This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] CPU 100%, Running Slow

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, my computer seem to have slowed down recently. I noticed when I run a program it maxes out my cpu and makes loading pages from the internet super slow. It does this for almost any larger program, I can only do one thing at a time.
I have a Dell Demension 4600, Pentium 4 CPU 2.6 GHz, 1.25 GB of Ram, Windows XP SP3. I have added my hijack this report. Could you please check to see if there is anything out of the ordinary. Thanks


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:15:11 PM, on 1/4/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16945)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG8\Identity Protection\agent\Bin\AVGIDSAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgfws8.exe
C:\Program Files\AVG\AVG8\Identity Protection\agent\Bin\AVGIDSWatcher.exe
C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
G:\Dad\PrfldSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\System32\wbem\unsecapp.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\AVG\AVG8\Identity Protection\agent\bin\AVGIDSUI.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AVG\AVG8\Identity Protection\agent\bin\AVGIDSMonitor.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\BitComet\BitComet.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Browser Defender BHO - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: PC Tools Browser Guard - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [AVGIDS] "C:\Program Files\AVG\AVG8\Identity Protection\agent\bin\AVGIDSUI.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgfws8.exe
O23 - Service: AVGIDSAgent - AVG - C:\Program Files\AVG\AVG8\Identity Protection\agent\Bin\AVGIDSAgent.exe
O23 - Service: AVGIDSWatcher - AVG - C:\Program Files\AVG\AVG8\Identity Protection\agent\Bin\AVGIDSWatcher.exe
O23 - Service: Browser Defender Update Service - Threat Expert Ltd. - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Private Folder Service (prfldsvc) - Unknown owner - G:\Dad\PrfldSvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

–
End of file - 9349 bytes
Hi Budz,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Let's get a deeper scan.

Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
If you do not receive notice about possible rootkit activity remain on the Rootkit/Malware tab & make sure the 'Show All' button is unticked.
  • Click the Scan button and let the program do its work. GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop

Download OTL to your desktop.
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • Copy and paste the following bold text in to the window Under the Custom Scan box

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Please post back with
  • GMER log
  • both OTL logs
Thanks for responsing Tomk. I downloaded the GMER program, but it scanned for awhile then instantly shuts down and reboots my computer. I tried this 4 times with the same results, I had no other programs running. Are there other steps I should try?
Here's the 2 files:

OTL Extras logfile created on: 1/8/2010 6:42:45 PM - Run 1
OTL by OldTimer - Version 3.1.21.2 Folder = C:\Documents and Settings\Dad\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 61.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 1920 3840 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 63.88 Gb Free Space | 42.86% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PAIN
Current User Name: Dad
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "%programfiles%\internet explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"25422:TCP" = 25422:TCP:*:Enabled:BitComet 25422 TCP
"25422:UDP" = 25422:UDP:*:Enabled:BitComet 25422 UDP
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\AVG\AVG8\avgemc.exe" = C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG8\avgupd.exe" = C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG8\avgnsx.exe" = C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe – ()
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe – ()
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe – ( )
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\RealFlightG3\RealFlight.exe" = C:\Program Files\RealFlightG3\RealFlight.exe:*:Enabled:Radio Control Simulator – (Knife Edge Software)
"G:\Program Files\THQ\Dawn of War - Dark Crusade\DarkCrusade.exe" = G:\Program Files\THQ\Dawn of War - Dark Crusade\DarkCrusade.exe:*:Enabled:DarkCrusade – File not found
"D:\setup\HPZnet01.exe" = D:\setup\HPZnet01.exe:*:Enabled:hpznet01.exe – File not found
"D:\setup\HPONICIFS01.EXE" = D:\setup\HPONICIFS01.EXE:*:Enabled:hponicifs01.exe – File not found


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{03B1B42B-F6DE-41d9-8CFF-DC44E895C7A7}" = PhotoGallery
"{0611BD4E-4FE4-4a62-B0C0-18A4CC463428}" = CP_Package_Variety1
"{09984AEC-6B9F-4ca7-B78D-CB44D4771DA3}" = Destinations
"{10C69612-017B-45F5-B986-7D113D5A2EA3}" = MSN Toolbar
"{1330F885-F8E4-4c36-9B88-E19F82042C06}" = 3100_3200_3300trb
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{15EE79F4-4ED1-4267-9B0F-351009325D7D}" = HP Software Update
"{172975EB-9465-4861-95B5-C7BB6D3DE62A}" = DocumentViewer
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1C139D7D-9FEA-468d-A9C8-2A6E3BDE564A}" = CP_Package_Variety3
"{21DB3D90-D816-4092-A260-CA3F6B55A6DD}" = Sonic_PrimoSDK
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{23A7B376-BBEC-4e76-BBD7-0F155E70D74B}" = CP_Panorama1Config
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 13
"{2B65C841-EC48-4087-8021-6DBB9C1DE5E6}" = 3200
"{2CADCEAB-D5DA-44D6-B5FC-7DEE87AB3C0C}" = Unload
"{30C19FF2-7FBA-4d09-B9DE-1659977F64F6}" = TrayApp
"{32BDCCB8-9DC8-496d-9DB1-F77510775BDB}" = InstantShareDevices
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36E47DA1-10E1-45d9-8B19-14D19607CDCF}" = CP_CalendarTemplates1
"{3B0F52AC-EF5C-4831-B221-06C782E41280}" = Quicken 2008
"{3E386744-10FA-44b2-98C9-DF7A270DECB3}" = HP PSC & OfficeJet 5.3.A
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{50E7BB78-02B4-469a-9D8B-B2F42835F90E}" = ProductContextNPI
"{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder
"{567C23E1-7580-4185-B8C2-30805677297C}" = NewCopy_CDA
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{56EE8B17-8274-418d-89AC-C057C5DB251E}" = RandMap
"{56F6A91D-46D4-4919-ABE6-55BD17DEB039}" = Quick Movie Magic 1.0E
"{56F8AFC3-FA98-4ff1-9673-8A026CBF85BE}" = WebReg
"{5A01C58E-B0EC-49b9-AD71-7C0468688087}" = CP_Package_Basic1
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{5F26311C-B135-4F7F-B11E-8E650F83651E}" = DeviceFunctionQFolder
"{644EA08F-87D2-48C0-AE94-B327D1C85A97}" = Microsoft Private Folder 1.0
"{66BA8C26-AFE4-4408-807B-43E76B57EF53}" = SkinsHP1
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{698D7E61-E4BF-4CA6-8A09-CF6BDBFDEF65}" = Battlefield 1942
"{6BB6627C-694F-4FDC-A3E5-C7F4BED4C724}" = DocProc
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7583D2F8-8E7D-40C5-9862-4D218006FB84}" = AVG Identity Protection
"{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7C03270C-4FAB-4F5C-B10D-52FEDA190790}" = DocumentViewerQFolder
"{7E27304E-BAA2-4d90-A34E-76641FAFABB4}" = CP_AtenaShokunin1Config
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{923A7F5A-1E8C-4FBE-8DF6-85940A60A79F}" = Readme
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A195B13E-A5E3-4BAF-A995-7F70F445CD06}" = ScannerCopy
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A5BB5365-EFB4-44c3-A7E2-EB59B7EFD23D}" = CueTour
"{A790BEB1-BCCF-4EC6-807B-5708B36E8A79}" = Intel® PROSet
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-1033-0000-7760-000000000002}" = Adobe Acrobat 7.0 Professional
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B276997E-4367-4b1b-A39C-4CAE7464337A}" = AiO_Scan_CDA
"{B4D279F1-4309-49cc-A4B5-3A0D2E59C7B5}" = PanoStandAlone
"{B60E7826-F117-4d26-8165-D2DC5A494AB0}" = Fax_CDA
"{B64E3AFC-59EF-4f18-BF11-E751462450D3}" = AiOSoftwareNPI
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Plus Web Player
"{B74D4E10-6884-0000-0000-000000000103}" = Adobe Bridge 1.0
"{B824B5C9-849F-4b9e-9EA7-6FD8CD8116DA}" = CP_Package_Variety2
"{B996AE66-10DB-4ac5-B151-E8B4BFBC42FC}" = BufferChm
"{BE6890C7-31EF-478C-812E-1E2899ABFCA9}" = B57Inst
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem driver
"{C506A18C-1469-4678-B094-F4EC9DAE6DB7}" = Scan
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D057AA08-8CBF-42E3-9EAB-23B8FED1C279}" = Battlefield 1942: The Road To Rome
"{D07643A3-CE41-4286-8C78-EB9C83E76DDB}" = PunkBuster for Battlefield Vietnam
"{D3EE034D-5B92-4A55-AA02-2E6D0A6A96EE}" = Windows Resource Kit Tools - SubInAcl.exe
"{D78653C3-A8FF-415F-92E6-D774E634FF2D}" = Dell ResourceCD
"{DBCC73BA-C69A-4BF5-B4BF-F07501EE7039}" = AnswerWorks 5.0 English Runtime
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E3F90083-80D4-4b5a-87C7-E97E12F5516D}" = HPProductAssistant
"{E82BF103-904F-49C0-B77F-6EC110B71E87}" = Sound Blaster Audigy 2
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"{EA103B64-C0E4-4C0E-A506-751590E1653D}" = SolutionCenter
"{F1931CAB-C7DD-4825-8A58-BC5278805200}" = 3100_3200_3300_Help
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F4C2E5F5-2970-45f4-ABD3-C180C4D961C4}" = Status
"{FA61D601-A0FC-48BD-AE7A-54946BCD7FB6}_is1" = BitPim 1.0.7.20090805
"Ad-Aware" = Ad-Aware
"Adobe Acrobat 7.0 Professional" = Adobe Acrobat 7.1.0 Professional
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"Any Video Converter Professional_is1" = Any Video Converter Professional 2.7.3
"Any Video Converter_is1" = Any Video Converter 2.7.1
"AVG8Uninstall" = AVG 8.5
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.3
"AVS4YOU Video Converter 6_is1" = AVS Video Converter 6
"BFG-Azada - Ancient Magic" = Azada ™: Ancient Magic
"BFGC" = Big Fish Games Client
"BitComet" = BitComet 1.07
"Boggle_is1" = Boggle
"Browser Defender_is1" = Browser Defender [removed]
"dBpoweramp DSP Effects" = dBpoweramp DSP Effects
"dBpoweramp FLAC Codec" = dBpoweramp FLAC Codec
"dBpoweramp Music Converter" = dBpoweramp Music Converter
"DesertCombat" = DesertCombat 0.7
"DesertCombat_Public_Alpha__0.2" = DesertCombat Public Alpha 0.4J
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DVD Flick_is1" = DVD Flick 1.3.0.7
"DVD-CLONER VII_is1" = DVD-CLONER V7.00 Build 990
"GameSpy Arcade" = GameSpy Arcade
"GOM Player" = GOM Player
"HijackThis" = HijackThis 2.0.2
"HP Document Viewer" = HP Document Viewer 5.3
"HP Imaging Device Functions" = HP Imaging Device Functions 5.3
"HP Photo & Imaging" = HP Image Zone 5.3
"HP Solution Center & Imaging Support Tools" = HP Solution Center & Imaging Support Tools 5.3
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{BE6890C7-31EF-478C-812E-1E2899ABFCA9}" = Broadcom Driver Installer
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MOVAVI VideoSuite 3.4" = MOVAVI VideoSuite 3.4
"Mozilla Firefox (3.0.16)" = Mozilla Firefox (3.0.16)
"MPEG2 Codec(libmpeg2/mad)" = MPEG2 Codec(libmpeg2/mad)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"Ogg Codecs" = Ogg Codecs 0.81.15562
"Pdf995" = Pdf995 (installed by TaxCut)
"PdfEdit995" = PdfEdit995 (installed by TaxCut)
"PROSet" = Intel® PRO Network Adapters and Drivers
"RealAlt_is1" = Real Alternative 1.9.0
"RealFlightG3Pro" = RealFlight G3 R/C Simulator
"RealPlayer 12.0" = RealPlayer
"Spyware Doctor" = Spyware Doctor 7.0
"Tweak UI 2.10" = Tweak UI
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 8/23/2009 1:12:45 AM | Computer Name = PAIN | Source = Application Error | ID = 1000
Description = Faulting application bf1942.exe, version 0.0.0.0, faulting module
bf1942.exe, version 0.0.0.0, fault address 0x000931cc.

