I removed all programs as suggested, including limewire. When I rebooted, the active desktop was disabled. Still running slow.
Here is log and at the end of the log, I have also listed all active processes.
OTL logfile created on: 7/7/2009 6:33:56 PM - Run 2
OTL by OldTimer - Version 3.0.6.5 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
503.36 Mb Total Physical Memory | 173.77 Mb Available Physical Memory | 34.52% Memory free
1.20 Gb Paging File | 0.71 Gb Available in Paging File | 59.29% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 107.53 Gb Total Space | 63.38 Gb Free Space | 58.94% Space Free | Partition Type: NTFS
Drive D: | 4.24 Gb Total Space | 0.66 Gb Free Space | 15.61% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: PC1
Current User Name: Owner
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\Softex\OmniPass\OPXPApp.exe ()
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Comodo\Firewall\cmdagent.exe (COMODO)
PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\notepad.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
PRC - C:\WINDOWS\System32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
PRC - C:\Program Files\Comodo\Firewall\CPF.exe (COMODO)
PRC - C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\WINDOWS\System32\taskmgr.exe (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (Apple Mobile Device [On_Demand | Stopped]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (avg8emc [Auto | Running]) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd [Auto | Running]) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Bonjour Service [Disabled | Stopped]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (CmdAgent [Auto | Running]) – C:\Program Files\Comodo\Firewall\cmdagent.exe (COMODO)
SRV - (gupdate1c9d115998455f8 [Auto | Stopped]) – C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (IntuitUpdateService [Auto | Running]) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (iPod Service [On_Demand | Stopped]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (KodakCCS [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\KodakCCS.exe (Eastman Kodak Company)
SRV - (Lavasoft Ad-Aware Service [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (LVCOMSer [Auto | Running]) – C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
SRV - (LVPrcSrv [Auto | Running]) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (NVSvc [Auto | Stopped]) – C:\WINDOWS\System32\nvsvc32.exe (NVIDIA Corporation)
SRV - (omniserv [Disabled | Stopped]) – C:\Program Files\Softex\OmniPass\Omniserv.exe ()
SRV - (Symantec Core LC [Disabled | Stopped]) – File not found
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (ALCXWDM [On_Demand | Running]) – C:\WINDOWS\System32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (AvgLdx86 [System | Running]) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (CmdMon [System | Running]) – C:\WINDOWS\System32\DRIVERS\cmdmon.sys (Comodo Research Lab., Inc.)
DRV - (DcCam [System | Running]) – C:\WINDOWS\System32\DRIVERS\DcCam.sys (Eastman Kodak Company)
DRV - (DcFpoint [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\DcFpoint.sys (Eastman Kodak Company)
DRV - (DCFS2K [Auto | Running]) – C:\WINDOWS\System32\drivers\dcfs2k.sys (Eastman Kodak Company)
DRV - (DcLps [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\DcLps.sys (Eastman Kodak Company)
DRV - (DcPTP [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\DcPTP.sys (Eastman Kodak Company)
DRV - (Exportit [System | Stopped]) – C:\WINDOWS\System32\DRIVERS\exportit.sys (Eastman Kodak Company)
DRV - (fasttx2k [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\fasttx2k.sys (Promise Technology, Inc.)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (ialm [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (Inspect [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\inspect.sys (COMODO)
DRV - (Lbd [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (ltmodem5 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ltmdmnt.sys (LT)
DRV - (LVPr2Mon [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\LVPr2Mon.sys ()
DRV - (LVUSBSta [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (MREMPR5 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MREMPR5.sys (Motive, Inc.)
DRV - (MRENDIS5 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MRENDIS5.sys (Motive, Inc.)
DRV - (mrtRate [Auto | Running]) – C:\WINDOWS\System32\drivers\MrtRate.sys (Marimba, Inc.)
DRV - (nv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (nv_agp [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\nv_agp.sys (NVIDIA Corporation)
DRV - (pfc [On_Demand | Running]) – C:\WINDOWS\System32\drivers\pfc.sys (Padus, Inc.)
DRV - (PID_PEPI [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\LV302V32.SYS (Logitech Inc.)
DRV - (ppsio2 [Auto | Running]) – C:\WINDOWS\System32\drivers\ppsio2.sys ()
DRV - (Ps2 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\PS2.sys (Hewlett-Packard Company)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\PxHelp20.sys (Sonic Solutions)
DRV - (QCDonner [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\LVCD.sys (Logitech Inc.)
DRV - (rtl8139 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\R8139n51.SYS (Realtek Semiconductor Corporation )
DRV - (S3Psddr [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\s3gnbm.sys (S3 Graphics, Inc.)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SiS315 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\sisgrp.sys (Silicon Integrated Systems Corporation)
DRV - (SISAGP [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\SISAGPX.sys (Silicon Integrated Systems Corporation)
DRV - (StillCam [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\serscan.sys (Microsoft Corporation)
DRV - (USBIO [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\usbio.sys (Thesycon GmbH, Germany)
DRV - (viaagp1 [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (vnccom [Auto | Running]) – C:\WINDOWS\System32\Drivers\vnccom.SYS (RDV Soft)
DRV - (vncdrv [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\vncdrv.sys (RDV Soft)
DRV - ({6080A529-897E-4629-A488-ABA0C29B635E} [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\ialmsbw.sys (Intel Corporation)
DRV - ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91} [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\ialmkchw.sys (Intel Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\System32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/07/07 18:10:31 | 00,000,000 | —D | M]
O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (&Google;) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [COMODO Firewall Pro] C:\Program Files\Comodo\Firewall\CPF.exe (COMODO)
O4 - HKLM..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [NVIEW] C:\WINDOWS\System32\nview.DLL (NVIDIA Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowLegacyWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowUnhashedWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 36
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRunBackup = -1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FF FF FF FF [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disableregistrytools = 0
O8 - Extra context menu item: &AIM; Search - Reg Error: Value error. File not found
O9 - Extra Button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll (AOL LLC)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O12 - Plugin for: .pdf - C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll (Adobe Systems Inc.)
O15 - HKLM\..Trusted Domains: 45 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: 319 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E2941E3-8E63-11D4-9D5A-00902742D6E0}
http://146.145.127.148/iNotes.cab (iNotes Class)
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} Reg Error: Value error. (Yahoo! Audio Conferencing)
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325}
http://mail.philaymca.org/iNotes6W.cab (iNotes6 Class)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}
http://office.microsoft.com/officeupdate/content/opuc.cab (Office Update Installation Engine)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166}
http://cdn.scan.onecare.live.com/resource/…lscbase5483.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.microsoft.com/microsoftupdat…b?1237767327250 (WUWebControl Class)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.microsoft.com/microsoftupdat…b?1237767270703 (MUWebControl Class)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09}
https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx (Get_ActiveX Control)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592}
http://zone.msn.com/binFramework/v10/ZIntro.cab32846.cab (ZoneIntro Class)
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://active.macromedia.com/flash2/cabs/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DB0474CC-8EF6-47FC-905B-23FC58A70817} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {E93A6FCA-C052-45DF-AC9B-B729066092F8} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O16 - DPF: vzTCPConfig Reg Error: Value error. (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\OPXPGina: DllName - C:\Program Files\Softex\OmniPass\opxpgina.dll - C:\Program Files\Softex\OmniPass\opxpgina.dll ()
O24 - Desktop Components:0 () - C:\Program Files\Messenger\profsydy.html
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/07/28 07:07:38 | 00,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2008/07/20 13:17:26 | 00,000,090 | —- | M] () - D:\AUTORUN.INF – [ FAT32 ]
O33 - MountPoints2\{4729c152-3c75-11dc-8af9-000c6e35d416}\Shell - "" = AutoRun
O33 - MountPoints2\{4729c152-3c75-11dc-8af9-000c6e35d416}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{4729c152-3c75-11dc-8af9-000c6e35d416}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
========== Files/Folders - Created Within 30 Days ==========
[2009/07/07 18:16:03 | 00,000,000 | —D | C] – C:\_OTL
[2009/07/07 18:11:07 | 00,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2009/07/07 18:11:06 | 00,410,984 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deploytk.dll
[2009/07/07 18:11:05 | 00,148,888 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2009/07/07 18:11:05 | 00,144,792 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2009/07/07 18:11:04 | 00,144,792 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2009/07/06 22:37:05 | 00,513,536 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2009/07/06 22:02:27 | 00,000,704 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/07/06 22:02:20 | 00,038,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/07/06 22:02:18 | 00,019,096 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/07/06 22:02:18 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/07/06 21:45:04 | 00,000,000 | —D | C] – C:\WINDOWS\System32\CatRoot_bak
[2009/07/06 21:42:29 | 00,272,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bthport.sys
