I uninstalled Smart Defrag 1.10 and disabled utorrent.
I wanted to let you know that the 3 hot links that you gave me concerning P2P dangers were all broken links. So I was unable to read the info you wanted me to read. So I have not uninstalled utorrent as of yet. I use it for something that is very important to me so I am little reluctant to uninstall it for this reason. However, that isn't to say that I won't, but I want to read up on it first. If you have any other similar links to articles I would be very happy to read them.
Also, Kaspersky is redoing their online scan and it is unavailable right now.
Here are the other logs:
Malwarebytes:
Malwarebytes' Anti-Malware 1.44
Database version: 3723
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18882
2/10/2010 11:55:30 PM
mbam-log-2010-02-10 (23-55-30).txt
Scan type: Quick Scan
Objects scanned: 113188
Time elapsed: 5 minute(s), 29 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
OTL log:
OTL logfile created on: 2/11/2010 12:07:15 AM - Run 1
OTL by OldTimer - Version 3.1.28.0 Folder = C:\Users\Alan\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18882)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 80.00% Memory free
8.00 Gb Paging File | 7.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): c:\pagefile.sys 4987 4987 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 278.56 Gb Total Space | 116.06 Gb Free Space | 41.66% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 19.53 Gb Total Space | 19.44 Gb Free Space | 99.55% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: ALAN-PC
Current User Name: Alan
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Users\Alan\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\ZoomText 9.1\ZtUac.exe (Ai Squared )
PRC - C:\Program Files\ZoomText 9.1\ZoomTextHelperService.exe (Ai Squared )
PRC - C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation)
PRC - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\Windows\System32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation)
PRC - C:\Windows\System32\vmnetdhcp.exe (VMware, Inc.)
PRC - C:\Program Files\VMware\VMware Player\vmware-authd.exe (VMware, Inc.)
PRC - C:\Windows\System32\vmnat.exe (VMware, Inc.)
PRC - C:\Windows\System32\WUDFHost.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
PRC - C:\Windows\System32\mobsync.exe (Microsoft Corporation)
PRC - C:\Windows\System32\Crypserv.exe (CrypKey (Canada) Ltd.)
========== Modules (SafeList) ==========
MOD - C:\Users\Alan\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (Akamai) – c:\Program Files\Common Files\Akamai\rswin_3647.dll ()
SRV - (avg8wd) – C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8emc) – C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (ZoomText Helper Service) – C:\Program Files\ZoomText 9.1\ZoomTextHelperService.exe (Ai Squared )
SRV - (nvsvc) – C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation)
SRV - (Stereo Service) – C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (fsssvc) – C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Essentials\MsMpEng.exe (Microsoft Corporation)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (wlidsvc) – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
SRV - (odserv) – C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (VMnetDHCP) – C:\Windows\System32\vmnetdhcp.exe (VMware, Inc.)
SRV - (VMAuthdService) – C:\Program Files\VMware\VMware Player\vmware-authd.exe (VMware, Inc.)
SRV - (VMware NAT Service) – C:\Windows\System32\vmnat.exe (VMware, Inc.)
SRV - (ufad-ws60) – C:\Program Files\VMware\VMware Player\vmware-ufad.exe (VMware, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (Crypkey License) – C:\Windows\System32\Crypserv.exe (CrypKey (Canada) Ltd.)
SRV - (ehstart) – C:\Windows\ehome\ehstart.dll (Microsoft Corporation)
SRV - (ose) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (IDriverT) – C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (Diskeeper) – C:\Program Files\Executive Software\DiskeeperLite\DKService.exe (Executive Software International, Inc.)
========== Driver Services (SafeList) ==========
DRV - (AvgLdx86) – C:\Windows\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\Windows\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX) – C:\Windows\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (vmm) – C:\Windows\System32\drivers\VMM.sys (Microsoft Corporation)
DRV - (Ai2sXP) – C:\Windows\System32\drivers\Ai2sXP.sys (Ai Squared )
DRV - (Ai2Mmpd) – C:\Windows\System32\drivers\Ai2Mmpd.sys (Ai Squared )
DRV - (Ai2Chroniker) – C:\Windows\System32\drivers\Ai2Chroniker.sys (Ai Squared )
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (fssfltr) – C:\Windows\System32\drivers\fssfltr.sys (Microsoft Corporation)
DRV - (VX3000) – C:\Windows\System32\drivers\VX3000.sys (Microsoft Corporation)
DRV - (MpFilter) – C:\Windows\System32\drivers\MpFilter.sys (Microsoft Corporation)
DRV - (MpNWMon) – C:\Windows\System32\drivers\MpNWMon.sys (Microsoft Corporation)
DRV - (Point32) – C:\Windows\System32\drivers\point32k.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\Windows\System32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (atksgt) – C:\Windows\System32\drivers\atksgt.sys ()
DRV - (lirsgt) – C:\Windows\System32\drivers\lirsgt.sys ()
DRV - (sptd) – C:\Windows\System32\Drivers\sptd.sys ()
DRV - (vmci) – C:\Windows\System32\drivers\vmci.sys (VMware, Inc.)
DRV - (VMnetuserif) – C:\Windows\System32\drivers\vmnetuserif.sys (VMware, Inc.)
DRV - (vmkbd) – C:\Windows\System32\drivers\VMkbd.sys (VMware, Inc.)
DRV - (vmx86) – C:\Windows\System32\drivers\vmx86.sys (VMware, Inc.)
DRV - (hcmon) – C:\Windows\System32\drivers\hcmon.sys (VMware, Inc.)
DRV - (VMparport) – C:\Windows\System32\drivers\vmparport.sys (VMware, Inc.)
DRV - (VMnetBridge) – C:\Windows\System32\drivers\vmnetbridge.sys (VMware, Inc.)
DRV - (VMnetAdapter) – C:\Windows\System32\drivers\vmnetadapter.sys (VMware, Inc.)
