Thanks oldman960 for the reply. I would have replied quicker but I was out of town for a few days. Below is the info requested from your instructions:
Malwarebytes' Anti-Malware 1.38
Database version: 2403
Windows 5.1.2600 Service Pack 3
7/10/2009 11:06:18 AM
mbam-log-2009-07-10 (11-06-18).txt
Scan type: Quick Scan
Objects scanned: 86194
Time elapsed: 7 minute(s), 58 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
********************************************************************************
******************
********************************************************************************
******************
OTL logfile created on: 7/10/2009 11:09:46 AM - Run 1
OTL by OldTimer - Version 3.0.6.5 Folder = C:\Documents and Settings\User\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.39 Gb Available Physical Memory | 69.53% Memory free
2.60 Gb Paging File | 2.08 Gb Available in Paging File | 79.80% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 40.40 Gb Free Space | 54.21% Space Free | Partition Type: NTFS
Drive D: | 279.47 Gb Total Space | 82.25 Gb Free Space | 29.43% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: NOSFERATU
Current User Name: User
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
PRC - C:\WINDOWS\System32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\Program Files\TVersity\Media Server\MediaServer.exe ()
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
PRC - C:\Program Files\Brownie\BrstsWnd.exe (brother)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\WINDOWS\System32\devldr32.exe (Creative Technology Ltd.)
PRC - C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
PRC - C:\Program Files\WiFiConnector\NintendoWFCReg.exe ()
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Brownie\brpjp04a.exe (brother)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
PRC - C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
PRC - C:\WINDOWS\System32\igfxsrvc.exe (Intel Corporation)
PRC - C:\Documents and Settings\User\Desktop\OTL.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (Apple Mobile Device [Auto | Running]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (avg8emc [Auto | Running]) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd [Auto | Running]) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Bonjour Service [Auto | Running]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (iPod Service [On_Demand | Running]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (NMSAccessU [Auto | Running]) – C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
SRV - (NVSvc [Auto | Running]) – C:\WINDOWS\System32\nvsvc32.exe (NVIDIA Corporation)
SRV - (Pml Driver HPZ12 [On_Demand | Stopped]) – C:\WINDOWS\System32\HPZipm12.exe (HP)
SRV - (TVersityMediaServer [Auto | Running]) – C:\Program Files\TVersity\Media Server\MediaServer.exe ()
SRV - (WinDefend [Auto | Running]) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (WMPNetworkSvc [Auto | Running]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (ASPI [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\ASPI32.sys (Adaptec)
DRV - (AvgLdx86 [System | Running]) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (ctljystk [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ctljystk.sys (Creative Technology Ltd.)
DRV - (E1000 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\e1000325.sys (Intel Corporation)
DRV - (emu10k [On_Demand | Running]) – C:\WINDOWS\System32\drivers\emu10k1m.sys (Creative Technology Ltd.)
DRV - (emu10k1 [On_Demand | Running]) – C:\WINDOWS\System32\drivers\ctlfacem.sys (Creative Technology Ltd.)
DRV - (gameenum [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HPZid412 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\HPZid412.sys (HP)
DRV - (HPZipr12 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\HPZipr12.sys (HP)
DRV - (HPZius12 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\HPZius12.sys (HP)
DRV - (ialm [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (nv [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (RT25USBAP [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\rt25usbap.sys (Ralink Technology Inc.)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sfman [On_Demand | Running]) – C:\WINDOWS\System32\drivers\sfmanm.sys (Creative Technology Ltd.)
DRV - (smwdm [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\smwdm.sys (Analog Devices, Inc.)
