Here's the 2 files:
OTL Extras logfile created on: 1/8/2010 6:42:45 PM - Run 1
OTL by OldTimer - Version 3.1.21.2 Folder = C:\Documents and Settings\Dad\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 61.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 1920 3840 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 63.88 Gb Free Space | 42.86% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: PAIN
Current User Name: Dad
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = htmlfile] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office10\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "%programfiles%\internet explorer\iexplore.exe" (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"25422:TCP" = 25422:TCP:*:Enabled:BitComet 25422 TCP
"25422:UDP" = 25422:UDP:*:Enabled:BitComet 25422 UDP
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\AVG\AVG8\avgemc.exe" = C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG8\avgupd.exe" = C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG8\avgnsx.exe" = C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe – ()
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe – ()
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe – ( )
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\RealFlightG3\RealFlight.exe" = C:\Program Files\RealFlightG3\RealFlight.exe:*:Enabled:Radio Control Simulator – (Knife Edge Software)
"G:\Program Files\THQ\Dawn of War - Dark Crusade\DarkCrusade.exe" = G:\Program Files\THQ\Dawn of War - Dark Crusade\DarkCrusade.exe:*:Enabled:DarkCrusade – File not found
"D:\setup\HPZnet01.exe" = D:\setup\HPZnet01.exe:*:Enabled:hpznet01.exe – File not found
"D:\setup\HPONICIFS01.EXE" = D:\setup\HPONICIFS01.EXE:*:Enabled:hponicifs01.exe – File not found
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{03B1B42B-F6DE-41d9-8CFF-DC44E895C7A7}" = PhotoGallery
"{0611BD4E-4FE4-4a62-B0C0-18A4CC463428}" = CP_Package_Variety1
"{09984AEC-6B9F-4ca7-B78D-CB44D4771DA3}" = Destinations
"{10C69612-017B-45F5-B986-7D113D5A2EA3}" = MSN Toolbar
"{1330F885-F8E4-4c36-9B88-E19F82042C06}" = 3100_3200_3300trb
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{15EE79F4-4ED1-4267-9B0F-351009325D7D}" = HP Software Update
"{172975EB-9465-4861-95B5-C7BB6D3DE62A}" = DocumentViewer
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1C139D7D-9FEA-468d-A9C8-2A6E3BDE564A}" = CP_Package_Variety3
"{21DB3D90-D816-4092-A260-CA3F6B55A6DD}" = Sonic_PrimoSDK
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{23A7B376-BBEC-4e76-BBD7-0F155E70D74B}" = CP_Panorama1Config
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 13
"{2B65C841-EC48-4087-8021-6DBB9C1DE5E6}" = 3200
"{2CADCEAB-D5DA-44D6-B5FC-7DEE87AB3C0C}" = Unload
"{30C19FF2-7FBA-4d09-B9DE-1659977F64F6}" = TrayApp
"{32BDCCB8-9DC8-496d-9DB1-F77510775BDB}" = InstantShareDevices
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36E47DA1-10E1-45d9-8B19-14D19607CDCF}" = CP_CalendarTemplates1
"{3B0F52AC-EF5C-4831-B221-06C782E41280}" = Quicken 2008
"{3E386744-10FA-44b2-98C9-DF7A270DECB3}" = HP PSC & OfficeJet 5.3.A
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{50E7BB78-02B4-469a-9D8B-B2F42835F90E}" = ProductContextNPI
"{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder
"{567C23E1-7580-4185-B8C2-30805677297C}" = NewCopy_CDA
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{56EE8B17-8274-418d-89AC-C057C5DB251E}" = RandMap
"{56F6A91D-46D4-4919-ABE6-55BD17DEB039}" = Quick Movie Magic 1.0E
"{56F8AFC3-FA98-4ff1-9673-8A026CBF85BE}" = WebReg
"{5A01C58E-B0EC-49b9-AD71-7C0468688087}" = CP_Package_Basic1
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{5F26311C-B135-4F7F-B11E-8E650F83651E}" = DeviceFunctionQFolder
"{644EA08F-87D2-48C0-AE94-B327D1C85A97}" = Microsoft Private Folder 1.0
"{66BA8C26-AFE4-4408-807B-43E76B57EF53}" = SkinsHP1
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{698D7E61-E4BF-4CA6-8A09-CF6BDBFDEF65}" = Battlefield 1942
"{6BB6627C-694F-4FDC-A3E5-C7F4BED4C724}" = DocProc
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7583D2F8-8E7D-40C5-9862-4D218006FB84}" = AVG Identity Protection
"{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7C03270C-4FAB-4F5C-B10D-52FEDA190790}" = DocumentViewerQFolder
"{7E27304E-BAA2-4d90-A34E-76641FAFABB4}" = CP_AtenaShokunin1Config
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{923A7F5A-1E8C-4FBE-8DF6-85940A60A79F}" = Readme
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A195B13E-A5E3-4BAF-A995-7F70F445CD06}" = ScannerCopy