Error - 8/23/2009 1:15:08 AM | Computer Name = PAIN | Source = Application Error | ID = 1000
Description = Faulting application bf1942.exe, version 0.0.0.0, faulting module
bf1942.exe, version 0.0.0.0, fault address 0x000931cc.

Error - 8/23/2009 1:16:28 AM | Computer Name = PAIN | Source = Application Error | ID = 1000
Description = Faulting application bf1942.exe, version 0.0.0.0, faulting module
bf1942.exe, version 0.0.0.0, fault address 0x000931cc.

Error - 8/23/2009 1:32:55 AM | Computer Name = PAIN | Source = Application Error | ID = 1000
Description = Faulting application bf1942.exe, version 0.0.0.0, faulting module
bf1942.exe, version 0.0.0.0, fault address 0x000931cc.

Error - 8/28/2009 11:08:05 PM | Computer Name = PAIN | Source = Application Error | ID = 1000
Description = Faulting application bf1942.exe, version 0.0.0.0, faulting module
bf1942.exe, version 0.0.0.0, fault address 0x000931cc.

Error - 8/29/2009 1:18:22 AM | Computer Name = PAIN | Source = Application Error | ID = 1000
Description = Faulting application bf1942.exe, version 0.0.0.0, faulting module
bf1942.exe, version 0.0.0.0, fault address 0x000931cc.

Error - 9/4/2009 10:23:14 PM | Computer Name = PAIN | Source = Application Error | ID = 1000
Description = Faulting application bf1942.exe, version 0.0.0.0, faulting module
bf1942.exe, version 0.0.0.0, fault address 0x000931cc.

Error - 9/4/2009 10:43:26 PM | Computer Name = PAIN | Source = Application Error | ID = 1000
Description = Faulting application bf1942.exe, version 0.0.0.0, faulting module
bf1942.exe, version 0.0.0.0, fault address 0x000910e6.

Error - 9/4/2009 11:33:30 PM | Computer Name = PAIN | Source = Application Error | ID = 1000
Description = Faulting application bf1942.exe, version 0.0.0.0, faulting module
bf1942.exe, version 0.0.0.0, fault address 0x000931cc.

Error - 9/5/2009 12:22:34 AM | Computer Name = PAIN | Source = Application Error | ID = 1000
Description = Faulting application bf1942.exe, version 0.0.0.0, faulting module
bf1942.exe, version 0.0.0.0, fault address 0x000931cc.

[ System Events ]
Error - 1/8/2010 3:30:31 PM | Computer Name = PAIN | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service upnphost with
arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56}

Error - 1/8/2010 3:35:13 PM | Computer Name = PAIN | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service upnphost with
arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56}

Error - 1/8/2010 6:23:36 PM | Computer Name = PAIN | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort1, did not respond within the timeout
period.

Error - 1/8/2010 6:24:49 PM | Computer Name = PAIN | Source = Service Control Manager | ID = 7000
Description = The Private Folder Service service failed to start due to the following
error: %%3

Error - 1/8/2010 6:30:29 PM | Computer Name = PAIN | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort1, did not respond within the timeout
period.

Error - 1/8/2010 6:31:50 PM | Computer Name = PAIN | Source = Service Control Manager | ID = 7000
Description = The Private Folder Service service failed to start due to the following
error: %%3

Error - 1/8/2010 6:37:21 PM | Computer Name = PAIN | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort1, did not respond within the timeout
period.

Error - 1/8/2010 6:38:42 PM | Computer Name = PAIN | Source = Service Control Manager | ID = 7000
Description = The Private Folder Service service failed to start due to the following
error: %%3

Error - 1/8/2010 6:44:12 PM | Computer Name = PAIN | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort1, did not respond within the timeout
period.

Error - 1/8/2010 6:45:38 PM | Computer Name = PAIN | Source = Service Control Manager | ID = 7000
Description = The Private Folder Service service failed to start due to the following
error: %%3


< End of report >

OTL logfile created on: 1/8/2010 6:42:45 PM - Run 1
OTL by OldTimer - Version 3.1.21.2 Folder = C:\Documents and Settings\Dad\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 61.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 1920 3840 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 63.88 Gb Free Space | 42.86% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PAIN
Current User Name: Dad
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Dad\Desktop\OTLCA8WBSNI.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgam.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgfws8.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\WINDOWS\system32\PnkBstrA.exe ()
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\AVG\AVG8\Identity Protection\agent\Bin\AVGIDSUI.exe (AVG)
PRC - C:\Program Files\AVG\AVG8\Identity Protection\agent\Bin\AVGIDSWatcher.exe (AVG)
PRC - C:\Program Files\AVG\AVG8\Identity Protection\agent\Bin\AVGIDSAgent.exe (AVG)
PRC - C:\Program Files\AVG\AVG8\Identity Protection\agent\Bin\AVGIDSMonitor.exe (AVG)
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\WINDOWS\system32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\CTSVCCDA.EXE (Creative Technology Ltd)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Dad\Desktop\OTLCA8WBSNI.exe (OldTimer Tools)


========== Win32 Services (SafeList) ==========

SRV - (prfldsvc) – File not found
SRV - (Browser Defender Update Service) – C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
SRV - (sdCoreService) – C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools)
SRV - (sdAuxService) – C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)
SRV - (avg8emc) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgfws8) – C:\Program Files\AVG\AVG8\avgfws8.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (PnkBstrA) – C:\WINDOWS\system32\PnkBstrA.exe ()
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (AVGIDSWatcher) – C:\Program Files\AVG\AVG8\Identity Protection\agent\Bin\AVGIDSWatcher.exe (AVG)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG8\Identity Protection\agent\Bin\AVGIDSAgent.exe (AVG)
SRV - (Adobe LM Service) – C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe (Adobe Systems)
SRV - (NVSvc) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (NetSvc) – C:\Program Files\Intel\NCS\Sync\NetSvc.exe (Intel® Corporation)
SRV - (Creative Service for CDROM Access) – C:\WINDOWS\system32\CTSVCCDA.EXE (Creative Technology Ltd)