DRV - (vstor2-ws60) – C:\Program Files\VMware\VMware Player\vstor2-ws60.sys (VMware, Inc.)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (VPCNetS2) – C:\Windows\System32\drivers\VMNetSrv.sys (Microsoft Corporation)
DRV - (StMp3Rec) – C:\Windows\System32\drivers\StMp3Rec.sys (Generic)
DRV - (NetworkX) – C:\Windows\system32\ckldrv.sys ()
DRV - (c65013264) – C:\Windows\System32\drivers\c6501.sys (C-Media Inc)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (MTsensor) – C:\Windows\System32\drivers\ASACPI.sys ()
DRV - (ASPI) – C:\Windows\System32\drivers\ASPI32.SYS (Adaptec)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1967107133-2219403178-301070691-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKU\S-1-5-21-1967107133-2219403178-301070691-1000\S-1-5-21-1967107133-2219403178-301070691-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.3
FF - prefs.js..extensions.enabledItems: [removed]:1.11.6a
FF - prefs.js..extensions.enabledItems: {CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}:3.0.1
FF - prefs.js..extensions.enabledItems: {fce36c1e-58d8-498a-b2a5-66ad1cedebbb}:0.76
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.7
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.8
FF - prefs.js..extensions.enabledItems: {3d7eb24f-2740-49df-8937-200b1cc08f8a}:[removed]
FF - prefs.js..extensions.enabledItems: {44d0a1b4-9c90-4f86-ac92-8680b5d6549e}:0.6.4.1
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.071101000055
FF - prefs.js..extensions.enabledItems: [removed]:1.5.1
FF - prefs.js..extensions.enabledItems: [removed]:0.3
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG8\Firefox [2010/02/04 21:33:34 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/02/08 17:48:52 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/01/17 23:55:23 | 000,000,000 | —D | M]
[2008/12/17 01:47:51 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\Mozilla\Extensions
[2010/02/10 12:29:46 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\Mozilla\Firefox\Profiles\oy3uhsk5.default\extensions
[2009/12/30 20:16:51 | 000,000,000 | —D | M] (Flashblock) – C:\Users\Alan\AppData\Roaming\Mozilla\Firefox\Profiles\oy3uhsk5.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
[2009/12/30 20:16:51 | 000,000,000 | —D | M] (Gmail Notifier) – C:\Users\Alan\AppData\Roaming\Mozilla\Firefox\Profiles\oy3uhsk5.default\extensions\{44d0a1b4-9c90-4f86-ac92-8680b5d6549e}
[2010/01/19 08:38:38 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\Alan\AppData\Roaming\Mozilla\Firefox\Profiles\oy3uhsk5.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/01/30 23:03:42 | 000,000,000 | —D | M] (No name found) – C:\Users\Alan\AppData\Roaming\Mozilla\Firefox\Profiles\oy3uhsk5.default\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}
[2010/01/07 11:32:12 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\Alan\AppData\Roaming\Mozilla\Firefox\Profiles\oy3uhsk5.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/01/11 23:14:03 | 000,000,000 | —D | M] (DownThemAll!) – C:\Users\Alan\AppData\Roaming\Mozilla\Firefox\Profiles\oy3uhsk5.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2008/12/17 01:47:52 | 000,000,000 | —D | M] (CustomizeGoogle) – C:\Users\Alan\AppData\Roaming\Mozilla\Firefox\Profiles\oy3uhsk5.default\extensions\{fce36c1e-58d8-498a-b2a5-66ad1cedebbb}
[2008/08/21 12:44:21 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\Mozilla\Firefox\Profiles\oy3uhsk5.default\extensions\filtersetg@updater
[2009/02/22 22:32:56 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\Mozilla\Firefox\Profiles\oy3uhsk5.default\extensions\[removed]
[2010/01/15 10:51:17 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\Mozilla\Firefox\Profiles\oy3uhsk5.default\extensions\[removed]
[2009/12/30 20:16:51 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\Mozilla\Firefox\Profiles\oy3uhsk5.default\extensions\[removed]
[2010/01/30 23:03:42 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\Mozilla\Firefox\Profiles\oy3uhsk5.default\extensions\[removed]
[2008/08/24 08:50:41 | 000,000,523 | —- | M] () – C:\Users\Alan\AppData\Roaming\Mozilla\Firefox\Profiles\oy3uhsk5.default\searchplugins\daemon-search.xml
[2010/02/10 12:29:46 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: ([2006/09/18 14:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O2 - BHO: (no name) - {E1FF080D-12A3-439A-A2EF-4BA95A3148E8} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Veoh Web Player Video Finder) - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll File not found
O3 - HKLM\..\Toolbar: (&Windows; Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKU\S-1-5-21-1967107133-2219403178-301070691-1000\..\Toolbar\ShellBrowser: (no name) - {1392B8D2-5C05-419F-A8F6-B9F15A596612} - No CLSID value found.
O4 - HKLM..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe (AMD)
O4 - HKLM..\Run: [C6501Sound] File not found
O4 - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4 - HKLM..\Run: [itype] C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
O4 - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-1967107133-2219403178-301070691-1000..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\S-1-5-21-1967107133-2219403178-301070691-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_04)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 172.16.1.191
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (avgrsstx.dll) - C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL) - C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Users\Alan\Pictures\DCIM\1.22.10 Lily's botoz\1.22.10 Lily's botox.JPG
O24 - Desktop BackupWallPaper: C:\Users\Alan\Pictures\DCIM\1.22.10 Lily's botoz\1.22.10 Lily's botox.JPG
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 14:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{3af0f345-a159-11de-b2f9-005056c00008}\Shell - "" = AutoRun
O33 - MountPoints2\{3af0f345-a159-11de-b2f9-005056c00008}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O33 - MountPoints2\{c35808c6-cc93-11dd-81ae-0018f30d6ff2}\Shell - "" = AutoRun
O33 - MountPoints2\{c35808c6-cc93-11dd-81ae-0018f30d6ff2}\Shell\AutoRun\command - "" = E:\autorun.exe – File not found
O33 - MountPoints2\{d27dbb0d-6f44-11dd-a2c0-0018f30d6ff2}\Shell - "" = AutoRun
O33 - MountPoints2\{d27dbb0d-6f44-11dd-a2c0-0018f30d6ff2}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010/02/11 00:04:28 | 000,549,376 | —- | C] (OldTimer Tools) – C:\Users\Alan\Desktop\OTL.exe
[2010/02/10 20:56:49 | 000,000,000 | —D | C] – C:\_OTM
[2010/02/09 11:37:16 | 000,000,000 | —D | C] – C:\Users\Alan\AppData\Local\Adobe
[2010/02/08 19:12:44 | 000,000,000 | —D | C] – C:\ProgramData\Office Genuine Advantage
[2010/02/08 18:01:32 | 000,000,000 | —D | C] – C:\ProgramData\WindowsSearch
[2010/02/08 15:30:37 | 000,000,000 | —D | C] – C:\Users\Alan\AppData\Roaming\Malwarebytes
[2010/02/08 15:30:33 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/02/08 15:30:32 | 000,019,160 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/02/08 15:30:32 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/02/08 15:30:32 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/02/07 09:27:05 | 000,000,000 | —D | C] – C:\Users\Alan\Documents\The KMPlayer
[2010/02/07 00:03:15 | 000,000,000 | —D | C] – C:\Users\Alan\AppData\Local\Ai Squared
[2010/02/05 23:31:05 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2010/02/05 23:29:50 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2010/02/05 23:27:05 | 000,000,000 | —D | C] – C:\Users\Alan\Desktop\Temp Cleaning Folder
[2010/02/05 16:32:20 | 000,000,000 | —D | C] – C:\Users\Alan\Desktop\Arcade
[2010/02/05 16:30:19 | 000,000,000 | —D | C] – C:\Users\Alan\Desktop\Downloads
[2010/02/05 11:09:42 | 000,000,000 | —D | C] – C:\Users\Alan\AppData\Roaming\Dexpot
[2010/02/05 10:57:37 | 000,000,000 | —D | C] – C:\Users\Alan\AppData\Roaming\Auslogics
[2010/02/05 01:29:01 | 000,032,768 | —- | C] (PcWinTech.com) – C:\Windows\System32\CleanMem.exe
[2010/02/05 01:28:58 | 000,000,000 | —D | C] – C:\Windows\CleanMem
[2010/02/05 01:28:58 | 000,000,000 | —D | C] – C:\Program Files\CleanMem
[2010/02/05 01:27:54 | 000,000,000 | —D | C] – C:\Program Files\Auslogics
[2010/02/05 01:24:29 | 000,000,000 | —D | C] – C:\Program Files\Sophos
[2010/02/05 01:22:16 | 000,000,000 | —D | C] – C:\Users\Alan\Desktop\PC Optimizer Toolkit
[2010/02/04 21:34:36 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Essentials
[2010/02/01 09:44:42 | 000,000,000 | —D | C] – C:\Program Files\Lame for Audacity
[2010/02/01 09:44:01 | 000,000,000 | —D | C] – C:\Program Files\Audacity
[2010/01/31 20:18:14 | 000,000,000 | —D | C] – C:\Users\Alan\Tracing
[2010/01/29 02:11:58 | 000,594,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2010/01/29 02:11:58 | 000,387,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2010/01/29 02:11:57 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2010/01/29 02:11:57 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2010/01/29 02:11:57 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2010/01/29 02:11:57 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ie4uinit.exe
[2010/01/29 02:11:57 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2010/01/29 02:11:57 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2010/01/29 02:11:57 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesysprep.dll
[2010/01/29 02:11:57 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iesetup.dll
[2010/01/29 02:11:57 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iernonce.dll
[2010/01/29 02:11:57 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2010/01/29 02:11:57 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2010/01/29 02:11:57 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2010/01/29 01:12:47 | 000,000,000 | —D | C] – C:\Program Files\Veoh Networks
[2010/01/23 00:07:20 | 000,000,000 | —D | C] – C:\Users\Alan\AppData\Roaming\gtk-2.0
[2010/01/23 00:07:17 | 000,000,000 | —D | C] – C:\Users\Alan\.thumbnails
[2010/01/22 09:48:06 | 000,000,000 | —D | C] – C:\Users\Alan\.gimp-2.6
[2010/01/22 09:47:41 | 000,000,000 | —D | C] – C:\Program Files\GIMP-2.0
[2010/01/19 08:29:44 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2010/01/19 08:29:44 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2010/01/19 08:29:44 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2010/01/17 23:55:17 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2010/01/17 14:00:06 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2010/01/17 14:00:04 | 000,000,000 | R–D | C] – C:\Program Files\Skype
[2010/01/13 19:47:32 | 000,156,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\t2embed.dll
[2010/01/13 19:47:32 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fontsub.dll
[2010/01/13 19:06:24 | 000,000,000 | —D | C] – C:\Program Files\Free Online TV Player
[2010/01/13 17:55:30 | 000,000,000 | —D | C] – C:\Program Files\The KMPlayer
========== Files - Modified Within 30 Days ==========
[2010/02/11 00:07:20 | 002,621,440 | -HS- | M] () – C:\Users\Alan\NTUSER.DAT
[2010/02/11 00:04:35 | 000,549,376 | —- | M] (OldTimer Tools) – C:\Users\Alan\Desktop\OTL.exe
[2010/02/10 23:47:05 | 000,034,800 | —- | M] () – C:\ProgramData\nvModes.dat
[2010/02/10 23:47:05 | 000,034,800 | —- | M] () – C:\ProgramData\nvModes.001
[2010/02/10 23:04:10 | 000,004,080 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/02/10 23:04:10 | 000,004,080 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/02/10 22:46:21 | 055,441,810 | —- | M] () – C:\Windows\System32\drivers\Avg\incavi.avm
[2010/02/10 21:08:57 | 000,711,600 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/02/10 21:08:57 | 000,611,038 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/02/10 21:08:57 | 000,107,604 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/02/10 21:04:39 | 000,000,445 | —- | M] () – C:\Windows\System\c6501.INI
[2010/02/10 21:04:20 | 000,002,487 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Audio Spooler.lnk
[2010/02/10 21:04:11 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/02/10 21:04:08 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/02/10 21:04:05 | 3488,079,872 | -HS- | M] () – C:\hiberfil.sys
[2010/02/10 21:02:47 | 000,524,288 | -HS- | M] () – C:\Users\Alan\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010/02/10 21:02:47 | 000,065,536 | -HS- | M] () – C:\Users\Alan\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010/02/10 20:37:36 | 002,544,286 | -H– | M] () – C:\Users\Alan\AppData\Local\IconCache.db
[2010/02/09 21:58:39 | 000,002,377 | —- | M] () – C:\Users\Alan\Desktop\Skype.lnk
[2010/02/09 00:05:53 | 000,012,997 | —- | M] () – C:\Users\Alan\Desktop\THE WOW BUDGET.ods
[2010/02/08 15:33:10 | 000,000,000 | —- | M] () – C:\Users\Alan\defogger_reenable
[2010/02/05 15:27:20 | 000,001,660 | —- | M] () – C:\Users\Public\Desktop\ZoomText 9.1.lnk
[2010/01/23 00:07:20 | 000,000,896 | —- | M] () – C:\Users\Alan\.recently-used.xbel
[2010/01/19 21:22:28 | 000,142,495 | —- | M] () – C:\Windows\System32\drivers\Avg\microavi.avg
[2010/01/14 11:12:06 | 000,181,120 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[2010/01/12 00:54:57 | 000,023,552 | —- | M] () – C:\Users\Alan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== Files Created - No Company Name ==========
[2010/02/08 15:33:10 | 000,000,000 | —- | C] () – C:\Users\Alan\defogger_reenable
[2010/01/23 00:07:20 | 000,000,896 | —- | C] () – C:\Users\Alan\.recently-used.xbel
[2010/01/17 15:49:47 | 000,002,377 | —- | C] () – C:\Users\Alan\Desktop\Skype.lnk
[2010/01/07 13:53:25 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/11/06 12:52:09 | 000,034,800 | —- | C] () – C:\ProgramData\nvModes.001
[2009/11/06 12:52:07 | 000,034,800 | —- | C] () – C:\ProgramData\nvModes.dat
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/07/28 15:19:48 | 000,000,094 | —- | C] () – C:\Windows\family.ini
[2009/07/16 15:50:42 | 000,000,680 | —- | C] () – C:\Users\Alan\AppData\Local\d3d9caps.dat
[2009/06/11 11:45:00 | 000,000,092 | —- | C] () – C:\Users\Alan\AppData\Local\fusioncache.dat
[2009/05/27 16:31:47 | 000,000,549 | —- | C] () – C:\Windows\ka.ini
[2009/02/01 03:46:00 | 000,000,044 | —- | C] () – C:\ProgramData\{3D55D1F4-1059-11DC-B281-197056D89593}
[2009/01/17 19:22:35 | 000,055,856 | —- | C] () – C:\Windows\System32\vnetinst.dll
[2008/12/27 01:26:48 | 000,339,968 | —- | C] () – C:\Windows\System32\pythoncom25.dll
[2008/12/27 01:26:48 | 000,114,688 | —- | C] () – C:\Windows\System32\pywintypes25.dll
[2008/12/23 23:02:18 | 000,000,023 | —- | C] () – C:\Windows\BlendSettings.ini
[2008/12/19 00:06:19 | 000,023,552 | —- | C] () – C:\Users\Alan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/12/17 19:20:45 | 000,004,224 | —- | C] () – C:\Windows\System32\drivers\NVStrap.sys
[2008/12/17 02:07:01 | 000,007,680 | —- | C] () – C:\Windows\System32\drivers\ASACPI.sys
[2008/12/17 02:06:27 | 000,015,498 | —- | C] () – C:\Windows\VX3000.ini
[2008/11/21 14:47:52 | 003,596,288 | —- | C] () – C:\Windows\System32\qt-dx331.dll
[2008/11/21 14:45:16 | 000,000,416 | —- | C] () – C:\Windows\System32\dtu100.dll.manifest
[2008/11/21 14:45:16 | 000,000,416 | —- | C] () – C:\Windows\System32\dpl100.dll.manifest
[2008/11/21 14:44:16 | 000,012,288 | —- | C] () – C:\Windows\System32\DivXWMPExtType.dll
[2008/11/18 20:16:07 | 000,138,184 | —- | C] () – C:\Windows\System32\drivers\PnkBstrK.sys
[2008/10/21 00:32:47 | 000,000,275 | —- | C] () – C:\Windows\MugE.ini
[2008/10/07 09:13:22 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSwedish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSpanish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelPortugese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelKorean.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelJapanese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelGerman.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\System32\AgCPanelFrench.dll
[2008/10/04 21:03:27 | 000,000,080 | —- | C] () – C:\Windows\SuperUtil.ini
[2008/09/16 00:11:54 | 000,279,712 | —- | C] () – C:\Windows\System32\drivers\atksgt.sys
[2008/09/16 00:11:53 | 000,025,888 | —- | C] () – C:\Windows\System32\drivers\lirsgt.sys
[2008/09/09 15:59:35 | 000,027,648 | —- | C] () – C:\Windows\System32\AVSredirect.dll
[2008/09/09 15:16:43 | 000,765,952 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2008/09/09 15:16:43 | 000,383,238 | —- | C] () – C:\Windows\System32\libmp3lame-0.dll
[2008/08/29 14:47:19 | 000,043,520 | —- | C] () – C:\Windows\System32\CmdLineExt03.dll
[2008/08/24 08:44:03 | 000,717,296 | —- | C] () – C:\Windows\System32\drivers\sptd.sys
[2008/08/21 15:03:02 | 000,000,097 | —- | C] () – C:\Windows\System32\PICSDK.ini
[2008/08/21 11:51:35 | 000,000,048 | —- | C] () – C:\Windows\R300.ini
[2008/08/21 10:52:49 | 000,000,184 | —- | C] () – C:\Windows\EViewer.INI
[2008/08/21 10:05:52 | 000,004,975 | R— | C] () – C:\Windows\c6501.ini
[2008/08/21 10:05:44 | 000,053,248 | —- | C] () – C:\Windows\System32\c6501rm.dll
[2008/08/21 08:39:54 | 000,009,511 | —- | C] () – C:\Windows\Ascd_tmp.ini
[2008/08/21 08:39:40 | 000,010,288 | —- | C] () – C:\Windows\System32\drivers\ASUSHWIO.SYS
[2008/08/21 08:20:35 | 000,000,083 | —- | C] () – C:\Windows\Crypkey.ini
[2008/08/21 08:20:31 | 000,018,432 | —- | C] () – C:\Windows\Setup_ck.dll
[2008/08/21 08:20:31 | 000,016,896 | —- | C] () – C:\Windows\System32\Ckldrv.sys
[2008/08/21 07:47:30 | 000,000,090 | —- | C] () – C:\Windows\TestSupp.ini
[2008/06/05 08:58:26 | 000,197,912 | —- | C] () – C:\Windows\System32\physxcudart_20.dll
[2008/04/14 19:20:46 | 000,237,568 | —- | C] () – C:\Windows\glut32.dll
[2008/02/13 12:54:52 | 000,467,001 | R— | C] () – C:\Windows\System32\W3MKDE.DLL
[2008/02/13 12:54:52 | 000,061,499 | R— | C] () – C:\Windows\System32\W3MKDERC.DLL
[2006/11/02 18:22:58 | 000,030,256 | —- | C] () – C:\Windows\System32\PMMailSend.dll
[2006/11/02 18:21:56 | 000,050,736 | —- | C] () – C:\Windows\System32\KESIMapiStub.dll
[2006/11/02 05:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 00:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2005/11/10 08:01:28 | 000,006,144 | —- | C] () – C:\Windows\System32\classxps.dll
[2005/11/10 08:01:24 | 000,397,312 | —- | C] () – C:\Windows\System32\ClassX.dll
[2005/02/27 14:44:56 | 000,393,216 | —- | C] () – C:\Windows\System32\jogl.dll
[2005/02/27 14:44:56 | 000,073,728 | —- | C] () – C:\Windows\System32\jogl_cg.dll
[1995/08/23 11:45:58 | 000,002,016 | —- | C] () – C:\Windows\Sg5w30.dll
[1995/08/23 11:45:54 | 000,214,899 | —- | C] () – C:\Windows\Aplib2.dll
[1995/08/23 11:45:42 | 000,034,144 | —- | C] () – C:\Windows\Aplib1.dll
[1995/08/23 11:45:40 | 000,006,784 | —- | C] () – C:\Windows\Accupage.dll
========== LOP Check ==========
[2010/02/05 10:57:37 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\Auslogics
[2008/12/17 13:37:42 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\BitTyrant
[2008/12/17 01:47:46 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\ClearPlay Inc
[2008/12/17 16:40:28 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\DAEMON Tools
[2008/12/17 16:40:27 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\DAEMON Tools Lite
[2008/12/17 16:40:27 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\DAEMON Tools Pro
[2010/02/05 12:30:11 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\Dexpot
[2008/12/17 01:47:46 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\EPSON
[2009/07/28 15:35:43 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\EssentialPIM
[2009/01/17 11:37:10 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\flightgear.org
[2009/01/17 11:37:18 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\fltk.org
[2009/02/21 02:17:09 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\GetRightToGo
[2009/01/19 00:37:07 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\Graboid Inc
[2008/12/17 01:47:46 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\GrabPro
[2010/01/23 00:07:20 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\gtk-2.0
[2009/07/28 15:13:27 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\HotSync
[2009/02/06 01:18:48 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\IObit
[2008/12/17 01:47:46 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\KESI
[2008/12/17 01:47:46 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\Leadertech
[2008/12/17 01:47:51 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\Mobipocket
[2009/07/28 15:34:48 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\Open Source Applications Foundation
[2010/01/02 01:44:11 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\OpenDNS Updater
[2008/12/17 01:47:52 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\OpenOffice.org
[2008/12/17 01:48:01 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\Orbit
[2009/07/28 15:34:47 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\Python-Eggs
[2009/07/09 13:05:08 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\QuotePad
[2009/11/16 00:44:10 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\RapidTyping
[2010/01/14 18:41:15 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\RFB&&D; Download Manager
[2009/12/30 23:03:22 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\SanDisk
[2008/12/17 01:49:17 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\SecondLife
[2009/01/18 23:52:53 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\Spacejock Software
[2009/07/28 15:37:33 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\TaskCoach
[2009/04/10 22:51:55 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\Thunderbird
[2009/07/09 13:02:01 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\TreeDBNotes 3
[2009/07/04 00:23:06 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\uqm
[2010/02/10 23:46:28 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\uTorrent
[2008/12/17 01:49:18 | 000,000,000 | —D | M] – C:\Users\Alan\AppData\Roaming\XRay Engine
[2008/12/17 01:47:29 | 000,000,000 | —D | M] – C:\Users\Guest\AppData\Roaming\BitTyrant
[2010/02/10 21:02:48 | 000,032,612 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:DFC5A2B2
< End of report >
Extras log (from OLT):
OTL Extras logfile created on: 2/11/2010 12:07:15 AM - Run 1
OTL by OldTimer - Version 3.1.28.0 Folder = C:\Users\Alan\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18882)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 80.00% Memory free
8.00 Gb Paging File | 7.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): c:\pagefile.sys 4987 4987 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 278.56 Gb Total Space | 116.06 Gb Free Space | 41.66% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 19.53 Gb Total Space | 19.44 Gb Free Space | 99.55% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: ALAN-PC
Current User Name: Alan
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\IEXPLORE.EXE (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-1967107133-2219403178-301070691-1000\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -nohome (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – C:\Program Files\VideoLAN\VLC\vlc.exe –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – C:\Program Files\VideoLAN\VLC\vlc.exe –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{12C52E84-12D6-45F1-9347-24C50E4B810E}" = lport=2869 | protocol=6 | dir=in | app=system |
"{BB862AD4-BEA7-4B54-A454-4E9670BB5168}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0501640C-19CF-49BF-9B57-8A8DFBA7E2F6}" = protocol=6 | dir=in | app=c:\program files\sightspeed\sightspeed.exe |
"{2021FBED-B9C1-4E1B-8094-20E64FE44880}" = protocol=17 | dir=in | app=c:\users\alan\appdata\local\google\google talk plugin\googletalkplugin.dll |
"{203B7D2A-3D40-4AB1-914B-3D4AD4DEA763}" = protocol=6 | dir=in | app=c:\program files\rockstar games\rockstar games social club\rgsclauncher.exe |
"{215FB159-6725-4B36-AC1C-1E951E495B3B}" = protocol=6 | dir=in | app=c:\users\alan\appdata\local\google\google talk plugin\googletalkplugin.dll |
"{3394767A-6AB8-4723-BC1F-61BF98762B06}" = dir=in | app=c:\program files\avg\avg8\avgemc.exe |
"{373C3B00-B9E6-430B-B836-F8C30D6F89DA}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{48D70861-B022-46A7-B868-AF086651277A}" = protocol=6 | dir=in | app=c:\users\alan\appdata\local\google\google talk plugin\googletalkplugin.exe |
"{5A8AF53D-16A1-4B3C-9896-E69EB03F2018}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{60B08A3E-BAE8-4A02-892C-50AE4C9668EE}" = protocol=6 | dir=in | app=c:\program files\zoomtext 9.1\zt.exe |
"{873F490B-07A6-46DC-A185-9CC54A00CDA7}" = protocol=17 | dir=in | app=c:\users\alan\appdata\local\google\google talk plugin\googletalkplugin.exe |
"{884F0362-1E6E-439E-BEDE-4B5DA28C0B65}" = protocol=6 | dir=in | app=c:\program files\zoomtext 9.1\zt.exe |
"{91AAD5B1-2901-46B9-AA83-4966BB6402EF}" = protocol=6 | dir=in | app=c:\program files\microsoft lifecam\lifecam.exe |
"{96E95352-3143-41E7-9826-6B9EE7B926B5}" = protocol=6 | dir=in | app=c:\users\alan\appdata\local\google\google talk plugin\googletalkplugin.exe |
"{A3071996-ABFC-4500-ACD1-BF8B312B4E76}" = dir=in | app=c:\program files\windows live\messenger\livecall.exe |
"{A3523C51-99CA-49D6-9E6D-9FAE24C7D95B}" = protocol=6 | dir=in | app=c:\program files\microsoft lifecam\lifeexp.exe |
"{A6ACF641-D843-40AA-9EED-00431BFBE660}" = protocol=17 | dir=in | app=c:\program files\zoomtext 9.1\zt.exe |
"{A84CAE42-4882-46D7-A15C-13DA3997620D}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{A85D5E4E-2BE2-4C5C-AED8-5FB48FCB2BA4}" = protocol=17 | dir=in | app=c:\program files\microsoft lifecam\lifecam.exe |
"{B0DA0CE7-33C1-457F-A6CC-6D5A9145EBBE}" = protocol=6 | dir=in | app=c:\users\alan\appdata\local\google\google talk plugin\googletalkplugin.dll |
"{B215949A-BAB1-4704-AA52-2E9BE93B5155}" = protocol=17 | dir=in | app=c:\users\alan\appdata\local\google\google talk plugin\googletalkplugin.dll |
"{B28205A9-0833-4718-B4AE-8412ADC96FAA}" = protocol=17 | dir=in | app=c:\program files\sightspeed\sightspeed.exe |
"{B780CFE9-9B4A-44BF-BD25-B4B3A77700F7}" = protocol=17 | dir=in | app=c:\program files\rockstar games\grand theft auto iv\launchgtaiv.exe |
"{C2EBAE21-1817-44BC-9526-5796E40D7C4B}" = protocol=6 | dir=in | app=c:\program files\rockstar games\grand theft auto iv\launchgtaiv.exe |
"{C46ABB1C-2F7F-44CC-9BDE-B4BC1749AE98}" = protocol=17 | dir=in | app=c:\program files\zoomtext 9.1\zt.exe |
"{C812FB58-CC81-47FA-8346-921EBA914D68}" = dir=in | app=c:\program files\avg\avg8\avgupd.exe |
"{D2EF0059-CA8E-4A5D-BF8A-F46472D36932}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{E99CF679-6A7B-4C97-BEEC-2D6A54BF33C5}" = protocol=17 | dir=in | app=c:\users\alan\appdata\local\google\google talk plugin\googletalkplugin.exe |
"{EA7D5ECB-F200-4FE5-B022-8B4ABE046036}" = protocol=17 | dir=in | app=c:\program files\microsoft lifecam\lifeexp.exe |
"{FC5DF286-0D6E-4844-841B-5947EFB82AAD}" = protocol=17 | dir=in | app=c:\program files\rockstar games\rockstar games social club\rgsclauncher.exe |
"TCP Query User{01A29EE2-7D99-44C1-B6FB-6E2A34C2E1BA}C:\windows\system32\electricsheep.scr" = protocol=6 | dir=in | app=c:\windows\system32\electricsheep.scr |
"TCP Query User{08472FB2-0B64-484E-906D-978F60604AB7}C:\program files\bittyrant\azureus.exe" = protocol=6 | dir=in | app=c:\program files\bittyrant\azureus.exe |
"TCP Query User{2EBC50D3-B54D-439D-B997-D1A0186F1E05}C:\program files\rockstar games\grand theft auto iv\gtaiv.exe" = protocol=6 | dir=in | app=c:\program files\rockstar games\grand theft auto iv\gtaiv.exe |
"TCP Query User{383056D8-2463-4253-BC11-E84753FEBB62}C:\program files\kurzweil educational systems\kurzweil 1000\kurzweil 1000.exe" = protocol=6 | dir=in | app=c:\program files\kurzweil educational systems\kurzweil 1000\kurzweil 1000.exe |
"TCP Query User{6C9475AE-549C-45F3-B882-217701530F1C}C:\program files\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"TCP Query User{745C77AB-30CD-4799-9BA9-51FCEE3213DB}C:\program files\bittyrant\azureus.exe" = protocol=6 | dir=in | app=c:\program files\bittyrant\azureus.exe |
"TCP Query User{A517BD55-B918-4C7D-8B62-02C452AD0809}C:\dead space\dead space.exe" = protocol=6 | dir=in | app=c:\dead space\dead space.exe |
"TCP Query User{B03D41C5-505A-4A5A-B84B-AC835F26F486}C:\users\alan\desktop\racer064c\racer\racer.exe" = protocol=6 | dir=in | app=c:\users\alan\desktop\racer064c\racer\racer.exe |
"TCP Query User{B434085D-F493-4C40-B254-30090C05850C}C:\program files\orbitdownloader\orbitnet.exe" = protocol=6 | dir=in | app=c:\program files\orbitdownloader\orbitnet.exe |
