Here's the OTL.txt log:
OTL logfile created on: 8/6/2009 4:03:19 PM - Run 1
OTL by OldTimer - Version 3.0.10.4 Folder = C:\Users\Nick\Desktop
Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.16609)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
958.31 Mb Total Physical Memory | 492.48 Mb Available Physical Memory | 51.39% Memory free
2.12 Gb Paging File | 1.41 Gb Available in Paging File | 66.66% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 137.18 Gb Total Space | 9.61 Gb Free Space | 7.01% Space Free | Partition Type: NTFS
Drive D: | 11.87 Gb Total Space | 1.87 Gb Free Space | 15.75% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: NICK-PC
Current User Name: Nick
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Windows\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe ( Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\HP\QuickPlay\QPService.exe (CyberLink Corp.)
PRC - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
PRC - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
PRC - C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe (Hewlett-Packard)
PRC - C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard Co.)
PRC - C:\Windows\ehome\ehtray.exe (Microsoft Corporation)
PRC - C:\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
PRC - C:\Windows\ehome\ehmsas.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Synaptics, Inc.)
PRC - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe ()
PRC - C:\Program Files\CyberLink\Shared Files\RichVideo.exe ()
PRC - C:\Windows\System32\DRIVERS\xaudio.exe (Conexant Systems, Inc.)
PRC - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe ()
PRC - C:\Windows\System32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\Windows\System32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe ()
PRC - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe (Hewlett-Packard)
PRC - C:\Users\Nick\Desktop\OTL.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (Adobe LM Service [On_Demand | Stopped]) – C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe ()
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Com4Qlb [On_Demand | Stopped]) – C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe (Hewlett-Packard Development Company, L.P.)
SRV - (ehRecvr [On_Demand | Stopped]) – C:\Windows\ehome\ehRecvr.exe (Microsoft Corporation)
SRV - (ehSched [On_Demand | Stopped]) – C:\Windows\ehome\ehsched.exe (Microsoft Corporation)
SRV - (ehstart [Auto | Stopped]) – C:\Windows\ehome\ehstart.dll (Microsoft Corporation)
SRV - (Eventlog [Auto | Running]) – C:\Windows\System32\wevtsvc.dll (Microsoft Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) – C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (GameConsoleService [On_Demand | Stopped]) – C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (HP Health Check Service [Auto | Running]) – c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe (Hewlett-Packard)
SRV - (hpqwmiex [Auto | Running]) – C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe (Hewlett-Packard Development Company, L.P.)
SRV - (IDriverT [On_Demand | Stopped]) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) – C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (Lavasoft Ad-Aware Service [Auto | Running]) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (LightScribeService [Auto | Running]) – C:\Program Files\Common Files\LightScribe\LSSrvc.exe (Hewlett-Packard Company)
SRV - (NetTcpPortSharing [Disabled | Stopped]) – C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (odserv [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (QPCapSvc [Auto | Running]) – C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe ()
SRV - (QPSched [Auto | Running]) – C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe ()
SRV - (RichVideo [Auto | Running]) – C:\Program Files\CyberLink\Shared Files\RichVideo.exe ()
SRV - (WinDefend [Auto | Running]) – C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) – C:\Program Files\Windows Media Player\wmpnetwk.exe (Microsoft Corporation)
SRV - (XAudioService [Auto | Running]) – C:\Windows\System32\DRIVERS\xaudio.exe (Conexant Systems, Inc.)
========== Driver Services (SafeList) ==========
DRV - (adp94xx [Disabled | Stopped]) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (adpahci [Disabled | Stopped]) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (adpu160m [Disabled | Stopped]) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (adpu320 [Disabled | Stopped]) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (Afc [On_Demand | Running]) – C:\Windows\System32\drivers\Afc.sys (Arcsoft, Inc.)
DRV - (aic78xx [Disabled | Stopped]) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (aliide [Disabled | Stopped]) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (arc [Disabled | Stopped]) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (arcsas [Disabled | Stopped]) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (athr [On_Demand | Running]) – C:\Windows\System32\DRIVERS\athr.sys (Atheros Communications, Inc.)
DRV - (BCM43XV [On_Demand | Stopped]) – C:\Windows\System32\DRIVERS\bcmwl6.sys (Broadcom Corporation)
DRV - (BrFiltLo [On_Demand | Stopped]) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp [On_Demand | Stopped]) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (Brserid [Disabled | Stopped]) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrSerWdm [Disabled | Stopped]) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm [Disabled | Stopped]) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer [On_Demand | Stopped]) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (cmdide [Disabled | Stopped]) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (E100B [On_Demand | Stopped]) – C:\Windows\System32\DRIVERS\e100b325.sys (Intel Corporation)
DRV - (E1G60 [On_Demand | Stopped]) – C:\Windows\System32\DRIVERS\E1G60I32.sys (Intel Corporation)
DRV - (elxstor [Disabled | Stopped]) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (HdAudAddService [On_Demand | Running]) – C:\Windows\System32\drivers\CHDART.sys (Conexant Systems Inc.)
DRV - (HpCISSs [Disabled | Stopped]) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (HpqKbFiltr [On_Demand | Running]) – C:\Windows\System32\DRIVERS\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (HpqRemHid [On_Demand | Running]) – C:\Windows\System32\DRIVERS\HpqRemHid.sys (Hewlett-Packard Development Company, L.P.)
DRV - (HSFHWAZL [On_Demand | Stopped]) – C:\Windows\System32\DRIVERS\VSTAZL3.SYS (Conexant Systems, Inc.)
DRV - (HSF_DPV [On_Demand | Running]) – C:\Windows\System32\DRIVERS\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWAZL [On_Demand | Running]) – C:\Windows\System32\DRIVERS\HSXHWAZL.sys (Conexant Systems, Inc.)
DRV - (ialm [On_Demand | Stopped]) – C:\Windows\System32\DRIVERS\igdkmd32.sys (Intel Corporation)
DRV - (iaStorV [Disabled | Stopped]) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (iirsp [Disabled | Stopped]) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (iteatapi [Disabled | Stopped]) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (iteraid [Disabled | Stopped]) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (Lbd [Boot | Running]) – C:\Windows\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (LSI_FC [Disabled | Stopped]) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (LSI_SAS [Disabled | Stopped]) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (LSI_SCSI [Disabled | Stopped]) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (mdmxsdk [Auto | Running]) – C:\Windows\System32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (megasas [Disabled | Stopped]) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (Mraid35x [Disabled | Stopped]) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (nfrd960 [Disabled | Stopped]) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (ntrigdigi [Disabled | Stopped]) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (NVENETFD [On_Demand | Running]) – C:\Windows\System32\DRIVERS\nvmfdx32.sys (NVIDIA Corporation)
DRV - (nvlddmkm [On_Demand | Running]) – C:\Windows\System32\DRIVERS\nvlddmkm.sys (NVIDIA Corporation)
DRV - (nvraid [Disabled | Stopped]) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nvsmu [On_Demand | Running]) – C:\Windows\System32\DRIVERS\nvsmu.sys (NVIDIA Corporation)
DRV - (nvstor [Disabled | Stopped]) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (ql2300 [Disabled | Stopped]) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (ql40xx [Disabled | Stopped]) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (rimmptsk [Auto | Running]) – C:\Windows\System32\DRIVERS\rimmptsk.sys (REDC)
DRV - (rimsptsk [Auto | Running]) – C:\Windows\System32\DRIVERS\rimsptsk.sys (REDC)
DRV - (rismxdp [Auto | Running]) – C:\Windows\System32\DRIVERS\rixdptsk.sys (REDC)
DRV - (secdrv [Auto | Running]) – C:\Windows\System32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SiSRaid2 [Disabled | Stopped]) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (SiSRaid4 [Disabled | Stopped]) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (Symc8xx [Disabled | Stopped]) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (Sym_hi [Disabled | Stopped]) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (Sym_u3 [Disabled | Stopped]) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (SynTP [On_Demand | Running]) – C:\Windows\System32\DRIVERS\SynTP.sys (Synaptics, Inc.)
DRV - (uliahci [Disabled | Stopped]) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (UlSata [Disabled | Stopped]) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (ulsata2 [Disabled | Stopped]) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (viaide [Disabled | Stopped]) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (vsmraid [Disabled | Stopped]) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (winachsf [On_Demand | Running]) – C:\Windows\System32\DRIVERS\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (XAudio [Auto | Running]) – C:\Windows\System32\DRIVERS\xaudio.sys (Conexant Systems, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…o&pf;=laptop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Ask"
FF - prefs.js..browser.search.order.1: "Ask"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {a7c6cf7f-112c-4500-a7ea-39801a327e5f}:1.0.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}:6.0.05
FF - prefs.js..extensions.enabledItems: {f701c26a-479a-4724-b4f1-870db12f063c}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:2
FF - prefs.js..extensions.enabledItems: 4
FF - prefs.js..extensions.enabledItems: 5
FF - prefs.js..extensions.enabledItems: 3
FF - prefs.js..extensions.enabledItems: [removed]:7
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.1
FF - prefs.js..keyword.URL: "
http://toolbar.ask.com/toolbarv/askRedirect?o=101757&gct;=&gc;=1&q;="
FF - prefs.js..network.proxy.backup.ftp: ""
FF - prefs.js..network.proxy.backup.ftp_port: 0
FF - prefs.js..network.proxy.backup.gopher: ""
FF - prefs.js..network.proxy.backup.gopher_port: 0
FF - prefs.js..network.proxy.backup.socks: ""
FF - prefs.js..network.proxy.backup.socks_port: 0
FF - prefs.js..network.proxy.backup.ssl: ""
FF - prefs.js..network.proxy.backup.ssl_port: 0
FF - prefs.js..network.proxy.ftp: "[removed]"
FF - prefs.js..network.proxy.ftp_port: 3128
FF - prefs.js..network.proxy.gopher: "[removed]"
FF - prefs.js..network.proxy.gopher_port: 3128
FF - prefs.js..network.proxy.http: "[removed]"
FF - prefs.js..network.proxy.http_port: 3128
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "[removed]"
FF - prefs.js..network.proxy.socks_port: 3128
FF - prefs.js..network.proxy.ssl: "200.65.127.161"
FF - prefs.js..network.proxy.ssl_port: 3128
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/01/29 20:21:18 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/03/03 15:57:19 | 00,000,000 | —D | M]
[2008/06/17 17:40:42 | 00,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\mozilla\Extensions
[2008/06/17 17:40:42 | 00,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/08/05 21:52:27 | 00,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\mozilla\Firefox\Profiles\tpph4uqr.default\extensions
[2009/01/17 13:44:27 | 00,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\mozilla\Firefox\Profiles\tpph4uqr.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}
[2008/10/11 10:01:55 | 00,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\mozilla\Firefox\Profiles\tpph4uqr.default\extensions\{f701c26a-479a-4724-b4f1-870db12f063c}
[2009/05/23 19:39:11 | 00,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\mozilla\Firefox\Profiles\tpph4uqr.default\extensions\[removed]
[2008/06/20 14:43:43 | 00,000,908 | —- | M] () – C:\Users\Nick\AppData\Roaming\Mozilla\FireFox\Profiles\tpph4uqr.default\searchplugins\imdb.xml
[2009/08/06 10:16:16 | 00,002,431 | —- | M] () – C:\Users\Nick\AppData\Roaming\Mozilla\FireFox\Profiles\tpph4uqr.default\searchplugins\youtube.xml
[2009/08/05 21:52:27 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions
[2008/07/19 12:11:40 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/03/14 16:16:21 | 00,000,000 | —D | M] – C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
[2008/07/19 12:11:36 | 00,023,040 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2008/07/19 12:11:36 | 00,134,144 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2007/04/10 17:21:08 | 00,163,256 | —- | M] (Microsoft Corporation) – C:\Program Files\mozilla firefox\plugins\np-mswmp.dll
[2008/09/03 17:11:24 | 00,054,600 | —- | M] (BitTorrent, Inc.) – C:\Program Files\mozilla firefox\plugins\npbittorrent.dll
[2008/07/19 12:11:38 | 00,065,536 | —- | M] (mozilla.org) – C:\Program Files\mozilla firefox\plugins\npnul32.dll
[2003/07/14 23:56:52 | 00,013,888 | —- | M] (Microsoft Corporation) – C:\Program Files\mozilla firefox\plugins\NPOFFICE.DLL
[2008/06/11 23:45:28 | 00,103,792 | —- | M] (Adobe Systems Inc.) – C:\Program Files\mozilla firefox\plugins\nppdf32.dll
[2008/05/29 07:24:14 | 00,001,394 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2008/05/29 07:24:14 | 00,002,193 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2008/05/29 07:24:14 | 00,001,534 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2008/05/29 07:24:14 | 00,002,642 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2008/05/29 07:24:14 | 00,001,706 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008/05/29 07:24:14 | 00,001,178 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2008/05/29 07:24:14 | 00,000,792 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (27 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (HP Print Clips) - {FFFFFFFF-FF12-44C5-91EC-068E3AA1B2D7} - c:\Program Files\HP\Smart Web Printing\hpswp_framework.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe (Hewlett-Packard Co.)
O4 - HKLM..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvSvc] C:\Windows\System32\nvsvc.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe ( Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [QlbCtrl] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe ( Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [QPService] C:\Program Files\HP\QuickPlay\QPService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [WAWifiMessage] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [BitTorrent DNA] C:\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
O4 - HKCU..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe (Microsoft Corporation)
O4 - HKCU..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe (Hewlett-Packard Company)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE File not found
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - Reg Error: Key error. File not found
O9 - Extra Button: HP Smart Select - {58ECB495-38F0-49cb-A538-10282ABF65E7} - c:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll (Hewlett-Packard Co.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx (CRLDownloadWrapper Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\microsoft shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\microsoft shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\Explorer.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/12/05 21:36:21 | 00,000,074 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2005/09/11 08:18:54 | 00,000,340 | -HS- | M] () - D:\AUTOMODE – [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\Windows\System32\lsdelete.exe ()
========== Files/Folders - Created Within 30 Days ==========
[2009/08/06 15:59:13 | 00,354,396 | —- | C] () – C:\Users\Nick\Desktop\SysProt.zip
[2009/08/06 15:58:36 | 00,514,048 | —- | C] (OldTimer Tools) – C:\Users\Nick\Desktop\OTL.exe
[2009/08/06 15:12:45 | 00,287,232 | —- | C] () – C:\Users\Nick\Desktop\gmer.exe
[2009/08/06 15:08:01 | 00,359,932 | —- | C] () – C:\Users\Nick\Desktop\dds.scr
[2009/08/06 15:03:29 | 00,359,932 | —- | C] () – C:\Users\Nick\Desktop\dds.pif
[2009/08/06 10:20:24 | 00,000,064 | —- | C] () – C:\Windows\ppp4.dat
[2009/08/06 10:20:24 | 00,000,003 | —- | C] () – C:\Windows\ppp3.dat
[2009/08/06 10:20:23 | 00,827,392 | —- | C] (ASC - AntiSpyware) – C:\Windows\System32\dddesot.dll
[2009/08/06 10:20:23 | 00,065,536 | —- | C] () – C:\Windows\System32\desot.exe
[2009/08/06 10:20:23 | 00,000,036 | —- | C] () – C:\Windows\System32\sysnet.dat
[2009/08/06 10:20:23 | 00,000,009 | —- | C] () – C:\Windows\System32\bennuar.old
[2009/08/06 10:01:08 | 00,000,000 | —D | C] – C:\Windows\temp
[2009/08/06 09:55:36 | 00,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2009/08/06 09:41:16 | 00,219,648 | —- | C] () – C:\Windows\PEV.exe
[2009/08/06 09:41:16 | 00,212,480 | —- | C] (SteelWerX) – C:\Windows\SWXCACLS.exe
[2009/08/06 09:41:16 | 00,161,792 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2009/08/06 09:41:16 | 00,136,704 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2009/08/06 09:41:16 | 00,098,816 | —- | C] () – C:\Windows\sed.exe
[2009/08/06 09:41:16 | 00,080,412 | —- | C] () – C:\Windows\grep.exe
[2009/08/06 09:41:16 | 00,068,096 | —- | C] () – C:\Windows\zip.exe
[2009/08/06 09:41:16 | 00,031,232 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2009/08/06 09:41:07 | 00,000,000 | —D | C] – C:\Windows\ERDNT
[2009/08/05 23:55:40 | 00,001,874 | —- | C] () – C:\Users\Nick\Desktop\HijackThis.lnk
[2009/08/05 22:59:50 | 00,001,152 | —- | C] () – C:\Windows\System32\windrv.sys
[2009/08/05 15:13:14 | 00,071,168 | —- | C] () – C:\Windows\System32\drivers\cujoyocpqwdraxqp.sys
[2009/08/05 15:13:10 | 00,000,230 | -H– | C] () – C:\Windows\tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job
[2009/08/05 15:13:08 | 00,000,230 | -H– | C] () – C:\Windows\tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job
[2009/08/05 15:13:04 | 00,212,484 | —- | C] () – C:\Windows\System32\msxml71.dll
[2009/07/25 17:31:17 | 00,025,600 | —- | C] () – C:\Users\Nick\Documents\Notable Picks.doc
[2009/07/24 12:31:36 | 00,000,000 | —D | C] – C:\Users\Nick\AppData\Roaming\Move Networks
[2009/07/21 10:18:40 | 00,000,000 | —D | C] – C:\ProgramData\Macrovision
[2009/07/21 10:18:26 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Adobe Systems Shared
[2009/07/20 19:12:20 | 00,001,642 | —- | C] () – C:\Users\Nick\Desktop\Bodog Casino.lnk
[2009/07/20 19:09:01 | 00,000,000 | —D | C] – C:\Program Files\Bodog Casino
[2009/07/13 16:05:27 | 73,020,2962 | —- | C] () – C:\Users\Nick\Desktop\DREAM 6 Part 3.avi
[2009/07/13 15:59:27 | 73,140,7322 | —- | C] () – C:\Users\Nick\Desktop\DREAM 6 Part 2.avi
[2009/07/13 15:57:53 | 73,012,1090 | —- | C] () – C:\Users\Nick\Desktop\DREAM 6 Part 1.avi
[2009/07/08 21:22:06 | 00,015,688 | —- | C] () – C:\Windows\System32\lsdelete.exe
[2009/07/08 21:20:05 | 00,064,160 | —- | C] (Lavasoft AB) – C:\Windows\System32\drivers\Lbd.sys
[2009/07/08 21:14:18 | 00,000,472 | —- | C] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2009/07/08 20:36:35 | 00,000,000 | -H-D | C] – C:\ProgramData\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
[2009/07/08 20:36:33 | 00,001,007 | —- | C] () – C:\Users\Public\Desktop\Ad-Aware.lnk
[2009/07/08 20:36:14 | 00,000,000 | —D | C] – C:\Program Files\Lavasoft
[2009/07/08 19:59:55 | 00,000,831 | —- | C] () – C:\Windows\System32\critical_warning.html
[2009/06/17 20:53:06 | 73,240,3712 | —- | C] () – C:\Users\Nick\Desktop\PRIDE 33 Part 1.avi
[2009/06/17 20:52:01 | 73,220,0960 | —- | C] () – C:\Users\Nick\Desktop\PRIDE 33 Part 2.avi
[2009/06/10 19:27:04 | 00,004,096 | -H– | C] () – C:\Users\Nick\AppData\Local\keyfile3.drm
[2009/05/25 14:24:15 | 00,000,000 | —D | C] – C:\Windows\Minidump
[2009/05/23 19:38:22 | 00,000,000 | —D | C] – C:\ProgramData\TVU Networks
[2009/03/02 22:30:52 | 00,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2009/02/26 14:13:04 | 02,256,384 | —- | C] () – C:\Windows\System32\x264vfw.dll
[2008/03/10 20:25:36 | 00,000,097 | —- | C] () – C:\Windows\System32\PICSDK.ini
[2008/03/10 20:20:20 | 00,000,044 | —- | C] () – C:\Windows\EPCX4400.ini
[2008/01/19 02:07:06 | 00,016,480 | —- | C] () – C:\Windows\System32\rixdicon.dll
[2006/11/02 05:35:32 | 00,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 03:25:21 | 00,061,440 | —- | C] () – C:\Windows\System32\igfxTMM.dll
[2006/11/02 03:23:31 | 00,000,240 | —- | C] () – C:\Windows\win.ini
[2006/11/02 03:23:31 | 00,000,215 | —- | C] () – C:\Windows\system.ini
[2006/11/02 00:40:29 | 00,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2006/03/09 15:58:00 | 01,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2005/10/14 03:56:50 | 03,596,288 | —- | C] () – C:\Windows\System32\qt-dx331.dll
[2005/10/14 03:56:50 | 00,921,600 | —- | C] () – C:\Windows\System32\VorbisEnc.dll
[2005/10/14 03:56:50 | 00,761,856 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2005/10/14 03:56:50 | 00,344,064 | —- | C] () – C:\Windows\System32\xvid.dll
[2005/10/14 03:56:50 | 00,237,568 | —- | C] () – C:\Windows\System32\OggDS.dll
[2005/10/14 03:56:50 | 00,188,416 | —- | C] () – C:\Windows\System32\vorbis.dll
[2005/10/14 03:56:50 | 00,155,136 | —- | C] () – C:\Windows\System32\unrar.dll
[2005/10/14 03:56:50 | 00,045,056 | —- | C] () – C:\Windows\System32\ogg.dll
[2003/01/07 16:05:08 | 00,002,695 | —- | C] () – C:\Windows\System32\OUTLPERF.INI
========== Files - Modified Within 30 Days ==========
[2009/08/06 15:59:16 | 00,354,396 | —- | M] () – C:\Users\Nick\Desktop\SysProt.zip
[2009/08/06 15:58:44 | 00,514,048 | —- | M] (OldTimer Tools) – C:\Users\Nick\Desktop\OTL.exe
[2009/08/06 15:38:42 | 00,000,432 | —- | M] () – C:\Windows\System32\drivers\etc\hosts.ics
[2009/08/06 15:38:37 | 00,000,162 | —- | M] () – C:\Users\Public\Documents\hpqp.ini
[2009/08/06 15:37:08 | 00,003,072 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/08/06 15:37:08 | 00,003,072 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/08/06 15:37:05 | 00,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2009/08/06 15:37:00 | 00,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2009/08/06 15:08:02 | 00,359,932 | —- | M] () – C:\Users\Nick\Desktop\dds.scr
[2009/08/06 15:03:32 | 00,359,932 | —- | M] () – C:\Users\Nick\Desktop\dds.pif
[2009/08/06 13:03:27 | 00,077,312 | —- | M] () – C:\Users\Nick\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/06 10:27:39 | 00,065,536 | —- | M] () – C:\Windows\System32\desot.exe
[2009/08/06 10:27:37 | 00,000,064 | —- | M] () – C:\Windows\ppp4.dat
[2009/08/06 10:27:37 | 00,000,003 | —- | M] () – C:\Windows\ppp3.dat
[2009/08/06 10:21:16 | 00,027,240 | —- | M] () – C:\Users\Nick\AppData\Roaming\nvModes.dat
[2009/08/06 10:21:16 | 00,027,240 | —- | M] () – C:\Users\Nick\AppData\Roaming\nvModes.001
[2009/08/06 10:20:23 | 00,827,392 | —- | M] (ASC - AntiSpyware) – C:\Windows\System32\dddesot.dll
[2009/08/06 10:20:23 | 00,000,036 | —- | M] () – C:\Windows\System32\sysnet.dat
[2009/08/06 10:20:23 | 00,000,009 | —- | M] () – C:\Windows\System32\bennuar.old
[2009/08/06 09:55:53 | 00,000,215 | —- | M] () – C:\Windows\system.ini
[2009/08/06 09:55:27 | 00,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2009/08/05 23:55:40 | 00,001,874 | —- | M] () – C:\Users\Nick\Desktop\HijackThis.lnk
[2009/08/05 22:59:50 | 00,001,152 | —- | M] () – C:\Windows\System32\windrv.sys
[2009/08/05 15:13:15 | 00,071,168 | —- | M] () – C:\Windows\System32\drivers\cujoyocpqwdraxqp.sys
[2009/08/05 15:13:14 | 00,000,230 | -H– | M] () – C:\Windows\tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job
[2009/08/05 15:13:12 | 00,000,230 | -H– | M] () – C:\Windows\tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job
[2009/08/05 15:13:04 | 00,212,484 | —- | M] () – C:\Windows\System32\msxml71.dll
[2009/08/03 21:13:26 | 00,000,472 | —- | M] () – C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2009/07/30 11:16:36 | 00,287,232 | —- | M] () – C:\Users\Nick\Desktop\gmer.exe
[2009/07/25 17:47:16 | 00,025,600 | —- | M] () – C:\Users\Nick\Documents\Notable Picks.doc
[2009/07/21 10:18:11 | 00,002,082 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
[2009/07/20 19:12:20 | 00,001,642 | —- | M] () – C:\Users\Nick\Desktop\Bodog Casino.lnk
[2009/07/20 17:26:33 | 73,140,7322 | —- | M] () – C:\Users\Nick\Desktop\DREAM 6 Part 2.avi
[2009/07/20 17:25:52 | 73,020,2962 | —- | M] () – C:\Users\Nick\Desktop\DREAM 6 Part 3.avi
[2009/07/20 17:25:35 | 73,012,1090 | —- | M] () – C:\Users\Nick\Desktop\DREAM 6 Part 1.avi
[2009/07/13 05:48:54 | 00,219,648 | —- | M] () – C:\Windows\PEV.exe
[2009/07/08 21:13:10 | 00,015,688 | —- | M] () – C:\Windows\System32\lsdelete.exe
[2009/07/08 21:07:26 | 00,064,160 | —- | M] (Lavasoft AB) – C:\Windows\System32\drivers\Lbd.sys
[2009/07/08 20:36:33 | 00,001,007 | —- | M] () – C:\Users\Public\Desktop\Ad-Aware.lnk
[2009/07/08 20:04:31 | 00,000,831 | —- | M] () – C:\Windows\System32\critical_warning.html
[2009/06/19 13:03:53 | 73,220,0960 | —- | M] () – C:\Users\Nick\Desktop\PRIDE 33 Part 2.avi
[2009/06/19 13:03:48 | 73,240,3712 | —- | M] () – C:\Users\Nick\Desktop\PRIDE 33 Part 1.avi
[2009/06/19 11:25:51 | 00,043,520 | —- | M] () – C:\Users\Nick\Documents\eBay.xls
[2009/06/10 19:27:04 | 00,004,096 | -H– | M] () – C:\Users\Nick\AppData\Local\keyfile3.drm
[2009/05/23 19:38:21 | 00,000,816 | —- | M] () – C:\Users\Public\Desktop\TVUPlayer.lnk
[2009/05/17 15:04:07 | 00,720,952 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2009/05/17 15:04:07 | 00,621,552 | —- | M] () – C:\Windows\System32\perfh009.dat
[2009/05/17 15:04:07 | 00,104,868 | —- | M] () – C:\Windows\System32\perfc009.dat
========== LOP Check ==========
[2009/07/24 12:32:00 | 00,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming
[2008/03/11 18:45:55 | 00,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\ArcSoft
[2009/03/22 17:45:14 | 00,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\avidemux
[2009/08/01 20:19:20 | 00,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\BitTorrent
[2008/07/20 11:16:22 | 00,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\CyberLink
[2009/08/06 15:57:25 | 00,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\DNA
[2008/03/08 16:59:17 | 00,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\eMule
[2008/03/10 20:44:22 | 00,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\EPSON
[2008/06/18 14:53:28 | 00,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\FileZilla
[2008/03/08 16:43:13 | 00,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\Kazaa Lite
[2008/03/10 20:33:34 | 00,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\Leadertech
[2006/11/02 05:37:34 | 00,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\Media Center Programs
[2008/06/06 13:02:43 | 00,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\mIRC
[2009/07/24 16:19:38 | 00,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\Move Networks
[2008/03/10 15:04:46 | 00,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\muvee Technologies
[2008/09/28 16:45:29 | 00,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\OpenOffice.org2
[2009/03/10 22:05:51 | 00,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\PeerNetworking
[2008/04/27 15:47:29 | 00,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\SopCast
[2008/03/11 18:51:07 | 00,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\Template
[2008/06/14 20:12:53 | 00,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\TVU Networks
[2008/03/10 15:09:11 | 00,000,000 | —D | M] – C:\Users\Nick\AppData\Roaming\WildTangent
[2009/08/03 21:13:26 | 00,000,472 | —- | M] () – C:\Windows\Tasks\Ad-Aware Update (Weekly).job
[2009/08/06 15:37:05 | 00,000,006 | -H– | M] () – C:\Windows\Tasks\SA.DAT
[2009/08/06 15:32:17 | 00,032,614 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2009/08/05 15:13:14 | 00,000,230 | -H– | M] () – C:\Windows\Tasks\{7B02EF0B-A410-4938-8480-9BA26420A627}.job
[2009/08/05 15:13:12 | 00,000,230 | -H– | M] () – C:\Windows\Tasks\{BB65B0FB-5712-401b-B616-E69AC55E2757}.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:DFC5A2B2
< End of report >
Here's the Extras.txt Log:
OTL Extras logfile created on: 8/6/2009 4:03:19 PM - Run 1
OTL by OldTimer - Version 3.0.10.4 Folder = C:\Users\Nick\Desktop
Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.16609)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
958.31 Mb Total Physical Memory | 492.48 Mb Available Physical Memory | 51.39% Memory free
2.12 Gb Paging File | 1.41 Gb Available in Paging File | 66.66% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 137.18 Gb Total Space | 9.61 Gb Free Space | 7.01% Space Free | Partition Type: NTFS
Drive D: | 11.87 Gb Total Space | 1.87 Gb Free Space | 15.75% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: NICK-PC
Current User Name: Nick
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.exe [@ = exefile] – C:\Windows\System32\desot.exe ()
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
.js [@ = Reg Error: Value error.] – Reg Error: Key error. File not found
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-1575482397-4069540635-46351700-1000]
"EnableNotifications" = 0
"EnableNotificationsRef" = 2
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"2103:TCP" = 2103:TCP:*:Enabled:@xpsp2res.dll,-22003
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink – File not found
"%systemroot%\system32\winnt\cssrs.exe" = %systemroot%\system32\winnt\cssrs.exe:*:Enabled:@xpsp2res.dll,-22019 – File not found
"C:\Program Files\BitTorrent\bittorrent.exe" = C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent – (BitTorrent, Inc.)
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01CC93CC-101C-4E89-82DE-B3D44EEFDC60}" = lport=67 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{37B23E13-7DAD-43DD-A524-8EF375C14F0F}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{3DABC49B-C92A-4003-BF0C-0E675058D4F2}" = lport=547 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{6B4737EA-1119-441D-B573-2F58ECE8B899}" = lport=68 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{7F810CC9-AF16-4324-9579-563B6180ACD9}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{ADBAD719-CC8A-4B5F-8A01-54B70349151F}" = lport=53 | protocol=17 | dir=in | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{D1CBCEDE-B525-4E9B-B1BA-6D43289E0D59}" = lport=2869 | protocol=6 | dir=in | app=system |
"{E8EC07E8-3E20-4F86-AB7A-791AB1F1ED39}" = rport=2869 | protocol=6 | dir=out | app=system |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0C47624C-E43A-434E-BBA5-8A63C869B46F}" = protocol=17 | dir=in | app=c:\program files\dna\btdna.exe |
"{111AB774-4123-476F-BAB3-B39287DEC087}" = dir=in | app=c:\program files\hp\quickplay\qp.exe |
"{13F57FA0-60CC-4B9C-AF8D-50EF102ABF48}" = dir=out | svc=sharedaccess | app=%systemroot%\system32\svchost.exe |
"{15F9A471-8027-46D7-B87D-3B00E00613F1}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe |
"{1F7F852B-30EC-4F03-A20F-988C28581E87}" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{46058D6B-2121-4AE6-8BD5-E6A6A9BB8A92}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{5F1BB71C-2B26-404D-8B05-C6D02D21555E}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{72D3C1A4-1A95-40AB-A238-7DD093A1AD12}" = protocol=6 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{7363C71B-4DEF-46F7-A0EB-FF71F4268A36}" = dir=in | app=c:\program files\hp\quickplay\qpservice.exe |
"{751EC4FE-5F28-4A6B-9185-FE56225470B4}" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{75433EF6-AC77-4CF7-BEB8-8965990CE3E9}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{9B22924B-C76E-4D1F-9509-C7228B4666A1}" = protocol=6 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"{A2B81A71-49EC-4C2C-B930-11C31640ACEC}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{AB0254F5-E566-466E-8F27-5397DECC650E}" = protocol=6 | dir=in | app=c:\program files\dna\btdna.exe |
"{B53655B4-6403-4A16-BB77-041FD462C49C}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{C37260FB-131B-4500-A57D-8BFBFF249E97}" = protocol=58 | dir=in | name=@hnetcfg.dll,-148 |
"{C485A96F-A8B8-4909-8ACD-72674FB3B5AF}" = protocol=17 | dir=in | app=c:\program files\earthlink totalaccess\taskpanl.exe |
"{D9778C69-A22E-4913-88F7-3CEFDAECC583}" = protocol=17 | dir=in | app=c:\program files\common files\aol\loader\aolload.exe |
"TCP Query User{260A96E5-37FD-45BE-81A4-84A43B188B9E}C:\program files\tvuplayer\tvuplayer.exe" = protocol=6 | dir=in | app=c:\program files\tvuplayer\tvuplayer.exe |
"TCP Query User{2A03C20F-4DE7-4212-BEFD-66DC4C8E2514}C:\program files\tvants\tvants.exe" = protocol=6 | dir=in | app=c:\program files\tvants\tvants.exe |
"TCP Query User{41843896-D815-441F-B990-00DBFC9C5A6D}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{4186703A-0F02-4F45-91ED-9FA23FDD47B9}C:\program files\sopcast\adv\sopadver.exe" = protocol=6 | dir=in | app=c:\program files\sopcast\adv\sopadver.exe |
"TCP Query User{4F16F2D5-7B8A-40C1-A932-1C8BA9A9BBAC}C:\program files\emule\emule.exe" = protocol=6 | dir=in | app=c:\program files\emule\emule.exe |
"TCP Query User{57C9A586-5E11-450C-AC3E-3619DE7DCA53}C:\program files\macromedia\dreamweaver 8\dreamweaver.exe" = protocol=6 | dir=in | app=c:\program files\macromedia\dreamweaver 8\dreamweaver.exe |
"TCP Query User{5F57D4C2-4DDE-444C-ABCA-D366D977283A}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"TCP Query User{7C52C5E4-69FF-405D-ACB0-B6774B6A14B6}C:\program files\kazaa lite tools k++\kazaalite.kpp" = protocol=6 | dir=in | app=c:\program files\kazaa lite tools k++\kazaalite.kpp |
"TCP Query User{9372BAC8-EF5C-4882-8986-2EBFDF87DC36}C:\windows\system32\winnt\cssrs.exe" = protocol=6 | dir=in | app=c:\windows\system32\winnt\cssrs.exe |
"TCP Query User{BE7CEDE3-679B-4435-98AF-F7FDF2FCB159}C:\program files\mirc\mirc.exe" = protocol=6 | dir=in | app=c:\program files\mirc\mirc.exe |
"TCP Query User{E5377DB2-4A7E-4B26-AEAE-00DBCE528165}C:\program files\real\realplayer\realplay.exe" = protocol=6 | dir=in | app=c:\program files\real\realplayer\realplay.exe |
"TCP Query User{E5D51521-CCA3-4BD7-B62D-9630F3B1944C}C:\program files\sopcast\sopcast.exe" = protocol=6 | dir=in | app=c:\program files\sopcast\sopcast.exe |
"TCP Query User{FFE6F917-5BE7-4651-8927-65AAC7235469}C:\program files\kazaa lite tools\kazaalite.kpp" = protocol=6 | dir=in | app=c:\program files\kazaa lite tools\kazaalite.kpp |
"UDP Query User{2751409C-AC51-4C07-ACD9-B7B4082A9AC3}C:\program files\emule\emule.exe" = protocol=17 | dir=in | app=c:\program files\emule\emule.exe |
"UDP Query User{4D55AF11-AD46-4B63-BCEE-E8C5449BF1A6}C:\program files\macromedia\dreamweaver 8\dreamweaver.exe" = protocol=17 | dir=in | app=c:\program files\macromedia\dreamweaver 8\dreamweaver.exe |
"UDP Query User{5B3E893A-7A41-4ACC-A084-4516DA3C31C1}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{60B8014D-D6F2-43D7-8260-0862FDCB9B35}C:\program files\tvuplayer\tvuplayer.exe" = protocol=17 | dir=in | app=c:\program files\tvuplayer\tvuplayer.exe |
"UDP Query User{8E48350F-4A43-43F3-A221-F98397F72F6A}C:\program files\kazaa lite tools k++\kazaalite.kpp" = protocol=17 | dir=in | app=c:\program files\kazaa lite tools k++\kazaalite.kpp |
"UDP Query User{8F5C8C0F-CA2A-4535-8A40-3E6C8A287BF6}C:\program files\tvants\tvants.exe" = protocol=17 | dir=in | app=c:\program files\tvants\tvants.exe |
"UDP Query User{96153D55-9052-436D-B6EA-7A242D47496F}C:\windows\system32\winnt\cssrs.exe" = protocol=17 | dir=in | app=c:\windows\system32\winnt\cssrs.exe |
"UDP Query User{990BD21C-BE08-4F48-8CF3-09928BA36B5D}C:\program files\real\realplayer\realplay.exe" = protocol=17 | dir=in | app=c:\program files\real\realplayer\realplay.exe |
"UDP Query User{9E167AD7-B22B-408E-94C7-208692A918A3}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"UDP Query User{A7056C2A-B5E7-42C6-ACCC-C050A1981F4C}C:\program files\sopcast\sopcast.exe" = protocol=17 | dir=in | app=c:\program files\sopcast\sopcast.exe |
"UDP Query User{B61D5348-C8A7-4C17-ABDD-8FBBF5E43CE3}C:\program files\sopcast\adv\sopadver.exe" = protocol=17 | dir=in | app=c:\program files\sopcast\adv\sopadver.exe |
"UDP Query User{C2EFABF5-2BBA-48A5-872C-60566E968D2E}C:\program files\mirc\mirc.exe" = protocol=17 | dir=in | app=c:\program files\mirc\mirc.exe |
"UDP Query User{CA58A50F-7C47-4A0B-9FF4-790B292C34DE}C:\program files\kazaa lite tools\kazaalite.kpp" = protocol=17 | dir=in | app=c:\program files\kazaa lite tools\kazaalite.kpp |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{06E74B9B-631F-4378-BF3A-40D868450C05}" = HPPhotoSmartPhotobookHolidayPack1
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{082F8ABA-84D5-4837-9DFC-F365D91A07D4}" = HP Smart Web Printing
"{11BB336F-0E58-4977-B866-F24FA334616B}" = HP Active Support Library
"{12A76360-388E-4B27-ABEB-D5FC5378DD2A}" = HPPhotoSmartPhotobookWebPack1
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{172AEB5E-CBB2-4CDD-A4CF-388600825839}" = HPPhotoSmartPhotobookPlayfulPack1
"{1BDC9633-895B-4842-BCB6-8FA1EC2A3C5A}" = Adobe Shockwave Player
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Suite
"{209CDA54-D390-46A2-A97C-7BF61734418D}" = WeatherBug Gadget
"{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant
"{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Driver Installation Program
"{28EDCE9C-3304-4331-8AB3-F3EBE94C35B4}" = HP Help and Support
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.30 E1
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP QuickPlay 3.6
"{471B83B9-29D8-41EC-9974-56BB8A457A8B}" = EPSON Stylus CX4400 Series Scanner Driver Update
"{4CACFCD9-F71B-413A-8DF5-1A6419D5CDC6}" = Cards_Calendar_OrderGift_DoMorePlugout
"{4D49757C-367A-4333-BDB3-68966162B14E}" = HP User Guides 0087
"{5546CDB5-2CE2-498B-B059-5B3BF81FC41F}" = Macromedia Extension Manager
"{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.51.01
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check
"{68471BF2-F1F7-4C89-BBBA-400B94996596}" = ESU for Microsoft Vista
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{7DC4A410-9986-4329-9E5D-687B2C42CA39}" = HP QuickTouch 1.00 C4
"{89E052B2-5CA5-4B7A-AF0C-28CA2836B030}" = HPPhotoSmartPhotobookModernPack1
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{9885A11E-60E4-417C-B58B-8B31B21C0B8A}" = HP Easy Setup - Frontend
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A07840FC-CE63-4CB8-8030-EF4B9805925A}" = HPPhotoSmartDiscLabel_PaperLabel
"{AB40272D-92AB-4F30-B36B-22EDE16F8FE5}" = HP Update
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{AC95121F-1576-45B8-82F7-3911D27882E6}" = HPPhotoSmartPhotobookScrapbookPack1
"{ADFB9653-F44C-460C-BF58-189CC552DFFE}" = hpphotosmartdisclabelplugin
"{b02df929-29a7-4fd2-9a70-81a644b635f7}" = HP Total Care Advisor
"{B4E91E95-A5BA-4E50-A465-DB7EFEB176E8}" = HPPhotoSmartDiscLabel_PrintOnDisc
"{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5
"{BD0E2B92-3814-46F0-893B-4612EA010C7E}" = HP Customer Experience Enhancements
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CBAE4F50-9FC9-4557-AB36-9826DF3C103C}" = HP Wireless Assistant
"{CC4A73BF-938E-4C19-A553-853C035C9BA1}" = LightScribe System Software 1.10.13.1
"{DD3C88A0-C53C-41D0-A21B-6D021981D23E}" = HPPhotoSmartDiscLabelContent1
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{EFB21DE7-8C19-4A88-BB28-A766E16493BC}" = Adobe Photoshop CS
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F636EE9A-F9EC-4606-BCFA-77DD0E210788}" = HPPhotoSmartDiscLabel_Tattoo
"{F7F3B252-E772-48AA-93EB-7964BC326067}" = MSCU for Microsoft Vista
"Ad-Aware" = Ad-Aware
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Bodog Casino" = Bodog Casino
"Boilsoft Video Joiner_is1" = Boilsoft Video Joiner 5.01
"CCleaner" = CCleaner (remove only)
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CNXT_MODEM_HDA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Cool's_Codec_pack_4.12" = Codec Pack - All In 1 6.0.3.0
"eMule" = eMule
"EPSON Printer and Utilities" = EPSON Printer Software
"EPSON Scanner" = EPSON Scan
"Hauppauge MCE2005 Software Encoder" = Hauppauge MCE XP/Vista Software Encoder (2.0.25149)
"HijackThis" = HijackThis 2.0.2
"HP Photosmart Essential" = HP Photosmart Essential 2.5
"HP Smart Web Printing" = HP Smart Web Printing
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"Kazaa Lite Tools K++" = Kazaa Lite Tools K++
"Mozilla Firefox (3.0.1)" = Mozilla Firefox (3.0.1)
"NVIDIA Drivers" = NVIDIA Drivers
"Silent Package Run-Time Sample" = EPSON CX4400 Series User's Guide
"SopCast" = SopCast 3.0.3
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TVUPlayer" = TVUPlayer [removed]
"ViewpointMediaPlayer" = Viewpoint Media Player
"WildTangent hp Master Uninstall" = My HP Games
"WinRAR archiver" = WinRAR archiver
"x264vfw" = x264vfw - H.264/MPEG-4 AVC codec (remove only)
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"BitTorrent" = BitTorrent
"BitTorrent DNA" = DNA
"Move Media Player" = Move Media Player
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 8/6/2009 3:05:36 PM | Computer Name = Nick-PC | Source = Windows Search Service | ID = 3083
Description =
Error - 8/6/2009 6:03:31 PM | Computer Name = Nick-PC | Source = Windows Search Service | ID = 3083
Description =
Error - 8/6/2009 6:08:02 PM | Computer Name = Nick-PC | Source = Windows Search Service | ID = 3083
Description =
Error - 8/6/2009 6:12:46 PM | Computer Name = Nick-PC | Source = Windows Search Service | ID = 3083
Description =
Error - 8/6/2009 6:33:57 PM | Computer Name = Nick-PC | Source = EventSystem | ID = 4609
Description =
Error - 8/6/2009 6:39:35 PM | Computer Name = Nick-PC | Source = Windows Search Service | ID = 3083
Description =
Error - 8/6/2009 6:46:09 PM | Computer Name = Nick-PC | Source = Windows Search Service | ID = 3083
Description =
Error - 8/6/2009 6:47:00 PM | Computer Name = Nick-PC | Source = WerSvc | ID = 5007
Description =
Error - 8/6/2009 6:57:28 PM | Computer Name = Nick-PC | Source = Windows Search Service | ID = 3083
Description =
Error - 8/6/2009 6:58:37 PM | Computer Name = Nick-PC | Source = Windows Search Service | ID = 3083
Description =
[ System Events ]
Error - 8/6/2009 6:34:27 PM | Computer Name = Nick-PC | Source = DCOM | ID = 10005
Description =
Error - 8/6/2009 6:34:36 PM | Computer Name = Nick-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 8/6/2009 6:34:36 PM | Computer Name = Nick-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 8/6/2009 6:36:41 PM | Computer Name = Nick-PC | Source = ACPI | ID = 327686
Description = IRQARB: ACPI BIOS does not contain an IRQ for the device in PCI slot
12, function 0. Please contact your system vendor for technical assistance.
Error - 8/6/2009 6:36:41 PM | Computer Name = Nick-PC | Source = ACPI | ID = 327686
Description = IRQARB: ACPI BIOS does not contain an IRQ for the device in PCI slot
13, function 0. Please contact your system vendor for technical assistance.
Error - 8/6/2009 6:36:53 PM | Computer Name = Nick-PC | Source = Microsoft-Windows-Kernel-WHEA | ID = 6
Description =
Error - 8/6/2009 6:37:01 PM | Computer Name = Nick-PC | Source = Microsoft-Windows-Eventlog | ID = 23
Description =
Error - 8/6/2009 6:38:38 PM | Computer Name = Nick-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 8/6/2009 6:38:42 PM | Computer Name = Nick-PC | Source = ipnathlp | ID = 34001
Description = The ICS_IPV6 failed to configure IPv6 stack.
Error - 8/6/2009 6:38:42 PM | Computer Name = Nick-PC | Source = ipnathlp | ID = 30013
Description = The DHCP allocator has disabled itself on IP address 192.168.1.4,
since the IP address is outside the 192.168.0.0/255.255.255.0 scope from which addresses
are being allocated to DHCP clients. To enable the DHCP allocator on this IP address,
change the scope to include the IP address, or change the IP address to fall within
the scope.
< End of report >
And here's the SysProtLog:
SysProt AntiRootkit v1.0.1.0
by swatkat
********************************************************************************
**********
********************************************************************************
**********
No Hidden Processes found
********************************************************************************
**********
********************************************************************************
**********
Kernel Modules:
Module Name: \SystemRoot\System32\Drivers\dump_dumpata.sys
Service Name: —
Module Base: 85A35000
Module End: 85A40000
Hidden: Yes
Module Name: \SystemRoot\System32\Drivers\dump_atapi.sys
Service Name: —
Module Base: 85AB0000
Module End: 85AB8000
Hidden: Yes
Module Name: \??\C:\Users\Nick\AppData\Local\Temp\aujasnkj.sys
Service Name: aujasnkj
Module Base: 96622000
Module End: 96637000
Hidden: Yes
********************************************************************************
**********
********************************************************************************
**********
No SSDT Hooks found
********************************************************************************
**********
********************************************************************************
**********
Kernel Hooks:
Hooked Function: IofCompleteRequest
At Address: 81C27F8C
Jump To: 89AF2123
Module Name: _unknown_
Hooked Function: IofCallDriver
At Address: 81C27F1F
Jump To: 8A8AA572
Module Name: _unknown_
********************************************************************************
**********
********************************************************************************
**********
No IRP Hooks found
********************************************************************************
**********
********************************************************************************
**********
Ports:
Local Address: NICK-PC.MSHOME.NET:50030
Remote Address: CF-IN-F102.GOOGLE.COM:HTTP
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: NICK-PC.MSHOME.NET:50028
Remote Address: 199.16.83.72:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: NICK-PC.MSHOME.NET:50027
Remote Address: 63-217-8-146.STATIC.PCCWGLOBAL.NET:HTTP
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: NICK-PC.MSHOME.NET:50026
Remote Address: 199.16.83.72:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: NICK-PC.MSHOME.NET:50024
Remote Address: [removed]:HTTPS
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: NICK-PC.MSHOME.NET:50021
Remote Address: AD1.RM.VIP.SP2.YAHOO.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: NICK-PC.MSHOME.NET:50020
Remote Address: 63-217-8-121.STATIC.PCCWGLOBAL.NET:HTTP
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: NICK-PC.MSHOME.NET:50017
Remote Address: S1.RD.SK1.YAHOO.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: NICK-PC.MSHOME.NET:50016
Remote Address: BS2.ADS.VIP.SP1.YAHOO.COM:HTTP
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: NICK-PC.MSHOME.NET:49191
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Windows\System32\alg.exe
State: LISTENING
Local Address: NICK-PC.MSHOME.NET:NETBIOS-SSN
Remote Address: 0.0.0.0:0
Type: TCP
Process: System
State: LISTENING
Local Address: NICK-PC:50011
Remote Address: LOCALHOST:50010
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: NICK-PC:50010
Remote Address: LOCALHOST:50011
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: NICK-PC:50009
Remote Address: LOCALHOST:50008
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: NICK-PC:50008
Remote Address: LOCALHOST:50009
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: NICK-PC:49179
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Windows\System32\services.exe
State: LISTENING
Local Address: NICK-PC:49156
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Windows\System32\lsass.exe
State: LISTENING
Local Address: NICK-PC:49155
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Windows\System32\svchost.exe
State: LISTENING
Local Address: NICK-PC:49154
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Windows\System32\svchost.exe
State: LISTENING
Local Address: NICK-PC:49153
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Windows\System32\svchost.exe
State: LISTENING
Local Address: NICK-PC:49152
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Windows\System32\wininit.exe
State: LISTENING
Local Address: NICK-PC:26154
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\DNA\btdna.exe
State: LISTENING
Local Address: NICK-PC:EPMAP
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Windows\System32\svchost.exe
State: LISTENING
Local Address: NICK-PC.MSHOME.NET:49537
Remote Address: NA
Type: UDP
Process: C:\Windows\System32\svchost.exe
State: NA
Local Address: NICK-PC.MSHOME.NET:49187
Remote Address: NA
Type: UDP
Process: C:\Program Files\DNA\btdna.exe
State: NA
Local Address: NICK-PC.MSHOME.NET:SSDP
Remote Address: NA
Type: UDP
Process: C:\Windows\System32\svchost.exe
State: NA
Local Address: NICK-PC.MSHOME.NET:SSDP
Remote Address: NA
Type: UDP
Process: C:\Program Files\DNA\btdna.exe
State: NA
Local Address: NICK-PC.MSHOME.NET:138
Remote Address: NA
Type: UDP
Process: System
State: NA
Local Address: NICK-PC.MSHOME.NET:NETBIOS-NS
Remote Address: NA
Type: UDP
Process: System
State: NA
Local Address: NICK-PC:49538
Remote Address: NA
Type: UDP
Process: C:\Windows\System32\svchost.exe
State: NA
Local Address: NICK-PC:49488
Remote Address: NA
Type: UDP
Process: C:\Program Files\DNA\btdna.exe
State: NA
Local Address: NICK-PC:49254
Remote Address: NA
Type: UDP
Process: C:\Windows\System32\svchost.exe
State: NA
Local Address: NICK-PC:49189
Remote Address: NA
Type: UDP
Process: C:\Windows\System32\svchost.exe
State: NA
Local Address: NICK-PC:SSDP
Remote Address: NA
Type: UDP
Process: C:\Windows\System32\svchost.exe
State: NA
Local Address: NICK-PC:49210
Remote Address: NA
Type: UDP
Process: C:\Windows\System32\svchost.exe
State: NA
Local Address: NICK-PC:49208
Remote Address: NA
Type: UDP
Process: C:\Windows\System32\svchost.exe
State: NA
Local Address: NICK-PC:49188
Remote Address: NA
Type: UDP
Process: C:\Windows\System32\svchost.exe
State: NA
Local Address: NICK-PC:26154
Remote Address: NA
Type: UDP
Process: C:\Program Files\DNA\btdna.exe
State: NA
Local Address: NICK-PC:LLMNR
Remote Address: NA
Type: UDP
Process: C:\Windows\System32\svchost.exe
State: NA
Local Address: NICK-PC:IPSEC-MSFT
Remote Address: NA
Type: UDP
Process: C:\Windows\System32\svchost.exe
State: NA
Local Address: NICK-PC:500
Remote Address: NA
Type: UDP
Process: C:\Windows\System32\svchost.exe
State: NA
Local Address: NICK-PC:123
Remote Address: NA
Type: UDP
Process: C:\Windows\System32\svchost.exe
State: NA
Local Address: NICK-PC:DOMAIN
Remote Address: NA
Type: UDP
Process: C:\Windows\System32\svchost.exe
State: NA
********************************************************************************
**********
********************************************************************************
**********
Hidden files/folders:
Object: C:\System Volume Information\DFSR
Status: Access denied
Object: C:\System Volume Information\MountPointManagerRemoteDatabase
Status: Access denied
Object: C:\System Volume Information\SPP
Status: Access denied
Object: C:\System Volume Information\tracking.log
Status: Access denied
Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl
Status: Access denied
Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl
Status: Access denied
Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl
Status: Access denied
Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl
Status: Access denied
Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTMsMpPsSession.etl
Status: Access denied