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A5BB5365-EFB4-44c3-A7E2-EB59B7EFD23D}" = CueTour
"{A790BEB1-BCCF-4EC6-807B-5708B36E8A79}" = Intel® PROSet
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-1033-0000-7760-000000000002}" = Adobe Acrobat 7.0 Professional
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B276997E-4367-4b1b-A39C-4CAE7464337A}" = AiO_Scan_CDA
"{B4D279F1-4309-49cc-A4B5-3A0D2E59C7B5}" = PanoStandAlone
"{B60E7826-F117-4d26-8165-D2DC5A494AB0}" = Fax_CDA
"{B64E3AFC-59EF-4f18-BF11-E751462450D3}" = AiOSoftwareNPI
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Plus Web Player
"{B74D4E10-6884-0000-0000-000000000103}" = Adobe Bridge 1.0
"{B824B5C9-849F-4b9e-9EA7-6FD8CD8116DA}" = CP_Package_Variety2
"{B996AE66-10DB-4ac5-B151-E8B4BFBC42FC}" = BufferChm
"{BE6890C7-31EF-478C-812E-1E2899ABFCA9}" = B57Inst
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C3ABE126-2BB2-4246-BFE1-6797679B3579}" = LG USB Modem driver
"{C506A18C-1469-4678-B094-F4EC9DAE6DB7}" = Scan
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D057AA08-8CBF-42E3-9EAB-23B8FED1C279}" = Battlefield 1942: The Road To Rome
"{D07643A3-CE41-4286-8C78-EB9C83E76DDB}" = PunkBuster for Battlefield Vietnam
"{D3EE034D-5B92-4A55-AA02-2E6D0A6A96EE}" = Windows Resource Kit Tools - SubInAcl.exe
"{D78653C3-A8FF-415F-92E6-D774E634FF2D}" = Dell ResourceCD
"{DBCC73BA-C69A-4BF5-B4BF-F07501EE7039}" = AnswerWorks 5.0 English Runtime
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E3F90083-80D4-4b5a-87C7-E97E12F5516D}" = HPProductAssistant
"{E82BF103-904F-49C0-B77F-6EC110B71E87}" = Sound Blaster Audigy 2
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"{EA103B64-C0E4-4C0E-A506-751590E1653D}" = SolutionCenter
"{F1931CAB-C7DD-4825-8A58-BC5278805200}" = 3100_3200_3300_Help
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F4C2E5F5-2970-45f4-ABD3-C180C4D961C4}" = Status
"{FA61D601-A0FC-48BD-AE7A-54946BCD7FB6}_is1" = BitPim 1.0.7.20090805
"Ad-Aware" = Ad-Aware
"Adobe Acrobat 7.0 Professional" = Adobe Acrobat 7.1.0 Professional
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"Any Video Converter Professional_is1" = Any Video Converter Professional 2.7.3
"Any Video Converter_is1" = Any Video Converter 2.7.1
"AVG8Uninstall" = AVG 8.5
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.3
"AVS4YOU Video Converter 6_is1" = AVS Video Converter 6
"BFG-Azada - Ancient Magic" = Azada ™: Ancient Magic
"BFGC" = Big Fish Games Client
"BitComet" = BitComet 1.07
"Boggle_is1" = Boggle
"Browser Defender_is1" = Browser Defender [removed]
"dBpoweramp DSP Effects" = dBpoweramp DSP Effects
"dBpoweramp FLAC Codec" = dBpoweramp FLAC Codec
"dBpoweramp Music Converter" = dBpoweramp Music Converter
"DesertCombat" = DesertCombat 0.7
"DesertCombat_Public_Alpha__0.2" = DesertCombat Public Alpha 0.4J
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DVD Flick_is1" = DVD Flick 1.3.0.7
"DVD-CLONER VII_is1" = DVD-CLONER V7.00 Build 990
"GameSpy Arcade" = GameSpy Arcade
"GOM Player" = GOM Player
"HijackThis" = HijackThis 2.0.2
"HP Document Viewer" = HP Document Viewer 5.3
"HP Imaging Device Functions" = HP Imaging Device Functions 5.3
"HP Photo & Imaging" = HP Image Zone 5.3
"HP Solution Center & Imaging Support Tools" = HP Solution Center & Imaging Support Tools 5.3
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{BE6890C7-31EF-478C-812E-1E2899ABFCA9}" = Broadcom Driver Installer
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MOVAVI VideoSuite 3.4" = MOVAVI VideoSuite 3.4
"Mozilla Firefox (3.0.16)" = Mozilla Firefox (3.0.16)
"MPEG2 Codec(libmpeg2/mad)" = MPEG2 Codec(libmpeg2/mad)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"Ogg Codecs" = Ogg Codecs 0.81.15562
"Pdf995" = Pdf995 (installed by TaxCut)
"PdfEdit995" = PdfEdit995 (installed by TaxCut)
"PROSet" = Intel® PRO Network Adapters and Drivers
"RealAlt_is1" = Real Alternative 1.9.0
"RealFlightG3Pro" = RealFlight G3 R/C Simulator
"RealPlayer 12.0" = RealPlayer
"Spyware Doctor" = Spyware Doctor 7.0
"Tweak UI 2.10" = Tweak UI
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Move Networks Player - IE" = Move Networks Media Player for Internet Explorer
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 8/23/2009 1:12:45 AM | Computer Name = PAIN | Source = Application Error | ID = 1000
Description = Faulting application bf1942.exe, version 0.0.0.0, faulting module
bf1942.exe, version 0.0.0.0, fault address 0x000931cc.