DRV - (USBAAPL [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\usbaapl.sys (Apple, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Bing"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "
http://en-US.start2.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.0.2
FF - prefs.js..extensions.enabledItems: {097d3191-e6fa-4728-9826-b533d755359d}:0.7.10
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5
FF - prefs.js..extensions.enabledItems: {0545b830-f0aa-4d7e-8820-50a4629a56fe}:3.9.2
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.6.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}:6.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}:6.0.14
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.07103010
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG8\Firefox [2009/06/18 10:49:56 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2008/12/13 20:12:10 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/07/01 19:23:02 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/07/10 01:01:52 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/07/10 01:01:51 | 00,000,000 | —D | M]
[2009/01/27 02:53:18 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\mozilla\Extensions
[2009/01/27 02:53:18 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\mozilla\Extensions\{6334D996-EA3E-4a0e-AA8D-15BA56B37241}
[2008/06/19 13:40:23 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/07/09 22:30:05 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\mozilla\Firefox\Profiles\q39s6nxh.default\extensions
[2009/05/28 10:01:04 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\mozilla\Firefox\Profiles\q39s6nxh.default\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
[2009/03/17 00:34:35 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\mozilla\Firefox\Profiles\q39s6nxh.default\extensions\{097d3191-e6fa-4728-9826-b533d755359d}
[2009/07/01 19:35:24 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\mozilla\Firefox\Profiles\q39s6nxh.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/04/10 13:01:08 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\mozilla\Firefox\Profiles\q39s6nxh.default\extensions\{c50ca3c4-5656-43c2-a061-13e717f73fc8}
[2009/04/16 22:30:34 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\mozilla\Firefox\Profiles\q39s6nxh.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/05/03 01:13:08 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\mozilla\Firefox\Profiles\q39s6nxh.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2008/07/14 23:16:04 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\mozilla\Firefox\Profiles\q39s6nxh.default\extensions\[removed]
[2009/06/26 21:07:06 | 00,002,164 | —- | M] () – C:\Documents and Settings\User\Application Data\Mozilla\FireFox\Profiles\q39s6nxh.default\searchplugins\bing.xml
[2009/07/09 22:30:05 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2009/07/10 01:01:51 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2007/12/04 22:56:56 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}
[2008/12/13 20:12:23 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
[2009/04/10 13:09:12 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/06/11 17:16:31 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
[2009/06/24 08:26:10 | 00,023,544 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/06/24 08:26:11 | 00,137,208 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2007/08/07 13:35:32 | 00,049,152 | —- | M] (Adobe Systems, Inc.) – C:\Program Files\mozilla firefox\plugins\np32dsw.dll
[2009/05/21 11:33:58 | 00,410,984 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeploytk.dll
[2009/02/06 12:44:28 | 01,447,296 | —- | M] (Microsoft Corporation) – C:\Program Files\mozilla firefox\plugins\npLegitCheckPlugin.dll
[2009/06/24 08:26:12 | 00,065,016 | —- | M] (mozilla.org) – C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2008/03/15 19:21:30 | 00,144,720 | —- | M] (RealNetworks, Inc.) – C:\Program Files\mozilla firefox\plugins\nppl3260.dll
[2009/06/05 21:44:30 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin.dll
[2009/06/05 21:44:30 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll
[2009/06/05 21:44:30 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll
[2009/06/05 21:44:31 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll
[2009/06/05 21:44:31 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll
[2009/06/05 21:44:31 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll
[2009/06/05 21:44:31 | 00,143,360 | —- | M] (Apple Inc.) – C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll
[2008/03/15 19:21:38 | 00,024,576 | —- | M] (RealNetworks, Inc.) – C:\Program Files\mozilla firefox\plugins\nprjplug.dll
[2008/03/15 19:21:26 | 00,081,920 | —- | M] (RealNetworks, Inc.) – C:\Program Files\mozilla firefox\plugins\nprpjplug.dll
[2009/06/24 06:27:00 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/06/24 06:27:00 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/06/24 06:27:00 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/06/24 06:27:00 | 00,002,344 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/06/24 06:27:00 | 00,002,371 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/06/24 06:27:00 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/06/24 06:27:00 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (318535 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 127.0.0.1 www.163ns.com
O1 - Hosts: 127.0.0.1 163ns.com
O1 - Hosts: 10928 more lines…
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx ()
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BrStsWnd] C:\Program Files\Brownie\BrstsWnd.exe (brother)
O4 - HKLM..\Run: [igfxhkcmd] C:\WINDOWS\System32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxpers] C:\WINDOWS\System32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [igfxtray] C:\WINDOWS\System32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [itype] C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\System32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O4 - HKCU..\Run: [PowerBar] File not found
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Run Nintendo Wi-Fi USB Connector Registration Tool.lnk = C:\Program Files\WiFiConnector\NintendoWFCReg.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_14.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll (Intertrust Technologies, Inc.)
O15 - HKLM\..Trusted Domains: 58 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 65 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://www.update.microsoft.com/windowsupd…b?1188597297246 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\intu-qt2008 {05E53CE9-66C8-4a9e-A99F-FDB7A8E7B596} - C:\Program Files\QuickTax 2008\ic2008pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O24 - Desktop Components:1 () -
http://gamercard.xbox.com/philscar.card
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/01/29 16:42:54 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{5d8c8b8e-279f-11de-9d02-000cf1bbc867}\Shell - "" = AutoRun
O33 - MountPoints2\{5d8c8b8e-279f-11de-9d02-000cf1bbc867}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{5d8c8b8e-279f-11de-9d02-000cf1bbc867}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
========== Files/Folders - Created Within 30 Days ==========
[2009/07/10 11:08:11 | 00,513,536 | —- | C] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
[2009/07/10 10:54:00 | 00,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\Malwarebytes
[2009/07/10 10:53:54 | 00,000,704 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/07/10 10:53:50 | 00,038,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/07/10 10:53:48 | 00,019,096 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/07/10 10:53:48 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/07/10 10:53:48 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/07/10 10:52:54 | 03,561,744 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\User\Desktop\mbam-setup.exe
[2009/07/10 10:20:32 | 00,265,216 | —- | C] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\TFC.exe
[2009/07/10 01:01:55 | 00,001,610 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/07/10 00:59:55 | 08,114,720 | —- | C] (Mozilla) – C:\Documents and Settings\User\Desktop\Firefox Setup 3.5.exe
[2009/07/03 22:13:24 | 00,000,000 | —D | C] – C:\WINDOWS\Performance
[2009/07/03 22:12:33 | 00,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\Microsoft Corporation
[2009/07/03 22:12:03 | 00,001,964 | —- | C] () – C:\Documents and Settings\User\Desktop\Windows 7 Upgrade Advisor Beta.lnk
[2009/07/03 22:11:59 | 00,000,000 | —D | C] – C:\Program Files\Microsoft Windows 7 Upgrade Advisor
[2009/07/03 21:58:54 | 06,567,936 | —- | C] () – C:\Documents and Settings\User\Desktop\Windows7UpgradeAdvisor.msi
[2009/07/02 21:59:56 | 00,023,561 | —- | C] () – C:\Documents and Settings\User\Desktop\fat32format.zip
[2009/07/02 12:45:38 | 00,000,000 | —D | C] – C:\Documents and Settings\User\Desktop\iTunesExport.UI-1.5
[2009/07/02 12:44:03 | 00,041,007 | —- | C] () – C:\Documents and Settings\User\Desktop\iTunesExport.UI-1.5.zip
[2009/07/01 19:06:01 | 01,089,593 | —- | C] () – C:\WINDOWS\System32\dllcache\ntprint.cat
[2009/07/01 19:02:50 | 00,000,000 | —D | C] – C:\WINDOWS\System32\XPSViewer
[2009/07/01 19:02:39 | 00,000,000 | —D | C] – C:\Program Files\MSBuild
[2009/07/01 19:02:15 | 00,000,000 | —D | C] – C:\Program Files\Reference Assemblies
[2009/07/01 19:01:12 | 00,597,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe
[2009/07/01 19:01:12 | 00,117,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\prntvpt.dll
[2009/07/01 19:01:12 | 00,089,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll
[2009/07/01 19:01:11 | 01,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpssvcs.dll
[2009/07/01 19:01:11 | 01,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpssvcs.dll
[2009/07/01 19:01:11 | 00,575,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpsshhdr.dll
[2009/07/01 19:01:11 | 00,575,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpsshhdr.dll
[2009/07/01 18:54:02 | 00,000,753 | —- | C] () – C:\Documents and Settings\User\Desktop\Shortcut to iexplore.exe.lnk
[2009/07/01 18:41:30 | 00,001,742 | —- | C] () – C:\Documents and Settings\User\Desktop\HijackThis.lnk
[2009/07/01 18:40:51 | 00,812,344 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\User\Desktop\HJTInstall.exe
[2009/07/01 10:29:40 | 01,839,104 | —- | C] () – C:\Documents and Settings\User\Desktop\memtest86+-2.11.iso
[2009/07/01 10:20:05 | 00,052,257 | —- | C] () – C:\Documents and Settings\User\Desktop\memtest86+-2.11.iso.zip
[2009/07/01 00:24:18 | 00,000,330 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/07/01 00:21:05 | 00,000,000 | —D | C] – C:\Program Files\Windows Defender
[2009/07/01 00:18:59 | 05,154,304 | —- | C] () – C:\Documents and Settings\User\Desktop\WindowsDefender.msi