========== Driver Services (SafeList) ==========

DRV - (PCTCore) – C:\WINDOWS\system32\drivers\PCTCore.sys (PC Tools)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Lbd) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (Avgfwfd) – C:\WINDOWS\system32\drivers\avgfwdx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgfwdx) – C:\WINDOWS\system32\drivers\avgfwdx.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgRkx86) – C:\WINDOWS\System32\Drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSDriver) – C:\Program Files\AVG\AVG8\Identity Protection\agent\driver\platform_XP\AVGIDSDriver.sys (AVG Technologies )
DRV - (AVGIDSFilter) – C:\Program Files\AVG\AVG8\Identity Protection\agent\driver\platform_XP\AVGIDSFilter.sys (AVG Technologies )
DRV - (AVGIDSShim) – C:\Program Files\AVG\AVG8\Identity Protection\agent\driver\platform_XP\AVGIDSShim.sys (AVG Technologies )
DRV - (AVGIDSErHr) – C:\WINDOWS\System32\Drivers\AVGIDSErHr.sys (AVG Technologies )
DRV - (PxHelp20) – C:\WINDOWS\system32\DRIVERS\PxHelp20.sys (Sonic Solutions)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (Secdrv) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (UsbDiag) – C:\WINDOWS\system32\drivers\lgusbdiag.sys (LG Electronics Inc.)
DRV - (USBModem) – C:\WINDOWS\system32\drivers\lgusbmodem.sys (LG Electronics Inc.)
DRV - (usbbus) – C:\WINDOWS\system32\drivers\lgusbbus.sys (LG Electronics Inc.)
DRV - (Prvflder) – C:\WINDOWS\system32\drivers\prvflder.sys (Windows ® 2000 DDK provider)
DRV - (HPZius12) – C:\WINDOWS\system32\drivers\HPZius12.sys (HP)
DRV - (HPZipr12) – C:\WINDOWS\system32\drivers\HPZipr12.sys (HP)
DRV - (HPZid412) – C:\WINDOWS\system32\drivers\HPZid412.sys (HP)
DRV - (Ptilink) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (ctdvda2k) – C:\WINDOWS\system32\drivers\ctdvda2k.sys (Creative Technology Ltd)
DRV - (ctaud2k) Creative Audio Driver (WDM) – C:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (hap16v2k) – C:\WINDOWS\system32\drivers\hap16v2k.sys (Creative Technology Ltd)
DRV - (ha10kx2k) – C:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (PfModNT) – C:\WINDOWS\system32\drivers\pfmodnt.sys (Creative Technology Ltd.)
DRV - (E100B) Intel® – C:\WINDOWS\system32\drivers\e100b325.sys (Intel Corporation)
DRV - (emupia) – C:\WINDOWS\system32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) – C:\WINDOWS\system32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – C:\WINDOWS\system32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (OMCI) – C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS (Dell Computer Corporation)
DRV - (StillCam) – C:\WINDOWS\system32\drivers\serscan.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.071303000004
FF - prefs.js..extensions.enabledItems: {66E978CD-981F-47DF-AC42-E3CF417C1467}:0.4
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0

FF - HKLM\software\mozilla\Mozilla Firefox 3.0.16\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/12/28 04:08:06 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.16\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/12/18 01:14:08 | 00,000,000 | —D | M]

[2009/03/27 21:33:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Dad\Application Data\Mozilla\Extensions
[2010/01/07 12:55:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v7wp6yps.default\extensions
[2009/04/22 15:30:58 | 00,000,000 | —D | M] (New Tab Homepage) – C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v7wp6yps.default\extensions\{66E978CD-981F-47DF-AC42-E3CF417C1467}
[2009/03/27 22:07:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v7wp6yps.default\extensions\[removed]
[2010/01/07 21:41:33 | 00,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: (734 bytes) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll (BitComet)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [AsioReg] C:\WINDOWS\System32\CTASIO.DLL (Creative Technology Ltd)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [AVGIDS] C:\Program Files\AVG\AVG8\Identity Protection\agent\bin\AVGIDSUI.exe (AVG)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &D;&ownload; &with; BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: &D;&ownload; all video with BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: &D;&ownload; all with BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll (BitComet)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/12/20 17:12:44 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{7d025e8e-cef9-11dd-9bd9-0007e95117dd}\Shell\AutoRun\command - "" = F:\setupSNK.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2008/12/20 12:03:14 | 00,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16892003295952896)