Error - 8/23/2009 1:15:08 AM | Computer Name = PAIN | Source = Application Error | ID = 1000
Description = Faulting application bf1942.exe, version 0.0.0.0, faulting module
bf1942.exe, version 0.0.0.0, fault address 0x000931cc.
Error - 8/23/2009 1:16:28 AM | Computer Name = PAIN | Source = Application Error | ID = 1000
Description = Faulting application bf1942.exe, version 0.0.0.0, faulting module
bf1942.exe, version 0.0.0.0, fault address 0x000931cc.
Error - 8/23/2009 1:32:55 AM | Computer Name = PAIN | Source = Application Error | ID = 1000
Description = Faulting application bf1942.exe, version 0.0.0.0, faulting module
bf1942.exe, version 0.0.0.0, fault address 0x000931cc.
Error - 8/28/2009 11:08:05 PM | Computer Name = PAIN | Source = Application Error | ID = 1000
Description = Faulting application bf1942.exe, version 0.0.0.0, faulting module
bf1942.exe, version 0.0.0.0, fault address 0x000931cc.
Error - 8/29/2009 1:18:22 AM | Computer Name = PAIN | Source = Application Error | ID = 1000
Description = Faulting application bf1942.exe, version 0.0.0.0, faulting module
bf1942.exe, version 0.0.0.0, fault address 0x000931cc.
Error - 9/4/2009 10:23:14 PM | Computer Name = PAIN | Source = Application Error | ID = 1000
Description = Faulting application bf1942.exe, version 0.0.0.0, faulting module
bf1942.exe, version 0.0.0.0, fault address 0x000931cc.
Error - 9/4/2009 10:43:26 PM | Computer Name = PAIN | Source = Application Error | ID = 1000
Description = Faulting application bf1942.exe, version 0.0.0.0, faulting module
bf1942.exe, version 0.0.0.0, fault address 0x000910e6.
Error - 9/4/2009 11:33:30 PM | Computer Name = PAIN | Source = Application Error | ID = 1000
Description = Faulting application bf1942.exe, version 0.0.0.0, faulting module
bf1942.exe, version 0.0.0.0, fault address 0x000931cc.
Error - 9/5/2009 12:22:34 AM | Computer Name = PAIN | Source = Application Error | ID = 1000
Description = Faulting application bf1942.exe, version 0.0.0.0, faulting module
bf1942.exe, version 0.0.0.0, fault address 0x000931cc.
[ System Events ]
Error - 1/8/2010 3:30:31 PM | Computer Name = PAIN | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service upnphost with
arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56}
Error - 1/8/2010 3:35:13 PM | Computer Name = PAIN | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service upnphost with
arguments "" in order to run the server: {204810B9-73B2-11D4-BF42-00B0D0118B56}
Error - 1/8/2010 6:23:36 PM | Computer Name = PAIN | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort1, did not respond within the timeout
period.
Error - 1/8/2010 6:24:49 PM | Computer Name = PAIN | Source = Service Control Manager | ID = 7000
Description = The Private Folder Service service failed to start due to the following
error: %%3
Error - 1/8/2010 6:30:29 PM | Computer Name = PAIN | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort1, did not respond within the timeout
period.
Error - 1/8/2010 6:31:50 PM | Computer Name = PAIN | Source = Service Control Manager | ID = 7000
Description = The Private Folder Service service failed to start due to the following
error: %%3
Error - 1/8/2010 6:37:21 PM | Computer Name = PAIN | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort1, did not respond within the timeout
period.
Error - 1/8/2010 6:38:42 PM | Computer Name = PAIN | Source = Service Control Manager | ID = 7000
Description = The Private Folder Service service failed to start due to the following
error: %%3
Error - 1/8/2010 6:44:12 PM | Computer Name = PAIN | Source = atapi | ID = 262153
Description = The device, \Device\Ide\IdePort1, did not respond within the timeout
period.