[2009/07/01 00:17:40 | 00,897,920 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\User\Desktop\WGAPluginInstall.exe
[2009/07/01 00:01:09 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/06/30 00:48:39 | 00,000,000 | —D | C] – C:\Program Files\Lavasoft
[2009/06/28 19:10:05 | 00,000,000 | —D | C] – C:\Program Files\Western Digital Corporation
[2009/06/26 21:32:16 | 00,000,000 | —D | C] – C:\Documents and Settings\User\My Documents\CDBurnerXP Projects
[2009/06/26 21:32:16 | 00,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\Canneverbe_Limited
[2009/06/26 21:32:04 | 00,001,612 | —- | C] () – C:\Documents and Settings\All Users\Desktop\CDBurnerXP.lnk
[2009/06/26 21:32:03 | 00,000,000 | —D | C] – C:\Program Files\CDBurnerXP
[2009/06/26 21:29:47 | 03,211,338 | —- | C] (Canneverbe Limited ) – C:\Documents and Settings\User\Desktop\cdbxp_setup_4.2.4.1351.exe
[2009/06/26 21:16:20 | 08,114,720 | —- | C] (Mozilla) – C:\Documents and Settings\User\Desktop\Firefox Setup 3.5 RC 3.exe
[2009/06/19 23:37:39 | 00,000,151 | —- | C] () – C:\WINDOWS\wininit.ini
[2009/06/19 22:18:09 | 00,000,000 | R–D | C] – C:\Documents and Settings\User\Desktop\Audio_Video Tools
[2009/06/19 22:14:51 | 00,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\Regensoft
[2009/06/18 17:11:09 | 00,000,000 | —D | C] – C:\Documents and Settings\User\My Documents\Red Kawa
[2009/06/18 17:11:09 | 00,000,000 | —D | C] – C:\Documents and Settings\User\Application Data\Red Kawa
[2009/06/18 17:10:45 | 00,000,000 | —D | C] – C:\Program Files\Red Kawa
[2009/06/18 16:23:02 | 00,000,000 | —D | C] – C:\Documents and Settings\User\My Documents\Video Converter
[2009/06/18 16:23:02 | 00,000,000 | —D | C] – C:\Documents and Settings\User\Local Settings\Application Data\Video Converter
[2009/06/18 16:21:29 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\VideoConverter
[2009/06/11 17:16:29 | 00,148,888 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2009/06/11 17:16:29 | 00,144,792 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2009/06/11 17:16:29 | 00,144,792 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2009/03/06 22:39:59 | 00,000,145 | —- | C] () – C:\WINDOWS\BRVIDEO.INI
[2009/03/06 22:39:59 | 00,000,000 | —- | C] () – C:\WINDOWS\brmx2001.ini
[2009/03/06 22:39:34 | 00,000,114 | —- | C] () – C:\WINDOWS\System32\brlmw03a.ini
[2009/03/06 22:39:33 | 00,009,853 | —- | C] () – C:\WINDOWS\HL-2140.INI
[2009/03/06 22:38:52 | 00,000,426 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2009/03/06 22:25:45 | 00,000,315 | —- | C] () – C:\WINDOWS\Brownie.ini
[2009/02/05 19:26:56 | 00,116,736 | —- | C] () – C:\WINDOWS\System32\libsndfile-1.dll
[2009/01/25 16:10:48 | 00,179,200 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2009/01/08 18:01:22 | 00,629,760 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2008/08/12 18:32:06 | 03,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2008/08/12 18:32:05 | 00,007,680 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2008/08/12 18:32:05 | 00,000,547 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll.manifest
[2008/08/12 16:50:04 | 00,395,776 | —- | C] () – C:\WINDOWS\System32\libmplayer.dll
[2008/08/12 16:50:04 | 00,262,144 | —- | C] () – C:\WINDOWS\System32\TomsMoComp_ff.dll
[2008/08/12 16:50:04 | 00,112,640 | —- | C] () – C:\WINDOWS\System32\libmpeg2_ff.dll
[2008/08/12 16:50:03 | 02,255,360 | —- | C] () – C:\WINDOWS\System32\libavcodec.dll
[2008/08/12 15:16:36 | 00,000,038 | —- | C] () – C:\WINDOWS\avisplitter.ini
[2008/03/15 19:25:08 | 00,000,025 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2008/01/03 22:09:30 | 00,021,507 | —- | C] () – C:\WINDOWS\System32\piinged.dll
[2007/09/01 13:17:16 | 00,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2007/07/03 16:05:08 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2007/06/29 00:43:00 | 01,703,936 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2007/06/29 00:43:00 | 01,486,848 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2007/06/29 00:43:00 | 01,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2007/06/29 00:43:00 | 00,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2007/06/29 00:43:00 | 00,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2007/01/03 11:24:36 | 00,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/01/03 11:22:46 | 00,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/01/03 11:22:14 | 00,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2006/03/18 08:16:04 | 00,540,178 | —- | C] () – C:\WINDOWS\System32\x264vfw.dll
[2004/08/04 07:00:00 | 00,000,507 | —- | C] () – C:\WINDOWS\win.ini
[2004/08/04 07:00:00 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini
========== Files - Modified Within 30 Days ==========
[2009/07/10 11:08:21 | 00,513,536 | —- | M] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\OTL.exe
[2009/07/10 10:53:54 | 00,000,704 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/07/10 10:53:12 | 03,561,744 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\User\Desktop\mbam-setup.exe
[2009/07/10 10:32:26 | 00,000,330 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/07/10 10:32:23 | 00,000,434 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts.ics
[2009/07/10 10:31:36 | 00,001,374 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/07/10 10:30:46 | 00,000,315 | —- | M] () – C:\WINDOWS\Brownie.ini
[2009/07/10 10:29:53 | 00,178,842 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2009/07/10 10:29:22 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/07/10 10:29:19 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/07/10 10:20:40 | 00,265,216 | —- | M] (OldTimer Tools) – C:\Documents and Settings\User\Desktop\TFC.exe
[2009/07/10 01:01:55 | 00,001,610 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2009/07/10 01:00:56 | 08,114,720 | —- | M] (Mozilla) – C:\Documents and Settings\User\Desktop\Firefox Setup 3.5.exe
[2009/07/10 00:56:31 | 37,999,075 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/07/10 00:56:31 | 00,022,992 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/07/09 22:38:54 | 00,318,535 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2009/07/05 19:48:51 | 00,140,800 | —- | M] () – C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/07/04 20:16:49 | 00,000,038 | —- | M] () – C:\WINDOWS\avisplitter.ini
[2009/07/03 22:12:03 | 00,001,964 | —- | M] () – C:\Documents and Settings\User\Desktop\Windows 7 Upgrade Advisor Beta.lnk
[2009/07/03 22:06:32 | 00,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2009/07/03 21:59:08 | 06,567,936 | —- | M] () – C:\Documents and Settings\User\Desktop\Windows7UpgradeAdvisor.msi
[2009/07/02 22:00:01 | 00,023,561 | —- | M] () – C:\Documents and Settings\User\Desktop\fat32format.zip
[2009/07/02 12:44:09 | 00,041,007 | —- | M] () – C:\Documents and Settings\User\Desktop\iTunesExport.UI-1.5.zip
[2009/07/01 19:18:50 | 00,021,304 | —- | M] () – C:\Documents and Settings\User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/07/01 19:17:31 | 00,126,912 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/07/01 19:13:53 | 00,462,168 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/07/01 19:13:52 | 00,530,276 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/07/01 19:13:52 | 00,078,114 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/07/01 18:54:02 | 00,000,753 | —- | M] () – C:\Documents and Settings\User\Desktop\Shortcut to iexplore.exe.lnk
[2009/07/01 18:41:30 | 00,001,742 | —- | M] () – C:\Documents and Settings\User\Desktop\HijackThis.lnk
[2009/07/01 18:40:54 | 00,812,344 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\User\Desktop\HJTInstall.exe
[2009/07/01 10:20:09 | 00,052,257 | —- | M] () – C:\Documents and Settings\User\Desktop\memtest86+-2.11.iso.zip
[2009/07/01 00:19:00 | 05,154,304 | —- | M] () – C:\Documents and Settings\User\Desktop\WindowsDefender.msi
[2009/07/01 00:17:47 | 00,897,920 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\User\Desktop\WGAPluginInstall.exe
[2009/06/30 00:52:38 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/06/29 17:33:56 | 00,463,779 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/06/29 10:38:45 | 00,000,426 | —- | M] () – C:\WINDOWS\BRWMARK.INI
[2009/06/29 10:24:28 | 00,000,151 | —- | M] () – C:\WINDOWS\wininit.ini
[2009/06/29 08:56:07 | 00,308,658 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090709-223854.backup
[2009/06/27 21:19:00 | 00,000,318 | —- | M] () – C:\WINDOWS\tasks\HP DArC Task #Hewlett-Packard#7200#CN36I2C17SE0.job
[2009/06/26 21:32:04 | 00,001,612 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CDBurnerXP.lnk
[2009/06/26 21:29:56 | 03,211,338 | —- | M] (Canneverbe Limited ) – C:\Documents and Settings\User\Desktop\cdbxp_setup_4.2.4.1351.exe
[2009/06/26 21:16:32 | 08,114,720 | —- | M] (Mozilla) – C:\Documents and Settings\User\Desktop\Firefox Setup 3.5 RC 3.exe
[2009/06/19 22:24:08 | 00,308,658 | R— | M] () – C:\WINDOWS\System32\drivers\etc\hosts.20090629-085607.backup
[2009/06/18 10:49:10 | 00,027,784 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/06/17 11:27:56 | 00,038,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/06/17 11:27:44 | 00,019,096 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/06/11 16:50:24 | 00,327,688 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
========== LOP Check ==========
[2009/07/10 10:53:48 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/04/07 00:09:44 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2007/09/11 18:20:41 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CyberLink
[2009/06/18 18:10:16 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DVD Shrink
[2009/04/06 19:48:38 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intuit Canada
[2009/06/30 00:07:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/06/18 16:21:29 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\VideoConverter
[2009/07/10 10:54:00 | 00,000,000 | RH-D | M] – C:\Documents and Settings\User\Application Data
[2007/11/06 09:38:19 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\AccurateRip
[2009/03/06 22:55:45 | 00,000,000 | R–D | M] – C:\Documents and Settings\User\Application Data\Brother
[2009/06/26 21:32:16 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Canneverbe_Limited
[2009/07/04 20:47:30 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\com.zipeg
[2007/09/11 18:20:54 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\CyberLink
[2008/09/18 10:40:18 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\dBpoweramp
[2007/08/31 17:48:48 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\InterTrust
[2009/04/06 19:50:26 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Intuit Canada
[2008/07/15 00:04:52 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Move Networks
[2009/06/30 00:10:54 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\OpenOffice.org2
[2009/01/27 02:53:10 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Participatory Culture Foundation
[2009/03/08 16:04:02 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\PCF-VLC
[2009/06/18 17:11:09 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Red Kawa
[2009/06/19 22:14:51 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Regensoft
[2008/11/21 22:54:26 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\SystemRequirementsLab
[2007/09/02 18:55:58 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Thunderbird
[2009/04/12 15:20:45 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\U3
[2009/07/04 22:36:16 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\uTorrent
[2007/09/30 21:37:27 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Windows Desktop Search
[2009/05/21 22:14:35 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\Windows Live Writer
[2008/08/12 19:52:41 | 00,000,000 | —D | M] – C:\Documents and Settings\User\Application Data\WinFF
[2009/06/30 00:52:38 | 00,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2008/09/11 09:35:05 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2004/08/04 07:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/06/27 21:19:00 | 00,000,318 | —- | M] () – C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#7200#CN36I2C17SE0.job
[2008/05/27 20:04:48 | 00,000,298 | -H– | M] () – C:\WINDOWS\Tasks\Microsoft_Hardware_Launch_IType_exe.job
[2009/07/10 10:32:26 | 00,000,330 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2009/07/10 10:29:22 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >
********************************************************************************
******************
********************************************************************************
******************
OTL Extras logfile created on: 7/10/2009 11:09:46 AM - Run 1
OTL by OldTimer - Version 3.0.6.5 Folder = C:\Documents and Settings\User\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.39 Gb Available Physical Memory | 69.53% Memory free
2.60 Gb Paging File | 2.08 Gb Available in Paging File | 79.80% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 40.40 Gb Free Space | 54.21% Space Free | Partition Type: NTFS
Drive D: | 279.47 Gb Total Space | 82.25 Gb Free Space | 29.43% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: NOSFERATU
Current User Name: User
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger (Logitech Inc.)
C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 ()
C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger (Microsoft Corporation)
C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\QuickTime\QuickTimePlayer.exe:*:Enabled:QuickTime Player (Apple Inc.)
C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent ()
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger (Logitech Inc.)
C:\Program Files\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe:*:Enabled:Logitech Harmony Remote Software 7 ()
C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\World of Warcraft\WoW-1.12.0-enUS-downloader.exe:*:Enabled:Blizzard Downloader File not found
C:\Program Files\World of Warcraft\WoW-1.12.x-to-2.0.1-enUS-patch-downloader.exe:*:Enabled:Blizzard Downloader File not found
C:\Program Files\Participatory Culture Foundation\Miro\xulrunner\python\Miro_Downloader.exe:*:Enabled:Miro_Downloader File not found
C:\Program Files\Participatory Culture Foundation\Miro\Miro_Downloader.exe:*:Enabled:Miro_Downloader ()
C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour (Apple Inc.)
C:\Program Files\WiFiConnector\NintendoWFCReg.exe:*:Enabled:Nintendo Wi-Fi USB Connector ()
C:\Program Files\TVersity\Media Server\MediaServer.exe:*:Enabled:TVersity Media Server ()
C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger (Microsoft Corporation)
C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync (Microsoft Corporation)
C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes (Apple Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{184E7118-0295-43C4-B72C-1D54AA75AAF7}" = Windows Live Mail
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = Multimedia Launcher
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{2222B364-0854-4265-B32E-A142DB9DC7BB}" = Intel® PRO Network Connections [removed]
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 14
"{2CD2C0DB-81C3-416B-9FA6-589B9235359B}" = OpenOffice.org 2.4
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java™ SE Runtime Environment 6
"{345112D9-0930-4A68-AB71-A831BA5DE7AA}" = Microsoft IntelliType Pro 6.2
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3C52E7DA-C431-4239-B66B-1BF703D5B194}" = Windows Live Photo Gallery
"{4394DC3A-5DAC-4C80-A86E-FF462D0AD653}" = Windows 7 Upgrade Advisor Beta
"{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}" = Junk Mail filter update
"{4F50DB8D-3DA5-43CE-ADBB-4B5B862048A4}" = Logitech Harmony Remote
"{5C6F884D-680C-448B-B4C9-22296EE1B206}" = Logitech Harmony Remote Software 7
"{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail
"{659B48CD-0608-4ED5-94C0-0B6C87114F10}" = Apple Mobile Device Support
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer
"{70C592EC-AE9B-4734-928B-676E824FB41E}" = MFC RunTime files
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{8471021C-F529-43DE-84DF-3612E10F58C4}" = Remote Control USB Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
"{9284CACF-1859-4422-BD0C-46C0AF44765E}" = Brother HL-2140
"{9422C8EA-B0C6-4197-B8FC-DC797658CA00}" = Windows Live Sign-in Assistant
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A1BF9950-8CDB-468E-83FA-EACFB00EA7D5}" = Windows Live Sync
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AA0D2D5F-612B-45D3-8759-DA87206E5CC9}" = QuickTax 2008
"{B3EA8C67-C182-40E5-BCC7-6F132DA46AAD}" = Logitech Harmony Remote Software 7
"{B97CF5C3-0487-11D8-A36E-0050BAE317E1}" = DVD Solution
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C6CA8874-5F22-4AF0-9BE3-016BF299C536}" = Windows Live Essentials
"{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC5702D7-86E2-45A8-99D7-E8B976ADCC56}" = iTunes
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DDBB28C8-B2AA-45A1-8DCE-059A798509FB}" = MobileMe Control Panel
"{E40CE517-0D42-4198-96B4-C8232B257EB5}" = Data Lifeguard Diagnostic for Windows
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"Adobe Acrobat 5.0" = Adobe Acrobat 5.0
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"AVG8Uninstall" = AVG 8.5
"AviSynth" = AviSynth 2.5
"Bejeweled Deluxe 1.87" = Bejeweled Deluxe 1.87
"DVD Shrink_is1" = DVD Shrink 3.2
"ffdshow_is1" = ffdshow [rev 1723] [2007-12-24]
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"KLiteCodecPack_is1" = K-Lite Codec Pack 4.1.4 (Full)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Miro" = Miro
"Mozilla Firefox (3.5)" = Mozilla Firefox (3.5)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Nero - Burning Rom!UninstallKey" = Nero OEM
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"RealPlayer 6.0" = RealPlayer
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"SystemRequirementsLab" = System Requirements Lab
"TVersity Codec Pack" = TVersity Codec Pack 1.2
"TVersity Media Server " = TVersity Media Server 1.5 Beta
"Videora Xbox 360 Converter" = Videora Xbox 360 Converter 4.08
"WIC" = Windows Imaging Component
"WiFiConnector" = Nintendo Wi-Fi USB Connector Registration Tool
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinFF_is1" = WinFF 0.42
"WinLiveSuite_Wave3" = Windows Live Essentials
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XviD MPEG4 Video Codec" = XviD MPEG4 Video Codec (remove only)
"Zipeg" = Zipeg
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"uTorrent" = µTorrent
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 5/21/2009 11:09:45 PM | Computer Name = NOSFERATU | Source = MsiInstaller | ID = 10005
Description = Product: Windows Live Communications Platform – The installer has
encountered an unexpected error installing this package. This may indicate a problem
with this package. The error code is 2762. The arguments are: , ,
Error - 6/18/2009 5:28:02 PM | Computer Name = NOSFERATU | Source = Application Error | ID = 1000
Description = Faulting application videoconverter.exe, version 1.0.0.1, faulting
module unknown, version 0.0.0.0, fault address 0x00000023.
Error - 6/18/2009 5:35:25 PM | Computer Name = NOSFERATU | Source = Application Error | ID = 1000
Description = Faulting application videoconverter.exe, version 1.0.0.1, faulting
module unknown, version 0.0.0.0, fault address 0x00000023.
Error - 6/18/2009 10:51:09 PM | Computer Name = NOSFERATU | Source = Application Hang | ID = 1002
Description = Hanging application iTunes.exe, version 8.2.0.23, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 6/18/2009 10:52:22 PM | Computer Name = NOSFERATU | Source = Application Hang | ID = 1002
Description = Hanging application iTunes.exe, version 8.2.0.23, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 6/18/2009 10:54:35 PM | Computer Name = NOSFERATU | Source = Application Hang | ID = 1002
Description = Hanging application iTunes.exe, version 8.2.0.23, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 6/27/2009 1:34:46 AM | Computer Name = NOSFERATU | Source = Windows Search Service | ID = 3079
Description = Notifications for the volume d:\ are not active. Context: Windows
Application Details: The device is not ready. (0x80070015)
Error - 6/30/2009 1:49:27 AM | Computer Name = NOSFERATU | Source = Lavasoft Ad-Aware Service | ID = 0
Description =
Error - 7/2/2009 11:40:22 PM | Computer Name = NOSFERATU | Source = Application Hang | ID = 1002
Description = Hanging application iTunes.exe, version 8.2.0.23, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 7/10/2009 1:45:11 AM | Computer Name = NOSFERATU | Source = Application Error | ID = 1000
Description = Faulting application teatimer.exe, version 1.6.6.32, faulting module
teatimer.exe, version 1.6.6.32, fault address 0x0006e66e.
[ System Events ]
Error - 7/4/2009 7:43:21 PM | Computer Name = NOSFERATU | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the AVG Free8 E-mail Scanner
service to connect.
Error - 7/4/2009 7:43:21 PM | Computer Name = NOSFERATU | Source = Service Control Manager | ID = 7000
Description = The AVG Free8 E-mail Scanner service failed to start due to the following
error: %%1053
Error - 7/4/2009 7:43:34 PM | Computer Name = NOSFERATU | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Windows Media Player
Network Sharing Service service to connect.
Error - 7/4/2009 7:43:36 PM | Computer Name = NOSFERATU | Source = Service Control Manager | ID = 7000
Description = The Windows Media Player Network Sharing Service service failed to
start due to the following error: %%1053
Error - 7/5/2009 8:22:31 PM | Computer Name = NOSFERATU | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Windows Media Player
Network Sharing Service service to connect.
Error - 7/5/2009 8:22:35 PM | Computer Name = NOSFERATU | Source = Service Control Manager | ID = 7000
Description = The Windows Media Player Network Sharing Service service failed to
start due to the following error: %%1053
Error - 7/9/2009 11:10:08 PM | Computer Name = NOSFERATU | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Windows Media Player
Network Sharing Service service to connect.
Error - 7/9/2009 11:10:08 PM | Computer Name = NOSFERATU | Source = Service Control Manager | ID = 7000
Description = The Windows Media Player Network Sharing Service service failed to
start due to the following error: %%1053
Error - 7/10/2009 2:08:38 AM | Computer Name = NOSFERATU | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Windows Media Player
Network Sharing Service service to connect.
Error - 7/10/2009 2:08:38 AM | Computer Name = NOSFERATU | Source = Service Control Manager | ID = 7000
Description = The Windows Media Player Network Sharing Service service failed to
start due to the following error: %%1053
< End of report >