========== Files/Folders - Created Within 30 Days ==========

[2010/01/08 18:39:40 | 00,513,536 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Dad\Desktop\OTLCA8WBSNI.exe
[2010/01/08 12:04:03 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\My Documents\My Scans
[2010/01/04 18:18:35 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\My Documents\Computer Tools
[2010/01/02 13:10:33 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\Application Data\ImgBurn
[2010/01/02 11:58:31 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\My Documents\dvd
[2010/01/02 11:56:44 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\Application Data\DVD Flick
[2010/01/02 11:56:25 | 00,164,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\comct232.ocx
[2010/01/02 11:56:25 | 00,040,960 | —- | C] (vbAccelerator) – C:\WINDOWS\System32\ssubtmr6.dll
[2010/01/02 11:56:25 | 00,036,864 | —- | C] (Robdogg Inc.) – C:\WINDOWS\System32\trayicon_handler.ocx
[2010/01/02 11:56:25 | 00,028,672 | —- | C] (-) – C:\WINDOWS\System32\mousewheel.ocx
[2010/01/02 11:56:24 | 00,609,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\comctl32.ocx
[2010/01/02 11:56:24 | 00,212,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\richtx32.ocx
[2010/01/02 11:56:24 | 00,000,000 | —D | C] – C:\Program Files\DVD Flick
[2009/12/28 19:41:59 | 00,000,000 | —D | C] – C:\Movavi files
[2009/12/28 19:38:27 | 00,000,000 | —D | C] – C:\Program Files\MOVAVI
[2009/12/28 19:38:17 | 00,000,000 | —D | C] – C:\Program Files\MOVAVI VideoSuite 3.4
[2009/12/22 03:20:53 | 01,414,440 | —- | C] (Nero AG) – C:\WINDOWS\System32\ShellManager310E2D762.dll
[2009/12/22 02:34:08 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\Local Settings\Application Data\Ahead
[2009/12/22 02:27:57 | 02,388,176 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_30.dll
[2009/12/22 02:27:56 | 02,323,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_28.dll
[2009/12/21 14:31:13 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\Application Data\CyberLink
[2009/12/21 14:23:26 | 00,446,464 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\NVUNINST.EXE
[2009/12/21 14:19:14 | 00,000,000 | —D | C] – C:\Program Files\CyberLink
[2009/12/19 02:07:54 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\Application Data\Any Video Converter Professional
[2009/12/19 02:07:51 | 00,000,000 | —D | C] – C:\Program Files\Any Video Converter Professional
[2009/12/16 16:36:58 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\Local Settings\Application Data\Threat Expert
[2009/12/16 16:29:56 | 00,149,456 | —- | C] (PC Tools) – C:\WINDOWS\SGDetectionTool.dll
[2009/12/16 16:29:55 | 01,640,400 | —- | C] (Threat Expert Ltd.) – C:\WINDOWS\PCTBDCore.dll
[2009/12/16 16:29:55 | 00,165,840 | —- | C] (Threat Expert Ltd.) – C:\WINDOWS\PCTBDRes.dll
[2009/12/16 15:40:55 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\LG Dare Stuff
[2009/12/15 00:27:55 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\Application Data\AVS4YOU
[2009/12/15 00:27:51 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVS4YOU
[2009/12/15 00:25:48 | 00,024,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msxml3a.dll
[2009/12/15 00:25:48 | 00,000,000 | —D | C] – C:\Program Files\Common Files\AVSMedia
[2009/03/27 07:23:40 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Intuit
[2008/12/31 12:25:40 | 00,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2008/12/20 19:53:00 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2008/12/20 19:15:33 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2008/12/20 18:00:39 | 00,065,536 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll
[2008/12/20 17:12:30 | 00,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2005/05/11 23:36:48 | 00,012,288 | —- | C] (Hewlett-Packard Co.) – C:\WINDOWS\Fonts\RandFont.dll
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/01/08 18:39:44 | 00,513,536 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Dad\Desktop\OTLCA8WBSNI.exe
[2010/01/08 18:39:03 | 00,003,258 | —- | M] () – C:\Documents and Settings\Dad\Desktop\CPU 100%, Running Slow.url
[2010/01/08 17:44:50 | 00,178,882 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/01/08 17:44:00 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/01/08 17:43:55 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/01/08 17:43:52 | 00,000,000 | —- | M] () – C:\WINDOWS\MEMORY.DMP
[2010/01/08 14:29:58 | 00,190,976 | —- | M] () – C:\Documents and Settings\Dad\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/01/08 12:28:10 | 07,340,032 | —- | M] () – C:\Documents and Settings\Dad\ntuser.dat
[2010/01/08 12:25:41 | 00,185,732 | —- | M] () – C:\Documents and Settings\All Users\Documents\Return to work.pdf
[2010/01/08 12:08:50 | 00,000,000 | —- | M] () – C:\WINDOWS\hpqEmlSz.INI
[2010/01/08 09:17:37 | 00,000,178 | -HS- | M] () – C:\Documents and Settings\Dad\ntuser.ini
[2010/01/08 05:44:31 | 00,136,991 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2010/01/08 05:44:30 | 47,598,314 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/01/07 17:54:06 | 00,000,010 | —- | M] () – C:\WINDOWS\popcinfo.dat
[2010/01/07 12:59:01 | 00,030,036 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2010/01/07 12:59:01 | 00,030,036 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2010/01/07 12:59:01 | 00,029,760 | —- | M] () – C:\WINDOWS\System32\BMXCtrlState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2010/01/07 12:59:01 | 00,029,760 | —- | M] () – C:\WINDOWS\System32\BMXBkpCtrlState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2010/01/07 12:59:01 | 00,001,080 | —- | M] () – C:\WINDOWS\System32\settingsbkup.sfm
[2010/01/07 12:59:01 | 00,001,080 | —- | M] () – C:\WINDOWS\System32\settings.sfm
[2010/01/07 12:59:01 | 00,000,288 | —- | M] () – C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
[2010/01/07 12:59:01 | 00,000,288 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
[2010/01/07 01:59:49 | 00,000,768 | —- | M] () – C:\Documents and Settings\Dad\Desktop\MOVAVI VideoSuite 3.4.lnk
[2010/01/06 17:12:16 | 00,000,225 | —- | M] () – C:\Documents and Settings\Dad\Desktop\erie.craigslist.org-.url
[2010/01/06 03:45:09 | 00,069,176 | —- | M] () – C:\Documents and Settings\Dad\Desktop\Label.jpg
[2010/01/06 03:23:58 | 00,669,676 | —- | M] () – C:\Documents and Settings\Dad\Desktop\Mag Cover.jpg
[2010/01/04 22:32:42 | 00,000,276 | —- | M] () – C:\Documents and Settings\Dad\Desktop\Appearance - CamaroZ28.Com Message Board.url
[2010/01/03 22:59:48 | 00,000,141 | —- | M] () – C:\WINDOWS\wpd99.drv
[2010/01/03 22:23:43 | 00,000,474 | —- | M] () – C:\Documents and Settings\Dad\Desktop\Shared Documents.lnk
[2010/01/03 16:55:28 | 00,019,968 | —- | M] () – C:\Documents and Settings\Dad\My Documents\Pickeled Egg Recipe.doc
[2010/01/03 09:46:09 | 00,000,025 | —- | M] () – C:\WINDOWS\popcinfot.dat
[2010/01/02 13:12:47 | 00,000,728 | —- | M] () – C:\WINDOWS\win.ini
[2010/01/02 13:12:47 | 00,000,281 | RHS- | M] () – C:\boot.ini
[2010/01/02 13:12:47 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/01/02 11:56:30 | 00,001,577 | —- | M] () – C:\Documents and Settings\Dad\Desktop\DVD Flick.lnk
[2009/12/31 22:00:17 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/12/31 20:44:08 | 00,000,208 | —- | M] () – C:\Documents and Settings\Dad\Desktop\Two Wheel Texans - Bandit.url
[2009/12/31 20:33:32 | 00,000,158 | —- | M] () – C:\Documents and Settings\Dad\Desktop\GEZA Stretch Form-Fit Motorcycle Covers - Portable, TOWABLE, Daily Use.url
[2009/12/31 20:00:28 | 00,001,024 | —- | M] () – C:\Documents and Settings\Dad\.rnd
[2009/12/30 14:55:24 | 00,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/12/30 14:54:58 | 00,019,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/12/27 02:40:12 | 00,428,032 | —- | M] () – C:\Documents and Settings\Dad\My Documents\Blank Sudoko.doc
[2009/12/22 03:19:55 | 00,000,000 | —- | M] () – C:\WINDOWS\Irremote.ini
[2009/12/21 14:32:06 | 00,521,942 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/12/21 14:32:06 | 00,441,124 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/12/21 14:32:06 | 00,071,060 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/12/19 23:54:05 | 00,139,152 | —- | M] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009/12/19 23:53:57 | 00,111,928 | —- | M] () – C:\WINDOWS\System32\PnkBstrB.exe
[2009/12/19 02:07:58 | 00,000,770 | —- | M] () – C:\Documents and Settings\Dad\Desktop\Any Video Converter Professional.lnk
[2009/12/16 16:29:18 | 00,001,637 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Spyware Doctor.lnk
[2009/12/16 16:18:58 | 00,002,560 | —- | M] () – C:\WINDOWS\System32\drivers\mchInjDrv.sys
[2009/12/16 01:58:42 | 00,000,168 | —- | M] () – C:\Documents and Settings\Dad\Desktop\NetBenefits.url
[2009/12/15 11:24:48 | 00,293,376 | —- | M] () – C:\Documents and Settings\Dad\Desktop\gmer.exe
[2009/12/13 13:16:23 | 00,026,112 | —- | M] () – C:\Documents and Settings\All Users\Documents\Waffle Recipe.doc
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/01/08 17:10:36 | 00,293,376 | —- | C] () – C:\Documents and Settings\Dad\Desktop\gmer.exe
[2010/01/08 12:25:41 | 00,185,732 | —- | C] () – C:\Documents and Settings\All Users\Documents\Return to work.pdf
[2010/01/08 12:08:50 | 00,000,000 | —- | C] () – C:\WINDOWS\hpqEmlSz.INI
[2010/01/07 01:59:49 | 00,000,768 | —- | C] () – C:\Documents and Settings\Dad\Desktop\MOVAVI VideoSuite 3.4.lnk
[2010/01/06 03:36:17 | 00,069,176 | —- | C] () – C:\Documents and Settings\Dad\Desktop\Label.jpg
[2010/01/06 03:23:51 | 00,669,676 | —- | C] () – C:\Documents and Settings\Dad\Desktop\Mag Cover.jpg
[2010/01/04 22:18:44 | 00,003,258 | —- | C] () – C:\Documents and Settings\Dad\Desktop\CPU 100%, Running Slow.url
[2010/01/03 16:55:28 | 00,019,968 | —- | C] () – C:\Documents and Settings\Dad\My Documents\Pickeled Egg Recipe.doc
[2010/01/02 11:56:30 | 00,001,577 | —- | C] () – C:\Documents and Settings\Dad\Desktop\DVD Flick.lnk
[2009/12/31 20:33:32 | 00,000,158 | —- | C] () – C:\Documents and Settings\Dad\Desktop\GEZA Stretch Form-Fit Motorcycle Covers - Portable, TOWABLE, Daily Use.url
[2009/12/27 02:40:11 | 00,428,032 | —- | C] () – C:\Documents and Settings\Dad\My Documents\Blank Sudoko.doc
[2009/12/22 03:19:55 | 00,000,000 | —- | C] () – C:\WINDOWS\Irremote.ini
[2009/12/22 02:31:58 | 00,001,024 | —- | C] () – C:\Documents and Settings\Dad\.rnd
[2009/12/21 14:24:07 | 00,186,407 | —- | C] () – C:\WINDOWS\System32\nvapps.nvb
[2009/12/19 02:07:58 | 00,000,770 | —- | C] () – C:\Documents and Settings\Dad\Desktop\Any Video Converter Professional.lnk
[2009/12/17 00:12:02 | 00,000,276 | —- | C] () – C:\Documents and Settings\Dad\Desktop\Appearance - CamaroZ28.Com Message Board.url
[2009/12/16 16:29:56 | 00,767,952 | —- | C] () – C:\WINDOWS\BDTSupport.dll
[2009/12/16 16:29:56 | 00,000,883 | —- | C] () – C:\WINDOWS\RegSDImport.xml
[2009/12/16 16:29:56 | 00,000,880 | —- | C] () – C:\WINDOWS\RegISSImport.xml
[2009/12/16 16:29:56 | 00,000,131 | —- | C] () – C:\WINDOWS\IDB.zip
[2009/12/16 16:29:55 | 01,152,444 | —- | C] () – C:\WINDOWS\UDB.zip
[2009/12/16 16:29:45 | 00,007,387 | —- | C] () – C:\WINDOWS\System32\drivers\pctgntdi.cat
[2009/12/16 16:29:30 | 00,007,412 | —- | C] () – C:\WINDOWS\System32\drivers\PCTAppEvent.cat
[2009/12/16 16:29:18 | 00,001,637 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Spyware Doctor.lnk
[2009/12/16 16:29:13 | 00,007,383 | —- | C] () – C:\WINDOWS\System32\drivers\pctplsg.cat
[2009/12/16 16:18:58 | 00,002,560 | —- | C] () – C:\WINDOWS\System32\drivers\mchInjDrv.sys
[2009/12/13 13:16:23 | 00,026,112 | —- | C] () – C:\Documents and Settings\All Users\Documents\Waffle Recipe.doc
[2009/12/09 18:17:53 | 00,000,167 | —- | C] () – C:\WINDOWS\System32\AddPort.ini
[2009/12/09 18:15:56 | 00,000,686 | —- | C] () – C:\WINDOWS\hpntwksetup.ini
[2009/10/13 01:25:19 | 00,000,059 | —- | C] () – C:\WINDOWS\DCMVWR.INI
[2009/08/09 22:18:38 | 00,000,038 | —- | C] () – C:\Documents and Settings\Dad\Application Data\msnpromo.txt
[2009/04/18 21:36:31 | 00,000,140 | —- | C] () – C:\WINDOWS\RealFlight.INI
[2009/03/19 22:37:12 | 00,139,152 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009/03/11 18:21:44 | 00,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2009/02/17 19:34:38 | 01,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2009/02/13 12:09:48 | 00,000,067 | —- | C] () – C:\WINDOWS\Easy Video to iPod MP4 PSP 3GP Converter.INI
[2009/01/31 12:52:17 | 00,051,716 | —- | C] () – C:\WINDOWS\System32\pdf995mon.dll
[2009/01/31 12:52:17 | 00,000,141 | —- | C] () – C:\WINDOWS\wpd99.drv
[2009/01/03 08:26:28 | 00,000,120 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2009/01/02 01:43:07 | 00,190,976 | —- | C] () – C:\Documents and Settings\Dad\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/12/31 10:35:41 | 00,000,126 | —- | C] () – C:\Documents and Settings\Dad\Local Settings\Application Data\fusioncache.dat
[2008/12/27 00:14:03 | 00,077,824 | R— | C] () – C:\WINDOWS\System32\hpzids01.dll
[2008/12/27 00:10:24 | 00,001,127 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2008/12/26 22:20:30 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/12/20 18:01:13 | 00,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2008/12/20 18:00:54 | 00,066,807 | —- | C] () – C:\WINDOWS\System32\Aud2_Del.ini
[2008/12/20 18:00:54 | 00,000,030 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2008/12/20 18:00:45 | 00,005,515 | —- | C] () – C:\WINDOWS\System32\ENSDEF.INI
[2008/12/20 18:00:45 | 00,000,180 | —- | C] () – C:\WINDOWS\System32\KILL.INI
[2008/12/20 17:59:33 | 00,000,136 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2008/12/20 17:45:39 | 00,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
[2006/11/01 03:57:24 | 01,138,688 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2006/02/26 04:08:28 | 00,585,728 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2004/02/04 10:37:00 | 01,703,936 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2004/02/04 10:37:00 | 00,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2003/07/28 15:19:00 | 01,486,848 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2003/07/28 15:19:00 | 00,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2001/07/06 15:30:00 | 00,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini

========== LOP Check ==========

[2009/04/20 17:28:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Downloaded Installations
[2009/01/15 16:31:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HiddenSecretsNightmare
[2009/03/13 10:08:21 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Panasonic
[2009/02/02 00:39:50 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\pdf995
[2009/02/21 16:52:45 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayPond
[2009/05/23 22:01:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap Games
[2009/01/31 12:47:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TaxCut
[2010/01/08 18:39:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/06/11 11:29:45 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2009/12/16 14:45:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Dad\Application Data\Any Video Converter
[2010/01/06 12:28:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Dad\Application Data\Any Video Converter Professional
[2009/01/19 18:52:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Dad\Application Data\Big Fish Games
[2010/01/02 13:10:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Dad\Application Data\ImgBurn
[2009/03/28 11:51:08 | 00,000,000 | —D | M] – C:\Documents and Settings\Dad\Application Data\iWin
[2008/12/27 00:07:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Dad\Application Data\Leadertech
[2009/08/09 22:20:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Dad\Application Data\MSNInstaller
[2009/01/27 16:06:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Dad\Application Data\Opera
[2009/02/02 00:39:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Dad\Application Data\pdf995
[2009/04/02 22:23:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Dad\Application Data\Uniblue