Error - 1/8/2010 6:45:38 PM | Computer Name = PAIN | Source = Service Control Manager | ID = 7000
Description = The Private Folder Service service failed to start due to the following
error: %%3
< End of report >
OTL logfile created on: 1/8/2010 6:42:45 PM - Run 1
OTL by OldTimer - Version 3.1.21.2 Folder = C:\Documents and Settings\Dad\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 61.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 1920 3840 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.04 Gb Total Space | 63.88 Gb Free Space | 42.86% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: PAIN
Current User Name: Dad
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Dad\Desktop\OTLCA8WBSNI.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgam.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgfws8.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\WINDOWS\system32\PnkBstrA.exe ()
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\AVG\AVG8\Identity Protection\agent\Bin\AVGIDSUI.exe (AVG)
PRC - C:\Program Files\AVG\AVG8\Identity Protection\agent\Bin\AVGIDSWatcher.exe (AVG)
PRC - C:\Program Files\AVG\AVG8\Identity Protection\agent\Bin\AVGIDSAgent.exe (AVG)
PRC - C:\Program Files\AVG\AVG8\Identity Protection\agent\Bin\AVGIDSMonitor.exe (AVG)
PRC - C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
PRC - C:\WINDOWS\system32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\CTSVCCDA.EXE (Creative Technology Ltd)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Dad\Desktop\OTLCA8WBSNI.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (prfldsvc) – File not found
SRV - (Browser Defender Update Service) – C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
SRV - (sdCoreService) – C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools)
SRV - (sdAuxService) – C:\Program Files\Spyware Doctor\pctsAuxs.exe (PC Tools)
SRV - (avg8emc) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgfws8) – C:\Program Files\AVG\AVG8\avgfws8.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (PnkBstrA) – C:\WINDOWS\system32\PnkBstrA.exe ()
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (AVGIDSWatcher) – C:\Program Files\AVG\AVG8\Identity Protection\agent\Bin\AVGIDSWatcher.exe (AVG)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG8\Identity Protection\agent\Bin\AVGIDSAgent.exe (AVG)
SRV - (Adobe LM Service) – C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe (Adobe Systems)
SRV - (NVSvc) – C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
SRV - (NetSvc) – C:\Program Files\Intel\NCS\Sync\NetSvc.exe (Intel® Corporation)
SRV - (Creative Service for CDROM Access) – C:\WINDOWS\system32\CTSVCCDA.EXE (Creative Technology Ltd)
========== Driver Services (SafeList) ==========
DRV - (PCTCore) – C:\WINDOWS\system32\drivers\PCTCore.sys (PC Tools)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Lbd) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (Avgfwfd) – C:\WINDOWS\system32\drivers\avgfwdx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgfwdx) – C:\WINDOWS\system32\drivers\avgfwdx.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgRkx86) – C:\WINDOWS\System32\Drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSDriver) – C:\Program Files\AVG\AVG8\Identity Protection\agent\driver\platform_XP\AVGIDSDriver.sys (AVG Technologies )
DRV - (AVGIDSFilter) – C:\Program Files\AVG\AVG8\Identity Protection\agent\driver\platform_XP\AVGIDSFilter.sys (AVG Technologies )
DRV - (AVGIDSShim) – C:\Program Files\AVG\AVG8\Identity Protection\agent\driver\platform_XP\AVGIDSShim.sys (AVG Technologies )
DRV - (AVGIDSErHr) – C:\WINDOWS\System32\Drivers\AVGIDSErHr.sys (AVG Technologies )
DRV - (PxHelp20) – C:\WINDOWS\system32\DRIVERS\PxHelp20.sys (Sonic Solutions)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (Secdrv) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (UsbDiag) – C:\WINDOWS\system32\drivers\lgusbdiag.sys (LG Electronics Inc.)
DRV - (USBModem) – C:\WINDOWS\system32\drivers\lgusbmodem.sys (LG Electronics Inc.)
DRV - (usbbus) – C:\WINDOWS\system32\drivers\lgusbbus.sys (LG Electronics Inc.)
DRV - (Prvflder) – C:\WINDOWS\system32\drivers\prvflder.sys (Windows ® 2000 DDK provider)
DRV - (HPZius12) – C:\WINDOWS\system32\drivers\HPZius12.sys (HP)
DRV - (HPZipr12) – C:\WINDOWS\system32\drivers\HPZipr12.sys (HP)
DRV - (HPZid412) – C:\WINDOWS\system32\drivers\HPZid412.sys (HP)
DRV - (Ptilink) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (ctdvda2k) – C:\WINDOWS\system32\drivers\ctdvda2k.sys (Creative Technology Ltd)
DRV - (ctaud2k) Creative Audio Driver (WDM) – C:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (hap16v2k) – C:\WINDOWS\system32\drivers\hap16v2k.sys (Creative Technology Ltd)
DRV - (ha10kx2k) – C:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (PfModNT) – C:\WINDOWS\system32\drivers\pfmodnt.sys (Creative Technology Ltd.)
