This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Help, think I am about to crash!

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Our computer is operating extremely slow! We have AVG anti virus, COMOD Firewall running. However, we can not get SPYWAREBLASTER to complete a scan or SPYBOT SEARCH AND DESTROY to scan. The system really seems to be on the brink of crashing! We are running windows XP. Here is a copy of Hi-Jack this. I hope someone has some ideas.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:22:40 AM, on 7/5/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Verizon Online\Visual IP InSight\IPClient.exe
C:\Program Files\Comodo\Firewall\CPF.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\QuickTime\QTTask.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\taskmgr.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\msiexec.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [A Verizon App] C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
O4 - HKLM\..\Run: [IPInSightLAN 01] "C:\Program Files\Verizon Online\Visual IP InSight\IPClient.exe" -l
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - .DEFAULT User Startup: mod_sm.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: vzTCPConfig -
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1E2941E3-8E63-11D4-9D5A-00902742D6E0} (iNotes Class) - http://146.145.127.148/iNotes.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) -
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - http://mail.philaymca.org/iNotes6W.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} -
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase5483.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1237767327250
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} -
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} -
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1237767270703
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} -
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} -
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab32846.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {DB0474CC-8EF6-47FC-905B-23FC58A70817} -
O16 - DPF: {E93A6FCA-C052-45DF-AC9B-B729066092F8} -
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: Google Update Service (gupdate1c9d115998455f8) (gupdate1c9d115998455f8) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (file missing)
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O24 - Desktop Component 0: (no name) - C:\Program Files\Messenger\profsydy.html

–
End of file - 10957 bytes

Again, I hope someone can help out!

Happy 4th

Mark

Hello mbwenik,
Welcome to What the Tech.
My name is OCD, I will be helping you with your log today.

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

I am checking over your HijackThis log now, I will post back shortly with instructions.

mbwenik,

Please do not post on multiple forums as it puts a strain on the limited number of helpers available.
You must notify BC that you are already being helped here, and to close the log there.

- - - - - Next - - - - -

Please download ATF Cleaner by Atribune.
Download - http://www.nutnworks.com/downloads/ATF_Cleaner.exe

  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.

- - - - - Next - - - - -

Please download Malwarebytes' Anti-Malware from here or here

Double Click mbam-setup.exe to install the application.
  • Make sure a check mark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.< < Don't forget this!
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.
    (The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.)
  • Copy and Paste the entire report in your next reply.
- - - - - Next - - - - -

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
    You may need two posts to fit them both in.
- - - - - Next - - - - -

Reboot, on your next post please provide the following:
  • MBAM log
  • OTL logs (OTL.Txt & Extras.Txt
  • Tell me how your computer is running at the moment.

Here is the MBAM log

Malwarebytes' Anti-Malware 1.38
Database version: 2384
Windows 5.1.2600 Service Pack 2

7/6/2009 10:32:57 PM
mbam-log-2009-07-06 (22-32-57).txt

Scan type: Quick Scan
Objects scanned: 96073
Time elapsed: 25 minute(s), 54 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\Interface\{04a38f6b-006f-4247-ba4c-02a139d5531c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\xpre (Trojan.Downloader) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Here is OTL.Txt

OTL logfile created on: 7/6/2009 10:38:41 PM - Run 1
OTL by OldTimer - Version 3.0.6.5 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

503.36 Mb Total Physical Memory | 161.82 Mb Available Physical Memory | 32.15% Memory free
1.20 Gb Paging File | 0.58 Gb Available in Paging File | 48.25% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 107.53 Gb Total Space | 64.02 Gb Free Space | 59.54% Space Free | Partition Type: NTFS
Drive D: | 4.24 Gb Total Space | 0.66 Gb Free Space | 15.61% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PC1
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Comodo\Firewall\cmdagent.exe (COMODO)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
PRC - C:\Program Files\Comodo\Firewall\CPF.exe (COMODO)
PRC - C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\WINDOWS\System32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\taskmgr.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\SoftwareDistribution\Download\fa06e29c141c84f43a95ba02f93d3774\update\update.exe (Microsoft Corporation)
PRC - C:\Program Files\internet explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device [On_Demand | Stopped]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (avg8emc [Auto | Running]) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd [Auto | Running]) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Bonjour Service [Disabled | Stopped]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (CmdAgent [Auto | Running]) – C:\Program Files\Comodo\Firewall\cmdagent.exe (COMODO)
SRV - (gupdate1c9d115998455f8 [Auto | Stopped]) – C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (IntuitUpdateService [Auto | Stopped]) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (iPod Service [On_Demand | Stopped]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (KodakCCS [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\KodakCCS.exe (Eastman Kodak Company)
SRV - (Lavasoft Ad-Aware Service [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (LVCOMSer [Auto | Stopped]) – C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
SRV - (LVPrcSrv [Auto | Stopped]) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (NVSvc [Auto | Stopped]) – C:\WINDOWS\System32\nvsvc32.exe (NVIDIA Corporation)
SRV - (omniserv [Disabled | Stopped]) – C:\Program Files\Softex\OmniPass\Omniserv.exe ()
SRV - (Symantec Core LC [Disabled | Stopped]) – File not found
SRV - (Viewpoint Manager Service [Auto | Stopped]) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (ALCXWDM [On_Demand | Running]) – C:\WINDOWS\System32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (AvgLdx86 [System | Running]) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (CmdMon [System | Running]) – C:\WINDOWS\System32\DRIVERS\cmdmon.sys (Comodo Research Lab., Inc.)
DRV - (DcCam [System | Running]) – C:\WINDOWS\System32\DRIVERS\DcCam.sys (Eastman Kodak Company)
DRV - (DcFpoint [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\DcFpoint.sys (Eastman Kodak Company)
DRV - (DCFS2K [Auto | Running]) – C:\WINDOWS\System32\drivers\dcfs2k.sys (Eastman Kodak Company)
DRV - (DcLps [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\DcLps.sys (Eastman Kodak Company)
DRV - (DcPTP [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\DcPTP.sys (Eastman Kodak Company)
DRV - (Exportit [System | Stopped]) – C:\WINDOWS\System32\DRIVERS\exportit.sys (Eastman Kodak Company)
DRV - (fasttx2k [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\fasttx2k.sys (Promise Technology, Inc.)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (ialm [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (Inspect [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\inspect.sys (COMODO)
DRV - (Lbd [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (ltmodem5 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ltmdmnt.sys (LT)
DRV - (LVPr2Mon [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\LVPr2Mon.sys ()
DRV - (LVUSBSta [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (MREMPR5 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MREMPR5.sys (Motive, Inc.)
DRV - (MRENDIS5 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MRENDIS5.sys (Motive, Inc.)
DRV - (mrtRate [Auto | Running]) – C:\WINDOWS\System32\drivers\MrtRate.sys (Marimba, Inc.)
DRV - (nv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (nv_agp [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\nv_agp.sys (NVIDIA Corporation)
DRV - (pfc [On_Demand | Running]) – C:\WINDOWS\System32\drivers\pfc.sys (Padus, Inc.)
DRV - (PID_PEPI [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\LV302V32.SYS (Logitech Inc.)
DRV - (ppsio2 [Auto | Running]) – C:\WINDOWS\System32\drivers\ppsio2.sys ()
DRV - (Ps2 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\PS2.sys (Hewlett-Packard Company)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\PxHelp20.sys (Sonic Solutions)
DRV - (QCDonner [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\LVCD.sys (Logitech Inc.)
DRV - (rtl8139 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\R8139n51.SYS (Realtek Semiconductor Corporation )
DRV - (S3Psddr [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\s3gnbm.sys (S3 Graphics, Inc.)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SiS315 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\sisgrp.sys (Silicon Integrated Systems Corporation)
DRV - (SISAGP [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\SISAGPX.sys (Silicon Integrated Systems Corporation)
DRV - (StillCam [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\serscan.sys (Microsoft Corporation)
DRV - (USBIO [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\usbio.sys (Thesycon GmbH, Germany)
DRV - (viaagp1 [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (vnccom [Auto | Running]) – C:\WINDOWS\System32\Drivers\vnccom.SYS (RDV Soft)
DRV - (vncdrv [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\vncdrv.sys (RDV Soft)
DRV - ({6080A529-897E-4629-A488-ABA0C29B635E} [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\ialmsbw.sys (Intel Corporation)
DRV - ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91} [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\ialmkchw.sys (Intel Corporation)
DRV - (MBAMSwissArmy [On_Demand | Running]) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\System32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local



O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [COMODO Firewall Pro] C:\Program Files\Comodo\Firewall\CPF.exe (COMODO)
O4 - HKLM..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [NVIEW] C:\WINDOWS\System32\nview.DLL (NVIDIA Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowLegacyWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowUnhashedWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 36
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRunBackup = -1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FF FF FF FF [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disableregistrytools = 0
O8 - Extra context menu item: &AIM Search - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll (Sun Microsystems, Inc.)
O9 - Extra Button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll (AOL LLC)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O12 - Plugin for: .pdf - C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll (Adobe Systems Inc.)
O15 - HKLM\..Trusted Domains: 46 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: turbotax.com ([]https in Trusted sites)
O15 - HKCU\..Trusted Domains: 319 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E2941E3-8E63-11D4-9D5A-00902742D6E0} http://146.145.127.148/iNotes.cab (iNotes Class)
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} Reg Error: Value error. (Yahoo! Audio Conferencing)
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} http://mail.philaymca.org/iNotes6W.cab (iNotes6 Class)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc.cab (Office Update Installation Engine)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase5483.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/microsoftupdat…b?1237767327250 (WUWebControl Class)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1237767270703 (MUWebControl Class)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx (Get_ActiveX Control)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://zone.msn.com/binFramework/v10/ZIntro.cab32846.cab (ZoneIntro Class)
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA} http://java.sun.com/products/plugin/1.3.1/…-131_04-win.cab (Java Plug-in 1.3.1_04)
O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_04)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://active.macromedia.com/flash2/cabs/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DB0474CC-8EF6-47FC-905B-23FC58A70817} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {E93A6FCA-C052-45DF-AC9B-B729066092F8} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O16 - DPF: vzTCPConfig Reg Error: Value error. (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\OPXPGina: DllName - C:\Program Files\Softex\OmniPass\opxpgina.dll - C:\Program Files\Softex\OmniPass\opxpgina.dll ()
O24 - Desktop Components:0 () - C:\Program Files\Messenger\profsydy.html
O24 - Desktop Components:1 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/07/28 07:07:38 | 00,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2008/07/20 13:17:26 | 00,000,090 | —- | M] () - D:\AUTORUN.INF – [ FAT32 ]
O33 - MountPoints2\{4729c152-3c75-11dc-8af9-000c6e35d416}\Shell - "" = AutoRun
O33 - MountPoints2\{4729c152-3c75-11dc-8af9-000c6e35d416}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{4729c152-3c75-11dc-8af9-000c6e35d416}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[8 C:\WINDOWS\System32\*.tmp files]
[8 C:\WINDOWS\*.tmp files]
[2009/07/06 22:37:05 | 00,513,536 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2009/07/06 22:02:27 | 00,000,704 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/07/06 22:02:20 | 00,038,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/07/06 22:02:18 | 00,019,096 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/07/06 22:02:18 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/07/06 21:45:04 | 00,000,000 | —D | C] – C:\WINDOWS\System32\CatRoot_bak
[2009/07/06 21:31:32 | 00,000,000 | —D | C] – C:\WINDOWS\LastGood
[2009/07/05 09:34:38 | 00,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/07/05 09:34:21 | 00,064,160 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/07/05 09:31:09 | 00,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
[2009/07/05 09:31:07 | 00,000,875 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/07/05 00:18:08 | 00,001,742 | —- | C] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk
[2009/07/05 00:18:02 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/07/04 13:35:51 | 16,409,960 | —- | C] (Safer Networking Limited ) – C:\Documents and Settings\Owner\Desktop\setup-spybotsd162.exe
[2009/06/26 02:02:32 | 00,000,000 | -H-D | C] – C:\$AVG8.VAULT$
[2009/06/25 21:16:41 | 00,001,515 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG Free 8.5.lnk
[2009/06/25 21:16:39 | 00,108,552 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/06/25 21:16:39 | 00,011,952 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/06/25 21:16:38 | 00,335,752 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/06/25 21:16:21 | 37,774,500 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/06/25 21:16:21 | 00,463,779 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/06/25 21:16:21 | 00,012,796 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/06/25 21:16:20 | 06,061,540 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/06/25 21:16:20 | 00,000,000 | —D | C] – C:\WINDOWS\System32\drivers\Avg
[2009/06/25 21:15:58 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\avg8
[2009/06/25 21:13:38 | 00,000,000 | —D | C] – C:\Program Files\AVG
[2009/06/21 09:01:39 | 00,070,144 | —- | C] () – C:\Documents and Settings\Owner\My Documents\father's day.pub
[2009/06/19 15:18:09 | 00,020,992 | —- | C] () – C:\Documents and Settings\Owner\My Documents\oprah.doc
[2009/06/15 23:21:38 | 00,024,576 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Letter to Dr. Milrod.doc
[2009/06/15 22:34:11 | 00,024,064 | —- | C] () – C:\Documents and Settings\Owner\My Documents\June 15.doc
[2009/06/09 07:01:10 | 00,000,054 | -H– | C] () – C:\Documents and Settings\Owner\My Documents\~$y Saige Wenik.doc
[2009/06/08 17:05:31 | 00,549,564 | —- | C] () – C:\Documents and Settings\Owner\My Documents\PDRM0001.JPG
[2009/06/08 16:19:41 | 00,020,992 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Soy Saige Wenik.doc
[2008/10/23 07:52:51 | 00,000,032 | —- | C] () – C:\WINDOWS\ARC_CPR-AED-PR.ini
[2008/07/26 08:25:02 | 00,025,624 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2007/07/26 02:08:58 | 00,064,726 | -HS- | C] () – C:\WINDOWS\System32\dbjadjxg.ini
[2007/07/24 21:46:52 | 00,000,525 | -HS- | C] () – C:\WINDOWS\System32\maqxtjpo.ini
[2007/01/01 09:16:55 | 00,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2006/12/21 20:41:32 | 00,000,021 | —- | C] () – C:\WINDOWS\atid.ini
[2005/10/15 16:35:26 | 00,000,004 | —- | C] () – C:\WINDOWS\UccSpecB.sys
[2005/05/21 21:17:46 | 00,000,000 | —- | C] () – C:\WINDOWS\YIF05.INI
[2004/12/06 20:52:42 | 00,002,150 | —- | C] () – C:\WINDOWS\System32\ssmute.ini
[2004/10/02 16:57:54 | 00,000,169 | —- | C] () – C:\WINDOWS\magix.ini
[2004/10/02 16:57:53 | 00,000,919 | —- | C] () – C:\WINDOWS\mgxoschk.ini
[2004/09/11 10:04:35 | 00,000,074 | —- | C] () – C:\WINDOWS\lbbho.ini
[2004/09/04 08:59:22 | 00,000,036 | —- | C] () – C:\WINDOWS\TLCAPPS.INI
[2004/09/01 21:06:48 | 00,000,000 | —- | C] () – C:\WINDOWS\SETUP32.INI
[2004/07/26 08:01:55 | 00,000,045 | —- | C] () – C:\WINDOWS\Tlcpromo.ini
[2004/07/26 08:01:51 | 00,000,398 | —- | C] () – C:\WINDOWS\SBW95.ini
[2004/06/23 18:49:55 | 00,000,060 | —- | C] () – C:\WINDOWS\SIERRA.INI
[2004/06/23 17:38:30 | 00,000,383 | —- | C] () – C:\WINDOWS\ka.ini
[2004/06/06 09:21:37 | 00,086,030 | —- | C] () – C:\WINDOWS\System32\msdjgk.dll
[2004/05/16 15:26:07 | 00,001,890 | —- | C] () – C:\WINDOWS\7THLEVEL.INI
[2004/03/23 17:49:48 | 00,131,072 | —- | C] () – C:\WINDOWS\System32\sfarkxt.dll
[2004/03/23 17:49:47 | 00,068,096 | —- | C] () – C:\WINDOWS\System32\SFARKL.DLL
[2004/01/30 19:48:00 | 00,217,088 | —- | C] () – C:\WINDOWS\System32\libmySQL.dll
[2003/12/18 14:29:00 | 00,000,315 | —- | C] () – C:\WINDOWS\Belt.ini
[2003/12/09 13:16:52 | 00,442,368 | —- | C] ( ) – C:\WINDOWS\System32\comintfs.dll
[2003/12/07 15:45:53 | 00,061,440 | —- | C] () – C:\WINDOWS\System32\gl.dll
[2003/12/07 15:45:53 | 00,023,200 | —- | C] () – C:\WINDOWS\System32\drivers\ppsio2.sys
[2003/12/07 15:45:53 | 00,006,123 | —- | C] () – C:\WINDOWS\System32\e1.ini
[2003/11/08 09:33:15 | 00,010,301 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2003/09/18 23:09:16 | 00,000,024 | —- | C] () – C:\WINDOWS\qfnonl.ini
[2003/09/18 22:43:36 | 00,000,050 | —- | C] () – C:\WINDOWS\qwimp.ini
[2003/09/18 22:06:25 | 00,007,183 | —- | C] () – C:\WINDOWS\hpdj5100.ini
[2003/09/18 22:05:58 | 00,000,414 | —- | C] () – C:\WINDOWS\hpbvspst.ini
[2003/09/18 21:54:44 | 00,000,144 | —- | C] () – C:\WINDOWS\WININIT.INI
[2003/09/18 21:54:26 | 00,000,006 | —- | C] () – C:\WINDOWS\msoffice.ini
[2003/09/18 21:09:03 | 00,000,737 | —- | C] () – C:\WINDOWS\ODBC.INI
[2003/09/18 20:59:23 | 00,000,146 | —- | C] () – C:\WINDOWS\lotus.ini
[2003/09/18 20:23:16 | 00,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2003/05/31 14:29:50 | 00,019,968 | —- | C] () – C:\WINDOWS\System32\cpuinf32.dll
[2003/04/10 07:33:14 | 00,094,208 | —- | C] () – C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2003/04/10 07:33:14 | 00,077,824 | —- | C] () – C:\WINDOWS\System32\ProgressTrace.dll
[2003/04/10 07:10:20 | 00,167,936 | —- | C] () – C:\WINDOWS\System32\PCDrJNI_1_1.dll
[2003/04/10 07:08:02 | 00,024,576 | —- | C] () – C:\WINDOWS\System32\syscontr.dll
[2003/04/10 07:08:01 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2003/04/10 07:07:51 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/04/10 07:00:09 | 00,000,692 | —- | C] () – C:\WINDOWS\intuprof.ini
[2003/04/10 06:59:52 | 00,001,212 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2003/04/10 06:53:45 | 00,000,051 | —- | C] () – C:\WINDOWS\System32\mshrml.ini
[2003/04/10 06:36:30 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2003/04/10 06:16:02 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/04/10 06:06:11 | 00,299,073 | —- | C] () – C:\WINDOWS\System32\PythonCOM22.dll
[2003/04/10 06:06:11 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\PyWinTypes22.dll
[2003/04/10 06:05:46 | 00,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2003/04/10 05:53:32 | 00,000,802 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/04/10 05:37:43 | 00,000,552 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2003/04/10 05:37:23 | 00,000,698 | —- | C] () – C:\WINDOWS\win.ini
[2003/04/10 05:37:19 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini
[2003/04/10 03:08:18 | 00,000,438 | —- | C] () – C:\WINDOWS\System32\1_ssetup.ini
[2003/04/10 03:08:18 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\sunistlog.ini
[2002/06/10 15:16:22 | 00,066,482 | R— | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2000/09/08 18:53:50 | 00,073,839 | —- | C] () – C:\WINDOWS\System32\KodakOneTouch.dll
[1997/07/11 00:00:00 | 00,031,232 | —- | C] () – C:\WINDOWS\System32\XLREC.DLL
[1997/07/11 00:00:00 | 00,025,600 | —- | C] () – C:\WINDOWS\System32\RECNCL.DLL
[1997/07/11 00:00:00 | 00,022,016 | —- | C] () – C:\WINDOWS\System32\ODBCSTF.DLL
[1997/07/11 00:00:00 | 00,022,016 | —- | C] () – C:\WINDOWS\System32\DOCOBJ.DLL
[1997/07/11 00:00:00 | 00,012,288 | —- | C] () – C:\WINDOWS\System32\HLINKPRX.DLL
[1996/04/25 21:23:00 | 00,000,846 | —- | C] () – C:\WINDOWS\acroread.ini
[1996/02/22 21:23:00 | 00,222,928 | —- | C] () – C:\WINDOWS\System32\lobas09.dll
[1996/01/17 21:23:00 | 00,031,008 | —- | C] () – C:\WINDOWS\System32\ivtrn09.dll
[1996/01/15 21:23:00 | 00,334,016 | —- | C] () – C:\WINDOWS\System32\loflt09.dll
[1995/09/25 21:23:00 | 00,014,928 | —- | C] () – C:\WINDOWS\System32\wingen.drv
[1994/04/07 21:23:00 | 00,000,462 | —- | C] () – C:\WINDOWS\lodbf09.ini