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2008/04/13 13:36:38 | 00,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 13:36:38 | 00,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\dllcache\agp440.sys
[2008/04/13 13:36:38 | 00,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/04 01:07:41 | 00,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
[2004/08/04 01:07:41 | 00,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\AGP440.SYS

< MD5 for: ATAPI.SYS >
[2008/04/13 13:40:30 | 00,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 13:40:30 | 00,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\dllcache\atapi.sys
[2008/04/13 13:40:30 | 00,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/04 00:59:42 | 00,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 19:11:53 | 00,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 19:11:53 | 00,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/04 02:56:42 | 00,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2008/04/13 19:12:01 | 00,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 19:12:01 | 00,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2004/08/04 02:56:44 | 00,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/04 02:56:44 | 00,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 19:12:05 | 00,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 19:12:05 | 00,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll

< %systemroot%\*. /mp /s >

< >

< >

========== Alternate Data Streams ==========

@Alternate Data Stream - 183 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A3B8F70C
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
< End of report >
Budz,

I'm not familiar with the game Battlefield 1942 but it appears to keep trying to start and then hanging.

Your Java is out of date.

Java™ 6 can be updated from the Java Control Panel. Go Start > Control Panel(Classic View) > Java (looks like a coffee cup) > Update Tab > Update Now. An update should begin; follow the prompts.

Double click on OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Processes
explorer.exe

:OTL
SRV - (prfldsvc) – File not found
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O33 - MountPoints2\{7d025e8e-cef9-11dd-9bd9-0007e95117dd}\Shell\AutoRun\command - "" = F:\setupSNK.exe – File not found


:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
  • Reboot your computer
Please post the OTL log.



Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Here is the OTL file. I updated Java but I can't run the Kaspersky scan because it seems that Java is not working, it needs Java framework 1.5 or newer. All the setting were correct according to the Java site. It says it is current, I will try to get it working.
Battlefield 1942 is a first person shooter game from about 4-5 years ago. If there is a problem I could uninstall it. It's about 4G in size. – I got Java to run it was a firewall issue. I ran Kaspersky, it found no threats

OTL logfile created on: 1/9/2010 12:55:43 AM - Run 2
OTL by OldTimer - Version 3.1.21.2 Folder = C:\Documents and Settings\Dad\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 53.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): C:\pagefile.sys 1920 3840 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 63.74 Gb Free Space | 42.76% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Drive G: | 465.76 Gb Total Space | 370.22 Gb Free Space | 79.49% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: PAIN
Current User Name: Dad
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Dad\Desktop\OTLCA8WBSNI.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgam.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgfws8.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\WINDOWS\system32\PnkBstrA.exe ()
PRC - C:\Program Files\AVG\AVG8\Identity Protection\agent\Bin\AVGIDSUI.exe (AVG)
PRC - C:\Program Files\AVG\AVG8\Identity Protection\agent\Bin\AVGIDSWatcher.exe (AVG)
PRC - C:\Program Files\AVG\AVG8\Identity Protection\agent\Bin\AVGIDSAgent.exe (AVG)
PRC - C:\Program Files\AVG\AVG8\Identity Protection\agent\Bin\AVGIDSMonitor.exe (AVG)
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\WINDOWS\system32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\CTSVCCDA.EXE (Creative Technology Ltd)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Dad\Desktop\OTLCA8WBSNI.exe (OldTimer Tools)


========== Win32 Services (SafeList) ==========

SRV - (Browser Defender Update Service) – C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
SRV - (sdCoreService) – C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools)
SRV - (sdAuxService) – C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (avg8emc) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgfws8) – C:\Program Files\AVG\AVG8\avgfws8.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (PnkBstrA) – C:\WINDOWS\system32\PnkBstrA.exe ()
SRV - (AVGIDSWatcher) – C:\Program Files\AVG\AVG8\Identity Protection\agent\Bin\AVGIDSWatcher.exe (AVG)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG8\Identity Protection\agent\Bin\AVGIDSAgent.exe (AVG)
SRV - (Adobe LM Service) – C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe (Adobe Systems)
SRV - (NVSvc) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (prfldsvc) – G:\Dad\PrfldSvc.exe ()
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (NetSvc) – C:\Program Files\Intel\NCS\Sync\NetSvc.exe (Intel® Corporation)
SRV - (Creative Service for CDROM Access) – C:\WINDOWS\system32\CTSVCCDA.EXE (Creative Technology Ltd)


========== Driver Services (SafeList) ==========

DRV - (PCTCore) – C:\WINDOWS\system32\drivers\PCTCore.sys (PC Tools)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Lbd) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (Avgfwfd) – C:\WINDOWS\system32\drivers\avgfwdx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgfwdx) – C:\WINDOWS\system32\drivers\avgfwdx.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgRkx86) – C:\WINDOWS\System32\Drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSDriver) – C:\Program Files\AVG\AVG8\Identity Protection\agent\driver\platform_XP\AVGIDSDriver.sys (AVG Technologies )
DRV - (AVGIDSFilter) – C:\Program Files\AVG\AVG8\Identity Protection\agent\driver\platform_XP\AVGIDSFilter.sys (AVG Technologies )
DRV - (AVGIDSShim) – C:\Program Files\AVG\AVG8\Identity Protection\agent\driver\platform_XP\AVGIDSShim.sys (AVG Technologies )
DRV - (AVGIDSErHr) – C:\WINDOWS\System32\Drivers\AVGIDSErHr.sys (AVG Technologies )
DRV - (PxHelp20) – C:\WINDOWS\system32\DRIVERS\PxHelp20.sys (Sonic Solutions)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (Secdrv) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (UsbDiag) – C:\WINDOWS\system32\drivers\lgusbdiag.sys (LG Electronics Inc.)
DRV - (USBModem) – C:\WINDOWS\system32\drivers\lgusbmodem.sys (LG Electronics Inc.)
DRV - (usbbus) – C:\WINDOWS\system32\drivers\lgusbbus.sys (LG Electronics Inc.)
DRV - (Prvflder) – C:\WINDOWS\system32\drivers\prvflder.sys (Windows ® 2000 DDK provider)
DRV - (HPZius12) – C:\WINDOWS\system32\drivers\HPZius12.sys (HP)
DRV - (HPZipr12) – C:\WINDOWS\system32\drivers\HPZipr12.sys (HP)
DRV - (HPZid412) – C:\WINDOWS\system32\drivers\HPZid412.sys (HP)
DRV - (Ptilink) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (ctdvda2k) – C:\WINDOWS\system32\drivers\ctdvda2k.sys (Creative Technology Ltd)
DRV - (ctaud2k) Creative Audio Driver (WDM) – C:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (hap16v2k) – C:\WINDOWS\system32\drivers\hap16v2k.sys (Creative Technology Ltd)
DRV - (ha10kx2k) – C:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (PfModNT) – C:\WINDOWS\system32\drivers\pfmodnt.sys (Creative Technology Ltd.)
DRV - (E100B) Intel® – C:\WINDOWS\system32\drivers\e100b325.sys (Intel Corporation)
DRV - (emupia) – C:\WINDOWS\system32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) – C:\WINDOWS\system32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – C:\WINDOWS\system32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (OMCI) – C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS (Dell Computer Corporation)
DRV - (StillCam) – C:\WINDOWS\system32\drivers\serscan.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.071303000004
FF - prefs.js..extensions.enabledItems: {66E978CD-981F-47DF-AC42-E3CF417C1467}:0.4
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0

FF - HKLM\software\mozilla\Mozilla Firefox 3.0.16\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/12/28 04:08:06 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.16\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/12/18 01:14:08 | 00,000,000 | —D | M]