DRV - (E100B) Intel® – C:\WINDOWS\system32\drivers\e100b325.sys (Intel Corporation)
DRV - (emupia) – C:\WINDOWS\system32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k) – C:\WINDOWS\system32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) – C:\WINDOWS\system32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – C:\WINDOWS\system32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (OMCI) – C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS (Dell Computer Corporation)
DRV - (StillCam) – C:\WINDOWS\system32\drivers\serscan.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.071303000004
FF - prefs.js..extensions.enabledItems: {66E978CD-981F-47DF-AC42-E3CF417C1467}:0.4
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.0
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.16\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/12/28 04:08:06 | 00,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.16\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/12/18 01:14:08 | 00,000,000 | —D | M]
[2009/03/27 21:33:34 | 00,000,000 | —D | M] – C:\Documents and Settings\Dad\Application Data\Mozilla\Extensions
[2010/01/07 12:55:29 | 00,000,000 | —D | M] – C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v7wp6yps.default\extensions
[2009/04/22 15:30:58 | 00,000,000 | —D | M] (New Tab Homepage) – C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v7wp6yps.default\extensions\{66E978CD-981F-47DF-AC42-E3CF417C1467}
[2009/03/27 22:07:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\v7wp6yps.default\extensions\[removed]
[2010/01/07 21:41:33 | 00,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: (734 bytes) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (BitComet Helper) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll (BitComet)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
O4 - HKLM..\Run: [AsioReg] C:\WINDOWS\System32\CTASIO.DLL (Creative Technology Ltd)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [AVGIDS] C:\Program Files\AVG\AVG8\Identity Protection\agent\bin\AVGIDSUI.exe (AVG)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &D;&ownload; &with; BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: &D;&ownload; all video with BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: &D;&ownload; all with BitComet - C:\Program Files\BitComet\BitComet.exe (www.BitComet.com)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll (BitComet)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/12/20 17:12:44 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{7d025e8e-cef9-11dd-9bd9-0007e95117dd}\Shell\AutoRun\command - "" = F:\setupSNK.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2008/12/20 12:03:14 | 00,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16892003295952896)
========== Files/Folders - Created Within 30 Days ==========
[2010/01/08 18:39:40 | 00,513,536 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Dad\Desktop\OTLCA8WBSNI.exe
[2010/01/08 12:04:03 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\My Documents\My Scans
[2010/01/04 18:18:35 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\My Documents\Computer Tools
[2010/01/02 13:10:33 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\Application Data\ImgBurn
[2010/01/02 11:58:31 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\My Documents\dvd
[2010/01/02 11:56:44 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\Application Data\DVD Flick
[2010/01/02 11:56:25 | 00,164,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\comct232.ocx
[2010/01/02 11:56:25 | 00,040,960 | —- | C] (vbAccelerator) – C:\WINDOWS\System32\ssubtmr6.dll
[2010/01/02 11:56:25 | 00,036,864 | —- | C] (Robdogg Inc.) – C:\WINDOWS\System32\trayicon_handler.ocx
[2010/01/02 11:56:25 | 00,028,672 | —- | C] (-) – C:\WINDOWS\System32\mousewheel.ocx
[2010/01/02 11:56:24 | 00,609,824 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\comctl32.ocx
[2010/01/02 11:56:24 | 00,212,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\richtx32.ocx
[2010/01/02 11:56:24 | 00,000,000 | —D | C] – C:\Program Files\DVD Flick
[2009/12/28 19:41:59 | 00,000,000 | —D | C] – C:\Movavi files
[2009/12/28 19:38:27 | 00,000,000 | —D | C] – C:\Program Files\MOVAVI
[2009/12/28 19:38:17 | 00,000,000 | —D | C] – C:\Program Files\MOVAVI VideoSuite 3.4
[2009/12/22 03:20:53 | 01,414,440 | —- | C] (Nero AG) – C:\WINDOWS\System32\ShellManager310E2D762.dll
[2009/12/22 02:34:08 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\Local Settings\Application Data\Ahead
[2009/12/22 02:27:57 | 02,388,176 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_30.dll
[2009/12/22 02:27:56 | 02,323,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\d3dx9_28.dll
[2009/12/21 14:31:13 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\Application Data\CyberLink
[2009/12/21 14:23:26 | 00,446,464 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\NVUNINST.EXE
[2009/12/21 14:19:14 | 00,000,000 | —D | C] – C:\Program Files\CyberLink
[2009/12/19 02:07:54 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\Application Data\Any Video Converter Professional
[2009/12/19 02:07:51 | 00,000,000 | —D | C] – C:\Program Files\Any Video Converter Professional
[2009/12/16 16:36:58 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\Local Settings\Application Data\Threat Expert
[2009/12/16 16:29:56 | 00,149,456 | —- | C] (PC Tools) – C:\WINDOWS\SGDetectionTool.dll
[2009/12/16 16:29:55 | 01,640,400 | —- | C] (Threat Expert Ltd.) – C:\WINDOWS\PCTBDCore.dll
[2009/12/16 16:29:55 | 00,165,840 | —- | C] (Threat Expert Ltd.) – C:\WINDOWS\PCTBDRes.dll
[2009/12/16 15:40:55 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\LG Dare Stuff
[2009/12/15 00:27:55 | 00,000,000 | —D | C] – C:\Documents and Settings\Dad\Application Data\AVS4YOU
[2009/12/15 00:27:51 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVS4YOU
[2009/12/15 00:25:48 | 00,024,576 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\msxml3a.dll
[2009/12/15 00:25:48 | 00,000,000 | —D | C] – C:\Program Files\Common Files\AVSMedia
[2009/03/27 07:23:40 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Intuit
[2008/12/31 12:25:40 | 00,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2008/12/20 19:53:00 | 00,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2008/12/20 19:15:33 | 00,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2008/12/20 18:00:39 | 00,065,536 | —- | C] ( ) – C:\WINDOWS\System32\a3d.dll
[2008/12/20 17:12:30 | 00,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2005/05/11 23:36:48 | 00,012,288 | —- | C] (Hewlett-Packard Co.) – C:\WINDOWS\Fonts\RandFont.dll
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/01/08 18:39:44 | 00,513,536 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Dad\Desktop\OTLCA8WBSNI.exe
[2010/01/08 18:39:03 | 00,003,258 | —- | M] () – C:\Documents and Settings\Dad\Desktop\CPU 100%, Running Slow.url
[2010/01/08 17:44:50 | 00,178,882 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/01/08 17:44:00 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/01/08 17:43:55 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/01/08 17:43:52 | 00,000,000 | —- | M] () – C:\WINDOWS\MEMORY.DMP
[2010/01/08 14:29:58 | 00,190,976 | —- | M] () – C:\Documents and Settings\Dad\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/01/08 12:28:10 | 07,340,032 | —- | M] () – C:\Documents and Settings\Dad\ntuser.dat
[2010/01/08 12:25:41 | 00,185,732 | —- | M] () – C:\Documents and Settings\All Users\Documents\Return to work.pdf
[2010/01/08 12:08:50 | 00,000,000 | —- | M] () – C:\WINDOWS\hpqEmlSz.INI
[2010/01/08 09:17:37 | 00,000,178 | -HS- | M] () – C:\Documents and Settings\Dad\ntuser.ini
[2010/01/08 05:44:31 | 00,136,991 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2010/01/08 05:44:30 | 47,598,314 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/01/07 17:54:06 | 00,000,010 | —- | M] () – C:\WINDOWS\popcinfo.dat
[2010/01/07 12:59:01 | 00,030,036 | —- | M] () – C:\WINDOWS\System32\BMXStateBkp-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2010/01/07 12:59:01 | 00,030,036 | —- | M] () – C:\WINDOWS\System32\BMXState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2010/01/07 12:59:01 | 00,029,760 | —- | M] () – C:\WINDOWS\System32\BMXCtrlState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2010/01/07 12:59:01 | 00,029,760 | —- | M] () – C:\WINDOWS\System32\BMXBkpCtrlState-{00000002-00000000-00000002-00001102-00000004-10031102}.rfx
[2010/01/07 12:59:01 | 00,001,080 | —- | M] () – C:\WINDOWS\System32\settingsbkup.sfm
[2010/01/07 12:59:01 | 00,001,080 | —- | M] () – C:\WINDOWS\System32\settings.sfm
[2010/01/07 12:59:01 | 00,000,288 | —- | M] () – C:\WINDOWS\System32\DVCStateBkp-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
[2010/01/07 12:59:01 | 00,000,288 | —- | M] () – C:\WINDOWS\System32\DVCState-{00000002-00000000-00000002-00001102-00000004-10031102}.dat
[2010/01/07 01:59:49 | 00,000,768 | —- | M] () – C:\Documents and Settings\Dad\Desktop\MOVAVI VideoSuite 3.4.lnk
[2010/01/06 17:12:16 | 00,000,225 | —- | M] () – C:\Documents and Settings\Dad\Desktop\erie.craigslist.org-.url
[2010/01/06 03:45:09 | 00,069,176 | —- | M] () – C:\Documents and Settings\Dad\Desktop\Label.jpg
[2010/01/06 03:23:58 | 00,669,676 | —- | M] () – C:\Documents and Settings\Dad\Desktop\Mag Cover.jpg
[2010/01/04 22:32:42 | 00,000,276 | —- | M] () – C:\Documents and Settings\Dad\Desktop\Appearance - CamaroZ28.Com Message Board.url
[2010/01/03 22:59:48 | 00,000,141 | —- | M] () – C:\WINDOWS\wpd99.drv
[2010/01/03 22:23:43 | 00,000,474 | —- | M] () – C:\Documents and Settings\Dad\Desktop\Shared Documents.lnk
[2010/01/03 16:55:28 | 00,019,968 | —- | M] () – C:\Documents and Settings\Dad\My Documents\Pickeled Egg Recipe.doc
[2010/01/03 09:46:09 | 00,000,025 | —- | M] () – C:\WINDOWS\popcinfot.dat
[2010/01/02 13:12:47 | 00,000,728 | —- | M] () – C:\WINDOWS\win.ini
[2010/01/02 13:12:47 | 00,000,281 | RHS- | M] () – C:\boot.ini
[2010/01/02 13:12:47 | 00,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/01/02 11:56:30 | 00,001,577 | —- | M] () – C:\Documents and Settings\Dad\Desktop\DVD Flick.lnk
[2009/12/31 22:00:17 | 00,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/12/31 20:44:08 | 00,000,208 | —- | M] () – C:\Documents and Settings\Dad\Desktop\Two Wheel Texans - Bandit.url
[2009/12/31 20:33:32 | 00,000,158 | —- | M] () – C:\Documents and Settings\Dad\Desktop\GEZA Stretch Form-Fit Motorcycle Covers - Portable, TOWABLE, Daily Use.url
[2009/12/31 20:00:28 | 00,001,024 | —- | M] () – C:\Documents and Settings\Dad\.rnd
[2009/12/30 14:55:24 | 00,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/12/30 14:54:58 | 00,019,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/12/27 02:40:12 | 00,428,032 | —- | M] () – C:\Documents and Settings\Dad\My Documents\Blank Sudoko.doc
[2009/12/22 03:19:55 | 00,000,000 | —- | M] () – C:\WINDOWS\Irremote.ini
[2009/12/21 14:32:06 | 00,521,942 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/12/21 14:32:06 | 00,441,124 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/12/21 14:32:06 | 00,071,060 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/12/19 23:54:05 | 00,139,152 | —- | M] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009/12/19 23:53:57 | 00,111,928 | —- | M] () – C:\WINDOWS\System32\PnkBstrB.exe
[2009/12/19 02:07:58 | 00,000,770 | —- | M] () – C:\Documents and Settings\Dad\Desktop\Any Video Converter Professional.lnk
[2009/12/16 16:29:18 | 00,001,637 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Spyware Doctor.lnk
[2009/12/16 16:18:58 | 00,002,560 | —- | M] () – C:\WINDOWS\System32\drivers\mchInjDrv.sys
[2009/12/16 01:58:42 | 00,000,168 | —- | M] () – C:\Documents and Settings\Dad\Desktop\NetBenefits.url
[2009/12/15 11:24:48 | 00,293,376 | —- | M] () – C:\Documents and Settings\Dad\Desktop\gmer.exe
[2009/12/13 13:16:23 | 00,026,112 | —- | M] () – C:\Documents and Settings\All Users\Documents\Waffle Recipe.doc
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/01/08 17:10:36 | 00,293,376 | —- | C] () – C:\Documents and Settings\Dad\Desktop\gmer.exe
[2010/01/08 12:25:41 | 00,185,732 | —- | C] () – C:\Documents and Settings\All Users\Documents\Return to work.pdf
[2010/01/08 12:08:50 | 00,000,000 | —- | C] () – C:\WINDOWS\hpqEmlSz.INI
[2010/01/07 01:59:49 | 00,000,768 | —- | C] () – C:\Documents and Settings\Dad\Desktop\MOVAVI VideoSuite 3.4.lnk
[2010/01/06 03:36:17 | 00,069,176 | —- | C] () – C:\Documents and Settings\Dad\Desktop\Label.jpg
[2010/01/06 03:23:51 | 00,669,676 | —- | C] () – C:\Documents and Settings\Dad\Desktop\Mag Cover.jpg
[2010/01/04 22:18:44 | 00,003,258 | —- | C] () – C:\Documents and Settings\Dad\Desktop\CPU 100%, Running Slow.url
[2010/01/03 16:55:28 | 00,019,968 | —- | C] () – C:\Documents and Settings\Dad\My Documents\Pickeled Egg Recipe.doc
[2010/01/02 11:56:30 | 00,001,577 | —- | C] () – C:\Documents and Settings\Dad\Desktop\DVD Flick.lnk
[2009/12/31 20:33:32 | 00,000,158 | —- | C] () – C:\Documents and Settings\Dad\Desktop\GEZA Stretch Form-Fit Motorcycle Covers - Portable, TOWABLE, Daily Use.url
[2009/12/27 02:40:11 | 00,428,032 | —- | C] () – C:\Documents and Settings\Dad\My Documents\Blank Sudoko.doc
[2009/12/22 03:19:55 | 00,000,000 | —- | C] () – C:\WINDOWS\Irremote.ini
[2009/12/22 02:31:58 | 00,001,024 | —- | C] () – C:\Documents and Settings\Dad\.rnd
[2009/12/21 14:24:07 | 00,186,407 | —- | C] () – C:\WINDOWS\System32\nvapps.nvb
[2009/12/19 02:07:58 | 00,000,770 | —- | C] () – C:\Documents and Settings\Dad\Desktop\Any Video Converter Professional.lnk
[2009/12/17 00:12:02 | 00,000,276 | —- | C] () – C:\Documents and Settings\Dad\Desktop\Appearance - CamaroZ28.Com Message Board.url
[2009/12/16 16:29:56 | 00,767,952 | —- | C] () – C:\WINDOWS\BDTSupport.dll
[2009/12/16 16:29:56 | 00,000,883 | —- | C] () – C:\WINDOWS\RegSDImport.xml
[2009/12/16 16:29:56 | 00,000,880 | —- | C] () – C:\WINDOWS\RegISSImport.xml
[2009/12/16 16:29:56 | 00,000,131 | —- | C] () – C:\WINDOWS\IDB.zip
[2009/12/16 16:29:55 | 01,152,444 | —- | C] () – C:\WINDOWS\UDB.zip
[2009/12/16 16:29:45 | 00,007,387 | —- | C] () – C:\WINDOWS\System32\drivers\pctgntdi.cat
[2009/12/16 16:29:30 | 00,007,412 | —- | C] () – C:\WINDOWS\System32\drivers\PCTAppEvent.cat
[2009/12/16 16:29:18 | 00,001,637 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Spyware Doctor.lnk
[2009/12/16 16:29:13 | 00,007,383 | —- | C] () – C:\WINDOWS\System32\drivers\pctplsg.cat
[2009/12/16 16:18:58 | 00,002,560 | —- | C] () – C:\WINDOWS\System32\drivers\mchInjDrv.sys
[2009/12/13 13:16:23 | 00,026,112 | —- | C] () – C:\Documents and Settings\All Users\Documents\Waffle Recipe.doc
[2009/12/09 18:17:53 | 00,000,167 | —- | C] () – C:\WINDOWS\System32\AddPort.ini
[2009/12/09 18:15:56 | 00,000,686 | —- | C] () – C:\WINDOWS\hpntwksetup.ini
[2009/10/13 01:25:19 | 00,000,059 | —- | C] () – C:\WINDOWS\DCMVWR.INI
[2009/08/09 22:18:38 | 00,000,038 | —- | C] () – C:\Documents and Settings\Dad\Application Data\msnpromo.txt
[2009/04/18 21:36:31 | 00,000,140 | —- | C] () – C:\WINDOWS\RealFlight.INI
[2009/03/19 22:37:12 | 00,139,152 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009/03/11 18:21:44 | 00,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2009/02/17 19:34:38 | 01,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2009/02/13 12:09:48 | 00,000,067 | —- | C] () – C:\WINDOWS\Easy Video to iPod MP4 PSP 3GP Converter.INI
[2009/01/31 12:52:17 | 00,051,716 | —- | C] () – C:\WINDOWS\System32\pdf995mon.dll
[2009/01/31 12:52:17 | 00,000,141 | —- | C] () – C:\WINDOWS\wpd99.drv
[2009/01/03 08:26:28 | 00,000,120 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2009/01/02 01:43:07 | 00,190,976 | —- | C] () – C:\Documents and Settings\Dad\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/12/31 10:35:41 | 00,000,126 | —- | C] () – C:\Documents and Settings\Dad\Local Settings\Application Data\fusioncache.dat
[2008/12/27 00:14:03 | 00,077,824 | R— | C] () – C:\WINDOWS\System32\hpzids01.dll
[2008/12/27 00:10:24 | 00,001,127 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2008/12/26 22:20:30 | 00,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2008/12/20 18:01:13 | 00,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2008/12/20 18:00:54 | 00,066,807 | —- | C] () – C:\WINDOWS\System32\Aud2_Del.ini
[2008/12/20 18:00:54 | 00,000,030 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2008/12/20 18:00:45 | 00,005,515 | —- | C] () – C:\WINDOWS\System32\ENSDEF.INI
[2008/12/20 18:00:45 | 00,000,180 | —- | C] () – C:\WINDOWS\System32\KILL.INI
[2008/12/20 17:59:33 | 00,000,136 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2008/12/20 17:45:39 | 00,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll
[2006/11/01 03:57:24 | 01,138,688 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2006/02/26 04:08:28 | 00,585,728 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2004/02/04 10:37:00 | 01,703,936 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2004/02/04 10:37:00 | 00,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2003/07/28 15:19:00 | 01,486,848 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2003/07/28 15:19:00 | 00,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2001/07/06 15:30:00 | 00,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
========== LOP Check ==========
[2009/04/20 17:28:42 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Downloaded Installations
[2009/01/15 16:31:08 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\HiddenSecretsNightmare
[2009/03/13 10:08:21 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Panasonic
[2009/02/02 00:39:50 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\pdf995
[2009/02/21 16:52:45 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayPond
[2009/05/23 22:01:51 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap Games
[2009/01/31 12:47:27 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TaxCut
[2010/01/08 18:39:56 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/06/11 11:29:45 | 00,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2009/12/16 14:45:36 | 00,000,000 | —D | M] – C:\Documents and Settings\Dad\Application Data\Any Video Converter
[2010/01/06 12:28:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Dad\Application Data\Any Video Converter Professional
[2009/01/19 18:52:58 | 00,000,000 | —D | M] – C:\Documents and Settings\Dad\Application Data\Big Fish Games
[2010/01/02 13:10:33 | 00,000,000 | —D | M] – C:\Documents and Settings\Dad\Application Data\ImgBurn
[2009/03/28 11:51:08 | 00,000,000 | —D | M] – C:\Documents and Settings\Dad\Application Data\iWin
[2008/12/27 00:07:22 | 00,000,000 | —D | M] – C:\Documents and Settings\Dad\Application Data\Leadertech
[2009/08/09 22:20:24 | 00,000,000 | —D | M] – C:\Documents and Settings\Dad\Application Data\MSNInstaller
[2009/01/27 16:06:44 | 00,000,000 | —D | M] – C:\Documents and Settings\Dad\Application Data\Opera
[2009/02/02 00:39:50 | 00,000,000 | —D | M] – C:\Documents and Settings\Dad\Application Data\pdf995
[2009/04/02 22:23:02 | 00,000,000 | —D | M] – C:\Documents and Settings\Dad\Application Data\Uniblue
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: AGP440.SYS >
[2008/04/13 13:36:38 | 00,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 13:36:38 | 00,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\dllcache\agp440.sys
[2008/04/13 13:36:38 | 00,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/04 01:07:41 | 00,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
[2004/08/04 01:07:41 | 00,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\AGP440.SYS
< MD5 for: ATAPI.SYS >
[2008/04/13 13:40:30 | 00,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 13:40:30 | 00,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\dllcache\atapi.sys
[2008/04/13 13:40:30 | 00,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/04 00:59:42 | 00,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/13 19:11:53 | 00,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 19:11:53 | 00,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/04 02:56:42 | 00,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: NETLOGON.DLL >
[2008/04/13 19:12:01 | 00,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 19:12:01 | 00,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2004/08/04 02:56:44 | 00,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: SCECLI.DLL >
[2004/08/04 02:56:44 | 00,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 19:12:05 | 00,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 19:12:05 | 00,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll
< %systemroot%\*. /mp /s >
< >
< >
========== Alternate Data Streams ==========
@Alternate Data Stream - 183 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A3B8F70C
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8
< End of report >