"TCP Query User{CA19EEA6-197F-477F-BD7E-3A04ACEAAF9E}C:\program files\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"TCP Query User{DD69E6D3-CCD4-4E8B-A306-507EF8E1E221}C:\users\alan\documents\alan's documents\secondlife\slvoice.exe" = protocol=6 | dir=in | app=c:\users\alan\documents\alan's documents\secondlife\slvoice.exe |
"TCP Query User{ED8EA372-5D8C-46F9-9FB2-18422CF96852}C:\program files\orbitdownloader\orbitnet.exe" = protocol=6 | dir=in | app=c:\program files\orbitdownloader\orbitnet.exe |
"UDP Query User{1AC244A5-6E19-46EC-8332-7FCAF27B461A}C:\program files\orbitdownloader\orbitnet.exe" = protocol=17 | dir=in | app=c:\program files\orbitdownloader\orbitnet.exe |
"UDP Query User{29181DAF-9BCA-4968-BA47-2C3E0ED31128}C:\program files\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files\mozilla firefox\firefox.exe |
"UDP Query User{4A955AA3-BC5C-43B3-A5C7-ACE0074DA169}C:\program files\bittyrant\azureus.exe" = protocol=17 | dir=in | app=c:\program files\bittyrant\azureus.exe |
"UDP Query User{4F7086B5-AE7F-4596-B031-03D1E56B17DF}C:\program files\orbitdownloader\orbitnet.exe" = protocol=17 | dir=in | app=c:\program files\orbitdownloader\orbitnet.exe |
"UDP Query User{64899064-0E59-45E1-8EA9-74DDD1FFB717}C:\users\alan\desktop\racer064c\racer\racer.exe" = protocol=17 | dir=in | app=c:\users\alan\desktop\racer064c\racer\racer.exe |
"UDP Query User{699BBA50-F773-4C86-97A9-D62C307A6131}C:\windows\system32\electricsheep.scr" = protocol=17 | dir=in | app=c:\windows\system32\electricsheep.scr |
"UDP Query User{7431AA80-4B92-46D2-BFB4-AC25EDFD9A6A}C:\program files\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files\internet explorer\iexplore.exe |
"UDP Query User{7FA76597-3AF3-4168-9F21-AD0DC15C4276}C:\program files\kurzweil educational systems\kurzweil 1000\kurzweil 1000.exe" = protocol=17 | dir=in | app=c:\program files\kurzweil educational systems\kurzweil 1000\kurzweil 1000.exe |
"UDP Query User{A8573DEA-9090-45C8-A27F-8388BA95413A}C:\program files\bittyrant\azureus.exe" = protocol=17 | dir=in | app=c:\program files\bittyrant\azureus.exe |
"UDP Query User{D29BF2EF-E2B5-4A8F-B776-10B9C27AE7D2}C:\program files\rockstar games\grand theft auto iv\gtaiv.exe" = protocol=17 | dir=in | app=c:\program files\rockstar games\grand theft auto iv\gtaiv.exe |
"UDP Query User{DC840F58-1D35-4530-BA41-569B80BC7BE5}C:\users\alan\documents\alan's documents\secondlife\slvoice.exe" = protocol=17 | dir=in | app=c:\users\alan\documents\alan's documents\secondlife\slvoice.exe |
"UDP Query User{EC62895D-05CC-4D36-9C62-D680C9861632}C:\dead space\dead space.exe" = protocol=17 | dir=in | app=c:\dead space\dead space.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{03DE8444-C8D0-4C7E-9434-673D88498E7B}" = VoiceText ™
"{10A44844-4465-456E-8C97-80BDD4F68845}" = Windows Live ID Sign-in Assistant
"{139E303E-1050-497F-98B1-9AE87B15C463}" = Windows Live Family Safety
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1D14373E-7970-4F2F-A467-ACA4F0EA21E3}" = Google Earth
"{1E9A9E08-0366-45EE-9B66-51852F8D9812}" = Open Workbench
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{2174D448-F6A7-49EC-B42D-67FE626094E9}" = Kurzweil 1000 v.11
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{245F6C7A-0C22-4DE0-8202-2AAA620A1D3A}" = Microsoft XNA Framework Redistributable 2.0
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 17
"{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}" = EPSON Scan Assistant
"{3248F0A8-6813-11D6-A77B-00B0D0160040}" = Java™ 6 Update 4
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{342126E1-173C-4585-BFBE-3EBDD20E3E9E}" = Mobipocket Reader 6.2
"{34A5E174-93FD-496D-8073-13F63128AED6}" = ZoomText 9.1
"{3D5044A5-97B8-45C0-B956-BB2376569188}" = Windows Live Movie Maker
"{46CBBDF8-55B5-40DB-B459-7B848394309C}" = EPSON File Manager
"{48B3FB4D-CE22-488C-8E9F-24EBB77EAC0F}" = Microsoft Security Essentials
"{48F22622-1CC2-4A83-9C1E-644DD96F832D}" = EPSON Event Manager
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{4D87DC92-C328-46EC-A7B4-9C88129DC696}" = Dead Space™
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{67EDD823-135A-4D59-87BD-950616D6E857}" = EPSON Copy Utility 3
"{6B976ADF-8AE8-434E-B282-A06C7F624D2F}" = Python 2.5.2
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7353BAE6-5E49-46C4-A9B5-8A269A313789}" = Crysis WARHEAD®
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8CCD293C-0563-4EB0-BFAF-F279B61A6F32}" = ClearPlay Easy Updates
"{8D48DDA6-D5D4-4858-A4F1-4952293E0201}" = RCA Pearl (Model TH11, TC11 Series) Firmware Update Utility
"{8DC42D05-680B-41B0-8878-6C14D24602DB}" = QuickTime
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0014-0000-0000-0000000FF1CE}" = Microsoft Office Professional 2007
"{91120000-0014-0000-0000-0000000FF1CE}_PROR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-0014-0000-0000-0000000FF1CE}_PROR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{94A065E8-455D-41C1-AF1F-F0C1AF8F50F3}" = Microsoft IntelliType Pro 7.0
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{995F1E2E-F542-4310-8E1D-9926F5A279B3}" = Windows Live Toolbar
"{9FD6F1A8-5550-46AF-8509-271DF0E768B5}" = Dual-Core Optimizer
"{A0A77CDC-2419-4D5C-AD2C-E09E5926B806}" = Microsoft Antimalware
"{A182077A-8D6B-4194-B48A-B4DC37C69907}" = RealSpeak Solo for UK English Emily
"{A3F60446-48FB-48A8-B5FC-BB3430AEF806}" = Diskeeper Lite
"{A53A11EA-0095-493F-86FA-A15E8A86A405}" = VMware Player
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{AC54E544-3E42-443C-A91D-A00A6974C592}" = NVIDIA PhysX v8.10.13
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3
"{AD483998-2E9A-4405-83FF-6E503AF49CBB}" = Microsoft Virtual PC 2007 SP1
"{AE3CF174-872C-46C6-B9F6-C0593F3BC7B8}" = Microsoft Office Live Add-in 1.4
"{AFB1DFA5-FB56-4C9F-97A0-1607BC14BC0C}" = Smartparts Desktop
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B5749E57-AD4A-4B1B-ABC5-885FDBC286C9}" = D-Link AirPlus G Wireless LAN Adapter
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{D9140B72-FD9A-4650-8A24-03AC9827AAB8}" = Ai Squared Visual C++ Runtime
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E43ED0A0-C85E-40F0-807C-6A8A9D2FAEF3}_is1" = King's Bounty. The Legend (Remove Only)
"{E5D52570-5EF1-4576-A434-6CCD92268F0F}" = Google SketchUp 7
"{E622695B-3A22-4774-993D-318049488C0B}" = LDS Scriptures CD-ROM Resource Edition
"{E6B87DC4-2B3D-4483-ADFF-E483BF718991}" = OpenOffice.org 3.1
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{EF71A531-5B6C-4B20-8D1E-E6379C7FB6D3}" = Microsoft IntelliPoint 7.0
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F17B8386-A74A-4E4E-A7DD-435372991E14}" = Microsoft Visual Basic PowerPacks 2.0
"{F5346614-B7C4-4E94-826A-E2363155233D}" = EasyCleaner
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{FD6034A3-655C-49F0-B496-D4CBFD74D7A7}" = Palm Desktop by ACCESS
"{FF477885-5EA8-40D0-ADF3-D4C1B86FAEA4}" = EPSON Print CD
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"4Musics MP3 Bitrate Changer 5.0_is1" = 4Musics MP3 Bitrate Changer 5.0
"7-Zip" = 7-Zip 4.57
"AbiWord2" = AbiWord 2.6.6
"AbiwordToolsPlugins" = AbiWord Tools Plugins
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Audacity_is1" = Audacity 1.2.6
"AVG8Uninstall" = AVG Free 8.5
"CCleaner" = CCleaner
"Celestia_is1" = Celestia 1.6.0
"Chandler" = Chandler 1.0.3
"CleanMem" = CleanMem
"C-Media C6501 Like Sound Driver" = C-Media CM6501 Like Sound Driver
"comtypes-py2.5" = Python 2.5 comtypes-0.5.2
"Crysis WARHEAD®" = Crysis WARHEAD®
"dBpoweramp FLAC Codec" = dBpoweramp FLAC Codec
"dBpoweramp Music Converter" = dBpoweramp Music Converter
"EPSON Printer and Utilities" = EPSON Printer Software
"EPSON Scanner" = EPSON Scan
"ERUNT_is1" = ERUNT 1.1j
"EssentialPIM" = EssentialPIM
"Fireflies" = Fireflies Screensaver (remove only)
"Fraps" = Fraps
"Free Online TV Player_is1" = Free Online TV Player
"Freecorder Toolbar3.02" = Freecorder Toolbar 3.02 Application
"GetASFStream" = GetASFStream
"GPL Ghostscript 8.63" = GPL Ghostscript 8.63
"Holding Pattern Coach" = Holding Pattern Coach Screen Saver
"iDailyDiary_is1" = iDailyDiary 3.52
"JumpStart Advanced Preschool" = JumpStart Advanced Preschool
"JumpStart Advanced PreSchool Explore and Learn" = JumpStart Advanced PreSchool Explore and Learn
"JumpStart Art for Fun" = JumpStart Art for Fun
"JumpStart Languages" = JumpStart Languages
"LAME for Audacity_is1" = LAME v3.98.2 for Audacity
"LDS Gospel Resource" = LDS Gospel Resource
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MechWarrior 3" = MechWarrior 3
"Mechwarrior CD Patch" = Mechwarrior CD Patch 1.0
"Metacafe" = Metacafe
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft Security Essentials" = Microsoft Security Essentials
"Mozilla Firefox (3.5.7)" = Mozilla Firefox (3.5.7)
"Network Stumbler" = Network Stumbler 0.4.0 (remove only)
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"OpenAL" = OpenAL
"OpenDNS Updater" = OpenDNS Updater 2.2
"PIL-py2.5" = Python 2.5 PIL-1.1.6
"Privateer" = Privateer
"PROR" = Microsoft Office Professional 2007
"psyco-py2.5" = Python 2.5 psyco-1.6
"Punch! Home Design - AS3000" = Punch! Home Design - AS3000
"pywin32-py2.5" = Python 2.5 pywin32-212
"QuotePad_is1" = QuotePad 2.2
"RapidTyping" = RapidTyping
"RealCheckers_is1" = Real Checkers
"RFB&D; Download Manager_is1" = RFB&D; Download Manager
"RiftSpace" = RiftSpace
"RoughDraft" = RoughDraft 3.0
"SaverBeans Screensaver Pack" = SaverBeans Screensaver Pack 0.2
"Scribus [removed]" = Scribus [removed]
"SEO Note_is1" = SEO Note
"Silent Package Run-Time Sample" = EPSON SPR300 Reference Guide
"Sonar3_is1" = Sonar3
"Sophos-AntiRootkit" = Sophos Anti-Rootkit 1.5.0
"Stamina" = Stamina 2.5
"Streambox Vcr Suite_is1" = Streambox Vcr Suite 2
"SUPER ©" = SUPER © Version 2008.bld.33 (Sep 2, 2008)
"Task Coach_is1" = Task Coach 0.73.2
"The KMPlayer" = The KMPlayer (remove only)
"The Ur-Quan Masters" = The Ur-Quan Masters 0.6.2
"TreeDBNotes 3" = TreeDBNotes 3
"TypeFaster" = TypeFaster Typing Tutor
"UnityWebPlayer" = Unity Web Player
"uTorrent" = µTorrent
"Veoh Web Player Beta" = Veoh Web Player
"VLC media player" = VideoLAN VLC media player 0.8.6d
"WinAce Archiver" = WinAce Archiver
"WinGimp-2.0_is1" = GIMP 2.6.8
"WinLiveSuite_Wave3" = Windows Live Essentials
"wxPython2.8-ansi-py25_is1" = wxPython [removed] (ansi) for Python 2.5
"X Plugin Manager" = X Plugin Manager 2.20 BETA 6
"x2_allinone_bonus_package_is1" = X² All In One Bonus Package 1.04
"yWriter5_is1" = yWriter5
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-1967107133-2219403178-301070691-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Sansa Updater" = Sansa Updater
========== Last 10 Event Log Errors ==========
Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!
< End of report >
I did try agian to run a complete scan with SuperAntiSpyware and this time it did not crash on me! It did detect an adware cookie which I removed. Would you like to see this log also?
My computer seems to be running better and does not seem to be slowing down or constantly loading. However it was worse at sometimes during the day then others. So I will need to check this over the next day to see if there are any other problems. I thought that if I do find it slowing down and loading a lot then I would check the current running processes and copy and paste it to a txt document. Would this be helpful at all?