[2009/07/06 21:41:43 | 00,283,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pdh.dll
[2009/07/06 21:41:43 | 00,060,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\colbact.dll
[2009/07/06 21:41:41 | 00,473,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fastprox.dll
[2009/07/06 21:41:41 | 00,399,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rpcss.dll
[2009/07/06 21:41:41 | 00,227,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvse.exe
[2009/07/06 21:41:41 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\services.exe
[2009/07/06 21:41:40 | 00,453,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvsd.dll
[2009/07/06 21:41:39 | 00,616,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\advapi32.dll
[2009/07/06 21:41:37 | 00,714,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntdll.dll
[2009/07/06 21:40:50 | 00,331,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msadce.dll
[2009/07/06 21:37:45 | 00,215,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wordpad.exe
[2009/07/05 09:34:38 | 00,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/07/05 09:34:21 | 00,064,160 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/07/05 09:31:09 | 00,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
[2009/07/05 09:31:07 | 00,000,875 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/07/05 00:18:08 | 00,001,742 | —- | C] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk
[2009/07/05 00:18:02 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/07/04 13:35:51 | 16,409,960 | —- | C] (Safer Networking Limited ) – C:\Documents and Settings\Owner\Desktop\setup-spybotsd162.exe
[2009/06/26 02:02:32 | 00,000,000 | -H-D | C] – C:\$AVG8.VAULT$
[2009/06/25 21:16:41 | 00,001,515 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG Free 8.5.lnk
[2009/06/25 21:16:39 | 00,108,552 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/06/25 21:16:39 | 00,011,952 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/06/25 21:16:38 | 00,335,752 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/06/25 21:16:21 | 37,858,695 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/06/25 21:16:21 | 00,463,779 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/06/25 21:16:21 | 00,014,032 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/06/25 21:16:20 | 06,061,540 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/06/25 21:16:20 | 00,000,000 | —D | C] – C:\WINDOWS\System32\drivers\Avg
[2009/06/25 21:15:58 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\avg8
[2009/06/25 21:13:38 | 00,000,000 | —D | C] – C:\Program Files\AVG
[2009/06/21 09:01:39 | 00,070,144 | —- | C] () – C:\Documents and Settings\Owner\My Documents\father's day.pub
[2009/06/19 15:18:09 | 00,020,992 | —- | C] () – C:\Documents and Settings\Owner\My Documents\oprah.doc
[2009/06/15 23:21:38 | 00,024,576 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Letter to Dr. Milrod.doc
[2009/06/15 22:34:11 | 00,024,064 | —- | C] () – C:\Documents and Settings\Owner\My Documents\June 15.doc
[2009/06/09 07:01:10 | 00,000,054 | -H– | C] () – C:\Documents and Settings\Owner\My Documents\~$y Saige Wenik.doc
[2009/06/08 17:05:31 | 00,549,564 | —- | C] () – C:\Documents and Settings\Owner\My Documents\PDRM0001.JPG
[2009/06/08 16:19:41 | 00,020,992 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Soy Saige Wenik.doc
[2008/10/23 07:52:51 | 00,000,032 | —- | C] () – C:\WINDOWS\ARC_CPR-AED-PR.ini
[2008/07/26 08:25:02 | 00,025,624 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2007/01/01 09:16:55 | 00,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2006/12/21 20:41:32 | 00,000,021 | —- | C] () – C:\WINDOWS\atid.ini
[2004/12/06 20:52:42 | 00,002,150 | —- | C] () – C:\WINDOWS\System32\ssmute.ini
[2004/10/02 16:57:54 | 00,000,169 | —- | C] () – C:\WINDOWS\magix.ini
[2004/10/02 16:57:53 | 00,000,919 | —- | C] () – C:\WINDOWS\mgxoschk.ini
[2004/09/11 10:04:35 | 00,000,074 | —- | C] () – C:\WINDOWS\lbbho.ini
[2004/09/04 08:59:22 | 00,000,036 | —- | C] () – C:\WINDOWS\TLCAPPS.INI
[2004/09/01 21:06:48 | 00,000,000 | —- | C] () – C:\WINDOWS\SETUP32.INI
[2004/07/26 08:01:55 | 00,000,045 | —- | C] () – C:\WINDOWS\Tlcpromo.ini
[2004/07/26 08:01:51 | 00,000,398 | —- | C] () – C:\WINDOWS\SBW95.ini
[2004/06/23 18:49:55 | 00,000,060 | —- | C] () – C:\WINDOWS\SIERRA.INI
[2004/06/23 17:38:30 | 00,000,383 | —- | C] () – C:\WINDOWS\ka.ini
[2004/06/06 09:21:37 | 00,086,030 | —- | C] () – C:\WINDOWS\System32\msdjgk.dll
[2004/05/16 15:26:07 | 00,001,890 | —- | C] () – C:\WINDOWS\7THLEVEL.INI
[2004/03/23 17:49:48 | 00,131,072 | —- | C] () – C:\WINDOWS\System32\sfarkxt.dll
[2004/03/23 17:49:47 | 00,068,096 | —- | C] () – C:\WINDOWS\System32\SFARKL.DLL
[2004/01/30 19:48:00 | 00,217,088 | —- | C] () – C:\WINDOWS\System32\libmySQL.dll
[2003/12/09 13:16:52 | 00,442,368 | —- | C] ( ) – C:\WINDOWS\System32\comintfs.dll
[2003/12/07 15:45:53 | 00,061,440 | —- | C] () – C:\WINDOWS\System32\gl.dll
[2003/12/07 15:45:53 | 00,023,200 | —- | C] () – C:\WINDOWS\System32\drivers\ppsio2.sys
[2003/12/07 15:45:53 | 00,006,123 | —- | C] () – C:\WINDOWS\System32\e1.ini
[2003/11/08 09:33:15 | 00,010,301 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2003/09/18 23:09:16 | 00,000,024 | —- | C] () – C:\WINDOWS\qfnonl.ini
[2003/09/18 22:43:36 | 00,000,050 | —- | C] () – C:\WINDOWS\qwimp.ini
[2003/09/18 22:06:25 | 00,007,183 | —- | C] () – C:\WINDOWS\hpdj5100.ini
[2003/09/18 22:05:58 | 00,000,414 | —- | C] () – C:\WINDOWS\hpbvspst.ini
[2003/09/18 21:54:44 | 00,000,144 | —- | C] () – C:\WINDOWS\WININIT.INI
[2003/09/18 21:54:26 | 00,000,006 | —- | C] () – C:\WINDOWS\msoffice.ini
[2003/09/18 21:09:03 | 00,000,737 | —- | C] () – C:\WINDOWS\ODBC.INI
[2003/09/18 20:59:23 | 00,000,146 | —- | C] () – C:\WINDOWS\lotus.ini
[2003/09/18 20:23:16 | 00,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2003/05/31 14:29:50 | 00,019,968 | —- | C] () – C:\WINDOWS\System32\cpuinf32.dll
[2003/04/10 07:33:14 | 00,094,208 | —- | C] () – C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2003/04/10 07:33:14 | 00,077,824 | —- | C] () – C:\WINDOWS\System32\ProgressTrace.dll
[2003/04/10 07:10:20 | 00,167,936 | —- | C] () – C:\WINDOWS\System32\PCDrJNI_1_1.dll
[2003/04/10 07:08:02 | 00,024,576 | —- | C] () – C:\WINDOWS\System32\syscontr.dll
[2003/04/10 07:08:01 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2003/04/10 07:07:51 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/04/10 07:00:09 | 00,000,692 | —- | C] () – C:\WINDOWS\intuprof.ini
[2003/04/10 06:59:52 | 00,001,212 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2003/04/10 06:53:45 | 00,000,051 | —- | C] () – C:\WINDOWS\System32\mshrml.ini
[2003/04/10 06:36:30 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2003/04/10 06:16:02 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/04/10 06:06:11 | 00,299,073 | —- | C] () – C:\WINDOWS\System32\PythonCOM22.dll
[2003/04/10 06:06:11 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\PyWinTypes22.dll
[2003/04/10 06:05:46 | 00,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2003/04/10 05:53:32 | 00,000,802 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/04/10 05:37:43 | 00,000,552 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2003/04/10 05:37:23 | 00,000,698 | —- | C] () – C:\WINDOWS\win.ini
[2003/04/10 05:37:19 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini
[2003/04/10 03:08:18 | 00,000,438 | —- | C] () – C:\WINDOWS\System32\1_ssetup.ini
[2003/04/10 03:08:18 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\sunistlog.ini
[2002/06/10 15:16:22 | 00,066,482 | R— | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2000/09/08 18:53:50 | 00,073,839 | —- | C] () – C:\WINDOWS\System32\KodakOneTouch.dll
[1997/07/11 00:00:00 | 00,031,232 | —- | C] () – C:\WINDOWS\System32\XLREC.DLL
[1997/07/11 00:00:00 | 00,025,600 | —- | C] () – C:\WINDOWS\System32\RECNCL.DLL
[1997/07/11 00:00:00 | 00,022,016 | —- | C] () – C:\WINDOWS\System32\ODBCSTF.DLL
[1997/07/11 00:00:00 | 00,022,016 | —- | C] () – C:\WINDOWS\System32\DOCOBJ.DLL
[1997/07/11 00:00:00 | 00,012,288 | —- | C] () – C:\WINDOWS\System32\HLINKPRX.DLL
[1996/04/25 21:23:00 | 00,000,846 | —- | C] () – C:\WINDOWS\acroread.ini
[1996/02/22 21:23:00 | 00,222,928 | —- | C] () – C:\WINDOWS\System32\lobas09.dll
[1996/01/17 21:23:00 | 00,031,008 | —- | C] () – C:\WINDOWS\System32\ivtrn09.dll
[1996/01/15 21:23:00 | 00,334,016 | —- | C] () – C:\WINDOWS\System32\loflt09.dll
[1995/09/25 21:23:00 | 00,014,928 | —- | C] () – C:\WINDOWS\System32\wingen.drv
[1994/04/07 21:23:00 | 00,000,462 | —- | C] () – C:\WINDOWS\lodbf09.ini
========== Files - Modified Within 30 Days ==========
[1 C:\Documents and Settings\Owner\My Documents\*.tmp files]
[2009/07/07 18:20:40 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/07/07 18:20:35 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/07/07 18:20:34 | 52,788,0192 | -HS- | M] () – C:\hiberfil.sys
[2009/07/07 18:10:30 | 00,148,888 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2009/07/07 18:10:29 | 00,410,984 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deploytk.dll
[2009/07/07 18:10:29 | 00,144,792 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2009/07/07 18:10:29 | 00,144,792 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2009/07/07 18:10:29 | 00,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2009/07/07 09:19:48 | 37,858,695 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/07/07 09:19:48 | 00,014,032 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/07/07 04:22:09 | 00,399,650 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/07/07 04:22:08 | 00,060,626 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/07/07 04:22:05 | 00,467,868 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/07/07 04:15:35 | 00,399,936 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/07/07 04:06:18 | 00,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/07/07 00:00:00 | 00,000,622 | —- | M] () – C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - Owner.job
[2009/07/06 22:37:08 | 00,513,536 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2009/07/06 22:02:27 | 00,000,704 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/07/06 09:38:03 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/07/05 09:50:00 | 00,027,784 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/07/05 09:49:56 | 00,335,752 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/07/05 09:33:12 | 00,064,160 | —- | M] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/07/05 09:31:07 | 00,000,875 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/07/05 00:18:08 | 00,001,742 | —- | M] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk
[2009/07/04 23:26:13 | 00,463,779 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/07/04 13:44:35 | 00,000,941 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Spybot - Search & Destroy.lnk
[2009/07/04 13:36:22 | 16,409,960 | —- | M] (Safer Networking Limited ) – C:\Documents and Settings\Owner\Desktop\setup-spybotsd162.exe
[2009/07/04 10:18:03 | 00,002,265 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2009/07/04 08:19:11 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/06/30 22:25:57 | 00,001,212 | —- | M] () – C:\WINDOWS\QUICKEN.INI
[2009/06/26 19:40:29 | 00,000,698 | —- | M] () – C:\WINDOWS\win.ini
[2009/06/26 19:35:48 | 00,042,496 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/06/25 22:02:01 | 00,001,821 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2009/06/25 21:16:41 | 00,001,515 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG Free 8.5.lnk
[2009/06/25 21:16:39 | 00,108,552 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/06/25 21:16:39 | 00,011,952 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/06/25 21:16:21 | 06,061,540 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/06/23 20:28:31 | 01,108,116 | -H– | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\IconCache.db
[2009/06/21 09:01:40 | 00,070,144 | —- | M] () – C:\Documents and Settings\Owner\My Documents\father's day.pub
[2009/06/19 15:18:10 | 00,020,992 | —- | M] () – C:\Documents and Settings\Owner\My Documents\oprah.doc
[2009/06/17 13:07:58 | 00,004,752 | -H– | M] () – C:\IPH.PH
[2009/06/17 11:27:56 | 00,038,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/06/17 11:27:44 | 00,019,096 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/06/17 10:28:16 | 00,001,642 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AIM 6.lnk
[2009/06/15 23:37:32 | 00,024,576 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Letter to Dr. Milrod.doc
[2009/06/15 23:21:17 | 00,024,064 | —- | M] () – C:\Documents and Settings\Owner\My Documents\June 15.doc
[2009/06/13 23:24:20 | 14,456,832 | R— | M] () – C:\Documents and Settings\All Users\Documents\ESBK.mbb
[2009/06/13 23:23:55 | 10,537,984 | R— | M] () – C:\Documents and Settings\All Users\Documents\ESBK.mb
[2009/06/09 07:01:10 | 00,000,054 | -H– | M] () – C:\Documents and Settings\Owner\My Documents\~$y Saige Wenik.doc
[2009/06/08 17:10:43 | 00,020,992 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Soy Saige Wenik.doc
========== LOP Check ==========
[2009/07/05 09:31:09 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/03/25 22:59:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{63A9FDE6-FCC7-4E26-A4CF-552A08431B32}
[2009/07/05 09:31:18 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
[2009/05/28 21:37:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2008/11/02 18:42:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2008/03/28 22:13:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avery
[2008/06/01 19:48:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Fashion Solitaire 1.2
[2009/03/22 17:30:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intuit
[2009/05/13 22:30:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Logishrd
[2009/01/30 18:44:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MakeMusic
[2008/06/29 10:59:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Motive
[2003/12/11 21:37:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN Messenger 6.0.0602
[2003/10/07 18:38:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN6
[2004/09/06 14:24:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2003/04/10 05:54:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2009/07/04 23:28:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/02/13 17:50:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Verizon
[2009/07/07 18:04:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2003/10/07 18:34:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Visual Networks
[2009/05/09 22:19:46 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Owner\Application Data
[2006/12/22 18:05:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\acccore
[2009/06/25 22:16:35 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Aim
[2007/03/02 22:54:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Arcsoft
[2007/04/08 10:18:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\COWON
[2003/10/26 13:51:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Games
[2007/04/08 10:14:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\interMute
[2003/10/18 09:14:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\InterVideo
[2008/03/16 19:04:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Intuit
[2004/02/21 19:44:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Leadertech
[2005/01/07 23:21:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Lycos
[2008/02/13 17:57:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Motive
[2007/05/21 20:59:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Move Networks
[2008/02/13 15:56:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\MSN6
[2007/01/01 09:21:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Panasonic
[2008/03/06 21:25:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\QQ Games Plugin
[2004/10/26 19:57:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\rawh
[2004/09/06 14:21:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Roxio
[2003/04/10 07:08:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SampleView
[2007/04/22 08:28:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Snapfish
[2003/08/02 18:07:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Template
[2009/01/12 17:17:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\U3
[2003/06/19 15:08:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\VERITAS
[2008/02/13 17:50:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Verizon
[2007/07/23 09:04:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\WeatherBug
[2004/12/06 21:52:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\winjt
[2008/07/20 21:20:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\WinPatrol
[2009/07/06 09:38:03 | 00,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2009/07/04 08:19:11 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2002/08/29 15:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/07/07 00:00:00 | 00,000,622 | —- | M] () – C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Owner.job
[2009/07/07 18:20:40 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 144 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A988B257
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >
OTL logfile created on: 7/7/2009 6:33:56 PM - Run 2
OTL by OldTimer - Version 3.0.6.5 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
503.36 Mb Total Physical Memory | 173.77 Mb Available Physical Memory | 34.52% Memory free
1.20 Gb Paging File | 0.71 Gb Available in Paging File | 59.29% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 107.53 Gb Total Space | 63.38 Gb Free Space | 58.94% Space Free | Partition Type: NTFS
Drive D: | 4.24 Gb Total Space | 0.66 Gb Free Space | 15.61% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: PC1
Current User Name: Owner
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\Softex\OmniPass\OPXPApp.exe ()
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Comodo\Firewall\cmdagent.exe (COMODO)
PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\notepad.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
PRC - C:\WINDOWS\System32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
PRC - C:\Program Files\Comodo\Firewall\CPF.exe (COMODO)
PRC - C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\WINDOWS\System32\taskmgr.exe (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (Apple Mobile Device [On_Demand | Stopped]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (avg8emc [Auto | Running]) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd [Auto | Running]) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Bonjour Service [Disabled | Stopped]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (CmdAgent [Auto | Running]) – C:\Program Files\Comodo\Firewall\cmdagent.exe (COMODO)
SRV - (gupdate1c9d115998455f8 [Auto | Stopped]) – C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (IntuitUpdateService [Auto | Running]) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (iPod Service [On_Demand | Stopped]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (KodakCCS [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\KodakCCS.exe (Eastman Kodak Company)
SRV - (Lavasoft Ad-Aware Service [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (LVCOMSer [Auto | Running]) – C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
SRV - (LVPrcSrv [Auto | Running]) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (NVSvc [Auto | Stopped]) – C:\WINDOWS\System32\nvsvc32.exe (NVIDIA Corporation)
SRV - (omniserv [Disabled | Stopped]) – C:\Program Files\Softex\OmniPass\Omniserv.exe ()
SRV - (Symantec Core LC [Disabled | Stopped]) – File not found
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (ALCXWDM [On_Demand | Running]) – C:\WINDOWS\System32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (AvgLdx86 [System | Running]) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (CmdMon [System | Running]) – C:\WINDOWS\System32\DRIVERS\cmdmon.sys (Comodo Research Lab., Inc.)
DRV - (DcCam [System | Running]) – C:\WINDOWS\System32\DRIVERS\DcCam.sys (Eastman Kodak Company)
DRV - (DcFpoint [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\DcFpoint.sys (Eastman Kodak Company)
DRV - (DCFS2K [Auto | Running]) – C:\WINDOWS\System32\drivers\dcfs2k.sys (Eastman Kodak Company)
DRV - (DcLps [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\DcLps.sys (Eastman Kodak Company)
DRV - (DcPTP [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\DcPTP.sys (Eastman Kodak Company)
DRV - (Exportit [System | Stopped]) – C:\WINDOWS\System32\DRIVERS\exportit.sys (Eastman Kodak Company)
DRV - (fasttx2k [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\fasttx2k.sys (Promise Technology, Inc.)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (ialm [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (Inspect [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\inspect.sys (COMODO)
DRV - (Lbd [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (ltmodem5 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ltmdmnt.sys (LT)
DRV - (LVPr2Mon [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\LVPr2Mon.sys ()
DRV - (LVUSBSta [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (MREMPR5 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MREMPR5.sys (Motive, Inc.)
DRV - (MRENDIS5 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MRENDIS5.sys (Motive, Inc.)
DRV - (mrtRate [Auto | Running]) – C:\WINDOWS\System32\drivers\MrtRate.sys (Marimba, Inc.)
DRV - (nv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (nv_agp [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\nv_agp.sys (NVIDIA Corporation)
DRV - (pfc [On_Demand | Running]) – C:\WINDOWS\System32\drivers\pfc.sys (Padus, Inc.)
DRV - (PID_PEPI [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\LV302V32.SYS (Logitech Inc.)
DRV - (ppsio2 [Auto | Running]) – C:\WINDOWS\System32\drivers\ppsio2.sys ()
DRV - (Ps2 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\PS2.sys (Hewlett-Packard Company)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\PxHelp20.sys (Sonic Solutions)
DRV - (QCDonner [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\LVCD.sys (Logitech Inc.)
DRV - (rtl8139 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\R8139n51.SYS (Realtek Semiconductor Corporation )
DRV - (S3Psddr [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\s3gnbm.sys (S3 Graphics, Inc.)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SiS315 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\sisgrp.sys (Silicon Integrated Systems Corporation)
DRV - (SISAGP [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\SISAGPX.sys (Silicon Integrated Systems Corporation)
DRV - (StillCam [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\serscan.sys (Microsoft Corporation)
DRV - (USBIO [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\usbio.sys (Thesycon GmbH, Germany)
DRV - (viaagp1 [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (vnccom [Auto | Running]) – C:\WINDOWS\System32\Drivers\vnccom.SYS (RDV Soft)
DRV - (vncdrv [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\vncdrv.sys (RDV Soft)
DRV - ({6080A529-897E-4629-A488-ABA0C29B635E} [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\ialmsbw.sys (Intel Corporation)
DRV - ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91} [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\ialmkchw.sys (Intel Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\System32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/07/07 18:10:31 | 00,000,000 | —D | M]
O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (&Google;) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [COMODO Firewall Pro] C:\Program Files\Comodo\Firewall\CPF.exe (COMODO)
O4 - HKLM..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [NVIEW] C:\WINDOWS\System32\nview.DLL (NVIDIA Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowLegacyWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowUnhashedWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 36
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRunBackup = -1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FF FF FF FF [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disableregistrytools = 0
O8 - Extra context menu item: &AIM; Search - Reg Error: Value error. File not found
O9 - Extra Button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll (AOL LLC)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O12 - Plugin for: .pdf - C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll (Adobe Systems Inc.)
O15 - HKLM\..Trusted Domains: 45 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: 319 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E2941E3-8E63-11D4-9D5A-00902742D6E0}
http://146.145.127.148/iNotes.cab (iNotes Class)
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} Reg Error: Value error. (Yahoo! Audio Conferencing)
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325}
http://mail.philaymca.org/iNotes6W.cab (iNotes6 Class)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}
http://office.microsoft.com/officeupdate/content/opuc.cab (Office Update Installation Engine)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166}
http://cdn.scan.onecare.live.com/resource/…lscbase5483.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.microsoft.com/microsoftupdat…b?1237767327250 (WUWebControl Class)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.microsoft.com/microsoftupdat…b?1237767270703 (MUWebControl Class)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09}
https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx (Get_ActiveX Control)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592}
http://zone.msn.com/binFramework/v10/ZIntro.cab32846.cab (ZoneIntro Class)
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://active.macromedia.com/flash2/cabs/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DB0474CC-8EF6-47FC-905B-23FC58A70817} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {E93A6FCA-C052-45DF-AC9B-B729066092F8} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O16 - DPF: vzTCPConfig Reg Error: Value error. (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\OPXPGina: DllName - C:\Program Files\Softex\OmniPass\opxpgina.dll - C:\Program Files\Softex\OmniPass\opxpgina.dll ()
O24 - Desktop Components:0 () - C:\Program Files\Messenger\profsydy.html
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/07/28 07:07:38 | 00,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2008/07/20 13:17:26 | 00,000,090 | —- | M] () - D:\AUTORUN.INF – [ FAT32 ]
O33 - MountPoints2\{4729c152-3c75-11dc-8af9-000c6e35d416}\Shell - "" = AutoRun
O33 - MountPoints2\{4729c152-3c75-11dc-8af9-000c6e35d416}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{4729c152-3c75-11dc-8af9-000c6e35d416}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
========== Files/Folders - Created Within 30 Days ==========
[2009/07/07 18:16:03 | 00,000,000 | —D | C] – C:\_OTL
[2009/07/07 18:11:07 | 00,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2009/07/07 18:11:06 | 00,410,984 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deploytk.dll
[2009/07/07 18:11:05 | 00,148,888 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2009/07/07 18:11:05 | 00,144,792 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2009/07/07 18:11:04 | 00,144,792 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2009/07/06 22:37:05 | 00,513,536 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2009/07/06 22:02:27 | 00,000,704 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/07/06 22:02:20 | 00,038,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/07/06 22:02:18 | 00,019,096 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/07/06 22:02:18 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/07/06 21:45:04 | 00,000,000 | —D | C] – C:\WINDOWS\System32\CatRoot_bak
[2009/07/06 21:42:29 | 00,272,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bthport.sys
[2009/07/06 21:41:43 | 00,283,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pdh.dll
[2009/07/06 21:41:43 | 00,060,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\colbact.dll
[2009/07/06 21:41:41 | 00,473,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fastprox.dll
[2009/07/06 21:41:41 | 00,399,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rpcss.dll
[2009/07/06 21:41:41 | 00,227,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvse.exe
[2009/07/06 21:41:41 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\services.exe
[2009/07/06 21:41:40 | 00,453,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvsd.dll
[2009/07/06 21:41:39 | 00,616,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\advapi32.dll
[2009/07/06 21:41:37 | 00,714,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntdll.dll
[2009/07/06 21:40:50 | 00,331,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msadce.dll
[2009/07/06 21:37:45 | 00,215,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wordpad.exe
[2009/07/05 09:34:38 | 00,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/07/05 09:34:21 | 00,064,160 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/07/05 09:31:09 | 00,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
[2009/07/05 09:31:07 | 00,000,875 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/07/05 00:18:08 | 00,001,742 | —- | C] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk
[2009/07/05 00:18:02 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/07/04 13:35:51 | 16,409,960 | —- | C] (Safer Networking Limited ) – C:\Documents and Settings\Owner\Desktop\setup-spybotsd162.exe
[2009/06/26 02:02:32 | 00,000,000 | -H-D | C] – C:\$AVG8.VAULT$
[2009/06/25 21:16:41 | 00,001,515 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG Free 8.5.lnk
[2009/06/25 21:16:39 | 00,108,552 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/06/25 21:16:39 | 00,011,952 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/06/25 21:16:38 | 00,335,752 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/06/25 21:16:21 | 37,858,695 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/06/25 21:16:21 | 00,463,779 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/06/25 21:16:21 | 00,014,032 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/06/25 21:16:20 | 06,061,540 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/06/25 21:16:20 | 00,000,000 | —D | C] – C:\WINDOWS\System32\drivers\Avg
[2009/06/25 21:15:58 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\avg8
[2009/06/25 21:13:38 | 00,000,000 | —D | C] – C:\Program Files\AVG
[2009/06/21 09:01:39 | 00,070,144 | —- | C] () – C:\Documents and Settings\Owner\My Documents\father's day.pub
[2009/06/19 15:18:09 | 00,020,992 | —- | C] () – C:\Documents and Settings\Owner\My Documents\oprah.doc
[2009/06/15 23:21:38 | 00,024,576 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Letter to Dr. Milrod.doc
[2009/06/15 22:34:11 | 00,024,064 | —- | C] () – C:\Documents and Settings\Owner\My Documents\June 15.doc
[2009/06/09 07:01:10 | 00,000,054 | -H– | C] () – C:\Documents and Settings\Owner\My Documents\~$y Saige Wenik.doc
[2009/06/08 17:05:31 | 00,549,564 | —- | C] () – C:\Documents and Settings\Owner\My Documents\PDRM0001.JPG
[2009/06/08 16:19:41 | 00,020,992 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Soy Saige Wenik.doc
[2008/10/23 07:52:51 | 00,000,032 | —- | C] () – C:\WINDOWS\ARC_CPR-AED-PR.ini
[2008/07/26 08:25:02 | 00,025,624 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2007/01/01 09:16:55 | 00,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2006/12/21 20:41:32 | 00,000,021 | —- | C] () – C:\WINDOWS\atid.ini
[2004/12/06 20:52:42 | 00,002,150 | —- | C] () – C:\WINDOWS\System32\ssmute.ini
[2004/10/02 16:57:54 | 00,000,169 | —- | C] () – C:\WINDOWS\magix.ini
[2004/10/02 16:57:53 | 00,000,919 | —- | C] () – C:\WINDOWS\mgxoschk.ini
[2004/09/11 10:04:35 | 00,000,074 | —- | C] () – C:\WINDOWS\lbbho.ini
[2004/09/04 08:59:22 | 00,000,036 | —- | C] () – C:\WINDOWS\TLCAPPS.INI
[2004/09/01 21:06:48 | 00,000,000 | —- | C] () – C:\WINDOWS\SETUP32.INI
[2004/07/26 08:01:55 | 00,000,045 | —- | C] () – C:\WINDOWS\Tlcpromo.ini
[2004/07/26 08:01:51 | 00,000,398 | —- | C] () – C:\WINDOWS\SBW95.ini
[2004/06/23 18:49:55 | 00,000,060 | —- | C] () – C:\WINDOWS\SIERRA.INI
[2004/06/23 17:38:30 | 00,000,383 | —- | C] () – C:\WINDOWS\ka.ini
[2004/06/06 09:21:37 | 00,086,030 | —- | C] () – C:\WINDOWS\System32\msdjgk.dll
[2004/05/16 15:26:07 | 00,001,890 | —- | C] () – C:\WINDOWS\7THLEVEL.INI
[2004/03/23 17:49:48 | 00,131,072 | —- | C] () – C:\WINDOWS\System32\sfarkxt.dll
[2004/03/23 17:49:47 | 00,068,096 | —- | C] () – C:\WINDOWS\System32\SFARKL.DLL
[2004/01/30 19:48:00 | 00,217,088 | —- | C] () – C:\WINDOWS\System32\libmySQL.dll
[2003/12/09 13:16:52 | 00,442,368 | —- | C] ( ) – C:\WINDOWS\System32\comintfs.dll
[2003/12/07 15:45:53 | 00,061,440 | —- | C] () – C:\WINDOWS\System32\gl.dll
[2003/12/07 15:45:53 | 00,023,200 | —- | C] () – C:\WINDOWS\System32\drivers\ppsio2.sys
[2003/12/07 15:45:53 | 00,006,123 | —- | C] () – C:\WINDOWS\System32\e1.ini
[2003/11/08 09:33:15 | 00,010,301 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2003/09/18 23:09:16 | 00,000,024 | —- | C] () – C:\WINDOWS\qfnonl.ini
[2003/09/18 22:43:36 | 00,000,050 | —- | C] () – C:\WINDOWS\qwimp.ini
[2003/09/18 22:06:25 | 00,007,183 | —- | C] () – C:\WINDOWS\hpdj5100.ini
[2003/09/18 22:05:58 | 00,000,414 | —- | C] () – C:\WINDOWS\hpbvspst.ini
[2003/09/18 21:54:44 | 00,000,144 | —- | C] () – C:\WINDOWS\WININIT.INI
[2003/09/18 21:54:26 | 00,000,006 | —- | C] () – C:\WINDOWS\msoffice.ini
[2003/09/18 21:09:03 | 00,000,737 | —- | C] () – C:\WINDOWS\ODBC.INI
[2003/09/18 20:59:23 | 00,000,146 | —- | C] () – C:\WINDOWS\lotus.ini
[2003/09/18 20:23:16 | 00,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2003/05/31 14:29:50 | 00,019,968 | —- | C] () – C:\WINDOWS\System32\cpuinf32.dll
[2003/04/10 07:33:14 | 00,094,208 | —- | C] () – C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2003/04/10 07:33:14 | 00,077,824 | —- | C] () – C:\WINDOWS\System32\ProgressTrace.dll
[2003/04/10 07:10:20 | 00,167,936 | —- | C] () – C:\WINDOWS\System32\PCDrJNI_1_1.dll
[2003/04/10 07:08:02 | 00,024,576 | —- | C] () – C:\WINDOWS\System32\syscontr.dll
[2003/04/10 07:08:01 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2003/04/10 07:07:51 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/04/10 07:00:09 | 00,000,692 | —- | C] () – C:\WINDOWS\intuprof.ini
[2003/04/10 06:59:52 | 00,001,212 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2003/04/10 06:53:45 | 00,000,051 | —- | C] () – C:\WINDOWS\System32\mshrml.ini
[2003/04/10 06:36:30 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2003/04/10 06:16:02 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/04/10 06:06:11 | 00,299,073 | —- | C] () – C:\WINDOWS\System32\PythonCOM22.dll
[2003/04/10 06:06:11 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\PyWinTypes22.dll
[2003/04/10 06:05:46 | 00,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2003/04/10 05:53:32 | 00,000,802 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/04/10 05:37:43 | 00,000,552 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2003/04/10 05:37:23 | 00,000,698 | —- | C] () – C:\WINDOWS\win.ini
[2003/04/10 05:37:19 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini
[2003/04/10 03:08:18 | 00,000,438 | —- | C] () – C:\WINDOWS\System32\1_ssetup.ini
[2003/04/10 03:08:18 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\sunistlog.ini
[2002/06/10 15:16:22 | 00,066,482 | R— | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2000/09/08 18:53:50 | 00,073,839 | —- | C] () – C:\WINDOWS\System32\KodakOneTouch.dll
[1997/07/11 00:00:00 | 00,031,232 | —- | C] () – C:\WINDOWS\System32\XLREC.DLL
[1997/07/11 00:00:00 | 00,025,600 | —- | C] () – C:\WINDOWS\System32\RECNCL.DLL
[1997/07/11 00:00:00 | 00,022,016 | —- | C] () – C:\WINDOWS\System32\ODBCSTF.DLL
[1997/07/11 00:00:00 | 00,022,016 | —- | C] () – C:\WINDOWS\System32\DOCOBJ.DLL
[1997/07/11 00:00:00 | 00,012,288 | —- | C] () – C:\WINDOWS\System32\HLINKPRX.DLL
[1996/04/25 21:23:00 | 00,000,846 | —- | C] () – C:\WINDOWS\acroread.ini
[1996/02/22 21:23:00 | 00,222,928 | —- | C] () – C:\WINDOWS\System32\lobas09.dll
[1996/01/17 21:23:00 | 00,031,008 | —- | C] () – C:\WINDOWS\System32\ivtrn09.dll
[1996/01/15 21:23:00 | 00,334,016 | —- | C] () – C:\WINDOWS\System32\loflt09.dll
[1995/09/25 21:23:00 | 00,014,928 | —- | C] () – C:\WINDOWS\System32\wingen.drv
[1994/04/07 21:23:00 | 00,000,462 | —- | C] () – C:\WINDOWS\lodbf09.ini
========== Files - Modified Within 30 Days ==========
[1 C:\Documents and Settings\Owner\My Documents\*.tmp files]
[2009/07/07 18:20:40 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/07/07 18:20:35 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/07/07 18:20:34 | 52,788,0192 | -HS- | M] () – C:\hiberfil.sys
[2009/07/07 18:10:30 | 00,148,888 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2009/07/07 18:10:29 | 00,410,984 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deploytk.dll
[2009/07/07 18:10:29 | 00,144,792 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2009/07/07 18:10:29 | 00,144,792 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2009/07/07 18:10:29 | 00,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2009/07/07 09:19:48 | 37,858,695 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/07/07 09:19:48 | 00,014,032 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/07/07 04:22:09 | 00,399,650 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/07/07 04:22:08 | 00,060,626 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/07/07 04:22:05 | 00,467,868 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/07/07 04:15:35 | 00,399,936 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/07/07 04:06:18 | 00,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/07/07 00:00:00 | 00,000,622 | —- | M] () – C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - Owner.job
[2009/07/06 22:37:08 | 00,513,536 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2009/07/06 22:02:27 | 00,000,704 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/07/06 09:38:03 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/07/05 09:50:00 | 00,027,784 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/07/05 09:49:56 | 00,335,752 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/07/05 09:33:12 | 00,064,160 | —- | M] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/07/05 09:31:07 | 00,000,875 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/07/05 00:18:08 | 00,001,742 | —- | M] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk
[2009/07/04 23:26:13 | 00,463,779 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/07/04 13:44:35 | 00,000,941 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Spybot - Search & Destroy.lnk
[2009/07/04 13:36:22 | 16,409,960 | —- | M] (Safer Networking Limited ) – C:\Documents and Settings\Owner\Desktop\setup-spybotsd162.exe
[2009/07/04 10:18:03 | 00,002,265 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2009/07/04 08:19:11 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/06/30 22:25:57 | 00,001,212 | —- | M] () – C:\WINDOWS\QUICKEN.INI
[2009/06/26 19:40:29 | 00,000,698 | —- | M] () – C:\WINDOWS\win.ini
[2009/06/26 19:35:48 | 00,042,496 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/06/25 22:02:01 | 00,001,821 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2009/06/25 21:16:41 | 00,001,515 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG Free 8.5.lnk
[2009/06/25 21:16:39 | 00,108,552 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/06/25 21:16:39 | 00,011,952 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/06/25 21:16:21 | 06,061,540 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/06/23 20:28:31 | 01,108,116 | -H– | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\IconCache.db
[2009/06/21 09:01:40 | 00,070,144 | —- | M] () – C:\Documents and Settings\Owner\My Documents\father's day.pub
[2009/06/19 15:18:10 | 00,020,992 | —- | M] () – C:\Documents and Settings\Owner\My Documents\oprah.doc
[2009/06/17 13:07:58 | 00,004,752 | -H– | M] () – C:\IPH.PH
[2009/06/17 11:27:56 | 00,038,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/06/17 11:27:44 | 00,019,096 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/06/17 10:28:16 | 00,001,642 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AIM 6.lnk
[2009/06/15 23:37:32 | 00,024,576 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Letter to Dr. Milrod.doc
[2009/06/15 23:21:17 | 00,024,064 | —- | M] () – C:\Documents and Settings\Owner\My Documents\June 15.doc
[2009/06/13 23:24:20 | 14,456,832 | R— | M] () – C:\Documents and Settings\All Users\Documents\ESBK.mbb
[2009/06/13 23:23:55 | 10,537,984 | R— | M] () – C:\Documents and Settings\All Users\Documents\ESBK.mb
[2009/06/09 07:01:10 | 00,000,054 | -H– | M] () – C:\Documents and Settings\Owner\My Documents\~$y Saige Wenik.doc
[2009/06/08 17:10:43 | 00,020,992 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Soy Saige Wenik.doc
========== LOP Check ==========
[2009/07/05 09:31:09 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/03/25 22:59:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{63A9FDE6-FCC7-4E26-A4CF-552A08431B32}
[2009/07/05 09:31:18 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
[2009/05/28 21:37:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2008/11/02 18:42:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2008/03/28 22:13:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avery
[2008/06/01 19:48:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Fashion Solitaire 1.2
[2009/03/22 17:30:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intuit
[2009/05/13 22:30:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Logishrd
[2009/01/30 18:44:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MakeMusic
[2008/06/29 10:59:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Motive
[2003/12/11 21:37:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN Messenger 6.0.0602
[2003/10/07 18:38:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN6
[2004/09/06 14:24:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2003/04/10 05:54:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2009/07/04 23:28:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/02/13 17:50:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Verizon
[2009/07/07 18:04:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2003/10/07 18:34:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Visual Networks
[2009/05/09 22:19:46 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Owner\Application Data
[2006/12/22 18:05:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\acccore
[2009/06/25 22:16:35 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Aim
[2007/03/02 22:54:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Arcsoft
[2007/04/08 10:18:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\COWON
[2003/10/26 13:51:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Games
[2007/04/08 10:14:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\interMute
[2003/10/18 09:14:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\InterVideo
[2008/03/16 19:04:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Intuit
[2004/02/21 19:44:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Leadertech
[2005/01/07 23:21:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Lycos
[2008/02/13 17:57:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Motive
[2007/05/21 20:59:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Move Networks
[2008/02/13 15:56:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\MSN6
[2007/01/01 09:21:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Panasonic
[2008/03/06 21:25:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\QQ Games Plugin
[2004/10/26 19:57:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\rawh
[2004/09/06 14:21:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Roxio
[2003/04/10 07:08:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SampleView
[2007/04/22 08:28:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Snapfish
[2003/08/02 18:07:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Template
[2009/01/12 17:17:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\U3
[2003/06/19 15:08:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\VERITAS
[2008/02/13 17:50:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Verizon
[2007/07/23 09:04:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\WeatherBug
[2004/12/06 21:52:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\winjt
[2008/07/20 21:20:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\WinPatrol
[2009/07/06 09:38:03 | 00,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2009/07/04 08:19:11 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2002/08/29 15:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/07/07 00:00:00 | 00,000,622 | —- | M] () – C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Owner.job
[2009/07/07 18:20:40 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 144 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A988B257
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >
OTL logfile created on: 7/7/2009 6:33:56 PM - Run 2
OTL by OldTimer - Version 3.0.6.5 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
503.36 Mb Total Physical Memory | 173.77 Mb Available Physical Memory | 34.52% Memory free
1.20 Gb Paging File | 0.71 Gb Available in Paging File | 59.29% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 107.53 Gb Total Space | 63.38 Gb Free Space | 58.94% Space Free | Partition Type: NTFS
Drive D: | 4.24 Gb Total Space | 0.66 Gb Free Space | 15.61% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: PC1
Current User Name: Owner
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\Softex\OmniPass\OPXPApp.exe ()
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Comodo\Firewall\cmdagent.exe (COMODO)
PRC - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
PRC - C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\notepad.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
PRC - C:\WINDOWS\System32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
PRC - C:\Program Files\Comodo\Firewall\CPF.exe (COMODO)
PRC - C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\WINDOWS\System32\taskmgr.exe (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (Apple Mobile Device [On_Demand | Stopped]) – C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (avg8emc [Auto | Running]) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd [Auto | Running]) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Bonjour Service [Disabled | Stopped]) – C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (CmdAgent [Auto | Running]) – C:\Program Files\Comodo\Firewall\cmdagent.exe (COMODO)
SRV - (gupdate1c9d115998455f8 [Auto | Stopped]) – C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
SRV - (gusvc [On_Demand | Stopped]) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (IntuitUpdateService [Auto | Running]) – C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe (Intuit Inc.)
SRV - (iPod Service [On_Demand | Stopped]) – C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (KodakCCS [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\KodakCCS.exe (Eastman Kodak Company)
SRV - (Lavasoft Ad-Aware Service [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (LVCOMSer [Auto | Running]) – C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
SRV - (LVPrcSrv [Auto | Running]) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (NVSvc [Auto | Stopped]) – C:\WINDOWS\System32\nvsvc32.exe (NVIDIA Corporation)
SRV - (omniserv [Disabled | Stopped]) – C:\Program Files\Softex\OmniPass\Omniserv.exe ()
SRV - (Symantec Core LC [Disabled | Stopped]) – File not found
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (ALCXWDM [On_Demand | Running]) – C:\WINDOWS\System32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (AvgLdx86 [System | Running]) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (CmdMon [System | Running]) – C:\WINDOWS\System32\DRIVERS\cmdmon.sys (Comodo Research Lab., Inc.)
DRV - (DcCam [System | Running]) – C:\WINDOWS\System32\DRIVERS\DcCam.sys (Eastman Kodak Company)
DRV - (DcFpoint [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\DcFpoint.sys (Eastman Kodak Company)
DRV - (DCFS2K [Auto | Running]) – C:\WINDOWS\System32\drivers\dcfs2k.sys (Eastman Kodak Company)
DRV - (DcLps [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\DcLps.sys (Eastman Kodak Company)
DRV - (DcPTP [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\DcPTP.sys (Eastman Kodak Company)
DRV - (Exportit [System | Stopped]) – C:\WINDOWS\System32\DRIVERS\exportit.sys (Eastman Kodak Company)
DRV - (fasttx2k [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\fasttx2k.sys (Promise Technology, Inc.)
DRV - (GEARAspiWDM [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (ialm [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (Inspect [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\inspect.sys (COMODO)
DRV - (Lbd [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (ltmodem5 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ltmdmnt.sys (LT)
DRV - (LVPr2Mon [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\LVPr2Mon.sys ()
DRV - (LVUSBSta [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (MREMPR5 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MREMPR5.sys (Motive, Inc.)
DRV - (MRENDIS5 [On_Demand | Stopped]) – C:\Program Files\Common Files\Motive\MRENDIS5.sys (Motive, Inc.)
DRV - (mrtRate [Auto | Running]) – C:\WINDOWS\System32\drivers\MrtRate.sys (Marimba, Inc.)
DRV - (nv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (nv_agp [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\nv_agp.sys (NVIDIA Corporation)
DRV - (pfc [On_Demand | Running]) – C:\WINDOWS\System32\drivers\pfc.sys (Padus, Inc.)
DRV - (PID_PEPI [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\LV302V32.SYS (Logitech Inc.)
DRV - (ppsio2 [Auto | Running]) – C:\WINDOWS\System32\drivers\ppsio2.sys ()
DRV - (Ps2 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\PS2.sys (Hewlett-Packard Company)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) – C:\WINDOWS\system32\DRIVERS\PxHelp20.sys (Sonic Solutions)
DRV - (QCDonner [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\LVCD.sys (Logitech Inc.)
DRV - (rtl8139 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\R8139n51.SYS (Realtek Semiconductor Corporation )
DRV - (S3Psddr [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\s3gnbm.sys (S3 Graphics, Inc.)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SiS315 [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\sisgrp.sys (Silicon Integrated Systems Corporation)
DRV - (SISAGP [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\SISAGPX.sys (Silicon Integrated Systems Corporation)
DRV - (StillCam [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\serscan.sys (Microsoft Corporation)
DRV - (USBIO [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\usbio.sys (Thesycon GmbH, Germany)
DRV - (viaagp1 [Boot | Running]) – C:\WINDOWS\System32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (vnccom [Auto | Running]) – C:\WINDOWS\System32\Drivers\vnccom.SYS (RDV Soft)
DRV - (vncdrv [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\vncdrv.sys (RDV Soft)
DRV - ({6080A529-897E-4629-A488-ABA0C29B635E} [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\ialmsbw.sys (Intel Corporation)
DRV - ({D31A0762-0CEB-444e-ACFF-B049A1F6FE91} [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\ialmkchw.sys (Intel Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\System32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/07/07 18:10:31 | 00,000,000 | —D | M]
O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (&Google;) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (Google Inc.)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [COMODO Firewall Pro] C:\Program Files\Comodo\Firewall\CPF.exe (COMODO)
O4 - HKLM..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [NVIEW] C:\WINDOWS\System32\nview.DLL (NVIDIA Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowLegacyWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowUnhashedWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 36
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRunBackup = -1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = FF FF FF FF [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disableregistrytools = 0
O8 - Extra context menu item: &AIM; Search - Reg Error: Value error. File not found
O9 - Extra Button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll (AOL LLC)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O12 - Plugin for: .pdf - C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll (Adobe Systems Inc.)
O15 - HKLM\..Trusted Domains: 45 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: 319 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://www.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E2941E3-8E63-11D4-9D5A-00902742D6E0}
http://146.145.127.148/iNotes.cab (iNotes Class)
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} Reg Error: Value error. (Yahoo! Audio Conferencing)
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325}
http://mail.philaymca.org/iNotes6W.cab (iNotes6 Class)
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}
http://office.microsoft.com/officeupdate/content/opuc.cab (Office Update Installation Engine)
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166}
http://cdn.scan.onecare.live.com/resource/…lscbase5483.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.microsoft.com/microsoftupdat…b?1237767327250 (WUWebControl Class)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.microsoft.com/microsoftupdat…b?1237767270703 (MUWebControl Class)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09}
https://h17000.www1.hp.com/ewfrf-JAVA/Secur…loadManager.ocx (Get_ActiveX Control)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592}
http://zone.msn.com/binFramework/v10/ZIntro.cab32846.cab (ZoneIntro Class)
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://active.macromedia.com/flash2/cabs/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DB0474CC-8EF6-47FC-905B-23FC58A70817} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {E93A6FCA-C052-45DF-AC9B-B729066092F8} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O16 - DPF: vzTCPConfig Reg Error: Value error. (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\OPXPGina: DllName - C:\Program Files\Softex\OmniPass\opxpgina.dll - C:\Program Files\Softex\OmniPass\opxpgina.dll ()
O24 - Desktop Components:0 () - C:\Program Files\Messenger\profsydy.html
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/07/28 07:07:38 | 00,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2008/07/20 13:17:26 | 00,000,090 | —- | M] () - D:\AUTORUN.INF – [ FAT32 ]
O33 - MountPoints2\{4729c152-3c75-11dc-8af9-000c6e35d416}\Shell - "" = AutoRun
O33 - MountPoints2\{4729c152-3c75-11dc-8af9-000c6e35d416}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{4729c152-3c75-11dc-8af9-000c6e35d416}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
========== Files/Folders - Created Within 30 Days ==========
[2009/07/07 18:16:03 | 00,000,000 | —D | C] – C:\_OTL
[2009/07/07 18:11:07 | 00,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2009/07/07 18:11:06 | 00,410,984 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deploytk.dll
[2009/07/07 18:11:05 | 00,148,888 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2009/07/07 18:11:05 | 00,144,792 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2009/07/07 18:11:04 | 00,144,792 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2009/07/06 22:37:05 | 00,513,536 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2009/07/06 22:02:27 | 00,000,704 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/07/06 22:02:20 | 00,038,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/07/06 22:02:18 | 00,019,096 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/07/06 22:02:18 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/07/06 21:45:04 | 00,000,000 | —D | C] – C:\WINDOWS\System32\CatRoot_bak
[2009/07/06 21:42:29 | 00,272,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\bthport.sys
[2009/07/06 21:41:43 | 00,283,648 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\pdh.dll
[2009/07/06 21:41:43 | 00,060,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\colbact.dll
[2009/07/06 21:41:41 | 00,473,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fastprox.dll
[2009/07/06 21:41:41 | 00,399,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\rpcss.dll
[2009/07/06 21:41:41 | 00,227,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvse.exe
[2009/07/06 21:41:41 | 00,110,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\services.exe
[2009/07/06 21:41:40 | 00,453,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wmiprvsd.dll
[2009/07/06 21:41:39 | 00,616,960 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\advapi32.dll
[2009/07/06 21:41:37 | 00,714,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ntdll.dll
[2009/07/06 21:40:50 | 00,331,776 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msadce.dll
[2009/07/06 21:37:45 | 00,215,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wordpad.exe
[2009/07/05 09:34:38 | 00,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/07/05 09:34:21 | 00,064,160 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/07/05 09:31:09 | 00,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
[2009/07/05 09:31:07 | 00,000,875 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/07/05 00:18:08 | 00,001,742 | —- | C] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk
[2009/07/05 00:18:02 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/07/04 13:35:51 | 16,409,960 | —- | C] (Safer Networking Limited ) – C:\Documents and Settings\Owner\Desktop\setup-spybotsd162.exe
[2009/06/26 02:02:32 | 00,000,000 | -H-D | C] – C:\$AVG8.VAULT$
[2009/06/25 21:16:41 | 00,001,515 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG Free 8.5.lnk
[2009/06/25 21:16:39 | 00,108,552 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/06/25 21:16:39 | 00,011,952 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/06/25 21:16:38 | 00,335,752 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/06/25 21:16:21 | 37,858,695 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/06/25 21:16:21 | 00,463,779 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/06/25 21:16:21 | 00,014,032 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/06/25 21:16:20 | 06,061,540 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/06/25 21:16:20 | 00,000,000 | —D | C] – C:\WINDOWS\System32\drivers\Avg
[2009/06/25 21:15:58 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\avg8
[2009/06/25 21:13:38 | 00,000,000 | —D | C] – C:\Program Files\AVG
[2009/06/21 09:01:39 | 00,070,144 | —- | C] () – C:\Documents and Settings\Owner\My Documents\father's day.pub
[2009/06/19 15:18:09 | 00,020,992 | —- | C] () – C:\Documents and Settings\Owner\My Documents\oprah.doc
[2009/06/15 23:21:38 | 00,024,576 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Letter to Dr. Milrod.doc
[2009/06/15 22:34:11 | 00,024,064 | —- | C] () – C:\Documents and Settings\Owner\My Documents\June 15.doc
[2009/06/09 07:01:10 | 00,000,054 | -H– | C] () – C:\Documents and Settings\Owner\My Documents\~$y Saige Wenik.doc
[2009/06/08 17:05:31 | 00,549,564 | —- | C] () – C:\Documents and Settings\Owner\My Documents\PDRM0001.JPG
[2009/06/08 16:19:41 | 00,020,992 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Soy Saige Wenik.doc
[2008/10/23 07:52:51 | 00,000,032 | —- | C] () – C:\WINDOWS\ARC_CPR-AED-PR.ini
[2008/07/26 08:25:02 | 00,025,624 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2007/01/01 09:16:55 | 00,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2006/12/21 20:41:32 | 00,000,021 | —- | C] () – C:\WINDOWS\atid.ini
[2004/12/06 20:52:42 | 00,002,150 | —- | C] () – C:\WINDOWS\System32\ssmute.ini
[2004/10/02 16:57:54 | 00,000,169 | —- | C] () – C:\WINDOWS\magix.ini
[2004/10/02 16:57:53 | 00,000,919 | —- | C] () – C:\WINDOWS\mgxoschk.ini
[2004/09/11 10:04:35 | 00,000,074 | —- | C] () – C:\WINDOWS\lbbho.ini
[2004/09/04 08:59:22 | 00,000,036 | —- | C] () – C:\WINDOWS\TLCAPPS.INI
[2004/09/01 21:06:48 | 00,000,000 | —- | C] () – C:\WINDOWS\SETUP32.INI
[2004/07/26 08:01:55 | 00,000,045 | —- | C] () – C:\WINDOWS\Tlcpromo.ini
[2004/07/26 08:01:51 | 00,000,398 | —- | C] () – C:\WINDOWS\SBW95.ini
[2004/06/23 18:49:55 | 00,000,060 | —- | C] () – C:\WINDOWS\SIERRA.INI
[2004/06/23 17:38:30 | 00,000,383 | —- | C] () – C:\WINDOWS\ka.ini
[2004/06/06 09:21:37 | 00,086,030 | —- | C] () – C:\WINDOWS\System32\msdjgk.dll
[2004/05/16 15:26:07 | 00,001,890 | —- | C] () – C:\WINDOWS\7THLEVEL.INI
[2004/03/23 17:49:48 | 00,131,072 | —- | C] () – C:\WINDOWS\System32\sfarkxt.dll
[2004/03/23 17:49:47 | 00,068,096 | —- | C] () – C:\WINDOWS\System32\SFARKL.DLL
[2004/01/30 19:48:00 | 00,217,088 | —- | C] () – C:\WINDOWS\System32\libmySQL.dll
[2003/12/09 13:16:52 | 00,442,368 | —- | C] ( ) – C:\WINDOWS\System32\comintfs.dll
[2003/12/07 15:45:53 | 00,061,440 | —- | C] () – C:\WINDOWS\System32\gl.dll
[2003/12/07 15:45:53 | 00,023,200 | —- | C] () – C:\WINDOWS\System32\drivers\ppsio2.sys
[2003/12/07 15:45:53 | 00,006,123 | —- | C] () – C:\WINDOWS\System32\e1.ini
[2003/11/08 09:33:15 | 00,010,301 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2003/09/18 23:09:16 | 00,000,024 | —- | C] () – C:\WINDOWS\qfnonl.ini
[2003/09/18 22:43:36 | 00,000,050 | —- | C] () – C:\WINDOWS\qwimp.ini
[2003/09/18 22:06:25 | 00,007,183 | —- | C] () – C:\WINDOWS\hpdj5100.ini
[2003/09/18 22:05:58 | 00,000,414 | —- | C] () – C:\WINDOWS\hpbvspst.ini
[2003/09/18 21:54:44 | 00,000,144 | —- | C] () – C:\WINDOWS\WININIT.INI
[2003/09/18 21:54:26 | 00,000,006 | —- | C] () – C:\WINDOWS\msoffice.ini
[2003/09/18 21:09:03 | 00,000,737 | —- | C] () – C:\WINDOWS\ODBC.INI
[2003/09/18 20:59:23 | 00,000,146 | —- | C] () – C:\WINDOWS\lotus.ini
[2003/09/18 20:23:16 | 00,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2003/05/31 14:29:50 | 00,019,968 | —- | C] () – C:\WINDOWS\System32\cpuinf32.dll
[2003/04/10 07:33:14 | 00,094,208 | —- | C] () – C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2003/04/10 07:33:14 | 00,077,824 | —- | C] () – C:\WINDOWS\System32\ProgressTrace.dll
[2003/04/10 07:10:20 | 00,167,936 | —- | C] () – C:\WINDOWS\System32\PCDrJNI_1_1.dll
[2003/04/10 07:08:02 | 00,024,576 | —- | C] () – C:\WINDOWS\System32\syscontr.dll
[2003/04/10 07:08:01 | 00,045,056 | —- | C] () – C:\WINDOWS\System32\hpreg.dll
[2003/04/10 07:07:51 | 00,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/04/10 07:00:09 | 00,000,692 | —- | C] () – C:\WINDOWS\intuprof.ini
[2003/04/10 06:59:52 | 00,001,212 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2003/04/10 06:53:45 | 00,000,051 | —- | C] () – C:\WINDOWS\System32\mshrml.ini
[2003/04/10 06:36:30 | 00,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2003/04/10 06:16:02 | 00,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/04/10 06:06:11 | 00,299,073 | —- | C] () – C:\WINDOWS\System32\PythonCOM22.dll
[2003/04/10 06:06:11 | 00,065,536 | —- | C] () – C:\WINDOWS\System32\PyWinTypes22.dll
[2003/04/10 06:05:46 | 00,016,896 | —- | C] () – C:\WINDOWS\System32\bcbmm.dll
[2003/04/10 05:53:32 | 00,000,802 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/04/10 05:37:43 | 00,000,552 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2003/04/10 05:37:23 | 00,000,698 | —- | C] () – C:\WINDOWS\win.ini
[2003/04/10 05:37:19 | 00,000,227 | —- | C] () – C:\WINDOWS\system.ini
[2003/04/10 03:08:18 | 00,000,438 | —- | C] () – C:\WINDOWS\System32\1_ssetup.ini
[2003/04/10 03:08:18 | 00,000,000 | —- | C] () – C:\WINDOWS\System32\sunistlog.ini
[2002/06/10 15:16:22 | 00,066,482 | R— | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2000/09/08 18:53:50 | 00,073,839 | —- | C] () – C:\WINDOWS\System32\KodakOneTouch.dll
[1997/07/11 00:00:00 | 00,031,232 | —- | C] () – C:\WINDOWS\System32\XLREC.DLL
[1997/07/11 00:00:00 | 00,025,600 | —- | C] () – C:\WINDOWS\System32\RECNCL.DLL
[1997/07/11 00:00:00 | 00,022,016 | —- | C] () – C:\WINDOWS\System32\ODBCSTF.DLL
[1997/07/11 00:00:00 | 00,022,016 | —- | C] () – C:\WINDOWS\System32\DOCOBJ.DLL
[1997/07/11 00:00:00 | 00,012,288 | —- | C] () – C:\WINDOWS\System32\HLINKPRX.DLL
[1996/04/25 21:23:00 | 00,000,846 | —- | C] () – C:\WINDOWS\acroread.ini
[1996/02/22 21:23:00 | 00,222,928 | —- | C] () – C:\WINDOWS\System32\lobas09.dll
[1996/01/17 21:23:00 | 00,031,008 | —- | C] () – C:\WINDOWS\System32\ivtrn09.dll
[1996/01/15 21:23:00 | 00,334,016 | —- | C] () – C:\WINDOWS\System32\loflt09.dll
[1995/09/25 21:23:00 | 00,014,928 | —- | C] () – C:\WINDOWS\System32\wingen.drv
[1994/04/07 21:23:00 | 00,000,462 | —- | C] () – C:\WINDOWS\lodbf09.ini
========== Files - Modified Within 30 Days ==========
[1 C:\Documents and Settings\Owner\My Documents\*.tmp files]
[2009/07/07 18:20:40 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/07/07 18:20:35 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/07/07 18:20:34 | 52,788,0192 | -HS- | M] () – C:\hiberfil.sys
[2009/07/07 18:10:30 | 00,148,888 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2009/07/07 18:10:29 | 00,410,984 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deploytk.dll
[2009/07/07 18:10:29 | 00,144,792 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2009/07/07 18:10:29 | 00,144,792 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2009/07/07 18:10:29 | 00,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2009/07/07 09:19:48 | 37,858,695 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/07/07 09:19:48 | 00,014,032 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/07/07 04:22:09 | 00,399,650 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/07/07 04:22:08 | 00,060,626 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/07/07 04:22:05 | 00,467,868 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/07/07 04:15:35 | 00,399,936 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2009/07/07 04:06:18 | 00,001,355 | —- | M] () – C:\WINDOWS\imsins.BAK
[2009/07/07 00:00:00 | 00,000,622 | —- | M] () – C:\WINDOWS\tasks\Norton Internet Security - Run Full System Scan - Owner.job
[2009/07/06 22:37:08 | 00,513,536 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2009/07/06 22:02:27 | 00,000,704 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/07/06 09:38:03 | 00,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/07/05 09:50:00 | 00,027,784 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2009/07/05 09:49:56 | 00,335,752 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2009/07/05 09:33:12 | 00,064,160 | —- | M] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2009/07/05 09:31:07 | 00,000,875 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/07/05 00:18:08 | 00,001,742 | —- | M] () – C:\Documents and Settings\Owner\Desktop\HijackThis.lnk
[2009/07/04 23:26:13 | 00,463,779 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2009/07/04 13:44:35 | 00,000,941 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Spybot - Search & Destroy.lnk
[2009/07/04 13:36:22 | 16,409,960 | —- | M] (Safer Networking Limited ) – C:\Documents and Settings\Owner\Desktop\setup-spybotsd162.exe
[2009/07/04 10:18:03 | 00,002,265 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2009/07/04 08:19:11 | 00,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/06/30 22:25:57 | 00,001,212 | —- | M] () – C:\WINDOWS\QUICKEN.INI
[2009/06/26 19:40:29 | 00,000,698 | —- | M] () – C:\WINDOWS\win.ini
[2009/06/26 19:35:48 | 00,042,496 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/06/25 22:02:01 | 00,001,821 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
[2009/06/25 21:16:41 | 00,001,515 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG Free 8.5.lnk
[2009/06/25 21:16:39 | 00,108,552 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2009/06/25 21:16:39 | 00,011,952 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2009/06/25 21:16:21 | 06,061,540 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2009/06/23 20:28:31 | 01,108,116 | -H– | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\IconCache.db
[2009/06/21 09:01:40 | 00,070,144 | —- | M] () – C:\Documents and Settings\Owner\My Documents\father's day.pub
[2009/06/19 15:18:10 | 00,020,992 | —- | M] () – C:\Documents and Settings\Owner\My Documents\oprah.doc
[2009/06/17 13:07:58 | 00,004,752 | -H– | M] () – C:\IPH.PH
[2009/06/17 11:27:56 | 00,038,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/06/17 11:27:44 | 00,019,096 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/06/17 10:28:16 | 00,001,642 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AIM 6.lnk
[2009/06/15 23:37:32 | 00,024,576 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Letter to Dr. Milrod.doc
[2009/06/15 23:21:17 | 00,024,064 | —- | M] () – C:\Documents and Settings\Owner\My Documents\June 15.doc
[2009/06/13 23:24:20 | 14,456,832 | R— | M] () – C:\Documents and Settings\All Users\Documents\ESBK.mbb
[2009/06/13 23:23:55 | 10,537,984 | R— | M] () – C:\Documents and Settings\All Users\Documents\ESBK.mb
[2009/06/09 07:01:10 | 00,000,054 | -H– | M] () – C:\Documents and Settings\Owner\My Documents\~$y Saige Wenik.doc
[2009/06/08 17:10:43 | 00,020,992 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Soy Saige Wenik.doc
========== LOP Check ==========
[2009/07/05 09:31:09 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/03/25 22:59:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{63A9FDE6-FCC7-4E26-A4CF-552A08431B32}
[2009/07/05 09:31:18 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
[2009/05/28 21:37:30 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2008/11/02 18:42:20 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2008/03/28 22:13:59 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Avery
[2008/06/01 19:48:52 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Fashion Solitaire 1.2
[2009/03/22 17:30:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Intuit
[2009/05/13 22:30:14 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Logishrd
[2009/01/30 18:44:23 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MakeMusic
[2008/06/29 10:59:13 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Motive
[2003/12/11 21:37:43 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN Messenger 6.0.0602
[2003/10/07 18:38:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN6
[2004/09/06 14:24:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2003/04/10 05:54:24 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBSI
[2009/07/04 23:28:25 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008/02/13 17:50:00 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Verizon
[2009/07/07 18:04:35 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2003/10/07 18:34:31 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Visual Networks
[2009/05/09 22:19:46 | 00,000,000 | RH-D | M] – C:\Documents and Settings\Owner\Application Data
[2006/12/22 18:05:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\acccore
[2009/06/25 22:16:35 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Aim
[2007/03/02 22:54:21 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Arcsoft
[2007/04/08 10:18:52 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\COWON
[2003/10/26 13:51:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Games
[2007/04/08 10:14:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\interMute
[2003/10/18 09:14:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\InterVideo
[2008/03/16 19:04:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Intuit
[2004/02/21 19:44:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Leadertech
[2005/01/07 23:21:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Lycos
[2008/02/13 17:57:42 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Motive
[2007/05/21 20:59:38 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Move Networks
[2008/02/13 15:56:00 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\MSN6
[2007/01/01 09:21:15 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Panasonic
[2008/03/06 21:25:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\QQ Games Plugin
[2004/10/26 19:57:16 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\rawh
[2004/09/06 14:21:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Roxio
[2003/04/10 07:08:43 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SampleView
[2007/04/22 08:28:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Snapfish
[2003/08/02 18:07:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Template
[2009/01/12 17:17:32 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\U3
[2003/06/19 15:08:11 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\VERITAS
[2008/02/13 17:50:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Verizon
[2007/07/23 09:04:53 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\WeatherBug
[2004/12/06 21:52:04 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\winjt
[2008/07/20 21:20:06 | 00,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\WinPatrol
[2009/07/06 09:38:03 | 00,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2009/07/04 08:19:11 | 00,000,284 | —- | M] () – C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
[2002/08/29 15:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/07/07 00:00:00 | 00,000,622 | —- | M] () – C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Owner.job
[2009/07/07 18:20:40 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 144 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A988B257
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >
svchost.exe
svchost.exe
alg.exe
svchost.exe
svchost.exe
explorer.exe
tskmgr.exe
LVComSer.exe
iexplore.exe
cftmon,.exe
hpdotdd01exe
cpf.exe
WinPatrol.exe
avgtray.exe
AAWTray.exe
jusched.exe
TeaTimer.exe
OTL.exe
SystemIdleProcess
System
avgnsx.exe
avgrsx.exe
jqs.exe
LVComSer.exe
LVPrcSrv.exe
smss.exe
crss.exe
winlogon.exe
services.exe
lsass.exe
svchost.exe
svchost.exe
svchost.exe
avgemc.exe
AAWService.exe
OPXApp.exe
avgcrsrvx.exe
avgwdsvc.exe
cmdagent.exe
IntuitUpdateServ
GoogleUpdate.exe
unsecapp.exe
wmiprvse.exe
svchost.exe
Any suggestions?
Mark