[2009/03/27 21:33:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Dad\Application Data\Mozilla\Extensions
[2010/01/07 12:55:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v7wp6yps.default\extensions
[2009/04/22 15:30:58 | 00,000,000 | —D | M] (New Tab Homepage) – C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v7wp6yps.default\extensions\{66E978CD-981F-47DF-AC42-E3CF417C1467}
[2009/03/27 22:07:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v7wp6yps.default\extensions\[removed]
[2010/01/09 00:53:31 | 00,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: (734 bytes) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll (BitComet)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [AsioReg] C:\WINDOWS\System32\CTASIO.DLL (Creative Technology Ltd)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [AVGIDS] C:\Program Files\AVG\AVG8\Identity Protection\agent\bin\AVGIDSUI.exe (AVG)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &D;&ownload; &with; BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: &D;&ownload; all video with BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: &D;&ownload; all with BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll (BitComet)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/12/20 17:12:44 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{7d025e8e-cef9-11dd-9bd9-0007e95117dd}\Shell\AutoRun\command - "" = F:\setupSNK.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/01/09 00:53:28 | 00,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/01/09 00:53:28 | 00,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/01/09 00:53:28 | 00,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/01/08 18:39:40 | 00,513,536 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Dad\Desktop\OTLCA8WBSNI.exe
[2010/01/08 12:04:03 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\My Documents\My Scans
[2010/01/04 18:18:35 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\My Documents\Computer Tools
[2010/01/02 13:10:33 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\Application Data\ImgBurn
[2010/01/02 11:58:31 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\My Documents\dvd
[2010/01/02 11:56:44 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\Application Data\DVD Flick
[2010/01/02 11:56:25 | 00,164,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\comct232.ocx
[2010/01/02 11:56:25 | 00,040,960 | —- | C] (vbAccelerator) – C:\WINDOWS\System32\ssubtmr6.dll
[2010/01/02 11:56:25 | 00,036,864 | —- | C] (Robdogg Inc.) – C:\WINDOWS\System32\trayicon_handler.ocx
[2010/01/02 11:56:25 | 00,028,672 | —- | C] (-) – C:\WINDOWS\System32\mousewheel.ocx
[2010/01/02 11:56:24 | 00,609,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\comctl32.ocx
[2010/01/02 11:56:24 | 00,212,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\richtx32.ocx
[2010/01/02 11:56:24 | 00,000,000 | —D | C] – C:\Program Files\DVD Flick
[2009/12/28 19:41:59 | 00,000,000 | —D | C] – C:\Movavi files
[2009/12/28 19:38:27 | 00,000,000 | —D | C] – C:\Program Files\MOVAVI
[2009/12/28 19:38:17 | 00,000,000 | —D | C] – C:\Program Files\MOVAVI VideoSuite 3.4
[2009/12/22 03:20:53 | 01,414,440 | —- | C] (Nero AG) – C:\WINDOWS\System32\ShellManager310E2D762.dll
[2009/12/22 02:34:08 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\Local Settings\Application Data\Ahead
[2009/12/22 02:27:57 | 02,388,176 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_30.dll
[2009/12/22 02:27:56 | 02,323,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_28.dll
[2009/12/21 14:31:13 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\Application Data\CyberLink
[2009/12/21 14:23:26 | 00,446,464 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\NVUNINST.EXE
[2009/12/21 14:19:14 | 00,000,000 | —D | C] – C:\Program Files\CyberLink
[2009/12/19 02:07:54 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\Application Data\Any Video Converter Professional
[2009/12/19 02:07:51 | 00,000,000 | —D | C] – C:\Program Files\Any Video Converter Professional
[2009/12/16 16:36:58 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\Local Settings\Application Data\Threat Expert
[2009/12/16 16:29:56 | 00,149,456 | —- | C] (PC Tools) – C:\WINDOWS\SGDetectionTool.dll
[2009/12/16 16:29:55 | 01,640,400 | —- | C] (Threat Expert Ltd.) – C:\WINDOWS\PCTBDCore.dll
[2009/12/16 16:29:55 | 00,165,840 | —- | C] (Threat Expert Ltd.) – C:\WINDOWS\PCTBDRes.dll
[2009/12/16 15:40:55 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\LG Dare Stuff
[2009/12/15 00:27:55 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\Application Data\AVS4YOU
[2009/12/15 00:27:51 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVS4YOU
[2009/12/15 00:25:48 | 00,024,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msxml3a.dll
[2009/12/15 00:25:48 | 00,000,000 | —D | C] – C:\Program Files\Common Files\AVSMedia
[2009/03/27 07:23:40 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Intuit
[2008/12/31 12:25:40 | 00,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2008/12/20 19:53:00 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2008/12/20 19:15:33 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2008/12/20 18:00:39 | 00,065,536 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll
[2008/12/20 17:12:30 | 00,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2005/05/11 23:36:48 | 00,012,288 | —- | C] (Hewlett-Packard Co.) – C:\WINDOWS\Fonts\RandFont.dll
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/01/09 00:54:07 | 00,003,390 | —- | M] () – C:\Documents and Settings\Dad\Desktop\CPU 100%, Running Slow.url
[2010/01/09 00:47:16 | 00,178,882 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/01/08 19:33:57 | 00,000,178 | -HS- | M] () – C:\Documents and Settings\Dad\ntuser.ini
[2010/01/08 19:23:53 | 00,000,225 | —- | M] () – C:\Documents and Settings\Dad\Desktop\erie.craigslist.org-.url
[2010/01/08 18:39:44 | 00,513,536 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Dad\Desktop\OTLCA8WBSNI.exe
[2010/01/08 17:44:00 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/01/08 17:43:55 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/01/08 17:43:52 | 00,000,000 | —- | M] () – C:\WINDOWS\MEMORY.DMP
[2010/01/08 14:29:58 | 00,190,976 | —- | M] () – C:\Documents and Settings\Dad\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/01/08 12:28:10 | 07,340,032 | —- | M] () – C:\Documents and Settings\Dad\ntuser.dat
[2010/01/08 12:25:41 | 00,185,732 | —- | M] () – C:\Documents and Settings\All Users\Documents\Return to work.pdf
[2010/01/08 12:08:50 | 00,000,000 | —- | M] () – C:\WINDOWS\hpqEmlSz.INI
[2010/01/08 05:44:31 | 00,136,991 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2010/01/08 05:44:30 | 47,598,314 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/01/07 17:54:06 | 00,000,010 | —- | M] () – C:\WINDOWS\popcinfo.dat
[2010/01/07 12:59:01 | 00,030,036 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2010/01/07 12:59:01 | 00,030,036 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2010/01/07 12:59:01 | 00,029,760 | —- | M] () – C:\WINDOWS\System32\BMXCtrlState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2010/01/07 12:59:01 | 00,029,760 | —- | M] () – C:\WINDOWS\System32\BMXBkpCtrlState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2010/01/07 12:59:01 | 00,001,080 | —- | M] () – C:\WINDOWS\System32\settingsbkup.sfm
[2010/01/07 12:59:01 | 00,001,080 | —- | M] () – C:\WINDOWS\System32\settings.sfm
[2010/01/07 12:59:01 | 00,000,288 | —- | M] () – C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
[2010/01/07 12:59:01 | 00,000,288 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
[2010/01/07 01:59:49 | 00,000,768 | —- | M] () – C:\Documents and Settings\Dad\Desktop\MOVAVI VideoSuite 3.4.lnk
[2010/01/06 03:45:09 | 00,069,176 | —- | M] () – C:\Documents and Settings\Dad\Desktop\Label.jpg
[2010/01/06 03:23:58 | 00,669,676 | —- | M] () – C:\Documents and Settings\Dad\Desktop\Mag Cover.jpg
[2010/01/04 22:32:42 | 00,000,276 | —- | M] () – C:\Documents and Settings\Dad\Desktop\Appearance - CamaroZ28.Com Message Board.url
[2010/01/03 22:59:48 | 00,000,141 | —- | M] () – C:\WINDOWS\wpd99.drv
[2010/01/03 22:23:43 | 00,000,474 | —- | M] () – C:\Documents and Settings\Dad\Desktop\Shared Documents.lnk
[2010/01/03 16:55:28 | 00,019,968 | —- | M] () – C:\Documents and Settings\Dad\My Documents\Pickeled Egg Recipe.doc
[2010/01/03 09:46:09 | 00,000,025 | —- | M] () – C:\WINDOWS\popcinfot.dat
[2010/01/02 13:12:47 | 00,000,728 | —- | M] () – C:\WINDOWS\win.ini
[2010/01/02 13:12:47 | 00,000,281 | RHS- | M] () – C:\boot.ini
[2010/01/02 13:12:47 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/01/02 11:56:30 | 00,001,577 | —- | M] () – C:\Documents and Settings\Dad\Desktop\DVD Flick.lnk
[2009/12/31 22:00:17 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/12/31 20:44:08 | 00,000,208 | —- | M] () – C:\Documents and Settings\Dad\Desktop\Two Wheel Texans - Bandit.url
[2009/12/31 20:00:28 | 00,001,024 | —- | M] () – C:\Documents and Settings\Dad\.rnd
[2009/12/30 14:55:24 | 00,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/12/30 14:54:58 | 00,019,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/12/27 02:40:12 | 00,428,032 | —- | M] () – C:\Documents and Settings\Dad\My Documents\Blank Sudoko.doc
[2009/12/22 03:19:55 | 00,000,000 | —- | M] () – C:\WINDOWS\Irremote.ini
[2009/12/21 14:32:06 | 00,521,942 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/12/21 14:32:06 | 00,441,124 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/12/21 14:32:06 | 00,071,060 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/12/19 23:54:05 | 00,139,152 | —- | M] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009/12/19 23:53:57 | 00,111,928 | —- | M] () – C:\WINDOWS\System32\PnkBstrB.exe
[2009/12/19 02:07:58 | 00,000,770 | —- | M] () – C:\Documents and Settings\Dad\Desktop\Any Video Converter Professional.lnk
[2009/12/16 16:29:18 | 00,001,637 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Spyware Doctor.lnk
[2009/12/16 16:18:58 | 00,002,560 | —- | M] () – C:\WINDOWS\System32\drivers\mchInjDrv.sys
[2009/12/16 01:58:42 | 00,000,168 | —- | M] () – C:\Documents and Settings\Dad\Desktop\NetBenefits.url
[2009/12/15 11:24:48 | 00,293,376 | —- | M] () – C:\Documents and Settings\Dad\Desktop\gmer.exe
[2009/12/13 13:16:23 | 00,026,112 | —- | M] () – C:\Documents and Settings\All Users\Documents\Waffle Recipe.doc
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/01/08 17:10:36 | 00,293,376 | —- | C] () – C:\Documents and Settings\Dad\Desktop\gmer.exe
[2010/01/08 12:25:41 | 00,185,732 | —- | C] () – C:\Documents and Settings\All Users\Documents\Return to work.pdf
[2010/01/08 12:08:50 | 00,000,000 | —- | C] () – C:\WINDOWS\hpqEmlSz.INI
[2010/01/07 01:59:49 | 00,000,768 | —- | C] () – C:\Documents and Settings\Dad\Desktop\MOVAVI VideoSuite 3.4.lnk
[2010/01/06 03:36:17 | 00,069,176 | —- | C] () – C:\Documents and Settings\Dad\Desktop\Label.jpg
[2010/01/06 03:23:51 | 00,669,676 | —- | C] () – C:\Documents and Settings\Dad\Desktop\Mag Cover.jpg
[2010/01/04 22:18:44 | 00,003,390 | —- | C] () – C:\Documents and Settings\Dad\Desktop\CPU 100%, Running Slow.url
[2010/01/03 16:55:28 | 00,019,968 | —- | C] () – C:\Documents and Settings\Dad\My Documents\Pickeled Egg Recipe.doc
[2010/01/02 11:56:30 | 00,001,577 | —- | C] () – C:\Documents and Settings\Dad\Desktop\DVD Flick.lnk
[2009/12/27 02:40:11 | 00,428,032 | —- | C] () – C:\Documents and Settings\Dad\My Documents\Blank Sudoko.doc
[2009/12/22 03:19:55 | 00,000,000 | —- | C] () – C:\WINDOWS\Irremote.ini
[2009/12/22 02:31:58 | 00,001,024 | —- | C] () – C:\Documents and Settings\Dad\.rnd
[2009/12/21 14:24:07 | 00,186,407 | —- | C] () – C:\WINDOWS\System32\nvapps.nvb
[2009/12/19 02:07:58 | 00,000,770 | —- | C] () – C:\Documents and Settings\Dad\Desktop\Any Video Converter Professional.lnk
[2009/12/17 00:12:02 | 00,000,276 | —- | C] () – C:\Documents and Settings\Dad\Desktop\Appearance - CamaroZ28.Com Message Board.url
[2009/12/16 16:29:56 | 00,767,952 | —- | C] () – C:\WINDOWS\BDTSupport.dll
[2009/12/16 16:29:56 | 00,000,883 | —- | C] () – C:\WINDOWS\RegSDImport.xml
[2009/12/16 16:29:56 | 00,000,880 | —- | C] () – C:\WINDOWS\RegISSImport.xml
[2009/12/16 16:29:56 | 00,000,131 | —- | C] () – C:\WINDOWS\IDB.zip
[2009/12/16 16:29:55 | 01,152,444 | —- | C] () – C:\WINDOWS\UDB.zip
[2009/12/16 16:29:45 | 00,007,387 | —- | C] () – C:\WINDOWS\System32\drivers\pctgntdi.cat
[2009/12/16 16:29:30 | 00,007,412 | —- | C] () – C:\WINDOWS\System32\drivers\PCTAppEvent.cat
[2009/12/16 16:29:18 | 00,001,637 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Spyware Doctor.lnk
[2009/12/16 16:29:13 | 00,007,383 | —- | C] () – C:\WINDOWS\System32\drivers\pctplsg.cat
[2009/12/16 16:18:58 | 00,002,560 | —- | C] () – C:\WINDOWS\System32\drivers\mchInjDrv.sys
[2009/12/13 13:16:23 | 00,026,112 | —- | C] () – C:\Documents and Settings\All Users\Documents\Waffle Recipe.doc
[2009/12/09 18:17:53 | 00,000,167 | —- | C] () – C:\WINDOWS\System32\AddPort.ini
[2009/12/09 18:15:56 | 00,000,686 | —- | C] () – C:\WINDOWS\hpntwksetup.ini
[2009/10/13 01:25:19 | 00,000,059 | —- | C] () – C:\WINDOWS\DCMVWR.INI
[2009/08/09 22:18:38 | 00,000,038 | —- | C] () – C:\Documents and Settings\Dad\Application Data\msnpromo.txt
[2009/04/18 21:36:31 | 00,000,140 | —- | C] () – C:\WINDOWS\RealFlight.INI
[2009/03/19 22:37:12 | 00,139,152 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009/03/11 18:21:44 | 00,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2009/02/17 19:34:38 | 01,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2009/02/13 12:09:48 | 00,000,067 | —- | C] () – C:\WINDOWS\Easy Video to iPod MP4 PSP 3GP Converter.INI
[2009/01/31 12:52:17 | 00,051,716 | —- | C] () – C:\WINDOWS\System32\pdf995mon.dll
[2009/01/31 12:52:17 | 00,000,141 | —- | C] () – C:\WINDOWS\wpd99.drv
[2009/01/03 08:26:28 | 00,000,120 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2009/01/02 01:43:07 | 00,190,976 | —- | C] () – C:\Documents and Settings\Dad\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/12/31 10:35:41 | 00,000,126 | —- | C] () – C:\Documents and Settings\Dad\Local Settings\Application Data\fusioncache.dat
[2008/12/27 00:14:03 | 00,077,824 | R— | C] () – C:\WINDOWS\System32\hpzids01.dll
[2008/12/27 00:10:24 | 00,001,127 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2008/12/26 22:20:30 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/12/20 18:01:13 | 00,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2008/12/20 18:00:54 | 00,066,807 | —- | C] () – C:\WINDOWS\System32\Aud2_Del.ini
[2008/12/20 18:00:54 | 00,000,030 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2008/12/20 18:00:45 | 00,005,515 | —- | C] () – C:\WINDOWS\System32\ENSDEF.INI
[2008/12/20 18:00:45 | 00,000,180 | —- | C] () – C:\WINDOWS\System32\KILL.INI
[2008/12/20 17:59:33 | 00,000,136 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2008/12/20 17:45:39 | 00,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
[2006/11/01 03:57:24 | 01,138,688 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2006/02/26 04:08:28 | 00,585,728 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2004/02/04 10:37:00 | 01,703,936 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2004/02/04 10:37:00 | 00,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2003/07/28 15:19:00 | 01,486,848 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2003/07/28 15:19:00 | 00,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2001/07/06 15:30:00 | 00,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini

========== Custom Scans ==========


< :Processes >

< explorer.exe >

< >

< :OTL >

< SRV - (prfldsvc) – File not found >

< O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) >
Invalid Switch: gp.cab (Reg Error: Key error.)

< O33 - MountPoints2\{7d025e8e-cef9-11dd-9bd9-0007e95117dd}\Shell\AutoRun\command - "" = F:\setupSNK.exe – File not found >

< >

< >

< :Commands >

< [purity] >

< [emptytemp] >

< [start explorer] >

< [Reboot] >

========== Alternate Data Streams ==========

@Alternate Data Stream - 183 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A3B8F70C
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8

< End of report >
Budz,

Please try the previous instructions for OTL again, but this time… click on the Run Fix button.

Try this technique to update Java.

Your Java is out of date and you have other old versions still on your computer, those old versions are now a security vulnerability:

Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer - Version 6 update 17

Then give Kaspersky a try again.
Sorry I didn't pay attention to the RunFix on OTL, here is the file. I downloaded an updated Java, and Kaspersky ran with no threats found. All processes killed ========== PROCESSES ========== No active process named explorer.exe was found! ========== OTL ========== Service prfldsvc stopped successfully! Service prfldsvc deleted successfully! File File not found not found. Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7} C:\WINDOWS\Downloaded Program Files\gp.inf not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7d025e8e-cef9-11dd-9bd9-0007e95117dd}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7d025e8e-cef9-11dd-9bd9-0007e95117dd}\ not found. File F:\setupSNK.exe not found. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: All Users User: Buddy ->Temp folder emptied: 7592039 bytes ->Temporary Internet Files folder emptied: 138447 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 105062311 bytes User: Dad ->Temp folder emptied: 116485709 bytes ->Temporary Internet Files folder emptied: 7218678 bytes ->Java cache emptied: 13819766 bytes ->FireFox cache emptied: 49549195 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33893 bytes User: log User: Mom ->Temp folder emptied: 824 bytes ->Temporary Internet Files folder emptied: 9323171 bytes ->Java cache emptied: 7595555 bytes ->FireFox cache emptied: 105660424 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 1145933 bytes %systemroot%\System32 .tmp files removed: 2832913 bytes Windows Temp folder emptied: 2031231 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 498792 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 57251 bytes RecycleBin emptied: 3787599266 bytes Total Files Cleaned = 4,021.00 mb OTL by OldTimer - Version 3.1.21.2 log created on 01092010_203937 Files\Folders moved on Reboot… Registry entries deleted on Reboot…
I updated my Malwarebytes program, ran it and found 2 infections. Attached are the results. My computer seems to run a bit better, but the malware program used between 80%-100% CPU with just that running. Malwarebytes' Anti-Malware 1.44 Database version: 3538 Windows 5.1.2600 Service Pack 3 Internet Explorer 7.0.5730.13 1/10/2010 10:31:25 PM mbam-log-2010-01-10 (22-31-25).txt Scan type: Full Scan (C:\|) Objects scanned: 213659 Time elapsed: 53 minute(s), 19 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\System Volume Information\_restore{B155A9EC-F7E0-46B6-A716-59B666E69A31}\RP533\A0068399.DLL (Adware.FunWeb) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{B155A9EC-F7E0-46B6-A716-59B666E69A31}\RP553\A0069854.exe (Adware.MyWebSearch) -> Quarantined and deleted successfully.
Budz,

The things MBAM found were not currently running on your system. They were buried in a restore point.

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and the click UPLOAD.
Tomk here are the 2 reports. DDS (Ver_09-12-01.01) - NTFSx86 Run by [removed] at 2:35:30.46 on Mon 01/11/2010 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_17 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1279.689 [GMT -5:00] AV: AVG Internet Security 3-pack *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} AV: Lavasoft Ad-Watch Live! Anti-Virus *On-access scanning disabled* (Updated) {A1C4F2E0-7FDE-4917-AFAE-013EFC3EDE33} FW: AVG Firewall *disabled* {8decf618-9569-4340-b34a-d78d28969b66} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\PROGRA~1\AVG\AVG8\avgfws8.exe C:\Program Files\AVG\AVG8\Identity Protection\agent\Bin\AVGIDSWatcher.exe C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe C:\WINDOWS\System32\CTsvcCDA.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\nvsvc32.exe C:\PROGRA~1\AVG\AVG8\avgam.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\WINDOWS\system32\HPZipm12.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\System32\svchost.exe -k imgsvc C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\Program Files\AVG\AVG8\avgcsrvx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\wscntfy.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\Program Files\AVG\AVG8\Identity Protection\agent\bin\AVGIDSUI.exe C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\taskmgr.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Documents and Settings\Dad\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: PC Tools Browser Guard BHO: {2a0f3d1b-0909-4ff4-b272-609cce6054e7} - c:\program files\spyware doctor\bdt\PCTBrowserDefender.dll BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll BHO: BitComet Helper: {39f7e362-828a-4b5a-bcaf-5b79bfdfea60} - c:\program files\bitcomet\tools\BitCometBHO_1.2.8.7.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.0988.2\msneshellx.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.0988.2\msneshellx.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll TB: PC Tools Browser Guard: {472734ea-242a-422b-adf8-83d1e48cc825} - c:\program files\spyware doctor\bdt\PCTBrowserDefender.dll EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [AsioReg] REGSVR32.EXE /S CTASIO.DLL mRun: [UpdReg] c:\windows\UpdReg.EXE mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [AVGIDS] "c:\program files\avg\avg8\identity protection\agent\bin\AVGIDSUI.exe" mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent IE: &D&ownload &with BitComet - c:\program files\bitcomet\BitComet.exe/AddLink.htm IE: &D&ownload all video with BitComet - c:\program files\bitcomet\BitComet.exe/AddVideo.htm IE: &D&ownload all with BitComet - c:\program files\bitcomet\BitComet.exe/AddAllLink.htm IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000 IE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://c:\program files\bitcomet\tools\BitCometBHO_1.2.8.7.dll/206 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Notify: avgrsstarter - avgrsstx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\dad\applic~1\mozilla\firefox\profiles\v7wp6yps.default\ FF - prefs.js: browser.startup.homepage - www.google.com FF - component: c:\program files\real\realplayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll FF - plugin: c:\documents and settings\dad\application data\mozilla\firefox\profiles\v7wp6yps.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npmnqmp071303000004.dll FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} ============= SERVICES / DRIVERS =============== R0 AVGIDSErHr;AVGIDSErHr;c:\windows\system32\drivers\AVGIDSErHr.sys [2009-2-26 25608] R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2008-12-20 12552] R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-6-11 64160] R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-9-23 207792] R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-12-20 335240] R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-12-20 27784] R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-12-20 108552] R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-4-23 908056] R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-1-8 297752] R2 avgfws8;AVG8 Firewall;c:\progra~1\avg\avg8\avgfws8.exe [2009-4-23 1370488] R2 AVGIDSWatcher;AVGIDSWatcher;c:\program files\avg\avg8\identity protection\agent\bin\AVGIDSWatcher.exe [2009-2-26 563720] R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\spyware doctor\bdt\BDTUpdateService.exe [2009-12-16 112592] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-1-18 1005904] R2 Prvflder;Prvflder;c:\windows\system32\drivers\prvflder.sys [2006-4-21 70912] R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [2008-12-20 29208] R3 AVGIDSDriver;AVGIDSDriver;c:\program files\avg\avg8\identity protection\agent\driver\platform_xp\AVGIDSDriver.sys [2009-2-26 121352] R3 AVGIDSFilter;AVGIDSFilter;c:\program files\avg\avg8\identity protection\agent\driver\platform_xp\AVGIDSFilter.sys [2009-2-26 30216] R3 AVGIDSShim;AVGIDSShim;c:\program files\avg\avg8\identity protection\agent\driver\platform_xp\AVGIDSShim.sys [2009-2-26 27232] S2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg8\identity protection\agent\bin\AVGIDSAgent.exe [2009-2-26 5576712] S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [2008-12-20 29208] S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2009-9-23 359624] S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2009-9-23 1141712] =============== Created Last 30 ================ 2010-01-11 03:31:51 54016 —-a-w- c:\windows\system32\drivers\igxkfy.sys 2010-01-10 01:35:01 0 d—–w- C:\_OTL 2010-01-09 18:55:32 73728 —-a-w- c:\windows\system32\javacpl.cpl 2010-01-08 17:08:50 0 —-a-w- c:\windows\hpqEmlSz.INI 2010-01-02 16:56:44 0 d—–w- c:\docume~1\dad\applic~1\DVD Flick 2010-01-02 16:56:25 40960 —-a-w- c:\windows\system32\ssubtmr6.dll 2010-01-02 16:56:25 36864 —-a-w- c:\windows\system32\trayicon_handler.ocx 2010-01-02 16:56:25 28672 —-a-w- c:\windows\system32\mousewheel.ocx 2010-01-02 16:56:25 164144 —-a-w- c:\windows\system32\comct232.ocx 2010-01-02 16:56:24 609824 —-a-w- c:\windows\system32\comctl32.ocx 2010-01-02 16:56:24 212240 —-a-w- c:\windows\system32\richtx32.ocx 2010-01-02 16:56:24 0 d—–w- c:\program files\DVD Flick 2009-12-29 00:41:59 0 d—–w- C:\Movavi files 2009-12-29 00:38:27 0 d—–w- c:\program files\MOVAVI 2009-12-29 00:38:17 0 d—–w- c:\program files\MOVAVI VideoSuite 3.4 2009-12-22 08:20:53 1414440 —-a-w- c:\windows\system32\ShellManager310E2D762.dll 2009-12-22 08:19:55 0 —-a-w- c:\windows\Irremote.ini 2009-12-22 07:31:58 1024 —-a-w- c:\documents and settings\dad\.rnd 2009-12-21 19:24:07 186407 —-a-w- c:\windows\system32\nvapps.nvb 2009-12-21 19:23:26 446464 —-a-w- c:\windows\system32\NVUNINST.EXE 2009-12-19 07:07:54 0 d—–w- c:\docume~1\dad\applic~1\Any Video Converter Professional 2009-12-19 07:07:51 0 d—–w- c:\program files\Any Video Converter Professional 2009-12-16 21:29:56 883 —-a-w- c:\windows\RegSDImport.xml 2009-12-16 21:29:56 880 —-a-w- c:\windows\RegISSImport.xml 2009-12-16 21:29:56 767952 —-a-w- c:\windows\BDTSupport.dll 2009-12-16 21:29:56 149456 —-a-w- c:\windows\SGDetectionTool.dll 2009-12-16 21:29:56 131 —-a-w- c:\windows\IDB.zip 2009-12-16 21:29:55 165840 —-a-w- c:\windows\PCTBDRes.dll 2009-12-16 21:29:55 1640400 —-a-w- c:\windows\PCTBDCore.dll 2009-12-16 21:29:55 1152444 —-a-w- c:\windows\UDB.zip 2009-12-16 21:29:45 7387 —-a-w- c:\windows\system32\drivers\pctgntdi.cat 2009-12-16 21:29:30 7412 —-a-w- c:\windows\system32\drivers\PCTAppEvent.cat 2009-12-16 21:29:13 7383 —-a-w- c:\windows\system32\drivers\pctplsg.cat 2009-12-16 21:18:58 2560 —-a-w- c:\windows\system32\drivers\mchInjDrv.sys 2009-12-15 05:27:55 0 d—–w- c:\docume~1\dad\applic~1\AVS4YOU 2009-12-15 05:27:51 0 d—–w- c:\docume~1\alluse~1\applic~1\AVS4YOU 2009-12-15 05:25:48 24576 —-a-w- c:\windows\system32\msxml3a.dll 2009-12-15 05:25:48 0 d—–w- c:\program files\common files\AVSMedia ==================== Find3M ==================== 2010-01-09 18:55:20 411368 —-a-w- c:\windows\system32\deploytk.dll 2010-01-07 21:07:14 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-01-07 21:07:04 19160 -c–a-w- c:\windows\system32\drivers\mbam.sys 2009-12-20 04:54:05 139152 -c–a-w- c:\windows\system32\drivers\PnkBstrK.sys 2009-12-20 04:53:57 111928 -c–a-w- c:\windows\system32\PnkBstrB.exe 2009-12-09 23:15:12 87959 -c–a-w- c:\windows\hpoins06.dat 2009-12-01 14:59:06 22560 -c–a-w- c:\docume~1\dad\applic~1\GDIPFONTCACHEV1.DAT 2009-11-14 00:47:32 90112 —-a-w- c:\windows\system32\dpl100.dll 2009-11-14 00:47:28 856064 —-a-w- c:\windows\system32\divx_xx0c.dll 2009-11-14 00:47:28 856064 —-a-w- c:\windows\system32\divx_xx07.dll 2009-11-14 00:47:28 847872 —-a-w- c:\windows\system32\divx_xx0a.dll 2009-11-14 00:47:28 843776 —-a-w- c:\windows\system32\divx_xx16.dll 2009-11-14 00:47:28 839680 —-a-w- c:\windows\system32\divx_xx11.dll 2009-11-14 00:47:28 696320 —-a-w- c:\windows\system32\DivX.dll 2009-10-29 07:46:59 832512 —-a-w- c:\windows\system32\wininet.dll 2009-10-29 07:46:52 78336 -c—-w- c:\windows\system32\ieencode.dll 2009-10-29 07:46:50 17408 -c–a-w- c:\windows\system32\corpol.dll 2009-10-21 05:38:36 75776 -c–a-w- c:\windows\system32\strmfilt.dll 2009-10-21 05:38:36 25088 -c–a-w- c:\windows\system32\httpapi.dll 2009-10-13 10:30:16 270336 -c–a-w- c:\windows\system32\oakley.dll ============= FINISH: 2:35:53.04 ===============

Attachments:

Budz,

Log looks good :D


You need to create a new Clean restore point:

Click Start Menu > Run > copy and paste

%SystemRoot%\System32\restore\rstrui.exe

Press OK. Choose Create a Restore Point then click Next. Name it (something you'll remember) and click Create, when the confirmation screen shows the restore point has been created click Close.

Remove all previous Restore Points
Click Start Menu > Run > copy and paste

cleanmgr

You may be asked to choose drive. Choose C: At top, click on More Options tab. Click Clean up… button in the System Restore box. Click on Yes button. When finished, click on Cancel button to exit.

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Check "Hide file extensions for known file types."
Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
Check "Hide protected operating system files."
Click Apply, and then click OK.

  • Double click on OTL to run it.
  • Click on CleanUp!
  • When done, you will be prompted to restart your computer. Please restart your computer.


The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
Tomk thanks for your time and help. :) Things look a lot better now, a good as I can expect from a 6 yr old computer. I knew I could count on you guys

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI