ok here we go. i think this is everything you are looking for.
All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
No active process named explorer.exe was found!
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9}\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\MSMSGS deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FB5F1910-F110-11d2-BB9E-00C04F795683}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FB5F1910-F110-11d2-BB9E-00C04F795683}\ not found.
Starting removal of ActiveX control {33564D57-9980-0010-8000-00AA00389B71}
C:\WINDOWS\Downloaded Program Files\wmv9dmo.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{33564D57-9980-0010-8000-00AA00389B71}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{33564D57-9980-0010-8000-00AA00389B71}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{33564D57-9980-0010-8000-00AA00389B71}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{33564D57-9980-0010-8000-00AA00389B71}\ not found.
Starting removal of ActiveX control {A7EA8AD2-287F-11D3-B120-006008C39542}
C:\WINDOWS\Downloaded Program Files\default.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{A7EA8AD2-287F-11D3-B120-006008C39542}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A7EA8AD2-287F-11D3-B120-006008C39542}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{A7EA8AD2-287F-11D3-B120-006008C39542}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{A7EA8AD2-287F-11D3-B120-006008C39542}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A7EA8AD2-287F-11D3-B120-006008C39542}\ not found.
Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
C:\WINDOWS\Downloaded Program Files\gp.inf not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
C:\WINDOWS\System32\appmgmt\MACHINE folder moved successfully.
C:\WINDOWS\System32\appmgmt\S-1-5-21-515967899-1229272821-682003330-1003 folder moved successfully.
C:\WINDOWS\System32\appmgmt folder moved successfully.
Folder C:\found files whatever\ not found.
C:\WINDOWS\SET3.tmp deleted successfully.
C:\WINDOWS\SET7.tmp deleted successfully.
C:\WINDOWS\002383_.tmp deleted successfully.
C:\WINDOWS\005489_.tmp deleted successfully.
C:\WINDOWS\System32\CONFIG.TMP deleted successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\AVG\AVG8\avgemc.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\AVG\AVG8\avgupd.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\AVG\AVG8\avgnsx.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\\C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe deleted successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: All Users
User: gg
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 15622 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
User: home
->Temp folder emptied: 508490570 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Java cache emptied: 14885870 bytes
->Flash cache emptied: 315961 bytes
User: Default User.WINDOWS
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 0 bytes
User: All Users.WINDOWS
User: NetworkService.NT AUTHORITY
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: LocalService.NT AUTHORITY
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
User: augustus able
->Temp folder emptied: 849112523 bytes
->Temporary Internet Files folder emptied: 45812467 bytes
->Java cache emptied: 66182247 bytes
->Flash cache emptied: 79088 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 483 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33722 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 1,416.00 mb
[EMPTYFLASH]
User: Default User
User: All Users
User: gg
->Flash cache emptied: 0 bytes
User: NetworkService
User: LocalService
User: Administrator
User: home
->Flash cache emptied: 0 bytes
User: Default User.WINDOWS
->Flash cache emptied: 0 bytes
User: All Users.WINDOWS
User: NetworkService.NT AUTHORITY
User: LocalService.NT AUTHORITY
User: augustus able
->Flash cache emptied: 0 bytes
Total Flash Files Cleaned = 0.00 mb
OTL by OldTimer - Version 3.2.4.1 log created on 05052010_214808
Files\Folders moved on Reboot…
Registry entries deleted on Reboot…
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4052
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
5/5/2010 10:22:17 PM
mbam-log-2010-05-05 (22-22-17).txt
Scan type: Quick scan
Objects scanned: 153593
Time elapsed: 17 minute(s), 52 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Program Files\Common\_helper.sig (Malware.Trace) -> Quarantined and deleted successfully.
eset scan=======
C:\Adobe\Acrobat 7.0\Setup Files\RdrBig\ENU\Program Files\Terminal Reality\4x4 Evo2\4x42.exe probably unknown NewHeur_PE virus
OTL logfile created on: 5/7/2010 6:55:23 PM - Run 2
OTL by OldTimer - Version 3.2.4.1 Folder = C:\Documents and Settings\augustus able\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
512.00 Mb Total Physical Memory | 240.00 Mb Available Physical Memory | 47.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 72.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 127.97 Gb Total Space | 95.01 Gb Free Space | 74.24% Space Free | Partition Type: FAT32
D: Drive not present or media not loaded
Drive E: | 654.81 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: HOME-3XQK3JVJDE
Current User Name: augustus able
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\augustus able\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\HPZipm12.exe (HP)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\augustus able\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9emc) – C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\HPZipm12.exe (HP)
========== Driver Services (SafeList) ==========
DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (wdm_opl3sax) YAMAHA OPL3-SAx Audio Driver (WDM) – C:\WINDOWS\system32\drivers\opl3sax.sys (Yamaha Corp.)
DRV - (EL90X) – C:\WINDOWS\system32\drivers\el90xnd5.sys (3Com Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: ([2001/08/23 12:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O12 - Plugin for: .do - C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll (Adobe Systems Inc.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.microsoft.com/windowsupdate/…b?1243653217515 (WUWebControl Class)
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab (HP Download Manager)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203}
http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab (GMNRev Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB}
http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-29-0.cab (EPUImageControl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwa…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\Documents and Settings\augustus able\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\augustus able\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/03/26 18:19:08 | 000,000,194 | —- | M] () - C:\AUTOEXEC.BAT – [ FAT32 ]
O32 - AutoRun File - [2005/07/29 20:24:42 | 000,000,044 | R— | M] () - E:\autorun.inf – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2009/05/29 20:53:56 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)
========== Files/Folders - Created Within 30 Days ==========
[2010/05/06 18:51:51 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2010/05/05 21:48:08 | 000,000,000 | —D | C] – C:\_OTL
[2010/05/04 21:49:29 | 000,000,000 | -HSD | C] – C:\FOUND.017
[2010/05/04 21:49:29 | 000,000,000 | -HSD | C] – C:\FOUND.016
[2010/05/04 21:49:29 | 000,000,000 | -HSD | C] – C:\FOUND.015
[2010/05/04 21:49:29 | 000,000,000 | -HSD | C] – C:\FOUND.014
[2010/05/04 21:49:29 | 000,000,000 | -HSD | C] – C:\FOUND.013
[2010/05/04 21:49:29 | 000,000,000 | -HSD | C] – C:\FOUND.012
[2010/05/04 21:49:29 | 000,000,000 | -HSD | C] – C:\FOUND.011
[2010/05/04 21:49:29 | 000,000,000 | -HSD | C] – C:\FOUND.010
[2010/05/04 21:49:29 | 000,000,000 | -HSD | C] – C:\FOUND.004
[2010/05/04 21:49:29 | 000,000,000 | -HSD | C] – C:\FOUND.003
[2010/05/04 21:49:29 | 000,000,000 | -HSD | C] – C:\FOUND.002
[2010/05/04 21:49:26 | 000,000,000 | -HSD | C] – C:\FOUND.061
[2010/05/04 21:49:26 | 000,000,000 | -HSD | C] – C:\FOUND.060
[2010/05/04 21:49:26 | 000,000,000 | -HSD | C] – C:\FOUND.001
[2010/05/04 21:49:26 | 000,000,000 | -HSD | C] – C:\FOUND.000
[2010/05/04 21:49:26 | 000,000,000 | -H-D | C] – C:\Config.Msi
[2010/05/04 21:49:25 | 000,000,000 | -HSD | C] – C:\FOUND.059
[2010/05/04 21:49:25 | 000,000,000 | -HSD | C] – C:\FOUND.058
[2010/05/04 21:48:16 | 000,000,000 | -HSD | C] – C:\FOUND.057
[2010/05/04 21:47:00 | 000,000,000 | -HSD | C] – C:\FOUND.056
[2010/05/04 21:47:00 | 000,000,000 | -HSD | C] – C:\FOUND.055
[2010/05/04 21:47:00 | 000,000,000 | -HSD | C] – C:\FOUND.054
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.053
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.052
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.051
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.050
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.049
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.048
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.047
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.046
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.045
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.044
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.043
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.042
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.041
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.040
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.039
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.038
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.037
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.036
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.035
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.034
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.033
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.032
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.031
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.030
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.029
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.028
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.027
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.026
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.025
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.024
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.023
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.022
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.021
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.020
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.019
[2010/05/04 21:46:59 | 000,000,000 | -HSD | C] – C:\FOUND.018
[2010/05/04 20:17:15 | 000,570,880 | —- | C] (OldTimer Tools) – C:\Documents and Settings\augustus able\Desktop\OTL.exe
[2010/05/02 19:47:07 | 000,012,464 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/05/02 19:40:31 | 003,558,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\moviemk.exe
[2010/05/02 19:32:59 | 000,000,000 | —D | C] – C:\Documents and Settings\augustus able\Desktop\Unused Desktop Shortcuts
========== Files - Modified Within 30 Days ==========
[2010/05/07 18:37:40 | 000,000,438 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{19EC8709-8E90-4F72-A317-CA9CE6ADC554}.job
[2010/05/07 12:06:00 | 000,088,566 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/05/07 12:05:58 | 000,013,050 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/05/07 06:54:38 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/05/07 06:54:30 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/05/07 06:52:20 | 001,835,008 | —- | M] () – C:\Documents and Settings\augustus able\ntuser.dat
[2010/05/07 06:52:14 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\augustus able\ntuser.ini
[2010/05/05 22:38:18 | 004,286,566 | -H– | M] () – C:\Documents and Settings\augustus able\Local Settings\Application Data\IconCache.db
[2010/05/04 20:18:54 | 000,293,376 | —- | M] () – C:\Documents and Settings\augustus able\Desktop\xjcbr3vl.exe
[2010/05/04 20:17:16 | 000,570,880 | —- | M] (OldTimer Tools) – C:\Documents and Settings\augustus able\Desktop\OTL.exe
[2010/05/02 20:08:56 | 000,004,507 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/05/02 20:08:54 | 000,355,086 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/05/02 20:08:54 | 000,311,604 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/05/02 20:08:54 | 000,039,992 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/05/02 19:47:16 | 000,242,896 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/05/02 19:47:08 | 000,029,512 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/05/02 19:47:08 | 000,012,464 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/05/02 19:46:14 | 000,216,200 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/05/02 19:33:36 | 000,000,104 | —- | M] () – C:\Documents and Settings\augustus able\Desktop\Shortcut to E-mail.lnk
[2010/05/02 19:33:30 | 000,000,104 | —- | M] () – C:\Documents and Settings\augustus able\Desktop\Internet.lnk
[2010/05/01 10:28:16 | 000,226,728 | R— | M] (Coupons, Inc.) – C:\WINDOWS\System32\cpnprt2.cid
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
========== Files Created - No Company Name ==========
[2010/05/04 20:18:51 | 000,293,376 | —- | C] () – C:\Documents and Settings\augustus able\Desktop\xjcbr3vl.exe
[2010/05/02 19:33:35 | 000,000,104 | —- | C] () – C:\Documents and Settings\augustus able\Desktop\Shortcut to E-mail.lnk
[2010/05/02 19:33:28 | 000,000,104 | —- | C] () – C:\Documents and Settings\augustus able\Desktop\Internet.lnk
[2009/06/15 11:52:24 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2009/05/30 23:31:45 | 000,077,824 | —- | C] () – C:\WINDOWS\System32\HPZIDS01.dll
[2006/10/22 12:22:00 | 001,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2006/10/22 12:22:00 | 001,470,464 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2006/10/22 12:22:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2006/10/22 12:22:00 | 000,581,632 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2006/10/22 12:22:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2006/10/22 12:22:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2006/10/22 12:22:00 | 000,212,992 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
========== LOP Check ==========
[2009/11/02 15:51:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Grisoft
[2009/11/02 16:05:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\Avg7
[2009/11/02 16:29:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users.WINDOWS\Application Data\avg9
[2009/11/22 16:56:54 | 000,000,000 | —D | M] – C:\Documents and Settings\augustus able\Application Data\E-centives
[2010/05/07 18:37:40 | 000,000,438 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{19EC8709-8E90-4F72-A317-CA9CE6ADC554}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2007/10/08 10:25:08 | 000,011,539 | —- | M] () – C:\ComboFix3.txt
[2010/05/07 06:54:26 | 805,306,368 | -HS- | M] () – C:\PAGEFILE.SYS
[2009/05/25 07:41:52 | 000,003,736 | —- | M] () – C:\VundoFix.txt
[2006/03/26 18:14:04 | 000,001,660 | RHS- | M] () – C:\MSDOS.SYS
[2009/05/29 23:52:24 | 000,000,282 | RHS- | M] () – C:\boot.ini
[2007/10/06 11:13:20 | 002,028,640 | —- | M] () – C:\sp1aexpress_usa.exe
[2006/03/26 18:19:08 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2000/06/08 17:00:00 | 000,110,080 | RHS- | M] () – C:\IO.SYS
[2006/03/26 18:19:08 | 000,000,194 | —- | M] () – C:\AUTOEXEC.BAT
[2006/03/26 18:09:20 | 000,241,696 | RH– | M] () – C:\CLASSES.1ST
[2006/03/26 18:19:10 | 000,000,000 | —- | M] () – C:\CONFIG.BAK
[2007/06/07 23:27:06 | 000,000,146 | —- | M] () – C:\YServer.txt
[2006/03/26 18:29:10 | 000,000,512 | -HS- | M] () – C:\BOOTSECT.DOS
[2009/05/31 16:27:06 | 000,250,048 | RHS- | M] () – C:\ntldr
[2009/05/29 23:44:40 | 000,047,564 | RHS- | M] () – C:\ntdetect.com
[2007/07/15 22:10:52 | 000,000,000 | —- | M] () – C:\CB_Server_Errors.txt
[2007/06/13 12:56:56 | 000,028,074 | —- | M] () – C:\EXIFTable.dbf
[2006/03/26 17:10:32 | 021,920,944 | —- | M] (NVIDIA Corporation) – C:\84.21_forceware_winxp2k_english_whql.exe
[2006/01/29 16:41:12 | 001,579,352 | —- | M] () – C:\HiSpeed.exe
[2009/05/24 07:48:42 | 000,006,752 | —- | M] () – C:\ComboFix.txt
[2007/07/15 22:11:02 | 000,000,786 | —- | M] () – C:\administrativeInfo.dbf
[2007/07/15 22:11:02 | 000,003,089 | —- | M] () – C:\pathnameTable.dbf
[2007/07/15 22:11:02 | 000,004,608 | —- | M] () – C:\pathnameTable.cdx
[2007/07/15 22:11:02 | 000,036,891 | —- | M] () – C:\imageTable.dbf
[2007/06/13 12:55:16 | 000,001,024 | —- | M] () – C:\imageTable.fpt
[2007/06/13 12:56:56 | 000,003,072 | —- | M] () – C:\EXIFTable.cdx
[2005/02/16 11:06:00 | 000,218,112 | —- | M] (Soeperman Enterprises Ltd.) – C:\HijackThis.exe
[2007/07/15 22:11:02 | 000,020,480 | —- | M] () – C:\imageTable.cdx
[2007/07/15 22:11:02 | 000,003,762 | —- | M] () – C:\albumTable.dbf
[2007/07/15 22:11:02 | 000,004,608 | —- | M] () – C:\albumTable.cdx
[2006/03/28 10:46:54 | 000,002,076 | —- | M] () – C:\hijackthis.log
[2007/06/13 12:49:52 | 000,000,392 | —- | M] () – C:\ROFTable.dbf
[2007/07/15 22:11:02 | 000,095,298 | —- | M] () – C:\albumImagesTable.dbf
[2007/07/15 22:11:02 | 000,012,800 | —- | M] () – C:\albumImagesTable.cdx
[2007/06/13 12:49:52 | 000,000,456 | —- | M] () – C:\keywordTable.dbf
[2007/06/13 12:49:52 | 000,004,608 | —- | M] () – C:\keywordTable.cdx
[2007/06/13 12:49:52 | 000,000,360 | —- | M] () – C:\keywordImagesTable.dbf
[2007/06/13 12:49:52 | 000,003,072 | —- | M] () – C:\ROFTable.cdx
[2007/06/13 12:49:52 | 000,006,144 | —- | M] () – C:\keywordImagesTable.cdx
[2007/06/13 12:56:56 | 000,000,378 | —- | M] () – C:\managedFolderTable.dbf
[2007/06/13 12:49:52 | 000,000,360 | —- | M] () – C:\ROFImagesTable.dbf
[2007/06/13 12:49:52 | 000,006,144 | —- | M] () – C:\ROFImagesTable.cdx
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2007/10/09 23:55:48 | 000,012,104 | —- | M] () – C:\ComboFix2.txt
[2007/10/10 01:40:56 | 000,103,370 | —- | M] () – C:\ComboFix-quarantined-files.txt
[2010/05/05 21:56:12 | 000,000,109 | —- | M] () – C:\mbam-error.txt
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2009/05/29 20:58:02 | 000,380,928 | —- | M] () – C:\WINDOWS\system32\config\system.sav
[2009/05/29 20:58:02 | 000,630,784 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/05/29 20:58:02 | 000,090,112 | —- | M] () – C:\WINDOWS\system32\config\default.sav
< %systemroot%\system32\drivers\*.sys /90 >
[2010/05/02 19:47:08 | 000,029,512 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\system32\drivers\avgmfx86.sys
[2010/05/02 19:46:14 | 000,216,200 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\system32\drivers\avgldx86.sys
[2010/05/02 19:47:16 | 000,242,896 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\system32\drivers\avgtdix.sys
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\system32\drivers\mbam.sys
[2010/02/24 08:11:08 | 000,455,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\mrxsmb.sys
[2010/02/11 07:02:16 | 000,226,880 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\tcpip6.sys
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\system32\drivers\mbamswissarmy.sys
< >
< >
< End of report >
OTL Extras logfile created on: 5/7/2010 6:55:23 PM - Run 2
OTL by OldTimer - Version 3.2.4.1 Folder = C:\Documents and Settings\augustus able\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
512.00 Mb Total Physical Memory | 240.00 Mb Available Physical Memory | 47.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 72.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 127.97 Gb Total Space | 95.01 Gb Free Space | 74.24% Space Free | Partition Type: FAT32
D: Drive not present or media not loaded
Drive E: | 654.81 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: HOME-3XQK3JVJDE
Current User Name: augustus able
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\System32\usmt\migwiz.exe" = C:\WINDOWS\System32\usmt\migwiz.exe:*:Disabled:Files and Settings Transfer Wizard – (Microsoft Corporation)
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe – ()
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Development Company, L.P.)
"C:\Program Files\AVG\AVG9\avgemc.exe" = C:\Program Files\AVG\AVG9\avgemc.exe:*:Enabled:avgemc.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe – (AVG Technologies CZ, s.r.o.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3A316611-45D1-429C-AA26-B71259C44689}" = HP Photosmart, Officejet and Deskjet 7.0.A
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{AC76BA86-7AD7-1033-7B44-A91000000001}" = Adobe Reader 9.1
"{C8753E28-2680-49BF-BD48-DD38FD086EFE}" = AiO_Scan_CDA
"{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}" = HP Product Detection
"{F2527115-B8BF-4FDB-B5DA-5AADFB7C13E1}" = The Sims Complete Collection
"{F3760724-B29D-465B-BC53-E5D72095BCC4}" = Scan
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AVG9Uninstall" = AVG Free 9.0
"Coupon Printer for Windows4.0" = Coupon Printer for Windows
"ESET Online Scanner" = ESET Online Scanner v3
"HijackThis" = HijackThis 2.0.2
"ie8" = Windows Internet Explorer 8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"NVIDIA Drivers" = NVIDIA Drivers
"Windows XP Service Pack" = Windows XP Service Pack 3
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 2/17/2010 7:18:50 PM | Computer Name = HOME-3XQK3JVJDE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid.
Error - 2/17/2010 7:18:51 PM | Computer Name = HOME-3XQK3JVJDE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid.
Error - 2/17/2010 7:18:51 PM | Computer Name = HOME-3XQK3JVJDE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid.
Error - 2/17/2010 7:18:52 PM | Computer Name = HOME-3XQK3JVJDE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid.
Error - 2/17/2010 7:18:53 PM | Computer Name = HOME-3XQK3JVJDE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid.
Error - 2/17/2010 7:18:53 PM | Computer Name = HOME-3XQK3JVJDE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid.
Error - 2/17/2010 7:18:54 PM | Computer Name = HOME-3XQK3JVJDE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid.
Error - 2/17/2010 9:38:55 PM | Computer Name = HOME-3XQK3JVJDE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid.
Error - 2/17/2010 9:38:56 PM | Computer Name = HOME-3XQK3JVJDE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid.
Error - 2/17/2010 9:38:56 PM | Computer Name = HOME-3XQK3JVJDE | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: The data is invalid.
[ System Events ]
Error - 5/5/2010 9:38:20 PM | Computer Name = HOME-3XQK3JVJDE | Source = DCOM | ID = 10000
Description = Unable to start a DCOM Server: {FB7199AB-79BF-11D2-8D94-0000F875C541}.
The
error: "%2" Happened while starting this command: C:\Program Files\Messenger\msmsgs.exe
-Embedding
Error - 5/5/2010 10:43:58 PM | Computer Name = HOME-3XQK3JVJDE | Source = DCOM | ID = 10000
Description = Unable to start a DCOM Server: {FB7199AB-79BF-11D2-8D94-0000F875C541}.
The
error: "%2" Happened while starting this command: C:\Program Files\Messenger\msmsgs.exe
-Embedding
Error - 5/5/2010 10:48:11 PM | Computer Name = HOME-3XQK3JVJDE | Source = Service Control Manager | ID = 7034
Description = The NVIDIA Display Driver Service service terminated unexpectedly.
It has done this 1 time(s).
Error - 5/5/2010 10:48:11 PM | Computer Name = HOME-3XQK3JVJDE | Source = Service Control Manager | ID = 7034
Description = The Pml Driver HPZ12 service terminated unexpectedly. It has done
this 1 time(s).
Error - 5/5/2010 10:48:11 PM | Computer Name = HOME-3XQK3JVJDE | Source = Service Control Manager | ID = 7031
Description = The AVG Free WatchDog service terminated unexpectedly. It has done
this 1 time(s). The following corrective action will be taken in 0 milliseconds:
Restart the service.
Error - 5/5/2010 10:48:12 PM | Computer Name = HOME-3XQK3JVJDE | Source = Service Control Manager | ID = 7034
Description = The AVG Free E-mail Scanner service terminated unexpectedly. It has
done this 1 time(s).
Error - 5/5/2010 11:28:57 PM | Computer Name = HOME-3XQK3JVJDE | Source = DCOM | ID = 10000
Description = Unable to start a DCOM Server: {FB7199AB-79BF-11D2-8D94-0000F875C541}.
The
error: "%2" Happened while starting this command: C:\Program Files\Messenger\msmsgs.exe
-Embedding
Error - 5/6/2010 7:46:39 PM | Computer Name = HOME-3XQK3JVJDE | Source = DCOM | ID = 10000
Description = Unable to start a DCOM Server: {FB7199AB-79BF-11D2-8D94-0000F875C541}.
The
error: "%2" Happened while starting this command: C:\Program Files\Messenger\msmsgs.exe
-Embedding
Error - 5/6/2010 7:49:40 PM | Computer Name = HOME-3XQK3JVJDE | Source = Service Control Manager | ID = 7034
Description = The AVG Free E-mail Scanner service terminated unexpectedly. It has
done this 1 time(s).
Error - 5/7/2010 7:51:52 AM | Computer Name = HOME-3XQK3JVJDE | Source = DCOM | ID = 10000
Description = Unable to start a DCOM Server: {FB7199AB-79BF-11D2-8D94-0000F875C541}.
The
error: "%2" Happened while starting this command: C:\Program Files\Messenger\msmsgs.exe
-Embedding
< End of report >