========== Files - Modified Within 30 Days ==========

[8 C:\WINDOWS\System32\*.tmp files]
[8 C:\WINDOWS\*.tmp files]
[1 C:\Documents and Settings\Owner\My Documents\*.tmp files]
[2009/07/06 22:37:08 | 00,513,536 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2009/07/06 22:02:27 | 00,000,704 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/07/06 19:58:24 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/07/06 19:58:19 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/07/06 19:58:18 | 52,788,0192 | -HS- | M] () – C:\hiberfil.sys
[2009/07/06 09:38:03 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/07/06 00:00:00 | 00,000,622 | —- | M] () – C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - Owner.job
[2009/07/05 09:56:37 | 00,012,796 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/07/05 09:56:33 | 37,774,500 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/07/05 09:50:00 | 00,027,784 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/07/05 09:49:56 | 00,335,752 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/07/05 09:33:12 | 00,064,160 | —- | M] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/07/05 09:31:07 | 00,000,875 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/07/05 00:18:08 | 00,001,742 | —- | M] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk
[2009/07/04 23:26:13 | 00,463,779 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/07/04 13:44:35 | 00,000,941 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Spybot - Search & Destroy.lnk
[2009/07/04 13:36:22 | 16,409,960 | —- | M] (Safer Networking Limited ) – C:\Documents and Settings\Owner\Desktop\setup-spybotsd162.exe
[2009/07/04 10:18:03 | 00,002,265 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2009/07/04 08:19:11 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/06/30 22:25:57 | 00,001,212 | —- | M] () – C:\WINDOWS\QUICKEN.INI
[2009/06/26 19:40:29 | 00,000,698 | —- | M] () – C:\WINDOWS\win.ini
[2009/06/26 19:35:48 | 00,042,496 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/06/25 22:02:01 | 00,001,821 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2009/06/25 21:16:41 | 00,001,515 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG Free 8.5.lnk
[2009/06/25 21:16:39 | 00,108,552 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/06/25 21:16:39 | 00,011,952 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/06/25 21:16:21 | 06,061,540 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/06/23 20:28:31 | 01,108,116 | -H– | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\IconCache.db
[2009/06/21 09:01:40 | 00,070,144 | —- | M] () – C:\Documents and Settings\Owner\My Documents\father's day.pub
[2009/06/19 15:18:10 | 00,020,992 | —- | M] () – C:\Documents and Settings\Owner\My Documents\oprah.doc
[2009/06/17 13:07:58 | 00,004,752 | -H– | M] () – C:\IPH.PH
[2009/06/17 11:27:56 | 00,038,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/06/17 11:27:44 | 00,019,096 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/06/17 10:28:16 | 00,001,642 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AIM 6.lnk
[2009/06/15 23:37:32 | 00,024,576 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Letter to Dr. Milrod.doc
[2009/06/15 23:21:17 | 00,024,064 | —- | M] () – C:\Documents and Settings\Owner\My Documents\June 15.doc
[2009/06/13 23:24:20 | 14,456,832 | R— | M] () – C:\Documents and Settings\All Users\Documents\ESBK.mbb
[2009/06/13 23:23:55 | 10,537,984 | R— | M] () – C:\Documents and Settings\All Users\Documents\ESBK.mb
[2009/06/09 07:01:10 | 00,000,054 | -H– | M] () – C:\Documents and Settings\Owner\My Documents\~$y Saige Wenik.doc
[2009/06/08 17:10:43 | 00,020,992 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Soy Saige Wenik.doc

========== LOP Check ==========

[2009/07/05 09:31:09 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/03/25 22:59:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{63A9FDE6-FCC7-4E26-A4CF-552A08431B32}
[2009/07/05 09:31:18 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
[2009/05/28 21:37:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2008/11/02 18:42:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2008/03/28 22:13:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avery
[2008/06/01 19:48:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Fashion Solitaire 1.2
[2009/03/22 17:30:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intuit
[2009/05/13 22:30:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Logishrd
[2009/01/30 18:44:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MakeMusic
[2008/06/29 10:59:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Motive
[2003/12/11 21:37:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN Messenger 6.0.0602
[2003/10/07 18:38:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN6
[2004/09/06 14:24:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2003/04/10 05:54:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2009/07/04 23:28:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/02/13 17:50:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Verizon
[2009/06/17 10:28:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2003/10/07 18:34:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Visual Networks
[2009/05/09 22:19:46 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Owner\Application Data
[2006/12/22 18:05:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\acccore
[2009/06/25 22:16:35 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Aim
[2007/03/02 22:54:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Arcsoft
[2007/04/08 10:18:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\COWON
[2003/10/26 13:51:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Games
[2007/04/08 10:14:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\interMute
[2003/10/18 09:14:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\InterVideo
[2008/03/16 19:04:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Intuit
[2004/02/21 19:44:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Leadertech
[2005/01/07 23:21:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Lycos
[2008/02/13 17:57:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Motive
[2007/05/21 20:59:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Move Networks
[2008/02/13 15:56:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\MSN6
[2007/01/01 09:21:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Panasonic
[2008/03/06 21:25:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\QQ Games Plugin
[2004/10/26 19:57:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\rawh
[2004/09/06 14:21:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Roxio
[2003/04/10 07:08:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SampleView
[2007/04/22 08:28:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Snapfish
[2003/08/02 18:07:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Template
[2009/01/12 17:17:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\U3
[2003/06/19 15:08:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\VERITAS
[2008/02/13 17:50:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Verizon
[2007/07/23 09:04:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\WeatherBug
[2004/12/06 21:52:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\winjt
[2008/07/20 21:20:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\WinPatrol
[2009/07/06 09:38:03 | 00,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2009/07/04 08:19:11 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2002/08/29 15:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/07/06 00:00:00 | 00,000,622 | —- | M] () – C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Owner.job
[2009/07/06 19:58:24 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 144 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A988B257
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >

Here is Extras.Txt

OTL Extras logfile created on: 7/6/2009 10:38:41 PM - Run 1
OTL by OldTimer - Version 3.0.6.5 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

503.36 Mb Total Physical Memory | 161.82 Mb Available Physical Memory | 32.15% Memory free
1.20 Gb Paging File | 0.58 Gb Available in Paging File | 48.25% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 107.53 Gb Total Space | 64.02 Gb Free Space | 59.54% Space Free | Partition Type: NTFS
Drive D: | 4.24 Gb Total Space | 0.66 Gb Free Space | 15.61% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PC1
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"9051:UDP" = 9051:UDP:LocalSubNet:Enabled:Verizon Tech Wizard

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger (Logitech Inc.)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 (Microsoft Corporation)
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare ()
C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader (AOL LLC)
C:\Program Files\AIM6\aim6.exe:*:Enabled:AIM (AOL LLC)
C:\Program Files\TurboTax\Deluxe 2007\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax (Intuit, Inc.)
C:\Program Files\TurboTax\Deluxe 2007\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager (Intuit, Inc.)
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger (Yahoo! Inc.)
C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server (Yahoo! Inc.)
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe:LocalSubNet:Disabled:Intuit Update Shared Downloads Server (Intuit Inc.)
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger (Logitech Inc.)
C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour (Apple Inc.)
C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes (Apple Inc.)
C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe (AVG Technologies CZ, s.r.o.)
C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype (Skype Technologies S.A.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0008546E-DF6E-4CC1-AFD0-2CB8E16C95A2}" = Notifier
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{11B569C2-4BF6-4ED0-9D17-A4273943CB24}" = Adobe Photoshop Album 2.0 Starter Edition
"{14589F05-C658-4594-9429-D437BA688686}" = IntelliMover Data Transfer Demo
"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD
"{154508C0-07C5-4659-A7A0-E49968750D21}" = HLPPDOCK
"{1F7CCFA3-D926-4882-B2A5-A0217ED25597}" = PC-Doctor for Windows
"{216AB108-2AE1-4130-B3D5-20B2C4C80F8F}" = QuickTime
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{24D753CA-6AE9-4E30-8F5F-EFC93E08BF3D}" = Skype™ 4.0
"{25EF00A0-F17B-11D6-88EA-000476CD2443}(Verizon Online)" = Visual IP InSight(Verizon Online)
"{29521505-F489-4822-ADFA-32C6DEE4F114}" = TurboTax 2008 WinPerUserEducation
"{2A267BC6-F77F-4DD4-825F-7AEB1F68B4B1}" = HpSdpAppCoreApp
"{2CDCCE7E-55D5-40CC-AEA0-ABA54713501F}" = LUMIX Simple Viewer
"{2E7595EC-4FB1-4E29-93D4-9083C8A9B107}" = TurboTax ItsDeductible 2005
"{3248F0A8-6813-11D6-A77B-00B0D0150040}" = J2SE Runtime Environment 5.0 Update 4
"{3248F0A8-6813-11D6-A77B-00B0D0150060}" = J2SE Runtime Environment 5.0 Update 6
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{38441BE7-79B0-42B8-8297-833704F949FE}" = HLPIndex
"{3AF8FCCD-F51A-4014-9002-F195E1CBC876}" = Logitech QuickCam
"{3CA39B0C-BA85-4D42-AC0F-1FF5F60C3353}" = OTtBPSDK
"{3D047C15-C859-45F7-81CE-F2681778069B}" = iPod for Windows 2006-01-10
"{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}" = Google Earth
"{432C3720-37BF-4BD7-8E49-F38E090246D0}" = CR2
"{48BD24F5-13DE-493A-A7CE-28A85113FF0C}" = HP Deskjet printer preloaded drivers
"{48C82F7A-F100-4DAB-A310-8E18BF2159E1}" = ESSvpot
"{4F677FC7-7AA8-412B-A957-F13CBE1C7331}" = ESSSONIC
"{4FCC384C-18EA-4E25-9281-A06AE006D219}" = Weblink
"{54C8FE84-89C4-40E8-976C-439EB0729BD6}" = CardRd81
"{5EFCBB42-36AB-4FF9-B90C-E78C7B9EE7B3}" = iTunes
"{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA
"{60E80B13-8649-4A69-85E2-1AE99E061F43}" = ShowBiz DVD
"{643EAE81-920C-4931-9F0B-4B343B225CA6}" = ESSBrwr
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{71F6DF7D-B639-4FAD-BA93-E6DF267AA44D}" = DesignPro 5.4 Limited Edition
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7570F1CA-016D-46AC-B586-CD74645EFB52}" = TurboTax 2008 WinPerFedFormset
"{7DD9A065-2C86-4A9F-A5FF-796EC1B99DCA}" = AnswerWorks 4.0 Runtime - English
"{7E820A0C-8CD6-44A2-9963-A243B224CDB4}" = TurboTax 2008 wpaiper
"{87843A41-7808-4F2E-B13F-25C1E67CF2FD}" = ESShelp
"{88214092-836F-4E22-A5AC-569AC9EE6A0F}" = TurboTax 2008 WinPerReleaseEngine
"{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics 2 Driver
"{8BB4B58A-A402-4DE8-8FCD-287E60B88DD8}" = ESSCT
"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini
"{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
"{90190409-6000-11D3-8CFE-0050048383C9}" = Microsoft Publisher 2002
"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui
"{97AA0C55-AFAD-4126-B21C-F1318FB6DADA}" = Realtek RTL8139/810x Fast Ethernet NIC Driver Setup
"{98E8A2EF-4EAE-43B8-A172-74842B764777}" = InterVideo WinDVD Player
"{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL
"{9D8FEE90-0377-49A9-AEFB-525BDE549BA4}" = ESScore
"{9E5A03E3-6246-4920-9630-0527D5DA9B07}" = AnswerWorks 5.0 English Runtime
"{A0AF08BA-3630-4505-BFB2-A41F3837B0D0}" = SFR2
"{A0E27BA8-353A-4288-AB60-5DE8EDA18E16}" = Symantec Technical Support Web Controls
"{A5B3EB8A-4071-42F0-8E8E-7A8342AA8E69}" = ESSvpaht
"{A5CC2A09-E9D3-49EC-923D-03874BBD4C2C}" = Windows Defender Signatures
"{A8AD990E-355A-4413-8647-A9B168978423}_is1" = UltraVNC v1.0.2
"{A8B94669-8654-4126-BD28-D0D2412CDED6}" = TI Connect 1.6
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AADAC983-FDE9-42FA-8FD9-7BB324155593}" = HLPRFO
"{AC76BA86-7AD7-1033-7B44-A00000000001}" = Adobe Reader 6.0.1
"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK
"{AFA20D47-69C3-4030-8DF8-D37466E70F13}" = Apple Mobile Device Support
"{AFF1EA96-9C23-4249-B7D4-CD4B54D4582F}" = TurboTax ItsDeductible 2006
"{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}" = OfotoXMI
"{B1DB1AD8-C07E-4052-81A1-D2930232BA70}" = TurboTax 2008 wrapper
"{B23726CF-68BF-41A6-A4EB-72F12F87FE05}" = TurboTax 2008 WinPerTaxSupport
"{B376402D-58EA-45EA-BD50-DD924EB67A70}" = HP Memories Disc
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B43357AA-3A6D-4D94-B56E-43C44D09E548}" = Microsoft .NET Framework (English)
"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{B997C2A0-4383-41BF-B76E-9B8B7ECFB267}" = KSU
"{BBF7D230-8F25-4041-90A9-73FD03BE8640}" = DartViewer
"{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
"{CA60320D-6A16-49C8-A34F-84EEF4799567}" = ESSTUTOR
"{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software
"{D4936AAF-FFD0-44A1-A7EA-A2DB41CEB5BC}" = iPod for Windows 2005-09-23
"{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR
"{DBEA1034-5882-4A88-8033-81C4EF0CFA29}" = Google Toolbar for Internet Explorer
"{DC67641A-05C4-4FED-A462-1EB1DC6CF2F5}" = ArcSoft Software Suite
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E0828692-FD9D-459F-9312-C645C3CA6650}" = HP Photo and Imaging 2.0 - Deskjet Series
"{E6D9BC25-0DBC-4368-8E4A-7DEE80661CD9}" = TurboTax 2008 WinPerProgramHelp
"{EA2BEBD6-87B9-41E5-95AC-7E4C165A9475}" = WexTech AnswerWorks
"{EEF397AC-DAEF-4C04-90A9-5B2BD31875DC}" = Simple Installer - Multilanguage Version
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK
"{F4E57F49-84B4-4CF2-B0A1-8CA1752BDF7E}" = OmniPass
"{F61F2821-694C-475F-99AB-6AF2EFDF40FD}" = Quicken 2003 New User Edition
"{F71760CD-0F8B-4DCC-B7B7-6B223CC3843C}" = OTtBP
"{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS
"{FCDB1C92-03C6-4C76-8625-371224256091}" = ESSPDock
"{FDF9943A-3D5C-46B3-9679-586BD237DDEE}" = SKIN0001
"{FEDA56C4-82F3-46DD-8B50-FC592BBE1C0D}" = hp deskjet 5100
"{FEDE2483-87B7-44C1-A5BB-D75AEB8B6340}" = ESSEMAIL
"Action Replay Code Manager_is1" = Action Replay Code Manager
"Ad-Aware" = Ad-Aware
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Aim Plugin for QQ Games" = Aim Plugin for QQ Games
"AIM Toolbar" = AIM Toolbar 5.0
"AIM_6" = AIM 6
"AVG8Uninstall" = AVG Free 8.5
"BackWeb-1940576 Uninstaller" = Compaq Connections
"COMODO Firewall Pro" = COMODO Firewall Pro
"Google Chrome" = Google Chrome
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{3D047C15-C859-45F7-81CE-F2681778069B}" = iPod for Windows 2006-01-10
"InstallShield_{71F6DF7D-B639-4FAD-BA93-E6DF267AA44D}" = DesignPro 5.4 Limited Edition
"InstallShield_{831B265C-C203-4B72-A8F6-ECA1530957D3}" = LimeWire
"InstallShield_{D4936AAF-FFD0-44A1-A7EA-A2DB41CEB5BC}" = iPod for Windows 2005-09-23
"InstallShield_{F61F2821-694C-475F-99AB-6AF2EFDF40FD}" = Quicken 2003 New User Edition
"Instant Support" = Instant Support
"JRE 1.3.1_04" = Java 2 Runtime Environment Standard Edition v1.3.1_04
"KODAK Picture CD Volume 3 Issue 2" = KODAK Picture CD Volume 3 Issue 2
"LimeWire" = LimeWire 4.8.1
"lvdrivers_11.80" = Logitech QuickCam Driver Package
"Macromedia Shockwave Player" = Macromedia Shockwave Player
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework Full v1.0.3705 (1033)" = Microsoft .NET Framework (English) v1.0.3705
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"North Plainfield HS Directory 2005" = North Plainfield HS Directory 2005
"NVIDIA" = NVIDIA Windows 2000/XP Display Drivers
"PrimaScan 2400U" = PrimaScan 2400U
"PS2" = PS2
"Python 2.2 combined Win32 extensions" = Python 2.2 combined Win32 extensions
"RealPlayer 6.0" = RealOne Player
"Registry Mechanic_is1" = Registry Mechanic 7.0
"S3Display" = S3Display
"S3Gamma2" = S3Gamma2
"S3Info2" = S3Info2
"S3Overlay" = S3Overlay
"Shockwave" = Shockwave
"SmartMusic Content" = SmartMusic Content (shared music files)
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.4
"SpywareBlaster_is1" = SpywareBlaster 4.1
"TurboTax 2008" = TurboTax 2008
"TurboTax Deluxe 2003" = TurboTax Deluxe 2003
"TurboTax Deluxe 2004" = TurboTax Deluxe 2004
"TurboTax Deluxe 2005" = TurboTax Deluxe 2005
"TurboTax Deluxe 2007" = TurboTax Deluxe 2007
"TurboTax Deluxe Deduction Maximizer 2006" = TurboTax Deluxe Deduction Maximizer 2006
"ViewpointMediaPlayer" = Viewpoint Media Player
"VX2 Cleaner plug-in for Ad-Aware SE" = VX2 Cleaner plug-in for Ad-Aware SE
"Windows Live OneCare safety scanner" = Windows Live OneCare safety scanner
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 2
"WinPatrol" = WinPatrol 2008
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Messenger" = Yahoo! Messenger

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"ESPN Java Check" = ESPN Java Check
"GoToMeeting" = GoToMeeting 4.0.0.320
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 7/5/2009 7:30:00 AM | Computer Name = PC1 | Source = Google Update | ID = 20
Description =

Error - 7/5/2009 8:30:00 AM | Computer Name = PC1 | Source = Google Update | ID = 20
Description =

Error - 7/5/2009 9:32:01 AM | Computer Name = PC1 | Source = Lavasoft Ad-Aware Service | ID = 0
Description =

Error - 7/5/2009 10:16:33 AM | Computer Name = PC1 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 7.0.6000.16608, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 7/6/2009 5:21:48 PM | Computer Name = PC1 | Source = Google Update | ID = 20
Description =

Error - 7/6/2009 5:30:35 PM | Computer Name = PC1 | Source = Google Update | ID = 20
Description =

Error - 7/6/2009 6:30:33 PM | Computer Name = PC1 | Source = Google Update | ID = 20
Description =

Error - 7/6/2009 7:30:33 PM | Computer Name = PC1 | Source = Google Update | ID = 20
Description =

Error - 7/6/2009 8:06:48 PM | Computer Name = PC1 | Source = Google Update | ID = 20
Description =

Error - 7/6/2009 8:14:50 PM | Computer Name = PC1 | Source = Google Update | ID = 20
Description =

[ System Events ]
Error - 7/6/2009 7:59:49 PM | Computer Name = PC1 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.

Error - 7/6/2009 8:03:57 PM | Computer Name = PC1 | Source = Service Control Manager | ID = 7023
Description = The Computer Browser service terminated with the following error:
%%1460

Error - 7/6/2009 8:14:50 PM | Computer Name = PC1 | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 30 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)

Error - 7/6/2009 8:14:50 PM | Computer Name = PC1 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 29 minutes. NtpClient has no source of accurate
time.

Error - 7/6/2009 8:39:31 PM | Computer Name = PC1 | Source = Service Control Manager | ID = 7034
Description = The Viewpoint Manager Service service terminated unexpectedly. It
has done this 1 time(s).

Error - 7/6/2009 8:39:56 PM | Computer Name = PC1 | Source = Service Control Manager | ID = 7034
Description = The Intuit Update Service service terminated unexpectedly. It has
done this 1 time(s).

Error - 7/6/2009 8:42:30 PM | Computer Name = PC1 | Source = Service Control Manager | ID = 7034
Description = The LVCOMSer service terminated unexpectedly. It has done this 1
time(s).

Error - 7/6/2009 8:42:35 PM | Computer Name = PC1 | Source = Service Control Manager | ID = 7034
Description = The Process Monitor service terminated unexpectedly. It has done
this 1 time(s).

Error - 7/6/2009 8:44:50 PM | Computer Name = PC1 | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 60 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)

Error - 7/6/2009 8:44:50 PM | Computer Name = PC1 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 59 minutes. NtpClient has no source of accurate
time.


< End of report >

After rebooting, computer is slower now, to the point that it is basically unusable!

Any other suggestions?

Thank you and it really is appreciated!

Mark

mbwenik,

You have/had Limewire, a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/160500554
http://www.internetworldstats.com/articles/art053.htm

If you wish to keep it, please do not use it until your computer is cleaned.

I would recommend that you uninstall Limewire, however that choice is up to you.

- - - - - Next - - - - -

I see that Viewpoint is installed. Viewpoint, Viewpoint Manager, Viewpoint Media Player are Viewpoint components which are installed as a side effect of installing other software, most notably AOL and AOL Instant Messenger (AIM). Viewpoint Manager is responsible for managing and updating Viewpoint Media Player’s components. You can disable this using the Viewpoint Manager Control Panel found in the Windows Control Panel menu. By selecting Disable auto-updating for the Viewpoint Manager – the player will no longer attempt to check for updates. Anything that is installed without your consent is suspect. Read what Viewpoint says and make your own decision.

To provide a satisfying consumer experience and to operate effectively, the Viewpoint Media Player periodically sends information to servers at Viewpoint. Each installation of the Viewpoint Media Player is identifiable to Viewpoint via a Customer Unique Identifier (CUID), an alphanumeric identifier embedded in the Viewpoint Media Player. The Viewpoint Media Player randomly generates the CUID during installation and uses it to indicate a unique installation of the product. A CUID is never connected to a user's name, email address, or other personal contact information. CUIDs are used for the sole purpose of filtering redundant information. Each of these information exchanges occurs anonymously.

Viewpoint Manager is considered as foistware instead of malware since it is installed without user's approval but doesn't spy or do anything "bad".
This may change, read Viewpoint to Plunge Into Adware.
I recommend that you remove the Viewpoint products; however, decide for yourself.

- - - - - Next - - - - -

Scroll Down and locate the following programs:
  • Limewire
  • Viewpoint / Viewpoint Manager / Viewpoint Media Player
  • J2SE Runtime Environment 5.0 Update 4
  • J2SE Runtime Environment 5.0 Update 6
Select each one of the programs, then select remove.
(if the program is not listed don't be alarmed, just continue with the list)

Exit the Control Panel when finished.

- - - - - Next - - - - -

Please locate the folder in red and delete it and it's entire contents.
Be sure to delete the entire folder that is designated.
  • C:\Program Files\Viewpoint / Viewpoint Manager / Viewpoint Media Player (if you chose to remove it)
  • C:\Program Files\Limewire (if you chose to remove it)
Right click the file or folder, select Delete.

- - - - - Next - - - - -

Then download the latest version of Java , which is Version 6 Update 14, and click Yes at the page warning. Under "Platform" select Windows, then check the box to accept the License Agreement. Click Yes at the second page warning before downloading the Offline file.
There is no need to download the Sun Download manager but it is optional.

- - - - - Next - - - - -

Before you proceed with the next step please answer this question: Did you make these policy settings?

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present -

You or an administrator has set a policy which disables changing IE start page for the current user.

O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present -

You or an administrator has set a policy which restricts access to the 'Internet options' from within the IE or in the control panel.

  • If you did not set these policies, then please use the script in the code box below as shown.
  • If you did set these policies, then please remove the 06 and 07 lines from the code box below before running the OTL fix.
- - - - - Next - - - - -

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    SRV - (Viewpoint Manager Service [Auto | Stopped]) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O16 - DPF: {CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA} http://java.sun.com/products/plugin/1.3.1/…-131_04-win.cab (Java Plug-in 1.3.1_04)
    O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_04)
    O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
    O15 - HKLM\..Trusted Domains: 46 domain(s) and sub-domain(s) not assigned to a zone.
    O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
    O15 - HKCU\..Trusted Domains: turbotax.com ([]https in Trusted sites)
    O15 - HKCU\..Trusted Domains: 319 domain(s) and sub-domain(s) not assigned to a zone.
    O24 - Desktop Components:1 (My Current Home Page) - About:Home
    
    :Services
    
    :Reg
    
    :Files
    C:\WINDOWS\System32\dbjadjxg.ini
    C:\WINDOWS\System32\maqxtjpo.ini
    C:\WINDOWS\UccSpecB.sys
    C:\WINDOWS\YIF05.INI
    C:\WINDOWS\Belt.ini
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
- - - - - Next - - - - -

Reboot, on your next post please provide the following:
  • New OTL log (refer to previous post for directions, if necessary)
  • Tell me how your computer is running at the moment.

I removed all programs as suggested, including limewire. When I rebooted, the active desktop was disabled. Still running slow.

Here is log and at the end of the log, I have also listed all active processes.

OTL logfile created on: 7/7/2009 6:33:56 PM - Run 2
OTL by OldTimer - Version 3.0.6.5 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

503.36 Mb Total Physical Memory | 173.77 Mb Available Physical Memory | 34.52% Memory free
1.20 Gb Paging File | 0.71 Gb Available in Paging File | 59.29% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 107.53 Gb Total Space | 63.38 Gb Free Space | 58.94% Space Free | Partition Type: NTFS
Drive D: | 4.24 Gb Total Space | 0.66 Gb Free Space | 15.61% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PC1
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\Softex\OmniPass\OPXPApp.exe ()
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Comodo\Firewall\cmdagent.exe (COMODO)
PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\notepad.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
PRC - C:\WINDOWS\System32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
PRC - C:\Program Files\Comodo\Firewall\CPF.exe (COMODO)
PRC - C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\WINDOWS\System32\taskmgr.exe (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device [On_Demand | Stopped]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (avg8emc [Auto | Running]) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd [Auto | Running]) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Bonjour Service [Disabled | Stopped]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (CmdAgent [Auto | Running]) – C:\Program Files\Comodo\Firewall\cmdagent.exe (COMODO)
SRV - (gupdate1c9d115998455f8 [Auto | Stopped]) – C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (IntuitUpdateService [Auto | Running]) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (iPod Service [On_Demand | Stopped]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (KodakCCS [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\KodakCCS.exe (Eastman Kodak Company)
SRV - (Lavasoft Ad-Aware Service [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (LVCOMSer [Auto | Running]) – C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
SRV - (LVPrcSrv [Auto | Running]) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (NVSvc [Auto | Stopped]) – C:\WINDOWS\System32\nvsvc32.exe (NVIDIA Corporation)
SRV - (omniserv [Disabled | Stopped]) – C:\Program Files\Softex\OmniPass\Omniserv.exe ()
SRV - (Symantec Core LC [Disabled | Stopped]) – File not found
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (ALCXWDM [On_Demand | Running]) – C:\WINDOWS\System32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (AvgLdx86 [System | Running]) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (CmdMon [System | Running]) – C:\WINDOWS\System32\DRIVERS\cmdmon.sys (Comodo Research Lab., Inc.)
DRV - (DcCam [System | Running]) – C:\WINDOWS\System32\DRIVERS\DcCam.sys (Eastman Kodak Company)
DRV - (DcFpoint [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\DcFpoint.sys (Eastman Kodak Company)
DRV - (DCFS2K [Auto | Running]) – C:\WINDOWS\System32\drivers\dcfs2k.sys (Eastman Kodak Company)
DRV - (DcLps [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\DcLps.sys (Eastman Kodak Company)
DRV - (DcPTP [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\DcPTP.sys (Eastman Kodak Company)
DRV - (Exportit [System | Stopped]) – C:\WINDOWS\System32\DRIVERS\exportit.sys (Eastman Kodak Company)
DRV - (fasttx2k [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\fasttx2k.sys (Promise Technology, Inc.)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (ialm [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (Inspect [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\inspect.sys (COMODO)
DRV - (Lbd [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (ltmodem5 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ltmdmnt.sys (LT)
DRV - (LVPr2Mon [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\LVPr2Mon.sys ()
DRV - (LVUSBSta [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (MREMPR5 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MREMPR5.sys (Motive, Inc.)
DRV - (MRENDIS5 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MRENDIS5.sys (Motive, Inc.)
DRV - (mrtRate [Auto | Running]) – C:\WINDOWS\System32\drivers\MrtRate.sys (Marimba, Inc.)
DRV - (nv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (nv_agp [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\nv_agp.sys (NVIDIA Corporation)
DRV - (pfc [On_Demand | Running]) – C:\WINDOWS\System32\drivers\pfc.sys (Padus, Inc.)
DRV - (PID_PEPI [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\LV302V32.SYS (Logitech Inc.)
DRV - (ppsio2 [Auto | Running]) – C:\WINDOWS\System32\drivers\ppsio2.sys ()
DRV - (Ps2 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\PS2.sys (Hewlett-Packard Company)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\PxHelp20.sys (Sonic Solutions)
DRV - (QCDonner [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\LVCD.sys (Logitech Inc.)
DRV - (rtl8139 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\R8139n51.SYS (Realtek Semiconductor Corporation )
DRV - (S3Psddr [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\s3gnbm.sys (S3 Graphics, Inc.)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SiS315 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\sisgrp.sys (Silicon Integrated Systems Corporation)
DRV - (SISAGP [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\SISAGPX.sys (Silicon Integrated Systems Corporation)
DRV - (StillCam [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\serscan.sys (Microsoft Corporation)
DRV - (USBIO [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\usbio.sys (Thesycon GmbH, Germany)
DRV - (viaagp1 [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (vnccom [Auto | Running]) – C:\WINDOWS\System32\Drivers\vnccom.SYS (RDV Soft)
DRV - (vncdrv [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\vncdrv.sys (RDV Soft)
DRV - ({6080A529-897E-4629-A488-ABA0C29B635E} [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\ialmsbw.sys (Intel Corporation)
DRV - ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91} [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\ialmkchw.sys (Intel Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\System32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/07/07 18:10:31 | 00,000,000 | —D | M]


O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (&Google;) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [COMODO Firewall Pro] C:\Program Files\Comodo\Firewall\CPF.exe (COMODO)
O4 - HKLM..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [NVIEW] C:\WINDOWS\System32\nview.DLL (NVIDIA Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowLegacyWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowUnhashedWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 36
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRunBackup = -1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FF FF FF FF [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disableregistrytools = 0
O8 - Extra context menu item: &AIM; Search - Reg Error: Value error. File not found
O9 - Extra Button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll (AOL LLC)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O12 - Plugin for: .pdf - C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll (Adobe Systems Inc.)
O15 - HKLM\..Trusted Domains: 45 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: 319 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E2941E3-8E63-11D4-9D5A-00902742D6E0} http://146.145.127.148/iNotes.cab (iNotes Class)
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} Reg Error: Value error. (Yahoo! Audio Conferencing)
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} http://mail.philaymca.org/iNotes6W.cab (iNotes6 Class)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc.cab (Office Update Installation Engine)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase5483.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/microsoftupdat…b?1237767327250 (WUWebControl Class)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1237767270703 (MUWebControl Class)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx (Get_ActiveX Control)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://zone.msn.com/binFramework/v10/ZIntro.cab32846.cab (ZoneIntro Class)
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://active.macromedia.com/flash2/cabs/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DB0474CC-8EF6-47FC-905B-23FC58A70817} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {E93A6FCA-C052-45DF-AC9B-B729066092F8} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O16 - DPF: vzTCPConfig Reg Error: Value error. (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\OPXPGina: DllName - C:\Program Files\Softex\OmniPass\opxpgina.dll - C:\Program Files\Softex\OmniPass\opxpgina.dll ()
O24 - Desktop Components:0 () - C:\Program Files\Messenger\profsydy.html
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/07/28 07:07:38 | 00,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2008/07/20 13:17:26 | 00,000,090 | —- | M] () - D:\AUTORUN.INF – [ FAT32 ]
O33 - MountPoints2\{4729c152-3c75-11dc-8af9-000c6e35d416}\Shell - "" = AutoRun
O33 - MountPoints2\{4729c152-3c75-11dc-8af9-000c6e35d416}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{4729c152-3c75-11dc-8af9-000c6e35d416}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/07/07 18:16:03 | 00,000,000 | —D | C] – C:\_OTL
[2009/07/07 18:11:07 | 00,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2009/07/07 18:11:06 | 00,410,984 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deploytk.dll
[2009/07/07 18:11:05 | 00,148,888 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2009/07/07 18:11:05 | 00,144,792 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2009/07/07 18:11:04 | 00,144,792 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2009/07/06 22:37:05 | 00,513,536 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2009/07/06 22:02:27 | 00,000,704 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/07/06 22:02:20 | 00,038,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/07/06 22:02:18 | 00,019,096 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/07/06 22:02:18 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/07/06 21:45:04 | 00,000,000 | —D | C] – C:\WINDOWS\System32\CatRoot_bak
[2009/07/06 21:42:29 | 00,272,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bthport.sys
[2009/07/06 21:41:43 | 00,283,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pdh.dll
[2009/07/06 21:41:43 | 00,060,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\colbact.dll
[2009/07/06 21:41:41 | 00,473,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fastprox.dll
[2009/07/06 21:41:41 | 00,399,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rpcss.dll
[2009/07/06 21:41:41 | 00,227,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvse.exe
[2009/07/06 21:41:41 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\services.exe
[2009/07/06 21:41:40 | 00,453,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvsd.dll
[2009/07/06 21:41:39 | 00,616,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\advapi32.dll
[2009/07/06 21:41:37 | 00,714,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntdll.dll
[2009/07/06 21:40:50 | 00,331,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msadce.dll
[2009/07/06 21:37:45 | 00,215,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wordpad.exe
[2009/07/05 09:34:38 | 00,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/07/05 09:34:21 | 00,064,160 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/07/05 09:31:09 | 00,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
[2009/07/05 09:31:07 | 00,000,875 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/07/05 00:18:08 | 00,001,742 | —- | C] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk
[2009/07/05 00:18:02 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/07/04 13:35:51 | 16,409,960 | —- | C] (Safer Networking Limited ) – C:\Documents and Settings\Owner\Desktop\setup-spybotsd162.exe
[2009/06/26 02:02:32 | 00,000,000 | -H-D | C] – C:\$AVG8.VAULT$
[2009/06/25 21:16:41 | 00,001,515 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG Free 8.5.lnk
[2009/06/25 21:16:39 | 00,108,552 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/06/25 21:16:39 | 00,011,952 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/06/25 21:16:38 | 00,335,752 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/06/25 21:16:21 | 37,858,695 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/06/25 21:16:21 | 00,463,779 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/06/25 21:16:21 | 00,014,032 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/06/25 21:16:20 | 06,061,540 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/06/25 21:16:20 | 00,000,000 | —D | C] – C:\WINDOWS\System32\drivers\Avg
[2009/06/25 21:15:58 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\avg8
[2009/06/25 21:13:38 | 00,000,000 | —D | C] – C:\Program Files\AVG
[2009/06/21 09:01:39 | 00,070,144 | —- | C] () – C:\Documents and Settings\Owner\My Documents\father's day.pub
[2009/06/19 15:18:09 | 00,020,992 | —- | C] () – C:\Documents and Settings\Owner\My Documents\oprah.doc
[2009/06/15 23:21:38 | 00,024,576 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Letter to Dr. Milrod.doc
[2009/06/15 22:34:11 | 00,024,064 | —- | C] () – C:\Documents and Settings\Owner\My Documents\June 15.doc
[2009/06/09 07:01:10 | 00,000,054 | -H– | C] () – C:\Documents and Settings\Owner\My Documents\~$y Saige Wenik.doc
[2009/06/08 17:05:31 | 00,549,564 | —- | C] () – C:\Documents and Settings\Owner\My Documents\PDRM0001.JPG
[2009/06/08 16:19:41 | 00,020,992 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Soy Saige Wenik.doc
[2008/10/23 07:52:51 | 00,000,032 | —- | C] () – C:\WINDOWS\ARC_CPR-AED-PR.ini
[2008/07/26 08:25:02 | 00,025,624 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2007/01/01 09:16:55 | 00,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2006/12/21 20:41:32 | 00,000,021 | —- | C] () – C:\WINDOWS\atid.ini
[2004/12/06 20:52:42 | 00,002,150 | —- | C] () – C:\WINDOWS\System32\ssmute.ini
[2004/10/02 16:57:54 | 00,000,169 | —- | C] () – C:\WINDOWS\magix.ini
[2004/10/02 16:57:53 | 00,000,919 | —- | C] () – C:\WINDOWS\mgxoschk.ini
[2004/09/11 10:04:35 | 00,000,074 | —- | C] () – C:\WINDOWS\lbbho.ini
[2004/09/04 08:59:22 | 00,000,036 | —- | C] () – C:\WINDOWS\TLCAPPS.INI
[2004/09/01 21:06:48 | 00,000,000 | —- | C] () – C:\WINDOWS\SETUP32.INI
[2004/07/26 08:01:55 | 00,000,045 | —- | C] () – C:\WINDOWS\Tlcpromo.ini
[2004/07/26 08:01:51 | 00,000,398 | —- | C] () – C:\WINDOWS\SBW95.ini
[2004/06/23 18:49:55 | 00,000,060 | —- | C] () – C:\WINDOWS\SIERRA.INI
[2004/06/23 17:38:30 | 00,000,383 | —- | C] () – C:\WINDOWS\ka.ini
[2004/06/06 09:21:37 | 00,086,030 | —- | C] () – C:\WINDOWS\System32\msdjgk.dll
[2004/05/16 15:26:07 | 00,001,890 | —- | C] () – C:\WINDOWS\7THLEVEL.INI
[2004/03/23 17:49:48 | 00,131,072 | —- | C] () – C:\WINDOWS\System32\sfarkxt.dll
[2004/03/23 17:49:47 | 00,068,096 | —- | C] () – C:\WINDOWS\System32\SFARKL.DLL
[2004/01/30 19:48:00 | 00,217,088 | —- | C] () – C:\WINDOWS\System32\libmySQL.dll
[2003/12/09 13:16:52 | 00,442,368 | —- | C] ( ) – C:\WINDOWS\System32\comintfs.dll
[2003/12/07 15:45:53 | 00,061,440 | —- | C] () – C:\WINDOWS\System32\gl.dll
[2003/12/07 15:45:53 | 00,023,200 | —- | C] () – C:\WINDOWS\System32\drivers\ppsio2.sys
[2003/12/07 15:45:53 | 00,006,123 | —- | C] () – C:\WINDOWS\System32\e1.ini
[2003/11/08 09:33:15 | 00,010,301 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2003/09/18 23:09:16 | 00,000,024 | —- | C] () – C:\WINDOWS\qfnonl.ini
[2003/09/18 22:43:36 | 00,000,050 | —- | C] () – C:\WINDOWS\qwimp.ini
[2003/09/18 22:06:25 | 00,007,183 | —- | C] () – C:\WINDOWS\hpdj5100.ini
[2003/09/18 22:05:58 | 00,000,414 | —- | C] () – C:\WINDOWS\hpbvspst.ini
[2003/09/18 21:54:44 | 00,000,144 | —- | C] () – C:\WINDOWS\WININIT.INI
[2003/09/18 21:54:26 | 00,000,006 | —- | C] () – C:\WINDOWS\msoffice.ini
[2003/09/18 21:09:03 | 00,000,737 | —- | C] () – C:\WINDOWS\ODBC.INI
[2003/09/18 20:59:23 | 00,000,146 | —- | C] () – C:\WINDOWS\lotus.ini
[2003/09/18 20:23:16 | 00,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2003/05/31 14:29:50 | 00,019,968 | —- | C] () – C:\WINDOWS\System32\cpuinf32.dll
[2003/04/10 07:33:14 | 00,094,208 | —- | C] () – C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2003/04/10 07:33:14 | 00,077,824 | —- | C] () – C:\WINDOWS\System32\ProgressTrace.dll
[2003/04/10 07:10:20 | 00,167,936 | —- | C] () – C:\WINDOWS\System32\PCDrJNI_1_1.dll
[2003/04/10 07:08:02 | 00,024,576 | —- | C] () – C:\WINDOWS\System32\syscontr.dll
[2003/04/10 07:08:01 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2003/04/10 07:07:51 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/04/10 07:00:09 | 00,000,692 | —- | C] () – C:\WINDOWS\intuprof.ini
[2003/04/10 06:59:52 | 00,001,212 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2003/04/10 06:53:45 | 00,000,051 | —- | C] () – C:\WINDOWS\System32\mshrml.ini
[2003/04/10 06:36:30 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2003/04/10 06:16:02 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/04/10 06:06:11 | 00,299,073 | —- | C] () – C:\WINDOWS\System32\PythonCOM22.dll
[2003/04/10 06:06:11 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\PyWinTypes22.dll
[2003/04/10 06:05:46 | 00,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2003/04/10 05:53:32 | 00,000,802 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/04/10 05:37:43 | 00,000,552 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2003/04/10 05:37:23 | 00,000,698 | —- | C] () – C:\WINDOWS\win.ini
[2003/04/10 05:37:19 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini
[2003/04/10 03:08:18 | 00,000,438 | —- | C] () – C:\WINDOWS\System32\1_ssetup.ini
[2003/04/10 03:08:18 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\sunistlog.ini
[2002/06/10 15:16:22 | 00,066,482 | R— | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2000/09/08 18:53:50 | 00,073,839 | —- | C] () – C:\WINDOWS\System32\KodakOneTouch.dll
[1997/07/11 00:00:00 | 00,031,232 | —- | C] () – C:\WINDOWS\System32\XLREC.DLL
[1997/07/11 00:00:00 | 00,025,600 | —- | C] () – C:\WINDOWS\System32\RECNCL.DLL
[1997/07/11 00:00:00 | 00,022,016 | —- | C] () – C:\WINDOWS\System32\ODBCSTF.DLL
[1997/07/11 00:00:00 | 00,022,016 | —- | C] () – C:\WINDOWS\System32\DOCOBJ.DLL
[1997/07/11 00:00:00 | 00,012,288 | —- | C] () – C:\WINDOWS\System32\HLINKPRX.DLL
[1996/04/25 21:23:00 | 00,000,846 | —- | C] () – C:\WINDOWS\acroread.ini
[1996/02/22 21:23:00 | 00,222,928 | —- | C] () – C:\WINDOWS\System32\lobas09.dll
[1996/01/17 21:23:00 | 00,031,008 | —- | C] () – C:\WINDOWS\System32\ivtrn09.dll
[1996/01/15 21:23:00 | 00,334,016 | —- | C] () – C:\WINDOWS\System32\loflt09.dll
[1995/09/25 21:23:00 | 00,014,928 | —- | C] () – C:\WINDOWS\System32\wingen.drv
[1994/04/07 21:23:00 | 00,000,462 | —- | C] () – C:\WINDOWS\lodbf09.ini

========== Files - Modified Within 30 Days ==========

[1 C:\Documents and Settings\Owner\My Documents\*.tmp files]
[2009/07/07 18:20:40 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/07/07 18:20:35 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/07/07 18:20:34 | 52,788,0192 | -HS- | M] () – C:\hiberfil.sys
[2009/07/07 18:10:30 | 00,148,888 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2009/07/07 18:10:29 | 00,410,984 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deploytk.dll
[2009/07/07 18:10:29 | 00,144,792 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2009/07/07 18:10:29 | 00,144,792 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2009/07/07 18:10:29 | 00,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2009/07/07 09:19:48 | 37,858,695 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/07/07 09:19:48 | 00,014,032 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/07/07 04:22:09 | 00,399,650 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/07/07 04:22:08 | 00,060,626 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/07/07 04:22:05 | 00,467,868 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/07/07 04:15:35 | 00,399,936 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/07/07 04:06:18 | 00,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/07/07 00:00:00 | 00,000,622 | —- | M] () – C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - Owner.job
[2009/07/06 22:37:08 | 00,513,536 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2009/07/06 22:02:27 | 00,000,704 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/07/06 09:38:03 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/07/05 09:50:00 | 00,027,784 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/07/05 09:49:56 | 00,335,752 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/07/05 09:33:12 | 00,064,160 | —- | M] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/07/05 09:31:07 | 00,000,875 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/07/05 00:18:08 | 00,001,742 | —- | M] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk
[2009/07/04 23:26:13 | 00,463,779 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/07/04 13:44:35 | 00,000,941 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Spybot - Search & Destroy.lnk
[2009/07/04 13:36:22 | 16,409,960 | —- | M] (Safer Networking Limited ) – C:\Documents and Settings\Owner\Desktop\setup-spybotsd162.exe
[2009/07/04 10:18:03 | 00,002,265 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2009/07/04 08:19:11 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/06/30 22:25:57 | 00,001,212 | —- | M] () – C:\WINDOWS\QUICKEN.INI
[2009/06/26 19:40:29 | 00,000,698 | —- | M] () – C:\WINDOWS\win.ini
[2009/06/26 19:35:48 | 00,042,496 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/06/25 22:02:01 | 00,001,821 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2009/06/25 21:16:41 | 00,001,515 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG Free 8.5.lnk
[2009/06/25 21:16:39 | 00,108,552 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/06/25 21:16:39 | 00,011,952 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/06/25 21:16:21 | 06,061,540 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/06/23 20:28:31 | 01,108,116 | -H– | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\IconCache.db
[2009/06/21 09:01:40 | 00,070,144 | —- | M] () – C:\Documents and Settings\Owner\My Documents\father's day.pub
[2009/06/19 15:18:10 | 00,020,992 | —- | M] () – C:\Documents and Settings\Owner\My Documents\oprah.doc
[2009/06/17 13:07:58 | 00,004,752 | -H– | M] () – C:\IPH.PH
[2009/06/17 11:27:56 | 00,038,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/06/17 11:27:44 | 00,019,096 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/06/17 10:28:16 | 00,001,642 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AIM 6.lnk
[2009/06/15 23:37:32 | 00,024,576 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Letter to Dr. Milrod.doc
[2009/06/15 23:21:17 | 00,024,064 | —- | M] () – C:\Documents and Settings\Owner\My Documents\June 15.doc
[2009/06/13 23:24:20 | 14,456,832 | R— | M] () – C:\Documents and Settings\All Users\Documents\ESBK.mbb
[2009/06/13 23:23:55 | 10,537,984 | R— | M] () – C:\Documents and Settings\All Users\Documents\ESBK.mb
[2009/06/09 07:01:10 | 00,000,054 | -H– | M] () – C:\Documents and Settings\Owner\My Documents\~$y Saige Wenik.doc
[2009/06/08 17:10:43 | 00,020,992 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Soy Saige Wenik.doc

========== LOP Check ==========

[2009/07/05 09:31:09 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/03/25 22:59:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{63A9FDE6-FCC7-4E26-A4CF-552A08431B32}
[2009/07/05 09:31:18 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
[2009/05/28 21:37:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2008/11/02 18:42:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2008/03/28 22:13:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avery
[2008/06/01 19:48:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Fashion Solitaire 1.2
[2009/03/22 17:30:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intuit
[2009/05/13 22:30:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Logishrd
[2009/01/30 18:44:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MakeMusic
[2008/06/29 10:59:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Motive
[2003/12/11 21:37:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN Messenger 6.0.0602
[2003/10/07 18:38:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN6
[2004/09/06 14:24:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2003/04/10 05:54:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2009/07/04 23:28:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/02/13 17:50:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Verizon
[2009/07/07 18:04:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2003/10/07 18:34:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Visual Networks
[2009/05/09 22:19:46 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Owner\Application Data
[2006/12/22 18:05:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\acccore
[2009/06/25 22:16:35 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Aim
[2007/03/02 22:54:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Arcsoft
[2007/04/08 10:18:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\COWON
[2003/10/26 13:51:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Games
[2007/04/08 10:14:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\interMute
[2003/10/18 09:14:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\InterVideo
[2008/03/16 19:04:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Intuit
[2004/02/21 19:44:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Leadertech
[2005/01/07 23:21:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Lycos
[2008/02/13 17:57:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Motive
[2007/05/21 20:59:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Move Networks
[2008/02/13 15:56:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\MSN6
[2007/01/01 09:21:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Panasonic
[2008/03/06 21:25:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\QQ Games Plugin
[2004/10/26 19:57:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\rawh
[2004/09/06 14:21:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Roxio
[2003/04/10 07:08:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SampleView
[2007/04/22 08:28:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Snapfish
[2003/08/02 18:07:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Template
[2009/01/12 17:17:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\U3
[2003/06/19 15:08:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\VERITAS
[2008/02/13 17:50:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Verizon
[2007/07/23 09:04:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\WeatherBug
[2004/12/06 21:52:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\winjt
[2008/07/20 21:20:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\WinPatrol
[2009/07/06 09:38:03 | 00,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2009/07/04 08:19:11 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2002/08/29 15:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/07/07 00:00:00 | 00,000,622 | —- | M] () – C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Owner.job
[2009/07/07 18:20:40 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 144 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A988B257
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >
OTL logfile created on: 7/7/2009 6:33:56 PM - Run 2
OTL by OldTimer - Version 3.0.6.5 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

503.36 Mb Total Physical Memory | 173.77 Mb Available Physical Memory | 34.52% Memory free
1.20 Gb Paging File | 0.71 Gb Available in Paging File | 59.29% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 107.53 Gb Total Space | 63.38 Gb Free Space | 58.94% Space Free | Partition Type: NTFS
Drive D: | 4.24 Gb Total Space | 0.66 Gb Free Space | 15.61% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PC1
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\Softex\OmniPass\OPXPApp.exe ()
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Comodo\Firewall\cmdagent.exe (COMODO)
PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\notepad.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
PRC - C:\WINDOWS\System32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
PRC - C:\Program Files\Comodo\Firewall\CPF.exe (COMODO)
PRC - C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\WINDOWS\System32\taskmgr.exe (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device [On_Demand | Stopped]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (avg8emc [Auto | Running]) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd [Auto | Running]) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Bonjour Service [Disabled | Stopped]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (CmdAgent [Auto | Running]) – C:\Program Files\Comodo\Firewall\cmdagent.exe (COMODO)
SRV - (gupdate1c9d115998455f8 [Auto | Stopped]) – C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (IntuitUpdateService [Auto | Running]) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (iPod Service [On_Demand | Stopped]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (KodakCCS [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\KodakCCS.exe (Eastman Kodak Company)
SRV - (Lavasoft Ad-Aware Service [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (LVCOMSer [Auto | Running]) – C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
SRV - (LVPrcSrv [Auto | Running]) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (NVSvc [Auto | Stopped]) – C:\WINDOWS\System32\nvsvc32.exe (NVIDIA Corporation)
SRV - (omniserv [Disabled | Stopped]) – C:\Program Files\Softex\OmniPass\Omniserv.exe ()
SRV - (Symantec Core LC [Disabled | Stopped]) – File not found
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (ALCXWDM [On_Demand | Running]) – C:\WINDOWS\System32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (AvgLdx86 [System | Running]) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (CmdMon [System | Running]) – C:\WINDOWS\System32\DRIVERS\cmdmon.sys (Comodo Research Lab., Inc.)
DRV - (DcCam [System | Running]) – C:\WINDOWS\System32\DRIVERS\DcCam.sys (Eastman Kodak Company)
DRV - (DcFpoint [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\DcFpoint.sys (Eastman Kodak Company)
DRV - (DCFS2K [Auto | Running]) – C:\WINDOWS\System32\drivers\dcfs2k.sys (Eastman Kodak Company)
DRV - (DcLps [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\DcLps.sys (Eastman Kodak Company)
DRV - (DcPTP [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\DcPTP.sys (Eastman Kodak Company)
DRV - (Exportit [System | Stopped]) – C:\WINDOWS\System32\DRIVERS\exportit.sys (Eastman Kodak Company)
DRV - (fasttx2k [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\fasttx2k.sys (Promise Technology, Inc.)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (ialm [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (Inspect [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\inspect.sys (COMODO)
DRV - (Lbd [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (ltmodem5 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ltmdmnt.sys (LT)
DRV - (LVPr2Mon [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\LVPr2Mon.sys ()
DRV - (LVUSBSta [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (MREMPR5 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MREMPR5.sys (Motive, Inc.)
DRV - (MRENDIS5 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MRENDIS5.sys (Motive, Inc.)
DRV - (mrtRate [Auto | Running]) – C:\WINDOWS\System32\drivers\MrtRate.sys (Marimba, Inc.)
DRV - (nv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (nv_agp [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\nv_agp.sys (NVIDIA Corporation)
DRV - (pfc [On_Demand | Running]) – C:\WINDOWS\System32\drivers\pfc.sys (Padus, Inc.)
DRV - (PID_PEPI [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\LV302V32.SYS (Logitech Inc.)
DRV - (ppsio2 [Auto | Running]) – C:\WINDOWS\System32\drivers\ppsio2.sys ()
DRV - (Ps2 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\PS2.sys (Hewlett-Packard Company)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\PxHelp20.sys (Sonic Solutions)
DRV - (QCDonner [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\LVCD.sys (Logitech Inc.)
DRV - (rtl8139 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\R8139n51.SYS (Realtek Semiconductor Corporation )
DRV - (S3Psddr [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\s3gnbm.sys (S3 Graphics, Inc.)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SiS315 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\sisgrp.sys (Silicon Integrated Systems Corporation)
DRV - (SISAGP [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\SISAGPX.sys (Silicon Integrated Systems Corporation)
DRV - (StillCam [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\serscan.sys (Microsoft Corporation)
DRV - (USBIO [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\usbio.sys (Thesycon GmbH, Germany)
DRV - (viaagp1 [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (vnccom [Auto | Running]) – C:\WINDOWS\System32\Drivers\vnccom.SYS (RDV Soft)
DRV - (vncdrv [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\vncdrv.sys (RDV Soft)
DRV - ({6080A529-897E-4629-A488-ABA0C29B635E} [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\ialmsbw.sys (Intel Corporation)
DRV - ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91} [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\ialmkchw.sys (Intel Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\System32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/07/07 18:10:31 | 00,000,000 | —D | M]


O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (&Google;) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [COMODO Firewall Pro] C:\Program Files\Comodo\Firewall\CPF.exe (COMODO)
O4 - HKLM..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [NVIEW] C:\WINDOWS\System32\nview.DLL (NVIDIA Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowLegacyWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowUnhashedWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 36
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRunBackup = -1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FF FF FF FF [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disableregistrytools = 0
O8 - Extra context menu item: &AIM; Search - Reg Error: Value error. File not found
O9 - Extra Button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll (AOL LLC)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O12 - Plugin for: .pdf - C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll (Adobe Systems Inc.)
O15 - HKLM\..Trusted Domains: 45 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: 319 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E2941E3-8E63-11D4-9D5A-00902742D6E0} http://146.145.127.148/iNotes.cab (iNotes Class)
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} Reg Error: Value error. (Yahoo! Audio Conferencing)
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} http://mail.philaymca.org/iNotes6W.cab (iNotes6 Class)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc.cab (Office Update Installation Engine)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase5483.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/microsoftupdat…b?1237767327250 (WUWebControl Class)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1237767270703 (MUWebControl Class)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx (Get_ActiveX Control)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://zone.msn.com/binFramework/v10/ZIntro.cab32846.cab (ZoneIntro Class)
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://active.macromedia.com/flash2/cabs/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DB0474CC-8EF6-47FC-905B-23FC58A70817} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {E93A6FCA-C052-45DF-AC9B-B729066092F8} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O16 - DPF: vzTCPConfig Reg Error: Value error. (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\OPXPGina: DllName - C:\Program Files\Softex\OmniPass\opxpgina.dll - C:\Program Files\Softex\OmniPass\opxpgina.dll ()
O24 - Desktop Components:0 () - C:\Program Files\Messenger\profsydy.html
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/07/28 07:07:38 | 00,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2008/07/20 13:17:26 | 00,000,090 | —- | M] () - D:\AUTORUN.INF – [ FAT32 ]
O33 - MountPoints2\{4729c152-3c75-11dc-8af9-000c6e35d416}\Shell - "" = AutoRun
O33 - MountPoints2\{4729c152-3c75-11dc-8af9-000c6e35d416}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{4729c152-3c75-11dc-8af9-000c6e35d416}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/07/07 18:16:03 | 00,000,000 | —D | C] – C:\_OTL
[2009/07/07 18:11:07 | 00,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2009/07/07 18:11:06 | 00,410,984 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deploytk.dll
[2009/07/07 18:11:05 | 00,148,888 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2009/07/07 18:11:05 | 00,144,792 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2009/07/07 18:11:04 | 00,144,792 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2009/07/06 22:37:05 | 00,513,536 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2009/07/06 22:02:27 | 00,000,704 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/07/06 22:02:20 | 00,038,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/07/06 22:02:18 | 00,019,096 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/07/06 22:02:18 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/07/06 21:45:04 | 00,000,000 | —D | C] – C:\WINDOWS\System32\CatRoot_bak
[2009/07/06 21:42:29 | 00,272,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bthport.sys
[2009/07/06 21:41:43 | 00,283,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pdh.dll
[2009/07/06 21:41:43 | 00,060,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\colbact.dll
[2009/07/06 21:41:41 | 00,473,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fastprox.dll
[2009/07/06 21:41:41 | 00,399,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rpcss.dll
[2009/07/06 21:41:41 | 00,227,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvse.exe
[2009/07/06 21:41:41 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\services.exe
[2009/07/06 21:41:40 | 00,453,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvsd.dll
[2009/07/06 21:41:39 | 00,616,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\advapi32.dll
[2009/07/06 21:41:37 | 00,714,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntdll.dll
[2009/07/06 21:40:50 | 00,331,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msadce.dll
[2009/07/06 21:37:45 | 00,215,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wordpad.exe
[2009/07/05 09:34:38 | 00,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/07/05 09:34:21 | 00,064,160 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/07/05 09:31:09 | 00,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
[2009/07/05 09:31:07 | 00,000,875 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/07/05 00:18:08 | 00,001,742 | —- | C] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk
[2009/07/05 00:18:02 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/07/04 13:35:51 | 16,409,960 | —- | C] (Safer Networking Limited ) – C:\Documents and Settings\Owner\Desktop\setup-spybotsd162.exe
[2009/06/26 02:02:32 | 00,000,000 | -H-D | C] – C:\$AVG8.VAULT$
[2009/06/25 21:16:41 | 00,001,515 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG Free 8.5.lnk
[2009/06/25 21:16:39 | 00,108,552 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/06/25 21:16:39 | 00,011,952 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/06/25 21:16:38 | 00,335,752 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/06/25 21:16:21 | 37,858,695 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/06/25 21:16:21 | 00,463,779 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/06/25 21:16:21 | 00,014,032 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/06/25 21:16:20 | 06,061,540 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/06/25 21:16:20 | 00,000,000 | —D | C] – C:\WINDOWS\System32\drivers\Avg
[2009/06/25 21:15:58 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\avg8
[2009/06/25 21:13:38 | 00,000,000 | —D | C] – C:\Program Files\AVG
[2009/06/21 09:01:39 | 00,070,144 | —- | C] () – C:\Documents and Settings\Owner\My Documents\father's day.pub
[2009/06/19 15:18:09 | 00,020,992 | —- | C] () – C:\Documents and Settings\Owner\My Documents\oprah.doc
[2009/06/15 23:21:38 | 00,024,576 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Letter to Dr. Milrod.doc
[2009/06/15 22:34:11 | 00,024,064 | —- | C] () – C:\Documents and Settings\Owner\My Documents\June 15.doc
[2009/06/09 07:01:10 | 00,000,054 | -H– | C] () – C:\Documents and Settings\Owner\My Documents\~$y Saige Wenik.doc
[2009/06/08 17:05:31 | 00,549,564 | —- | C] () – C:\Documents and Settings\Owner\My Documents\PDRM0001.JPG
[2009/06/08 16:19:41 | 00,020,992 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Soy Saige Wenik.doc
[2008/10/23 07:52:51 | 00,000,032 | —- | C] () – C:\WINDOWS\ARC_CPR-AED-PR.ini
[2008/07/26 08:25:02 | 00,025,624 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2007/01/01 09:16:55 | 00,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2006/12/21 20:41:32 | 00,000,021 | —- | C] () – C:\WINDOWS\atid.ini
[2004/12/06 20:52:42 | 00,002,150 | —- | C] () – C:\WINDOWS\System32\ssmute.ini
[2004/10/02 16:57:54 | 00,000,169 | —- | C] () – C:\WINDOWS\magix.ini
[2004/10/02 16:57:53 | 00,000,919 | —- | C] () – C:\WINDOWS\mgxoschk.ini
[2004/09/11 10:04:35 | 00,000,074 | —- | C] () – C:\WINDOWS\lbbho.ini
[2004/09/04 08:59:22 | 00,000,036 | —- | C] () – C:\WINDOWS\TLCAPPS.INI
[2004/09/01 21:06:48 | 00,000,000 | —- | C] () – C:\WINDOWS\SETUP32.INI
[2004/07/26 08:01:55 | 00,000,045 | —- | C] () – C:\WINDOWS\Tlcpromo.ini
[2004/07/26 08:01:51 | 00,000,398 | —- | C] () – C:\WINDOWS\SBW95.ini
[2004/06/23 18:49:55 | 00,000,060 | —- | C] () – C:\WINDOWS\SIERRA.INI
[2004/06/23 17:38:30 | 00,000,383 | —- | C] () – C:\WINDOWS\ka.ini
[2004/06/06 09:21:37 | 00,086,030 | —- | C] () – C:\WINDOWS\System32\msdjgk.dll
[2004/05/16 15:26:07 | 00,001,890 | —- | C] () – C:\WINDOWS\7THLEVEL.INI
[2004/03/23 17:49:48 | 00,131,072 | —- | C] () – C:\WINDOWS\System32\sfarkxt.dll
[2004/03/23 17:49:47 | 00,068,096 | —- | C] () – C:\WINDOWS\System32\SFARKL.DLL
[2004/01/30 19:48:00 | 00,217,088 | —- | C] () – C:\WINDOWS\System32\libmySQL.dll
[2003/12/09 13:16:52 | 00,442,368 | —- | C] ( ) – C:\WINDOWS\System32\comintfs.dll
[2003/12/07 15:45:53 | 00,061,440 | —- | C] () – C:\WINDOWS\System32\gl.dll
[2003/12/07 15:45:53 | 00,023,200 | —- | C] () – C:\WINDOWS\System32\drivers\ppsio2.sys
[2003/12/07 15:45:53 | 00,006,123 | —- | C] () – C:\WINDOWS\System32\e1.ini
[2003/11/08 09:33:15 | 00,010,301 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2003/09/18 23:09:16 | 00,000,024 | —- | C] () – C:\WINDOWS\qfnonl.ini
[2003/09/18 22:43:36 | 00,000,050 | —- | C] () – C:\WINDOWS\qwimp.ini
[2003/09/18 22:06:25 | 00,007,183 | —- | C] () – C:\WINDOWS\hpdj5100.ini
[2003/09/18 22:05:58 | 00,000,414 | —- | C] () – C:\WINDOWS\hpbvspst.ini
[2003/09/18 21:54:44 | 00,000,144 | —- | C] () – C:\WINDOWS\WININIT.INI
[2003/09/18 21:54:26 | 00,000,006 | —- | C] () – C:\WINDOWS\msoffice.ini
[2003/09/18 21:09:03 | 00,000,737 | —- | C] () – C:\WINDOWS\ODBC.INI
[2003/09/18 20:59:23 | 00,000,146 | —- | C] () – C:\WINDOWS\lotus.ini
[2003/09/18 20:23:16 | 00,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2003/05/31 14:29:50 | 00,019,968 | —- | C] () – C:\WINDOWS\System32\cpuinf32.dll
[2003/04/10 07:33:14 | 00,094,208 | —- | C] () – C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2003/04/10 07:33:14 | 00,077,824 | —- | C] () – C:\WINDOWS\System32\ProgressTrace.dll
[2003/04/10 07:10:20 | 00,167,936 | —- | C] () – C:\WINDOWS\System32\PCDrJNI_1_1.dll
[2003/04/10 07:08:02 | 00,024,576 | —- | C] () – C:\WINDOWS\System32\syscontr.dll
[2003/04/10 07:08:01 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2003/04/10 07:07:51 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/04/10 07:00:09 | 00,000,692 | —- | C] () – C:\WINDOWS\intuprof.ini
[2003/04/10 06:59:52 | 00,001,212 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2003/04/10 06:53:45 | 00,000,051 | —- | C] () – C:\WINDOWS\System32\mshrml.ini
[2003/04/10 06:36:30 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2003/04/10 06:16:02 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/04/10 06:06:11 | 00,299,073 | —- | C] () – C:\WINDOWS\System32\PythonCOM22.dll
[2003/04/10 06:06:11 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\PyWinTypes22.dll
[2003/04/10 06:05:46 | 00,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2003/04/10 05:53:32 | 00,000,802 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/04/10 05:37:43 | 00,000,552 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2003/04/10 05:37:23 | 00,000,698 | —- | C] () – C:\WINDOWS\win.ini
[2003/04/10 05:37:19 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini
[2003/04/10 03:08:18 | 00,000,438 | —- | C] () – C:\WINDOWS\System32\1_ssetup.ini
[2003/04/10 03:08:18 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\sunistlog.ini
[2002/06/10 15:16:22 | 00,066,482 | R— | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2000/09/08 18:53:50 | 00,073,839 | —- | C] () – C:\WINDOWS\System32\KodakOneTouch.dll
[1997/07/11 00:00:00 | 00,031,232 | —- | C] () – C:\WINDOWS\System32\XLREC.DLL
[1997/07/11 00:00:00 | 00,025,600 | —- | C] () – C:\WINDOWS\System32\RECNCL.DLL
[1997/07/11 00:00:00 | 00,022,016 | —- | C] () – C:\WINDOWS\System32\ODBCSTF.DLL
[1997/07/11 00:00:00 | 00,022,016 | —- | C] () – C:\WINDOWS\System32\DOCOBJ.DLL
[1997/07/11 00:00:00 | 00,012,288 | —- | C] () – C:\WINDOWS\System32\HLINKPRX.DLL
[1996/04/25 21:23:00 | 00,000,846 | —- | C] () – C:\WINDOWS\acroread.ini
[1996/02/22 21:23:00 | 00,222,928 | —- | C] () – C:\WINDOWS\System32\lobas09.dll
[1996/01/17 21:23:00 | 00,031,008 | —- | C] () – C:\WINDOWS\System32\ivtrn09.dll
[1996/01/15 21:23:00 | 00,334,016 | —- | C] () – C:\WINDOWS\System32\loflt09.dll
[1995/09/25 21:23:00 | 00,014,928 | —- | C] () – C:\WINDOWS\System32\wingen.drv
[1994/04/07 21:23:00 | 00,000,462 | —- | C] () – C:\WINDOWS\lodbf09.ini

========== Files - Modified Within 30 Days ==========

[1 C:\Documents and Settings\Owner\My Documents\*.tmp files]
[2009/07/07 18:20:40 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/07/07 18:20:35 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/07/07 18:20:34 | 52,788,0192 | -HS- | M] () – C:\hiberfil.sys
[2009/07/07 18:10:30 | 00,148,888 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2009/07/07 18:10:29 | 00,410,984 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deploytk.dll
[2009/07/07 18:10:29 | 00,144,792 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2009/07/07 18:10:29 | 00,144,792 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2009/07/07 18:10:29 | 00,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2009/07/07 09:19:48 | 37,858,695 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/07/07 09:19:48 | 00,014,032 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/07/07 04:22:09 | 00,399,650 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/07/07 04:22:08 | 00,060,626 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/07/07 04:22:05 | 00,467,868 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/07/07 04:15:35 | 00,399,936 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/07/07 04:06:18 | 00,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/07/07 00:00:00 | 00,000,622 | —- | M] () – C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - Owner.job
[2009/07/06 22:37:08 | 00,513,536 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2009/07/06 22:02:27 | 00,000,704 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/07/06 09:38:03 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/07/05 09:50:00 | 00,027,784 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/07/05 09:49:56 | 00,335,752 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/07/05 09:33:12 | 00,064,160 | —- | M] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/07/05 09:31:07 | 00,000,875 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/07/05 00:18:08 | 00,001,742 | —- | M] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk
[2009/07/04 23:26:13 | 00,463,779 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/07/04 13:44:35 | 00,000,941 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Spybot - Search & Destroy.lnk
[2009/07/04 13:36:22 | 16,409,960 | —- | M] (Safer Networking Limited ) – C:\Documents and Settings\Owner\Desktop\setup-spybotsd162.exe
[2009/07/04 10:18:03 | 00,002,265 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2009/07/04 08:19:11 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/06/30 22:25:57 | 00,001,212 | —- | M] () – C:\WINDOWS\QUICKEN.INI
[2009/06/26 19:40:29 | 00,000,698 | —- | M] () – C:\WINDOWS\win.ini
[2009/06/26 19:35:48 | 00,042,496 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/06/25 22:02:01 | 00,001,821 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2009/06/25 21:16:41 | 00,001,515 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG Free 8.5.lnk
[2009/06/25 21:16:39 | 00,108,552 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/06/25 21:16:39 | 00,011,952 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/06/25 21:16:21 | 06,061,540 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/06/23 20:28:31 | 01,108,116 | -H– | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\IconCache.db
[2009/06/21 09:01:40 | 00,070,144 | —- | M] () – C:\Documents and Settings\Owner\My Documents\father's day.pub
[2009/06/19 15:18:10 | 00,020,992 | —- | M] () – C:\Documents and Settings\Owner\My Documents\oprah.doc
[2009/06/17 13:07:58 | 00,004,752 | -H– | M] () – C:\IPH.PH
[2009/06/17 11:27:56 | 00,038,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/06/17 11:27:44 | 00,019,096 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/06/17 10:28:16 | 00,001,642 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AIM 6.lnk
[2009/06/15 23:37:32 | 00,024,576 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Letter to Dr. Milrod.doc
[2009/06/15 23:21:17 | 00,024,064 | —- | M] () – C:\Documents and Settings\Owner\My Documents\June 15.doc
[2009/06/13 23:24:20 | 14,456,832 | R— | M] () – C:\Documents and Settings\All Users\Documents\ESBK.mbb
[2009/06/13 23:23:55 | 10,537,984 | R— | M] () – C:\Documents and Settings\All Users\Documents\ESBK.mb
[2009/06/09 07:01:10 | 00,000,054 | -H– | M] () – C:\Documents and Settings\Owner\My Documents\~$y Saige Wenik.doc
[2009/06/08 17:10:43 | 00,020,992 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Soy Saige Wenik.doc

========== LOP Check ==========

[2009/07/05 09:31:09 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/03/25 22:59:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{63A9FDE6-FCC7-4E26-A4CF-552A08431B32}
[2009/07/05 09:31:18 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
[2009/05/28 21:37:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2008/11/02 18:42:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2008/03/28 22:13:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avery
[2008/06/01 19:48:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Fashion Solitaire 1.2
[2009/03/22 17:30:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intuit
[2009/05/13 22:30:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Logishrd
[2009/01/30 18:44:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MakeMusic
[2008/06/29 10:59:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Motive
[2003/12/11 21:37:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN Messenger 6.0.0602
[2003/10/07 18:38:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN6
[2004/09/06 14:24:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2003/04/10 05:54:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2009/07/04 23:28:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/02/13 17:50:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Verizon
[2009/07/07 18:04:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2003/10/07 18:34:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Visual Networks
[2009/05/09 22:19:46 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Owner\Application Data
[2006/12/22 18:05:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\acccore
[2009/06/25 22:16:35 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Aim
[2007/03/02 22:54:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Arcsoft
[2007/04/08 10:18:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\COWON
[2003/10/26 13:51:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Games
[2007/04/08 10:14:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\interMute
[2003/10/18 09:14:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\InterVideo
[2008/03/16 19:04:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Intuit
[2004/02/21 19:44:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Leadertech
[2005/01/07 23:21:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Lycos
[2008/02/13 17:57:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Motive
[2007/05/21 20:59:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Move Networks
[2008/02/13 15:56:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\MSN6
[2007/01/01 09:21:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Panasonic
[2008/03/06 21:25:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\QQ Games Plugin
[2004/10/26 19:57:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\rawh
[2004/09/06 14:21:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Roxio
[2003/04/10 07:08:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SampleView
[2007/04/22 08:28:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Snapfish
[2003/08/02 18:07:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Template
[2009/01/12 17:17:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\U3
[2003/06/19 15:08:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\VERITAS
[2008/02/13 17:50:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Verizon
[2007/07/23 09:04:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\WeatherBug
[2004/12/06 21:52:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\winjt
[2008/07/20 21:20:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\WinPatrol
[2009/07/06 09:38:03 | 00,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2009/07/04 08:19:11 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2002/08/29 15:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/07/07 00:00:00 | 00,000,622 | —- | M] () – C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Owner.job
[2009/07/07 18:20:40 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 144 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A988B257
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >
OTL logfile created on: 7/7/2009 6:33:56 PM - Run 2
OTL by OldTimer - Version 3.0.6.5 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

503.36 Mb Total Physical Memory | 173.77 Mb Available Physical Memory | 34.52% Memory free
1.20 Gb Paging File | 0.71 Gb Available in Paging File | 59.29% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 107.53 Gb Total Space | 63.38 Gb Free Space | 58.94% Space Free | Partition Type: NTFS
Drive D: | 4.24 Gb Total Space | 0.66 Gb Free Space | 15.61% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PC1
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\Softex\OmniPass\OPXPApp.exe ()
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Comodo\Firewall\cmdagent.exe (COMODO)
PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\notepad.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
PRC - C:\WINDOWS\System32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
PRC - C:\Program Files\Comodo\Firewall\CPF.exe (COMODO)
PRC - C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\WINDOWS\System32\taskmgr.exe (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device [On_Demand | Stopped]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (avg8emc [Auto | Running]) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd [Auto | Running]) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Bonjour Service [Disabled | Stopped]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (CmdAgent [Auto | Running]) – C:\Program Files\Comodo\Firewall\cmdagent.exe (COMODO)
SRV - (gupdate1c9d115998455f8 [Auto | Stopped]) – C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (IntuitUpdateService [Auto | Running]) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (iPod Service [On_Demand | Stopped]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (KodakCCS [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\KodakCCS.exe (Eastman Kodak Company)
SRV - (Lavasoft Ad-Aware Service [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (LVCOMSer [Auto | Running]) – C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
SRV - (LVPrcSrv [Auto | Running]) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (NVSvc [Auto | Stopped]) – C:\WINDOWS\System32\nvsvc32.exe (NVIDIA Corporation)
SRV - (omniserv [Disabled | Stopped]) – C:\Program Files\Softex\OmniPass\Omniserv.exe ()
SRV - (Symantec Core LC [Disabled | Stopped]) – File not found
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (ALCXWDM [On_Demand | Running]) – C:\WINDOWS\System32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (AvgLdx86 [System | Running]) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (CmdMon [System | Running]) – C:\WINDOWS\System32\DRIVERS\cmdmon.sys (Comodo Research Lab., Inc.)
DRV - (DcCam [System | Running]) – C:\WINDOWS\System32\DRIVERS\DcCam.sys (Eastman Kodak Company)
DRV - (DcFpoint [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\DcFpoint.sys (Eastman Kodak Company)
DRV - (DCFS2K [Auto | Running]) – C:\WINDOWS\System32\drivers\dcfs2k.sys (Eastman Kodak Company)
DRV - (DcLps [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\DcLps.sys (Eastman Kodak Company)
DRV - (DcPTP [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\DcPTP.sys (Eastman Kodak Company)
DRV - (Exportit [System | Stopped]) – C:\WINDOWS\System32\DRIVERS\exportit.sys (Eastman Kodak Company)
DRV - (fasttx2k [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\fasttx2k.sys (Promise Technology, Inc.)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (ialm [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (Inspect [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\inspect.sys (COMODO)
DRV - (Lbd [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (ltmodem5 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ltmdmnt.sys (LT)
DRV - (LVPr2Mon [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\LVPr2Mon.sys ()
DRV - (LVUSBSta [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (MREMPR5 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MREMPR5.sys (Motive, Inc.)
DRV - (MRENDIS5 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MRENDIS5.sys (Motive, Inc.)
DRV - (mrtRate [Auto | Running]) – C:\WINDOWS\System32\drivers\MrtRate.sys (Marimba, Inc.)
DRV - (nv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (nv_agp [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\nv_agp.sys (NVIDIA Corporation)
DRV - (pfc [On_Demand | Running]) – C:\WINDOWS\System32\drivers\pfc.sys (Padus, Inc.)
DRV - (PID_PEPI [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\LV302V32.SYS (Logitech Inc.)
DRV - (ppsio2 [Auto | Running]) – C:\WINDOWS\System32\drivers\ppsio2.sys ()
DRV - (Ps2 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\PS2.sys (Hewlett-Packard Company)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\PxHelp20.sys (Sonic Solutions)
DRV - (QCDonner [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\LVCD.sys (Logitech Inc.)
DRV - (rtl8139 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\R8139n51.SYS (Realtek Semiconductor Corporation )
DRV - (S3Psddr [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\s3gnbm.sys (S3 Graphics, Inc.)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SiS315 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\sisgrp.sys (Silicon Integrated Systems Corporation)
DRV - (SISAGP [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\SISAGPX.sys (Silicon Integrated Systems Corporation)
DRV - (StillCam [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\serscan.sys (Microsoft Corporation)
DRV - (USBIO [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\usbio.sys (Thesycon GmbH, Germany)
DRV - (viaagp1 [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (vnccom [Auto | Running]) – C:\WINDOWS\System32\Drivers\vnccom.SYS (RDV Soft)
DRV - (vncdrv [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\vncdrv.sys (RDV Soft)
DRV - ({6080A529-897E-4629-A488-ABA0C29B635E} [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\ialmsbw.sys (Intel Corporation)
DRV - ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91} [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\ialmkchw.sys (Intel Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\System32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/07/07 18:10:31 | 00,000,000 | —D | M]


O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (&Google;) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [COMODO Firewall Pro] C:\Program Files\Comodo\Firewall\CPF.exe (COMODO)
O4 - HKLM..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [NVIEW] C:\WINDOWS\System32\nview.DLL (NVIDIA Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowLegacyWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowUnhashedWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 36
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRunBackup = -1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FF FF FF FF [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disableregistrytools = 0
O8 - Extra context menu item: &AIM; Search - Reg Error: Value error. File not found
O9 - Extra Button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll (AOL LLC)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O12 - Plugin for: .pdf - C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll (Adobe Systems Inc.)
O15 - HKLM\..Trusted Domains: 45 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: 319 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E2941E3-8E63-11D4-9D5A-00902742D6E0} http://146.145.127.148/iNotes.cab (iNotes Class)
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} Reg Error: Value error. (Yahoo! Audio Conferencing)
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} http://mail.philaymca.org/iNotes6W.cab (iNotes6 Class)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc.cab (Office Update Installation Engine)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase5483.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/microsoftupdat…b?1237767327250 (WUWebControl Class)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1237767270703 (MUWebControl Class)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx (Get_ActiveX Control)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://zone.msn.com/binFramework/v10/ZIntro.cab32846.cab (ZoneIntro Class)
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://active.macromedia.com/flash2/cabs/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DB0474CC-8EF6-47FC-905B-23FC58A70817} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {E93A6FCA-C052-45DF-AC9B-B729066092F8} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O16 - DPF: vzTCPConfig Reg Error: Value error. (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\OPXPGina: DllName - C:\Program Files\Softex\OmniPass\opxpgina.dll - C:\Program Files\Softex\OmniPass\opxpgina.dll ()
O24 - Desktop Components:0 () - C:\Program Files\Messenger\profsydy.html
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/07/28 07:07:38 | 00,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2008/07/20 13:17:26 | 00,000,090 | —- | M] () - D:\AUTORUN.INF – [ FAT32 ]
O33 - MountPoints2\{4729c152-3c75-11dc-8af9-000c6e35d416}\Shell - "" = AutoRun
O33 - MountPoints2\{4729c152-3c75-11dc-8af9-000c6e35d416}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{4729c152-3c75-11dc-8af9-000c6e35d416}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/07/07 18:16:03 | 00,000,000 | —D | C] – C:\_OTL
[2009/07/07 18:11:07 | 00,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2009/07/07 18:11:06 | 00,410,984 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deploytk.dll
[2009/07/07 18:11:05 | 00,148,888 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2009/07/07 18:11:05 | 00,144,792 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2009/07/07 18:11:04 | 00,144,792 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2009/07/06 22:37:05 | 00,513,536 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2009/07/06 22:02:27 | 00,000,704 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/07/06 22:02:20 | 00,038,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/07/06 22:02:18 | 00,019,096 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/07/06 22:02:18 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/07/06 21:45:04 | 00,000,000 | —D | C] – C:\WINDOWS\System32\CatRoot_bak
[2009/07/06 21:42:29 | 00,272,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bthport.sys
[2009/07/06 21:41:43 | 00,283,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pdh.dll
[2009/07/06 21:41:43 | 00,060,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\colbact.dll
[2009/07/06 21:41:41 | 00,473,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fastprox.dll
[2009/07/06 21:41:41 | 00,399,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rpcss.dll
[2009/07/06 21:41:41 | 00,227,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvse.exe
[2009/07/06 21:41:41 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\services.exe
[2009/07/06 21:41:40 | 00,453,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvsd.dll
[2009/07/06 21:41:39 | 00,616,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\advapi32.dll
[2009/07/06 21:41:37 | 00,714,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntdll.dll
[2009/07/06 21:40:50 | 00,331,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msadce.dll
[2009/07/06 21:37:45 | 00,215,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wordpad.exe
[2009/07/05 09:34:38 | 00,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/07/05 09:34:21 | 00,064,160 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/07/05 09:31:09 | 00,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
[2009/07/05 09:31:07 | 00,000,875 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/07/05 00:18:08 | 00,001,742 | —- | C] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk
[2009/07/05 00:18:02 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/07/04 13:35:51 | 16,409,960 | —- | C] (Safer Networking Limited ) – C:\Documents and Settings\Owner\Desktop\setup-spybotsd162.exe
[2009/06/26 02:02:32 | 00,000,000 | -H-D | C] – C:\$AVG8.VAULT$
[2009/06/25 21:16:41 | 00,001,515 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG Free 8.5.lnk
[2009/06/25 21:16:39 | 00,108,552 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/06/25 21:16:39 | 00,011,952 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/06/25 21:16:38 | 00,335,752 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/06/25 21:16:21 | 37,858,695 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/06/25 21:16:21 | 00,463,779 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/06/25 21:16:21 | 00,014,032 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/06/25 21:16:20 | 06,061,540 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/06/25 21:16:20 | 00,000,000 | —D | C] – C:\WINDOWS\System32\drivers\Avg
[2009/06/25 21:15:58 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\avg8
[2009/06/25 21:13:38 | 00,000,000 | —D | C] – C:\Program Files\AVG
[2009/06/21 09:01:39 | 00,070,144 | —- | C] () – C:\Documents and Settings\Owner\My Documents\father's day.pub
[2009/06/19 15:18:09 | 00,020,992 | —- | C] () – C:\Documents and Settings\Owner\My Documents\oprah.doc
[2009/06/15 23:21:38 | 00,024,576 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Letter to Dr. Milrod.doc
[2009/06/15 22:34:11 | 00,024,064 | —- | C] () – C:\Documents and Settings\Owner\My Documents\June 15.doc
[2009/06/09 07:01:10 | 00,000,054 | -H– | C] () – C:\Documents and Settings\Owner\My Documents\~$y Saige Wenik.doc
[2009/06/08 17:05:31 | 00,549,564 | —- | C] () – C:\Documents and Settings\Owner\My Documents\PDRM0001.JPG
[2009/06/08 16:19:41 | 00,020,992 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Soy Saige Wenik.doc
[2008/10/23 07:52:51 | 00,000,032 | —- | C] () – C:\WINDOWS\ARC_CPR-AED-PR.ini
[2008/07/26 08:25:02 | 00,025,624 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2007/01/01 09:16:55 | 00,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2006/12/21 20:41:32 | 00,000,021 | —- | C] () – C:\WINDOWS\atid.ini
[2004/12/06 20:52:42 | 00,002,150 | —- | C] () – C:\WINDOWS\System32\ssmute.ini
[2004/10/02 16:57:54 | 00,000,169 | —- | C] () – C:\WINDOWS\magix.ini
[2004/10/02 16:57:53 | 00,000,919 | —- | C] () – C:\WINDOWS\mgxoschk.ini
[2004/09/11 10:04:35 | 00,000,074 | —- | C] () – C:\WINDOWS\lbbho.ini
[2004/09/04 08:59:22 | 00,000,036 | —- | C] () – C:\WINDOWS\TLCAPPS.INI
[2004/09/01 21:06:48 | 00,000,000 | —- | C] () – C:\WINDOWS\SETUP32.INI
[2004/07/26 08:01:55 | 00,000,045 | —- | C] () – C:\WINDOWS\Tlcpromo.ini
[2004/07/26 08:01:51 | 00,000,398 | —- | C] () – C:\WINDOWS\SBW95.ini
[2004/06/23 18:49:55 | 00,000,060 | —- | C] () – C:\WINDOWS\SIERRA.INI
[2004/06/23 17:38:30 | 00,000,383 | —- | C] () – C:\WINDOWS\ka.ini
[2004/06/06 09:21:37 | 00,086,030 | —- | C] () – C:\WINDOWS\System32\msdjgk.dll
[2004/05/16 15:26:07 | 00,001,890 | —- | C] () – C:\WINDOWS\7THLEVEL.INI
[2004/03/23 17:49:48 | 00,131,072 | —- | C] () – C:\WINDOWS\System32\sfarkxt.dll
[2004/03/23 17:49:47 | 00,068,096 | —- | C] () – C:\WINDOWS\System32\SFARKL.DLL
[2004/01/30 19:48:00 | 00,217,088 | —- | C] () – C:\WINDOWS\System32\libmySQL.dll
[2003/12/09 13:16:52 | 00,442,368 | —- | C] ( ) – C:\WINDOWS\System32\comintfs.dll
[2003/12/07 15:45:53 | 00,061,440 | —- | C] () – C:\WINDOWS\System32\gl.dll
[2003/12/07 15:45:53 | 00,023,200 | —- | C] () – C:\WINDOWS\System32\drivers\ppsio2.sys
[2003/12/07 15:45:53 | 00,006,123 | —- | C] () – C:\WINDOWS\System32\e1.ini
[2003/11/08 09:33:15 | 00,010,301 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2003/09/18 23:09:16 | 00,000,024 | —- | C] () – C:\WINDOWS\qfnonl.ini
[2003/09/18 22:43:36 | 00,000,050 | —- | C] () – C:\WINDOWS\qwimp.ini
[2003/09/18 22:06:25 | 00,007,183 | —- | C] () – C:\WINDOWS\hpdj5100.ini
[2003/09/18 22:05:58 | 00,000,414 | —- | C] () – C:\WINDOWS\hpbvspst.ini
[2003/09/18 21:54:44 | 00,000,144 | —- | C] () – C:\WINDOWS\WININIT.INI
[2003/09/18 21:54:26 | 00,000,006 | —- | C] () – C:\WINDOWS\msoffice.ini
[2003/09/18 21:09:03 | 00,000,737 | —- | C] () – C:\WINDOWS\ODBC.INI
[2003/09/18 20:59:23 | 00,000,146 | —- | C] () – C:\WINDOWS\lotus.ini
[2003/09/18 20:23:16 | 00,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2003/05/31 14:29:50 | 00,019,968 | —- | C] () – C:\WINDOWS\System32\cpuinf32.dll
[2003/04/10 07:33:14 | 00,094,208 | —- | C] () – C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2003/04/10 07:33:14 | 00,077,824 | —- | C] () – C:\WINDOWS\System32\ProgressTrace.dll
[2003/04/10 07:10:20 | 00,167,936 | —- | C] () – C:\WINDOWS\System32\PCDrJNI_1_1.dll
[2003/04/10 07:08:02 | 00,024,576 | —- | C] () – C:\WINDOWS\System32\syscontr.dll
[2003/04/10 07:08:01 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2003/04/10 07:07:51 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/04/10 07:00:09 | 00,000,692 | —- | C] () – C:\WINDOWS\intuprof.ini
[2003/04/10 06:59:52 | 00,001,212 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2003/04/10 06:53:45 | 00,000,051 | —- | C] () – C:\WINDOWS\System32\mshrml.ini
[2003/04/10 06:36:30 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2003/04/10 06:16:02 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/04/10 06:06:11 | 00,299,073 | —- | C] () – C:\WINDOWS\System32\PythonCOM22.dll
[2003/04/10 06:06:11 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\PyWinTypes22.dll
[2003/04/10 06:05:46 | 00,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2003/04/10 05:53:32 | 00,000,802 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/04/10 05:37:43 | 00,000,552 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2003/04/10 05:37:23 | 00,000,698 | —- | C] () – C:\WINDOWS\win.ini
[2003/04/10 05:37:19 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini
[2003/04/10 03:08:18 | 00,000,438 | —- | C] () – C:\WINDOWS\System32\1_ssetup.ini
[2003/04/10 03:08:18 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\sunistlog.ini
[2002/06/10 15:16:22 | 00,066,482 | R— | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2000/09/08 18:53:50 | 00,073,839 | —- | C] () – C:\WINDOWS\System32\KodakOneTouch.dll
[1997/07/11 00:00:00 | 00,031,232 | —- | C] () – C:\WINDOWS\System32\XLREC.DLL
[1997/07/11 00:00:00 | 00,025,600 | —- | C] () – C:\WINDOWS\System32\RECNCL.DLL
[1997/07/11 00:00:00 | 00,022,016 | —- | C] () – C:\WINDOWS\System32\ODBCSTF.DLL
[1997/07/11 00:00:00 | 00,022,016 | —- | C] () – C:\WINDOWS\System32\DOCOBJ.DLL
[1997/07/11 00:00:00 | 00,012,288 | —- | C] () – C:\WINDOWS\System32\HLINKPRX.DLL
[1996/04/25 21:23:00 | 00,000,846 | —- | C] () – C:\WINDOWS\acroread.ini
[1996/02/22 21:23:00 | 00,222,928 | —- | C] () – C:\WINDOWS\System32\lobas09.dll
[1996/01/17 21:23:00 | 00,031,008 | —- | C] () – C:\WINDOWS\System32\ivtrn09.dll
[1996/01/15 21:23:00 | 00,334,016 | —- | C] () – C:\WINDOWS\System32\loflt09.dll
[1995/09/25 21:23:00 | 00,014,928 | —- | C] () – C:\WINDOWS\System32\wingen.drv
[1994/04/07 21:23:00 | 00,000,462 | —- | C] () – C:\WINDOWS\lodbf09.ini

========== Files - Modified Within 30 Days ==========

[1 C:\Documents and Settings\Owner\My Documents\*.tmp files]
[2009/07/07 18:20:40 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/07/07 18:20:35 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/07/07 18:20:34 | 52,788,0192 | -HS- | M] () – C:\hiberfil.sys
[2009/07/07 18:10:30 | 00,148,888 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2009/07/07 18:10:29 | 00,410,984 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deploytk.dll
[2009/07/07 18:10:29 | 00,144,792 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2009/07/07 18:10:29 | 00,144,792 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2009/07/07 18:10:29 | 00,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2009/07/07 09:19:48 | 37,858,695 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/07/07 09:19:48 | 00,014,032 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/07/07 04:22:09 | 00,399,650 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/07/07 04:22:08 | 00,060,626 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/07/07 04:22:05 | 00,467,868 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/07/07 04:15:35 | 00,399,936 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/07/07 04:06:18 | 00,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/07/07 00:00:00 | 00,000,622 | —- | M] () – C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - Owner.job
[2009/07/06 22:37:08 | 00,513,536 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2009/07/06 22:02:27 | 00,000,704 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/07/06 09:38:03 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/07/05 09:50:00 | 00,027,784 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/07/05 09:49:56 | 00,335,752 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/07/05 09:33:12 | 00,064,160 | —- | M] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/07/05 09:31:07 | 00,000,875 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/07/05 00:18:08 | 00,001,742 | —- | M] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk
[2009/07/04 23:26:13 | 00,463,779 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/07/04 13:44:35 | 00,000,941 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Spybot - Search & Destroy.lnk
[2009/07/04 13:36:22 | 16,409,960 | —- | M] (Safer Networking Limited ) – C:\Documents and Settings\Owner\Desktop\setup-spybotsd162.exe
[2009/07/04 10:18:03 | 00,002,265 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2009/07/04 08:19:11 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/06/30 22:25:57 | 00,001,212 | —- | M] () – C:\WINDOWS\QUICKEN.INI
[2009/06/26 19:40:29 | 00,000,698 | —- | M] () – C:\WINDOWS\win.ini
[2009/06/26 19:35:48 | 00,042,496 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/06/25 22:02:01 | 00,001,821 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2009/06/25 21:16:41 | 00,001,515 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG Free 8.5.lnk
[2009/06/25 21:16:39 | 00,108,552 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/06/25 21:16:39 | 00,011,952 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/06/25 21:16:21 | 06,061,540 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/06/23 20:28:31 | 01,108,116 | -H– | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\IconCache.db
[2009/06/21 09:01:40 | 00,070,144 | —- | M] () – C:\Documents and Settings\Owner\My Documents\father's day.pub
[2009/06/19 15:18:10 | 00,020,992 | —- | M] () – C:\Documents and Settings\Owner\My Documents\oprah.doc
[2009/06/17 13:07:58 | 00,004,752 | -H– | M] () – C:\IPH.PH
[2009/06/17 11:27:56 | 00,038,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/06/17 11:27:44 | 00,019,096 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/06/17 10:28:16 | 00,001,642 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AIM 6.lnk
[2009/06/15 23:37:32 | 00,024,576 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Letter to Dr. Milrod.doc
[2009/06/15 23:21:17 | 00,024,064 | —- | M] () – C:\Documents and Settings\Owner\My Documents\June 15.doc
[2009/06/13 23:24:20 | 14,456,832 | R— | M] () – C:\Documents and Settings\All Users\Documents\ESBK.mbb
[2009/06/13 23:23:55 | 10,537,984 | R— | M] () – C:\Documents and Settings\All Users\Documents\ESBK.mb
[2009/06/09 07:01:10 | 00,000,054 | -H– | M] () – C:\Documents and Settings\Owner\My Documents\~$y Saige Wenik.doc
[2009/06/08 17:10:43 | 00,020,992 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Soy Saige Wenik.doc

========== LOP Check ==========

[2009/07/05 09:31:09 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/03/25 22:59:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{63A9FDE6-FCC7-4E26-A4CF-552A08431B32}
[2009/07/05 09:31:18 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
[2009/05/28 21:37:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2008/11/02 18:42:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2008/03/28 22:13:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avery
[2008/06/01 19:48:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Fashion Solitaire 1.2
[2009/03/22 17:30:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intuit
[2009/05/13 22:30:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Logishrd
[2009/01/30 18:44:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MakeMusic
[2008/06/29 10:59:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Motive
[2003/12/11 21:37:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN Messenger 6.0.0602
[2003/10/07 18:38:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN6
[2004/09/06 14:24:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2003/04/10 05:54:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2009/07/04 23:28:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/02/13 17:50:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Verizon
[2009/07/07 18:04:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2003/10/07 18:34:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Visual Networks
[2009/05/09 22:19:46 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Owner\Application Data
[2006/12/22 18:05:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\acccore
[2009/06/25 22:16:35 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Aim
[2007/03/02 22:54:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Arcsoft
[2007/04/08 10:18:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\COWON
[2003/10/26 13:51:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Games
[2007/04/08 10:14:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\interMute
[2003/10/18 09:14:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\InterVideo
[2008/03/16 19:04:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Intuit
[2004/02/21 19:44:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Leadertech
[2005/01/07 23:21:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Lycos
[2008/02/13 17:57:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Motive
[2007/05/21 20:59:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Move Networks
[2008/02/13 15:56:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\MSN6
[2007/01/01 09:21:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Panasonic
[2008/03/06 21:25:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\QQ Games Plugin
[2004/10/26 19:57:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\rawh
[2004/09/06 14:21:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Roxio
[2003/04/10 07:08:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SampleView
[2007/04/22 08:28:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Snapfish
[2003/08/02 18:07:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Template
[2009/01/12 17:17:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\U3
[2003/06/19 15:08:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\VERITAS
[2008/02/13 17:50:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Verizon
[2007/07/23 09:04:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\WeatherBug
[2004/12/06 21:52:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\winjt
[2008/07/20 21:20:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\WinPatrol
[2009/07/06 09:38:03 | 00,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2009/07/04 08:19:11 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2002/08/29 15:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/07/07 00:00:00 | 00,000,622 | —- | M] () – C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Owner.job
[2009/07/07 18:20:40 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 144 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A988B257
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >

svchost.exe
svchost.exe
alg.exe
svchost.exe
svchost.exe
explorer.exe
tskmgr.exe
LVComSer.exe
iexplore.exe
cftmon,.exe
hpdotdd01exe
cpf.exe
WinPatrol.exe
avgtray.exe
AAWTray.exe
jusched.exe
TeaTimer.exe
OTL.exe
SystemIdleProcess
System
avgnsx.exe
avgrsx.exe
jqs.exe
LVComSer.exe
LVPrcSrv.exe
smss.exe
crss.exe
winlogon.exe
services.exe
lsass.exe
svchost.exe
svchost.exe
svchost.exe
avgemc.exe
AAWService.exe
OPXApp.exe
avgcrsrvx.exe
avgwdsvc.exe
cmdagent.exe
IntuitUpdateServ
GoogleUpdate.exe
unsecapp.exe
wmiprvse.exe
svchost.exe

Any suggestions?

Mark

mbwenik,

Can you tell me what you have your homepage set to. Your log indicates it is set to a blank page. Is this your intention?

- - - - - Next - - - - -

To reset your Active Desktop:

  • Open the Control Panel.
  • Open the Display icon.
  • Click the Desktop tab.
  • Click the Customize Desktop button.
  • Click the Web tab in the Desktop Items window.
  • If you wish to enable the Active Desktop, check My Current Home Page.
  • Add your current home page into your desktop or click New to add another web page and/or other Active Desktop features.
  • To update the content, click the Synchronize button
- - - - - Next - - - - -

You log shows signs of Norton or Symantec Products on your computer. Do you use these anymore?
If not please follow these instructions:

Remove Norton or Symantec Products

Note : You should first attempt to remove your Norton/Symantec product using Add/Remove Programs in the Windows Control Panel (Programs and Features, in Windows Vista). This is the best method.

Uninstall anything with Norton or Symantec in the name

After uninstalling using Windows Add/Remove Programs, run the Norton Removal Tool to ensure successful removal of all Norton references.

If no entries are present in the Windows Add/Remove Programs you still need to run Norton Removal Tool below.

Please go to http://service1.symantec.com/Support/tsgen…005033108162039 and select the product you have

  • Download the Norton Removal Tool.
  • Save the file to the Windows desktop.
  • On the Windows desktop, double-click the Norton Removal Tool icon.
  • Follow the on-screen instructions.
    Your computer may be restarted more than once, and you may be asked to repeat some steps after the computer restarts.
- - - - - Next - - - - -
  • Please re-run OTL (should still be on your desktop)
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open in a notepad window. OTL.Txt.
    Note:The log can be located in the OTL. folder on you C:\ drive if it fails to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of the file, and post it with your next reply.
- - - - - Next - - - - -

Reboot, on your next post please provide the following:
  • OTL log
  • Answer question about your homepage setting
  • Tell me how your computer is running at the moment.

Here are results…

We have our homepage set to yahoo!

Computer still seems to lag, especially internet. Also, we can not use the internet unless we turn off the Comodo firewall.

OTL logfile created on: 7/9/2009 10:08:53 PM - Run 3
OTL by OldTimer - Version 3.0.6.5 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

503.36 Mb Total Physical Memory | 100.95 Mb Available Physical Memory | 20.05% Memory free
1.20 Gb Paging File | 0.59 Gb Available in Paging File | 48.84% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 107.53 Gb Total Space | 63.35 Gb Free Space | 58.91% Space Free | Partition Type: NTFS
Drive D: | 4.24 Gb Total Space | 0.66 Gb Free Space | 15.61% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PC1
Current User Name: Owner
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\Softex\OmniPass\OPXPApp.exe ()
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Comodo\Firewall\cmdagent.exe (COMODO)
PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\Program Files\Comodo\Firewall\CPF.exe (COMODO)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\System32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
PRC - C:\WINDOWS\System32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\internet explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\wscntfy.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)

========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device [On_Demand | Stopped]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (avg8emc [Auto | Running]) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd [Auto | Running]) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Bonjour Service [Disabled | Stopped]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (CmdAgent [Auto | Running]) – C:\Program Files\Comodo\Firewall\cmdagent.exe (COMODO)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (IntuitUpdateService [Auto | Running]) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (iPod Service [On_Demand | Stopped]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (KodakCCS [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\KodakCCS.exe (Eastman Kodak Company)
SRV - (Lavasoft Ad-Aware Service [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (LVCOMSer [Auto | Running]) – C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
SRV - (LVPrcSrv [Auto | Running]) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (NVSvc [Auto | Stopped]) – C:\WINDOWS\System32\nvsvc32.exe (NVIDIA Corporation)
SRV - (omniserv [Disabled | Stopped]) – C:\Program Files\Softex\OmniPass\Omniserv.exe ()
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (ALCXWDM [On_Demand | Running]) – C:\WINDOWS\System32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (AvgLdx86 [System | Running]) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (CmdMon [System | Running]) – C:\WINDOWS\System32\DRIVERS\cmdmon.sys (Comodo Research Lab., Inc.)
DRV - (DcCam [System | Running]) – C:\WINDOWS\System32\DRIVERS\DcCam.sys (Eastman Kodak Company)
DRV - (DcFpoint [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\DcFpoint.sys (Eastman Kodak Company)
DRV - (DCFS2K [Auto | Running]) – C:\WINDOWS\System32\drivers\dcfs2k.sys (Eastman Kodak Company)
DRV - (DcLps [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\DcLps.sys (Eastman Kodak Company)
DRV - (DcPTP [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\DcPTP.sys (Eastman Kodak Company)
DRV - (Exportit [System | Stopped]) – C:\WINDOWS\System32\DRIVERS\exportit.sys (Eastman Kodak Company)
DRV - (fasttx2k [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\fasttx2k.sys (Promise Technology, Inc.)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (ialm [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (Inspect [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\inspect.sys (COMODO)
DRV - (Lbd [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (ltmodem5 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ltmdmnt.sys (LT)
DRV - (LVPr2Mon [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\LVPr2Mon.sys ()
DRV - (LVUSBSta [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (MREMPR5 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MREMPR5.sys (Motive, Inc.)
DRV - (MRENDIS5 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MRENDIS5.sys (Motive, Inc.)
DRV - (mrtRate [Auto | Running]) – C:\WINDOWS\System32\drivers\MrtRate.sys (Marimba, Inc.)
DRV - (nv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (nv_agp [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\nv_agp.sys (NVIDIA Corporation)
DRV - (pfc [On_Demand | Running]) – C:\WINDOWS\System32\drivers\pfc.sys (Padus, Inc.)
DRV - (PID_PEPI [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\LV302V32.SYS (Logitech Inc.)
DRV - (ppsio2 [Auto | Running]) – C:\WINDOWS\System32\drivers\ppsio2.sys ()
DRV - (Ps2 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\PS2.sys (Hewlett-Packard Company)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\PxHelp20.sys (Sonic Solutions)
DRV - (QCDonner [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\LVCD.sys (Logitech Inc.)
DRV - (rtl8139 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\R8139n51.SYS (Realtek Semiconductor Corporation )
DRV - (S3Psddr [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\s3gnbm.sys (S3 Graphics, Inc.)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SiS315 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\sisgrp.sys (Silicon Integrated Systems Corporation)
DRV - (SISAGP [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\SISAGPX.sys (Silicon Integrated Systems Corporation)
DRV - (StillCam [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\serscan.sys (Microsoft Corporation)
DRV - (USBIO [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\usbio.sys (Thesycon GmbH, Germany)
DRV - (viaagp1 [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (vnccom [Auto | Running]) – C:\WINDOWS\System32\Drivers\vnccom.SYS (RDV Soft)
DRV - (vncdrv [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\vncdrv.sys (RDV Soft)
DRV - ({6080A529-897E-4629-A488-ABA0C29B635E} [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\ialmsbw.sys (Intel Corporation)
DRV - ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91} [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\ialmkchw.sys (Intel Corporation)

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\System32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/07/07 18:10:31 | 00,000,000 | —D | M]


O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (&Google;) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [COMODO Firewall Pro] C:\Program Files\Comodo\Firewall\CPF.exe (COMODO)
O4 - HKLM..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [NVIEW] C:\WINDOWS\System32\nview.DLL (NVIDIA Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowLegacyWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowUnhashedWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 36
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRunBackup = -1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FF FF FF FF [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disableregistrytools = 0
O8 - Extra context menu item: &AIM; Search - Reg Error: Value error. File not found
O9 - Extra Button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll (AOL LLC)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O12 - Plugin for: .pdf - C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll (Adobe Systems Inc.)
O15 - HKLM\..Trusted Domains: 45 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: 319 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E2941E3-8E63-11D4-9D5A-00902742D6E0} http://146.145.127.148/iNotes.cab (iNotes Class)
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} Reg Error: Value error. (Yahoo! Audio Conferencing)
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} http://mail.philaymca.org/iNotes6W.cab (iNotes6 Class)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} http://office.microsoft.com/officeupdate/content/opuc.cab (Office Update Installation Engine)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/…lscbase5483.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/microsoftupdat…b?1237767327250 (WUWebControl Class)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat…b?1237767270703 (MUWebControl Class)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx (Get_ActiveX Control)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://zone.msn.com/binFramework/v10/ZIntro.cab32846.cab (ZoneIntro Class)
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://active.macromedia.com/flash2/cabs/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DB0474CC-8EF6-47FC-905B-23FC58A70817} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {E93A6FCA-C052-45DF-AC9B-B729066092F8} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O16 - DPF: vzTCPConfig Reg Error: Value error. (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\OPXPGina: DllName - C:\Program Files\Softex\OmniPass\opxpgina.dll - C:\Program Files\Softex\OmniPass\opxpgina.dll ()
O24 - Desktop Components:0 () - C:\Program Files\Messenger\profsydy.html
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/07/28 07:07:38 | 00,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2008/07/20 13:17:26 | 00,000,090 | —- | M] () - D:\AUTORUN.INF – [ FAT32 ]
O33 - MountPoints2\{4729c152-3c75-11dc-8af9-000c6e35d416}\Shell - "" = AutoRun
O33 - MountPoints2\{4729c152-3c75-11dc-8af9-000c6e35d416}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{4729c152-3c75-11dc-8af9-000c6e35d416}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found

========== Files/Folders - Created Within 30 Days ==========

[2009/07/09 22:03:23 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2009/07/07 18:16:03 | 00,000,000 | —D | C] – C:\_OTL
[2009/07/07 18:11:07 | 00,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2009/07/07 18:11:06 | 00,410,984 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deploytk.dll
[2009/07/07 18:11:05 | 00,148,888 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2009/07/07 18:11:05 | 00,144,792 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2009/07/07 18:11:04 | 00,144,792 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2009/07/06 22:37:05 | 00,513,536 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2009/07/06 22:02:27 | 00,000,704 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/07/06 22:02:20 | 00,038,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/07/06 22:02:18 | 00,019,096 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/07/06 22:02:18 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/07/06 21:45:04 | 00,000,000 | —D | C] – C:\WINDOWS\System32\CatRoot_bak
[2009/07/06 21:42:29 | 00,272,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bthport.sys
[2009/07/06 21:41:43 | 00,283,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pdh.dll
[2009/07/06 21:41:43 | 00,060,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\colbact.dll
[2009/07/06 21:41:41 | 00,473,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fastprox.dll
[2009/07/06 21:41:41 | 00,399,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rpcss.dll
[2009/07/06 21:41:41 | 00,227,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvse.exe
[2009/07/06 21:41:41 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\services.exe
[2009/07/06 21:41:40 | 00,453,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvsd.dll
[2009/07/06 21:41:39 | 00,616,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\advapi32.dll
[2009/07/06 21:41:37 | 00,714,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntdll.dll
[2009/07/06 21:40:50 | 00,331,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msadce.dll
[2009/07/06 21:37:45 | 00,215,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wordpad.exe
[2009/07/05 09:34:38 | 00,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/07/05 09:34:21 | 00,064,160 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/07/05 09:31:09 | 00,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
[2009/07/05 09:31:07 | 00,000,875 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/07/05 00:18:08 | 00,001,742 | —- | C] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk
[2009/07/05 00:18:02 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/07/04 13:35:51 | 16,409,960 | —- | C] (Safer Networking Limited ) – C:\Documents and Settings\Owner\Desktop\setup-spybotsd162.exe
[2009/06/26 02:02:32 | 00,000,000 | -H-D | C] – C:\$AVG8.VAULT$
[2009/06/25 21:16:41 | 00,001,515 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG Free 8.5.lnk
[2009/06/25 21:16:39 | 00,108,552 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/06/25 21:16:39 | 00,011,952 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/06/25 21:16:38 | 00,335,752 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/06/25 21:16:21 | 37,999,075 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/06/25 21:16:21 | 00,463,779 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/06/25 21:16:21 | 00,022,992 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/06/25 21:16:20 | 06,061,540 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/06/25 21:16:20 | 00,000,000 | —D | C] – C:\WINDOWS\System32\drivers\Avg
[2009/06/25 21:15:58 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\avg8
[2009/06/25 21:13:38 | 00,000,000 | —D | C] – C:\Program Files\AVG
[2009/06/21 09:01:39 | 00,070,144 | —- | C] () – C:\Documents and Settings\Owner\My Documents\father's day.pub
[2009/06/19 15:18:09 | 00,020,992 | —- | C] () – C:\Documents and Settings\Owner\My Documents\oprah.doc
[2009/06/15 23:21:38 | 00,024,576 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Letter to Dr. Milrod.doc
[2009/06/15 22:34:11 | 00,024,064 | —- | C] () – C:\Documents and Settings\Owner\My Documents\June 15.doc
[2008/10/23 07:52:51 | 00,000,032 | —- | C] () – C:\WINDOWS\ARC_CPR-AED-PR.ini
[2008/07/26 08:25:02 | 00,025,624 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2007/01/01 09:16:55 | 00,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2006/12/21 20:41:32 | 00,000,021 | —- | C] () – C:\WINDOWS\atid.ini
[2004/12/06 20:52:42 | 00,002,150 | —- | C] () – C:\WINDOWS\System32\ssmute.ini
[2004/10/02 16:57:54 | 00,000,169 | —- | C] () – C:\WINDOWS\magix.ini
[2004/10/02 16:57:53 | 00,000,919 | —- | C] () – C:\WINDOWS\mgxoschk.ini
[2004/09/11 10:04:35 | 00,000,074 | —- | C] () – C:\WINDOWS\lbbho.ini
[2004/09/04 08:59:22 | 00,000,036 | —- | C] () – C:\WINDOWS\TLCAPPS.INI
[2004/09/01 21:06:48 | 00,000,000 | —- | C] () – C:\WINDOWS\SETUP32.INI
[2004/07/26 08:01:55 | 00,000,045 | —- | C] () – C:\WINDOWS\Tlcpromo.ini
[2004/07/26 08:01:51 | 00,000,398 | —- | C] () – C:\WINDOWS\SBW95.ini
[2004/06/23 18:49:55 | 00,000,060 | —- | C] () – C:\WINDOWS\SIERRA.INI
[2004/06/23 17:38:30 | 00,000,383 | —- | C] () – C:\WINDOWS\ka.ini
[2004/06/06 09:21:37 | 00,086,030 | —- | C] () – C:\WINDOWS\System32\msdjgk.dll
[2004/05/16 15:26:07 | 00,001,890 | —- | C] () – C:\WINDOWS\7THLEVEL.INI
[2004/03/23 17:49:48 | 00,131,072 | —- | C] () – C:\WINDOWS\System32\sfarkxt.dll
[2004/03/23 17:49:47 | 00,068,096 | —- | C] () – C:\WINDOWS\System32\SFARKL.DLL
[2004/01/30 19:48:00 | 00,217,088 | —- | C] () – C:\WINDOWS\System32\libmySQL.dll
[2003/12/09 13:16:52 | 00,442,368 | —- | C] ( ) – C:\WINDOWS\System32\comintfs.dll
[2003/12/07 15:45:53 | 00,061,440 | —- | C] () – C:\WINDOWS\System32\gl.dll
[2003/12/07 15:45:53 | 00,023,200 | —- | C] () – C:\WINDOWS\System32\drivers\ppsio2.sys
[2003/12/07 15:45:53 | 00,006,123 | —- | C] () – C:\WINDOWS\System32\e1.ini
[2003/11/08 09:33:15 | 00,010,301 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2003/09/18 23:09:16 | 00,000,024 | —- | C] () – C:\WINDOWS\qfnonl.ini
[2003/09/18 22:43:36 | 00,000,050 | —- | C] () – C:\WINDOWS\qwimp.ini
[2003/09/18 22:06:25 | 00,007,183 | —- | C] () – C:\WINDOWS\hpdj5100.ini
[2003/09/18 22:05:58 | 00,000,414 | —- | C] () – C:\WINDOWS\hpbvspst.ini
[2003/09/18 21:54:44 | 00,000,144 | —- | C] () – C:\WINDOWS\WININIT.INI
[2003/09/18 21:54:26 | 00,000,006 | —- | C] () – C:\WINDOWS\msoffice.ini
[2003/09/18 21:09:03 | 00,000,737 | —- | C] () – C:\WINDOWS\ODBC.INI
[2003/09/18 20:59:23 | 00,000,146 | —- | C] () – C:\WINDOWS\lotus.ini
[2003/09/18 20:23:16 | 00,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2003/05/31 14:29:50 | 00,019,968 | —- | C] () – C:\WINDOWS\System32\cpuinf32.dll
[2003/04/10 07:33:14 | 00,094,208 | —- | C] () – C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2003/04/10 07:33:14 | 00,077,824 | —- | C] () – C:\WINDOWS\System32\ProgressTrace.dll
[2003/04/10 07:10:20 | 00,167,936 | —- | C] () – C:\WINDOWS\System32\PCDrJNI_1_1.dll
[2003/04/10 07:08:02 | 00,024,576 | —- | C] () – C:\WINDOWS\System32\syscontr.dll
[2003/04/10 07:08:01 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2003/04/10 07:07:51 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/04/10 07:00:09 | 00,000,692 | —- | C] () – C:\WINDOWS\intuprof.ini
[2003/04/10 06:59:52 | 00,001,212 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2003/04/10 06:53:45 | 00,000,051 | —- | C] () – C:\WINDOWS\System32\mshrml.ini
[2003/04/10 06:36:30 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2003/04/10 06:16:02 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/04/10 06:06:11 | 00,299,073 | —- | C] () – C:\WINDOWS\System32\PythonCOM22.dll
[2003/04/10 06:06:11 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\PyWinTypes22.dll
[2003/04/10 06:05:46 | 00,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2003/04/10 05:53:32 | 00,000,802 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/04/10 05:37:43 | 00,000,552 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2003/04/10 05:37:23 | 00,000,698 | —- | C] () – C:\WINDOWS\win.ini
[2003/04/10 05:37:19 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini
[2003/04/10 03:08:18 | 00,000,438 | —- | C] () – C:\WINDOWS\System32\1_ssetup.ini
[2003/04/10 03:08:18 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\sunistlog.ini
[2002/06/10 15:16:22 | 00,066,482 | R— | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2000/09/08 18:53:50 | 00,073,839 | —- | C] () – C:\WINDOWS\System32\KodakOneTouch.dll
[1997/07/11 00:00:00 | 00,031,232 | —- | C] () – C:\WINDOWS\System32\XLREC.DLL
[1997/07/11 00:00:00 | 00,025,600 | —- | C] () – C:\WINDOWS\System32\RECNCL.DLL
[1997/07/11 00:00:00 | 00,022,016 | —- | C] () – C:\WINDOWS\System32\ODBCSTF.DLL
[1997/07/11 00:00:00 | 00,022,016 | —- | C] () – C:\WINDOWS\System32\DOCOBJ.DLL
[1997/07/11 00:00:00 | 00,012,288 | —- | C] () – C:\WINDOWS\System32\HLINKPRX.DLL
[1996/04/25 21:23:00 | 00,000,846 | —- | C] () – C:\WINDOWS\acroread.ini
[1996/02/22 21:23:00 | 00,222,928 | —- | C] () – C:\WINDOWS\System32\lobas09.dll
[1996/01/17 21:23:00 | 00,031,008 | —- | C] () – C:\WINDOWS\System32\ivtrn09.dll
[1996/01/15 21:23:00 | 00,334,016 | —- | C] () – C:\WINDOWS\System32\loflt09.dll
[1995/09/25 21:23:00 | 00,014,928 | —- | C] () – C:\WINDOWS\System32\wingen.drv
[1994/04/07 21:23:00 | 00,000,462 | —- | C] () – C:\WINDOWS\lodbf09.ini

========== Files - Modified Within 30 Days ==========

[1 C:\Documents and Settings\Owner\My Documents\*.tmp files]
[2009/07/09 18:11:32 | 37,999,075 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/07/09 18:11:32 | 00,022,992 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/07/09 00:00:00 | 00,000,622 | —- | M] () – C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - Owner.job
[2009/07/08 19:33:52 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/07/08 19:33:43 | 52,788,0192 | -HS- | M] () – C:\hiberfil.sys
[2009/07/08 19:33:43 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/07/07 21:26:22 | 00,001,212 | —- | M] () – C:\WINDOWS\QUICKEN.INI
[2009/07/07 18:10:30 | 00,148,888 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2009/07/07 18:10:29 | 00,410,984 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deploytk.dll
[2009/07/07 18:10:29 | 00,144,792 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2009/07/07 18:10:29 | 00,144,792 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2009/07/07 18:10:29 | 00,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2009/07/07 04:22:09 | 00,399,650 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/07/07 04:22:08 | 00,060,626 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/07/07 04:22:05 | 00,467,868 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/07/07 04:15:35 | 00,399,936 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/07/07 04:06:18 | 00,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/07/06 22:37:08 | 00,513,536 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2009/07/06 22:02:27 | 00,000,704 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/07/06 09:38:03 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/07/05 09:50:00 | 00,027,784 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/07/05 09:49:56 | 00,335,752 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/07/05 09:33:12 | 00,064,160 | —- | M] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/07/05 09:31:07 | 00,000,875 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/07/05 00:18:08 | 00,001,742 | —- | M] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk
[2009/07/04 23:26:13 | 00,463,779 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/07/04 13:44:35 | 00,000,941 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Spybot - Search & Destroy.lnk
[2009/07/04 13:36:22 | 16,409,960 | —- | M] (Safer Networking Limited ) – C:\Documents and Settings\Owner\Desktop\setup-spybotsd162.exe
[2009/07/04 10:18:03 | 00,002,265 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2009/07/04 08:19:11 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/06/26 19:40:29 | 00,000,698 | —- | M] () – C:\WINDOWS\win.ini
[2009/06/26 19:35:48 | 00,042,496 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/06/25 21:16:41 | 00,001,515 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG Free 8.5.lnk
[2009/06/25 21:16:39 | 00,108,552 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/06/25 21:16:39 | 00,011,952 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/06/25 21:16:21 | 06,061,540 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/06/23 20:28:31 | 01,108,116 | -H– | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\IconCache.db
[2009/06/21 09:01:40 | 00,070,144 | —- | M] () – C:\Documents and Settings\Owner\My Documents\father's day.pub
[2009/06/19 15:18:10 | 00,020,992 | —- | M] () – C:\Documents and Settings\Owner\My Documents\oprah.doc
[2009/06/17 13:07:58 | 00,004,752 | -H– | M] () – C:\IPH.PH
[2009/06/17 11:27:56 | 00,038,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/06/17 11:27:44 | 00,019,096 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/06/17 10:28:16 | 00,001,642 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AIM 6.lnk
[2009/06/15 23:37:32 | 00,024,576 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Letter to Dr. Milrod.doc
[2009/06/15 23:21:17 | 00,024,064 | —- | M] () – C:\Documents and Settings\Owner\My Documents\June 15.doc
[2009/06/13 23:24:20 | 14,456,832 | R— | M] () – C:\Documents and Settings\All Users\Documents\ESBK.mbb
[2009/06/13 23:23:55 | 10,537,984 | R— | M] () – C:\Documents and Settings\All Users\Documents\ESBK.mb

========== LOP Check ==========

[2009/07/09 22:06:06 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/03/25 22:59:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{63A9FDE6-FCC7-4E26-A4CF-552A08431B32}
[2009/07/05 09:31:18 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
[2009/05/28 21:37:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2008/11/02 18:42:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2008/03/28 22:13:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avery
[2008/06/01 19:48:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Fashion Solitaire 1.2
[2009/03/22 17:30:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intuit
[2009/05/13 22:30:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Logishrd
[2009/01/30 18:44:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MakeMusic
[2008/06/29 10:59:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Motive
[2003/12/11 21:37:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN Messenger 6.0.0602
[2003/10/07 18:38:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN6
[2004/09/06 14:24:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2009/07/09 22:03:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2003/04/10 05:54:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2009/07/04 23:28:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/02/13 17:50:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Verizon
[2009/07/07 18:04:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2003/10/07 18:34:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Visual Networks
[2009/07/09 22:06:05 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Owner\Application Data
[2006/12/22 18:05:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\acccore
[2009/06/25 22:16:35 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Aim
[2007/03/02 22:54:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Arcsoft
[2007/04/08 10:18:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\COWON
[2003/10/26 13:51:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Games
[2007/04/08 10:14:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\interMute
[2003/10/18 09:14:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\InterVideo
[2008/03/16 19:04:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Intuit
[2004/02/21 19:44:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Leadertech
[2005/01/07 23:21:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Lycos
[2008/02/13 17:57:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Motive
[2007/05/21 20:59:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Move Networks
[2008/02/13 15:56:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\MSN6
[2007/01/01 09:21:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Panasonic
[2008/03/06 21:25:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\QQ Games Plugin
[2004/10/26 19:57:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\rawh
[2004/09/06 14:21:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Roxio
[2003/04/10 07:08:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SampleView
[2007/04/22 08:28:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Snapfish
[2003/08/02 18:07:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Template
[2009/01/12 17:17:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\U3
[2003/06/19 15:08:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\VERITAS
[2008/02/13 17:50:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Verizon
[2007/07/23 09:04:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\WeatherBug
[2004/12/06 21:52:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\winjt
[2008/07/20 21:20:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\WinPatrol
[2009/07/06 09:38:03 | 00,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2009/07/04 08:19:11 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2002/08/29 15:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/07/09 00:00:00 | 00,000,622 | —- | M] () – C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Owner.job
[2009/07/08 19:33:52 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 144 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A988B257
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >

mbwenik,

Can you please tell me when you installed the Comodo Firewall were you given the option to install the Comodo Anti-Virus also?
If so, did you install the Anti - Virus also?

It sounds like your firewall is not configured to allow Internet Explorer to access the Internet.

Please follow these instructions to try and determine how your firewall is setup.
There are two parts to the instructions. One part will walk you through the Help Manual. The other will have you following along in the actual Comodo Firewall program.
(make no changes unless you are confident in your decision)

Steps for navigating Comodo Help Manual:

  • Right Click the Comodo Firewall icon in the bottm right corner on your screen
  • Select Open > select Miscellaneous in the top menu > Help (will open in a new window)
  • Click the "+" to expand the menu for Firewall Tasks - Overview
  • Expand Advanced Tasks > Network Security Policy > Application Rules
  • Now that you have the Help menu open go back to the firewall program.
Steps for navigating Comodo firewall:
  • In the Comodo Firewall > select Firewall in the top menu
  • Select Advanced Tasks > Network Security Policy > Application Rules
  • Scroll through the list and locate Internet Explorer
  • Check and see if it is set to Allow
  • If it is not set to Allow, please provide me with what it does show
- - - - - Next - - - - -

On your next post please provide the following:
  • Answer my questions as completely as possible.

I must have a different version of Comodo, because I can not navigate it the way you have described. I do not remember having the option to install anti-virus. When I look at the applications under application control rules, there are 11 applications under internet explorer. Ten of the 11 are showing that they are blocked. The one that shows allow it is straight internet explorer, as opposed to the others that are linked to spyware blaster, intuit updater, etc. Here is the version of Comodo that I am using: [removed], Databse version 3.0

mbwenik,

Please disconnect from the Internet completely. Pull the plug from your modem or router to be certain.

Uninstall Comodo Firewall

Click Start > All Programs > Comodo > Firewall > Uninstall
Follow the onscreen prompts to remove Comodo from your computer

If your version doesn't have an uninstall feature please use the following instructions to remove Comodo.

Please go to Start Menu > Control Panel > Add/ Remove Programs
Scroll Down and locate the following program:

  • Comodo Firewall
Select the program, then select remove.

Exit the Control Panel when finished.

- - - - - Next - - - - -

Please enable your Windows Firewall
  • Click Start > Control Panel > Security Center
  • Select Windows Firewall
  • Under the General tab select the ON radio button
  • Click OK, exit the Control Panel
- - - - - Next - - - - -

Reboot, reconnect to the Internet

- - - - - Next - - - - -

Next please download the newest version of Comodo Firewall and AntiVirus.
The Anti-Virus is included in the download, but during installation you will receive the option to "Install the Firewall as a standalone"

DO NOT INSTALL IT AT THIS TIME.

Download Comodo Firewall (3.10)
  • Comodo - http://www.personalfirewall.comodo.com/
- - - - - Next - - - - -

Reboot, on your next post please provide the following:
  • Confirm that you have Windows Firewall activated.
  • Verify that you have downloaded, but not installed the new Comodo Firewall.
  • Tell me how your computer is running at the moment, is your Internet surfing limited in any way?

Windows firewall is now operating. Comodo was saved to a folder - not opened or run. Can use the internet and have mulitple windows open. Not very fast, but better than it was. Thanks, Mark

mbwenik,

Let's try and get the new Comodo Firewall installed and configured correctly.

Once again, please disconnect from the Internet.

Please Disable your Windows Firewall

  • Click Start > Control Panel > Security Center
  • Select Windows Firewall
  • Under the General tab select the OFF radio button
  • Click OK, exit the Control Panel
- - - - - Next - - - - -

Locate the Comodo Firewall you previously downloaded. - C:\Program Files\COMODO\Firewall\cfp.exe
  • Double Click the cfp.exe file to install Comodo
  • Follow the onscreen instructions to complete the installation
Do not install the Comodo Anti-Virus offered. Install the Firewall as a stand alone application.

- - - - - Next - - - - -

Reboot

- - - - - Next - - - - -

Once you have the Comodo Firewall installed you will need to "re-train"it to allow the programs you use.
  • In the Comodo Firewall > select Firewall in the top menu
  • Select Advanced > Firewall Behavior Settings > General Settings
  • Move the Firewall Security Level to Training Mode
  • Select the Alert Settings tab
  • Move the Alert Frequecny Level selector to Very High
  • Make sure all boxes are checked
  • Select OK to close
These settings can be changed once you have "trained" your firewall. You will receive popup warnings
from Comodo, please review each one carefully and decide if you wish to allow or block the particular program.

- - - - - Next - - - - -

Reboot, on your next post please provide the following:
  • Update me on the Comodo Firewall install and configuration, any problems?
  • Tell me how your computer is running at the moment.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI