00,717,296 | —- | C] () – C:\WINDOWS\System32\drivers\sptd.sys
[2008/03/21 00:27:32 | 00,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2008/03/19 03:41:08 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/03/15 10:05:34 | 00,000,038 | —- | C] () – C:\WINDOWS\AviSplitter.INI
[2008/03/14 04:37:09 | 00,000,026 | —- | C] () – C:\WINDOWS\System32\satsukidecodersettings.ini
[2008/02/21 03:05:44 | 03,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2007/09/27 11:51:02 | 00,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 11:48:48 | 00,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 11:48:28 | 00,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2007/08/13 20:45:02 | 00,077,824 | —- | C] () – C:\WINDOWS\System32\ctmmactl.dll
[2007/02/06 18:45:04 | 00,025,632 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2007/02/06 18:42:40 | 01,691,808 | —- | C] () – C:\WINDOWS\System32\drivers\Lvckap.sys
[2007/02/03 09:59:04 | 00,050,127 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2006/10/02 17:25:18 | 00,000,307 | —- | C] () – C:\WINDOWS\System32\kill.ini
[2003/01/07 15:05:08 | 00,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2001/08/23 14:00:00 | 00,000,603 | —- | C] () – C:\WINDOWS\win.ini
[2001/08/23 14:00:00 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini
[1998/06/12 11:38:06 | 00,095,232 | —- | C] () – C:\WINDOWS\System32\LFKODAK.DLL
[1998/06/12 11:38:04 | 00,306,688 | —- | C] () – C:\WINDOWS\System32\LFFPX7.DLL

========== Files - Modified Within 30 Days ==========

[11 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[2009/05/22 06:26:46 | 00,501,248 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Victor\Desktop\OTListIt2.exe
[2009/05/22 05:55:34 | 00,652,795 | —- | M] () – C:\Documents and Settings\Victor\Desktop\Snapshot_014.png
[2009/05/22 05:53:35 | 00,682,915 | —- | M] () – C:\Documents and Settings\Victor\Desktop\Snapshot_013.png
[2009/05/22 05:53:19 | 00,752,070 | —- | M] () – C:\Documents and Settings\Victor\Desktop\Snapshot_012.png
[2009/05/22 05:46:53 | 01,651,965 | —- | M] () – C:\Documents and Settings\Victor\Desktop\Snapshot_011.png
[2009/05/22 05:46:25 | 01,561,092 | —- | M] () – C:\Documents and Settings\Victor\Desktop\Snapshot_010.png
[2009/05/22 05:45:21 | 01,693,730 | —- | M] () – C:\Documents and Settings\Victor\Desktop\Snapshot_009.png
[2009/05/22 04:04:27 | 00,806,288 | —- | M] () – C:\Documents and Settings\Victor\Desktop\2628678624_6ea336b57c_o.png
[2009/05/22 04:01:31 | 00,907,179 | —- | M] () – C:\Documents and Settings\Victor\Desktop\2986484085_8ea8fc6a98_o.png
[2009/05/22 04:00:40 | 00,905,734 | —- | M] () – C:\Documents and Settings\Victor\Desktop\3045654259_f4b999f48e_o.png
[2009/05/22 03:48:23 | 00,306,139 | —- | M] () – C:\Documents and Settings\Victor\Desktop\rei_ayanami_plug_suit_by_Pixel_Reborn_1280x1024.jpg
[2009/05/22 03:45:08 | 00,911,494 | —- | M] () – C:\Documents and Settings\Victor\Desktop\2986483551_a7db5a4b39_o.png
[2009/05/22 02:40:14 | 06,629,814 | —- | M] () – C:\Documents and Settings\Victor\Desktop\untitledkk.bmp
[2009/05/22 02:18:25 | 03,235,254 | —- | M] () – C:\Documents and Settings\Victor\Desktop\untitled.bmp
[2009/05/22 01:38:46 | 00,739,869 | —- | M] () – C:\Documents and Settings\Victor\Desktop\Snapshot_008.png
[2009/05/22 01:36:10 | 01,142,373 | —- | M] () – C:\Documents and Settings\Victor\Desktop\Snapshot_007.png
[2009/05/22 01:35:39 | 01,163,418 | —- | M] () – C:\Documents and Settings\Victor\Desktop\Snapshot_006.png
[2009/05/22 01:34:54 | 00,726,963 | —- | M] () – C:\Documents and Settings\Victor\Desktop\Snapshot_005.png
[2009/05/22 01:26:41 | 00,746,117 | —- | M] () – C:\Documents and Settings\Victor\Desktop\Snapshot_004.png
[2009/05/22 01:26:02 | 01,104,499 | —- | M] () – C:\Documents and Settings\Victor\Desktop\Snapshot_003.png
[2009/05/22 01:25:57 | 01,155,337 | —- | M] () – C:\Documents and Settings\Victor\Desktop\Snapshot_002.png
[2009/05/22 01:24:43 | 00,814,919 | —- | M] () – C:\Documents and Settings\Victor\Desktop\Snapshot_001.png
[2009/05/21 22:59:57 | 00,001,159 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Second Life Release Candidate.lnk
[2009/05/21 22:35:22 | 00,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2009/05/21 21:12:33 | 36,309,322 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/05/21 19:45:17 | 00,248,452 | —- | M] () – C:\Documents and Settings\Victor\Desktop\cerulean.png
[2009/05/21 19:00:29 | 00,206,097 | —- | M] () – C:\Documents and Settings\Victor\Desktop\Untitled-1.psd
[2009/05/21 18:59:49 | 00,197,654 | —- | M] () – C:\Documents and Settings\Victor\Desktop\Celestial_Forms_Brushes_PS_by_Coby17_ps7.zip
[2009/05/21 09:40:24 | 00,058,917 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/05/21 08:08:35 | 01,578,616 | —- | M] () – C:\Documents and Settings\Victor\Desktop\2.wav
[2009/05/21 08:05:35 | 01,578,616 | —- | M] () – C:\Documents and Settings\Victor\Desktop\1.wav
[2009/05/21 08:00:05 | 00,789,344 | —- | M] () – C:\Documents and Settings\Victor\Desktop\take-off.wav
[2009/05/21 07:59:04 | 01,578,616 | —- | M] () – C:\Documents and Settings\Victor\Desktop\03 - TARDIS take-off.wav
[2009/05/21 07:35:13 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/05/21 07:34:43 | 00,000,280 | —- | M] () – C:\WINDOWS\System32\PDBootState
[2009/05/21 07:34:03 | 00,215,383 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2009/05/21 07:33:12 | 00,000,062 | -HS- | M] () – C:\Documents and Settings\Victor\Local Settings\desktop.ini
[2009/05/21 07:33:06 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/05/21 07:33:02 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/05/21 05:59:02 | 00,388,908 | —- | M] () – C:\Documents and Settings\Victor\Desktop\Snapshot_046.png
[2009/05/21 04:33:41 | 00,682,727 | —- | M] () – C:\Documents and Settings\Victor\Desktop\Snapshot_045.png
[2009/05/20 22:42:17 | 88,579,340 | —- | M] () – C:\Documents and Settings\Victor\Desktop\DW30.rar
[2009/05/20 22:18:49 | 26,516,796 | —- | M] () – C:\Documents and Settings\Victor\Desktop\KB2000(2).rar
[2009/05/20 22:15:57 | 00,013,491 | —- | M] () – C:\Documents and Settings\Victor\Desktop\KB2000.rar
[2009/05/20 05:41:51 | 01,601,922 | —- | M] () – C:\Documents and Settings\Victor\Desktop\Snapshot_043.png
[2009/05/20 05:41:45 | 01,594,764 | —- | M] () – C:\Documents and Settings\Victor\Desktop\Snapshot_042.png
[2009/05/19 16:09:43 | 00,001,854 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2009/05/19 12:13:02 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/05/18 19:52:28 | 00,031,056 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000005-00000000-00000008-00001102-00000004-20021102}.rfx
[2009/05/18 19:52:28 | 00,031,056 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000005-00000000-00000008-00001102-00000004-20021102}.rfx
[2009/05/18 19:52:28 | 00,030,528 | —- | M] () – C:\WINDOWS\System32\BMXCtrlState-{00000005-00000000-00000008-00001102-00000004-20021102}.rfx
[2009/05/18 19:52:28 | 00,030,528 | —- | M] () – C:\WINDOWS\System32\BMXBkpCtrlState-{00000005-00000000-00000008-00001102-00000004-20021102}.rfx
[2009/05/18 19:52:28 | 00,011,564 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000005-00000000-00000008-00001102-00000004-20021102}.rfx
[2009/05/18 19:52:16 | 04,932,558 | —- | M] () – C:\WINDOWS\{00000005-00000000-00000008-00001102-00000004-20021102}.CDF
[2009/05/18 19:52:16 | 04,932,558 | —- | M] () – C:\WINDOWS\{00000005-00000000-00000008-00001102-00000004-20021102}.BAK
[2009/05/18 19:46:28 | 00,001,076 | —- | M] () – C:\WINDOWS\System32\settingsbkup.sfm
[2009/05/18 19:46:28 | 00,001,076 | —- | M] () – C:\WINDOWS\System32\settings.sfm
[2009/05/18 19:32:29 | 00,031,744 | -HS- | M] () – C:\Documents and Settings\Victor\My Documents\Thumbs.db
[2009/05/15 21:56:57 | 00,001,777 | —- | M] () – C:\Documents and Settings\Victor\Desktop\HijackThis.lnk
[2009/05/15 21:39:22 | 01,945,560 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/05/15 20:12:52 | 00,000,219 | —- | M] () – C:\WINDOWS\System32\lsprst7.tgz
[2009/05/15 20:12:52 | 00,000,205 | —- | M] () – C:\WINDOWS\System32\lsprst7.dll
[2009/05/15 20:12:52 | 00,000,087 | —- | M] () – C:\WINDOWS\System32\ssprs.tgz
[2009/05/15 20:12:52 | 00,000,073 | —- | M] () – C:\WINDOWS\System32\ssprs.dll
[2009/05/15 20:12:51 | 00,000,021 | —- | M] () – C:\WINDOWS\SurCode.INI
[2009/05/15 18:43:46 | 03,194,693 | —- | M] () – C:\Documents and Settings\Victor\My Documents\Fraps 2.9.4 Build 7037.rar
[2009/05/15 18:43:29 | 00,000,531 | —- | M] () – C:\Documents and Settings\Victor\Desktop\Fraps.lnk
[2009/05/06 03:13:54 | 00,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2009/05/04 03:52:22 | 00,476,517 | —- | M] () – C:\Documents and Settings\Victor\My Documents\aaa.mp3
[2009/05/01 02:47:59 | 00,000,603 | —- | M] () – C:\WINDOWS\win.ini
[2009/05/01 02:47:59 | 00,000,281 | RHS- | M] () – C:\boot.ini
[2009/05/01 02:47:59 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2009/04/30 09:34:19 | 00,011,952 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/04/30 09:34:18 | 00,325,896 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/04/30 09:34:18 | 00,027,784 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/04/30 09:34:15 | 00,012,552 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgrkx86.sys
[2009/04/30 09:34:09 | 00,108,552 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/04/30 07:55:17 | 00,444,952 | —- | M] (Creative Labs) – C:\WINDOWS\System32\wrap_oal.dll
[2009/04/30 07:55:17 | 00,109,080 | —- | M] (Portions © Creative Labs Inc. and NVIDIA Corp.) – C:\WINDOWS\System32\OpenAL32.dll
[2009/04/24 18:53:15 | 00,211,949 | —- | M] () – C:\Documents and Settings\Victor\My Documents\1111.mp3
[2009/04/24 18:46:51 | 00,053,543 | —- | M] () – C:\Documents and Settings\Victor\My Documents\1.mp3
[2009/04/22 23:28:51 | 00,000,728 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Driver Sweeper.lnk

========== LOP Check ==========

[2009/04/30 06:27:38 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/03/24 14:05:50 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2009/04/07 16:34:33 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/03/14 14:58:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Adobe
[2008/03/14 06:21:21 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple
[2008/04/05 20:05:45 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2009/04/02 19:41:34 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg8
[2009/03/31 16:26:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\dscollect
[2009/04/28 20:49:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Fallout3
[2009/03/13 19:47:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FLEXnet
[2009/01/10 22:30:39 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google
[2009/05/21 17:57:45 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Google Updater
[2009/04/17 16:22:02 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\InstallShield
[2008/03/14 05:38:01 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Logishrd
[2008/03/14 05:38:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Logitech
[2009/01/22 22:29:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/04/30 07:12:26 | 00,000,000 | –SD | M] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2009/02/23 08:33:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Minnetonka Audio Software
[2008/12/07 20:27:18 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nero
[2008/08/04 18:10:26 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NOS
[2009/04/30 06:27:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\nView_Profiles
[2008/03/29 18:11:10 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Raxco
[2008/03/19 22:37:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Skype
[2009/05/18 19:42:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2009/04/15 20:26:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TechSmith
[2009/05/15 20:11:17 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/03/26 21:36:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Victor
[2008/03/14 04:26:54 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2008/03/19 22:18:40 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WLInstaller
[2009/04/21 18:27:31 | 00,000,000 | -H-D | M] – C:\Documents and Settings\Victor\Application Data
[2009/03/14 14:35:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor\Application Data\Adobe
[2008/08/16 01:52:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor\Application Data\Apple Computer
[2009/04/30 07:55:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor\Application Data\Creative
[2008/10/27 09:21:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor\Application Data\DAEMON Tools
[2008/04/05 15:37:55 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor\Application Data\DivX
[2008/03/17 21:54:49 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor\Application Data\GlobalSCAPE
[2008/03/14 05:46:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor\Application Data\Google
[2008/03/14 03:37:45 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor\Application Data\Identities
[2008/03/21 00:27:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor\Application Data\InstallShield
[2008/11/12 18:28:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor\Application Data\LegendCityOnline
[2009/05/16 18:37:30 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor\Application Data\LimeWire
[2008/09/10 06:49:45 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor\Application Data\Macromedia
[2009/01/22 22:29:57 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor\Application Data\Malwarebytes
[2008/03/14 04:37:30 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor\Application Data\Media Player Classic
[2009/04/21 18:35:24 | 00,000,000 | –SD | M] – C:\Documents and Settings\Victor\Application Data\Microsoft
[2008/12/05 12:27:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor\Application Data\Mozilla
[2008/11/16 14:45:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor\Application Data\Nero
[2008/08/17 20:30:09 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor\Application Data\NeroDigital™
[2009/03/31 01:34:07 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor\Application Data\OfficeUpdate12
[2008/07/20 03:46:31 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor\Application Data\Paltalk
[2009/03/13 15:57:23 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor\Application Data\Publish Providers
[2008/12/18 05:04:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor\Application Data\Real
[2009/05/07 21:50:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor\Application Data\SecondLife
[2008/10/27 09:36:40 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Victor\Application Data\SecuROM
[2009/05/03 22:26:25 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor\Application Data\Skype
[2009/05/03 21:57:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor\Application Data\skypePM
[2009/03/13 15:58:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor\Application Data\Sony
[2008/03/21 09:24:27 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor\Application Data\Sun
[2008/10/27 18:48:47 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor\Application Data\teamspeak2
[2009/05/21 07:29:12 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor\Application Data\uTorrent
[2008/03/25 18:59:10 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor\Application Data\vlc
[2009/02/01 04:04:54 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor\Application Data\Windows Desktop Search
[2009/03/31 01:30:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor\Application Data\Windows Live Writer
[2009/02/19 18:49:03 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor\Application Data\Windows Search
[2008/03/16 21:55:01 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor\Application Data\WinRAR
[2008/07/22 18:56:19 | 00,000,000 | —D | M] – C:\Documents and Settings\Victor\Application Data\Xilisoft Corporation
[2009/05/19 12:13:02 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2001/08/23 14:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/05/21 22:35:22 | 00,000,868 | —- | M] () – C:\WINDOWS\Tasks\Google Software Updater.job
[2009/05/21 07:33:06 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========


========== Alternate Data Streams ==========

@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:05EE1EEF
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:F35A93AD
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:888AFB86
< End of report >
Hi Victor1st,

You have a file infecter that an spread all drives on your computer including removable drives, so it is important to allow this tool to disinfect all drives.

Go here for
the tool download. Note there are 2 files to dwonload.
  • save both files to the same folder of your choice
  • disconnet from the internet
  • run the tool by double clicking rmgael.exe


After the tool has finished

Download OTScanit2 to your Desktop and double-click on it to extract the files. It will create a folder named OTS on your desktop.
  • Close ALL OTHER PROGRAMS.
  • Open the OTS folder and double-click on OTScanit.exe to start the program.
  • Check the box that says Scan All Users
  • Check the Radio button for Rootkit check YES
  • Under Additional Scans check the following:
    • File - Lop Check
    • File - Purity Scan
    • Evnt - EventViewer Errors/Warnings (last 10)
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Please attach the log in your next post.

To attach a file, do the following:
  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post

Note: if it is to large to attach then upload to Mediafire and post the sharing link in your next reply.

Thanks
Hi again :) I ran the scan and OTS, i couldnt find the rootkit rado button though? Anyway, the log is attached and the scan healed 9 infections, spread between the 2 main drives and the USB drive.

Attachments:

Hi Victor1st.

RootKit button-second box, second row :) unless the interface has changed.

Nothing of interest in OTL. How is the computer?

Are you connected to a network? This darn thing can spread across a network.


LimeWire
You have LimeWire, a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx

http://www.internetworldstats.com/articles…cles/art053.htm

I would recommend that you uninstall LimeWire, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.



You have some old vulnerable Java
  • Go to http://java.sun.com/javase/downloads/index.jsp
  • Scroll down to "Java Runtime Environment (JRE) 6 Update 13
  • Click the download button on the right.
If Information Bar pop-ups up, right-click on it and say it's OK to display the blocked content.
  • Select the platform (Windows, in your case), mutli language.
  • Accept the license agreement, click continue.
You do not have to install the Java Web Start ActiveX Control
  • Scroll down and click on Windows Offline Installation,
  • Save the file jre-6u13-windows-i586-p.exe to your desktop;
Do not select Run . Do not install it yet.

When the download is complete, close your browser.

Open Control Panel > Add/Remove Programs and uninstall
  • Java™ 6 Update 7
  • Java™ 6 Update 11
Do not uninstall Java TM 6 Update 13 if found! :yeah:

Reboot your computer.

  • Double-click on the saved file ( jre-6u13-windows-i586-p.exe) to install the update.
  • Delete the downloaded installation file after completing the above procedure and reboot if not prompted to do so.

Let me know how things are.

Thanks
Hi again :) It seems to have cleared it up, i always get that AVG pop up everyday and since the clean out, nothing :) PC seems to be loading IE faster too and ive updated Java. Thanks again!
Hi Victor1st,

Good to hear. Let's make sure nothing else got on board.

You will need to use Internet Explorer for this scan.
*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions.
  • You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computerr under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Change the Files of type to Text file (.txt)
  • Set the Save In to Desktop
  • click the Save button.
  • Please post this log in your next reply along with a new HijackThis log.

Please post back with
  • Kaspersky log
  • new HJT log

Thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI