This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

computer slow, popus: reply to emeraldnzl

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Emeraldnzl,
Here is that OTL you requested.

OTL logfile created on: 6/10/2010 3:39:58 PM - Run 2
OTL by OldTimer - Version 3.2.5.3 Folder = C:\Documents and Settings\Hunter\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.00 Mb Total Physical Memory | 248.00 Mb Available Physical Memory | 48.00% Memory free
1.00 Gb Paging File | 0.00 Gb Available in Paging File | 35.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.72 Gb Total Space | 84.15 Gb Free Space | 75.32% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: RAMSEY
Current User Name: Hunter
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/06/08 09:43:50 | 000,571,904 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Hunter\Desktop\OTL.exe
PRC - [2010/06/03 09:53:26 | 002,065,248 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgtray.exe
PRC - [2010/06/03 09:53:21 | 000,515,424 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgrsx.exe
PRC - [2010/06/03 09:53:18 | 000,620,896 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgnsx.exe
PRC - [2010/06/03 09:52:02 | 000,722,784 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgcsrvx.exe
PRC - [2010/06/03 09:51:58 | 001,101,152 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgchsvx.exe
PRC - [2010/06/02 15:04:37 | 000,308,064 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG9\avgwdsvc.exe
PRC - [2009/11/18 11:09:05 | 000,030,192 | —- | M] (Google) – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
PRC - [2009/11/13 16:19:06 | 000,198,160 | —- | M] (RealNetworks, Inc.) – C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2009/03/05 16:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) – C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2008/04/13 19:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2008/02/05 14:29:20 | 000,054,512 | —- | M] (Yahoo! Inc.) – C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
PRC - [2007/07/23 12:25:20 | 000,198,184 | —- | M] (SupportSoft, Inc.) – C:\Program Files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe
PRC - [2006/08/31 16:56:08 | 000,106,546 | —- | M] () – C:\pvsw\bin\w3dbsmgr.exe
PRC - [2006/01/17 14:03:06 | 000,135,168 | —- | M] (Musicmatch, Inc.) – C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
PRC - [2006/01/17 14:03:06 | 000,086,016 | —- | M] (Musicmatch, Inc.) – C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\MMDiag.exe
PRC - [2006/01/17 14:03:06 | 000,086,016 | —- | M] (Musicmatch Inc.) – C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_server.exe
PRC - [2004/07/19 08:17:00 | 000,151,552 | —- | M] () – C:\Program Files\Picasa\PicasaMediaDetector.exe
PRC - [2003/10/29 02:06:00 | 000,024,576 | R— | M] (BVRP Software) – C:\Program Files\Digital Line Detect\DLG.exe
PRC - [2003/09/04 15:30:28 | 000,139,264 | —- | M] () – C:\Program Files\Nova Development\Greeting Card Factory Deluxe\ReminderApp.exe
PRC - [2003/04/06 01:06:58 | 000,028,672 | —- | M] (Hewlett-Packard) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
PRC - [2003/04/06 00:55:04 | 000,311,296 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposts08.exe
PRC - [2003/04/06 00:45:10 | 000,286,720 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
PRC - [2003/04/06 00:37:38 | 000,147,456 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe
PRC - [2002/04/03 01:01:00 | 000,135,264 | —- | M] (Creative Technology Ltd) – C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe


========== Modules (SafeList) ==========

MOD - [2010/06/08 09:43:50 | 000,571,904 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Hunter\Desktop\OTL.exe
MOD - [2009/11/13 16:26:00 | 000,102,400 | —- | M] (RealPlayer) – C:\Program Files\Real\RealPlayer\browserrecord\chrome\hook\rpchromebrowserrecordhelper.dll
MOD - [2009/11/13 16:19:37 | 000,499,712 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\msvcp71.dll
MOD - [2009/08/13 08:55:04 | 001,748,992 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6001.22319_x-ww_f0b4c2df\GdiPlus.dll
MOD - [2008/04/13 19:10:20 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\msscript.ocx
MOD - [2004/07/10 14:31:14 | 000,348,160 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\msvcr71.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] – – (sdCoreService)
SRV - File not found [On_Demand | Stopped] – – (sdAuxService)
SRV - [2010/06/02 15:04:37 | 000,308,064 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG9\avgwdsvc.exe – (avg9wd)
SRV - [2010/04/19 10:25:38 | 000,430,152 | —- | M] () [On_Demand | Stopped] – C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe – (AVG Security Toolbar Service)
SRV - [2009/11/18 11:09:05 | 000,030,192 | —- | M] (Google) [On_Demand | Stopped] – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe – (GoogleDesktopManager-110309-193829)
SRV - [2008/02/21 13:22:15 | 000,016,680 | —- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] – C:\Program Files\Citrix\GoToAssist\508\g2aservice.exe – (GoToAssist)
SRV - [2007/03/07 16:47:46 | 000,076,848 | —- | M] () [Disabled | Stopped] – C:\Program Files\DellSupport\brkrsvc.exe – (DSBrokerService)
SRV - [2003/08/06 16:58:26 | 001,376,360 | —- | M] (America Online, Inc.) [Disabled | Stopped] – C:\Program Files\Common Files\AOL\ACS\acsd.exe – (AOL ACS)
SRV - [2003/03/08 23:31:02 | 000,065,795 | R— | M] (HP) [Disabled | Stopped] – C:\WINDOWS\SYSTEM32\HPZipm12.exe – (Pml Driver HPZ12)
SRV - [2003/03/03 13:33:40 | 000,143,360 | —- | M] (Intel® Corporation) [Disabled | Stopped] – C:\Program Files\Intel\NCS\Sync\NetSvc.exe – (NetSvc)
SRV - [2003/01/10 17:13:04 | 000,065,536 | —- | M] (America Online, Inc.) [Disabled | Stopped] – C:\WINDOWS\wanmpsvc.exe – (WANMiniportService) WAN Miniport (ATW)
SRV - [2002/12/17 19:23:30 | 000,311,872 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlagent.EXE – (SQLAgent$MICROSOFTBCM)


========== Driver Services (SafeList) ==========

DRV - [2010/06/03 09:53:22 | 000,242,896 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\avgtdix.sys – (AvgTdiX)
DRV - [2010/06/03 09:53:19 | 000,029,584 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\avgmfx86.sys – (AvgMfx86)
DRV - [2010/06/02 15:06:55 | 000,216,200 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\avgldx86.sys – (AvgLdx86)
DRV - [2009/09/16 10:22:48 | 000,214,664 | —- | M] (McAfee, Inc.) [Kernel | System | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\mfehidk.sys – (mfehidk)
DRV - [2009/09/16 10:22:48 | 000,079,816 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\mfeavfk.sys – (mfeavfk)
DRV - [2009/09/16 10:22:48 | 000,040,552 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\mfesmfk.sys – (mfesmfk)
DRV - [2009/09/16 10:22:48 | 000,035,272 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\mfebopk.sys – (mfebopk)
DRV - [2009/09/16 10:22:14 | 000,034,248 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\mferkdk.sys – (mferkdk)
DRV - [2008/04/13 13:45:29 | 000,010,624 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\gameenum.sys – (gameenum)
DRV - [2008/04/13 13:36:39 | 000,043,008 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\System32\DRIVERS\amdagp.sys – (amdagp)
DRV - [2008/04/13 13:36:39 | 000,040,960 | —- | M] (Silicon Integrated Systems Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\System32\DRIVERS\sisagp.sys – (sisagp)
DRV - [2007/08/14 17:02:04 | 000,082,248 | —- | M] (PCTools Research Pty Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\iksyssec.sys – (IKSysSec)
DRV - [2007/08/14 17:02:02 | 000,057,672 | —- | M] (PCTools Research Pty Ltd.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\iksysflt.sys – (IKSysFlt)
DRV - [2007/08/14 17:02:00 | 000,040,264 | —- | M] (PCTools Research Pty Ltd.) [File_System | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ikfilesec.sys – (IKFileSec)
DRV - [2007/02/25 13:10:48 | 000,005,376 | –S- | M] (Gteko Ltd.) [Kernel | Auto | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\dsunidrv.sys – (dsunidrv)
DRV - [2006/10/05 17:07:28 | 000,004,736 | —- | M] (Gteko Ltd.) [Kernel | On_Demand | Stopped] – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys – (DSproct)
DRV - [2004/10/07 20:16:04 | 000,035,840 | —- | M] (Oak Technology Inc.) [Kernel | System | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\AFS2K.SYS – (AFS2K)
DRV - [2004/08/04 00:29:49 | 000,019,455 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\wvchntxx.sys – (iAimFP4)
DRV - [2004/08/04 00:29:47 | 000,012,063 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\wsiintxx.sys – (iAimFP3)
DRV - [2004/08/04 00:29:45 | 000,023,615 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\wch7xxnt.sys – (iAimTV4)
DRV - [2004/08/04 00:29:43 | 000,033,599 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\watv04nt.sys – (iAimTV3)
DRV - [2004/08/04 00:29:42 | 000,019,551 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\watv02nt.sys – (iAimTV1)
DRV - [2004/08/04 00:29:41 | 000,029,311 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\watv01nt.sys – (iAimTV0)
DRV - [2004/08/04 00:29:37 | 000,012,415 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\wadv01nt.sys – (iAimFP0)
DRV - [2004/08/04 00:29:37 | 000,012,127 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\wadv02nt.sys – (iAimFP1)
DRV - [2004/08/04 00:29:37 | 000,011,775 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\wadv05nt.sys – (iAimFP2)
DRV - [2004/08/04 00:29:36 | 000,161,020 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\i81xnt5.sys – (i81x)
DRV - [2003/11/17 15:59:20 | 000,212,224 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\HSFHWBS2.sys – (HSFHWBS2)
DRV - [2003/11/17 15:58:02 | 000,680,704 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_CNXT.sys – (winachsf)
DRV - [2003/11/17 15:56:26 | 001,042,432 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\HSF_DP.sys – (HSF_DP)
DRV - [2003/11/03 13:46:00 | 001,330,940 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\nv4_mini.sys – (nv)
DRV - [2003/08/14 10:58:12 | 001,296,384 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\P16X.sys – (P16X) Creative SB Live! Series (WDM)
DRV - [2003/08/06 01:04:00 | 000,100,373 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\SYSTEM32\dla\tfsnudfa.sys – (tfsnudfa)
DRV - [2003/08/06 01:04:00 | 000,098,068 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\SYSTEM32\dla\tfsnudf.sys – (tfsnudf)
DRV - [2003/08/06 01:04:00 | 000,083,284 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\SYSTEM32\dla\tfsnifs.sys – (tfsnifs)
DRV - [2003/08/06 01:04:00 | 000,034,837 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\SYSTEM32\dla\tfsncofs.sys – (tfsncofs)
DRV - [2003/08/06 01:04:00 | 000,025,685 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\SYSTEM32\dla\tfsnboio.sys – (tfsnboio)
DRV - [2003/08/06 01:04:00 | 000,014,229 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\SYSTEM32\dla\tfsnopio.sys – (tfsnopio)
DRV - [2003/08/06 01:04:00 | 000,006,357 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\SYSTEM32\dla\tfsnpool.sys – (tfsnpool)
DRV - [2003/08/06 01:04:00 | 000,004,117 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\SYSTEM32\dla\tfsndrct.sys – (tfsndrct)
DRV - [2003/08/06 01:04:00 | 000,002,233 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\SYSTEM32\dla\tfsndres.sys – (tfsndres)
DRV - [2003/07/31 03:21:00 | 000,084,576 | —- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\drvmcdb.sys – (drvmcdb)
DRV - [2003/07/14 11:28:40 | 000,005,621 | —- | M] (Sonic Solutions) [File_System | System | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\sscdbhk5.sys – (sscdbhk5)
DRV - [2003/07/14 11:28:22 | 000,023,219 | —- | M] (Sonic Solutions) [File_System | System | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\ssrtln.sys – (ssrtln)
DRV - [2003/06/20 02:56:00 | 000,040,448 | —- | M] (Sonic Solutions) [File_System | Auto | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\drvnddm.sys – (drvnddm)
DRV - [2003/01/10 17:13:04 | 000,033,588 | —- | M] (America Online, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\wanatw4.sys – (wanatw) WAN Miniport (ATW)
DRV - [2002/11/08 13:45:06 | 000,017,217 | —- | M] (Dell Computer Corporation) [Kernel | System | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys – (omci)
DRV - [2001/08/17 14:07:44 | 000,019,072 | —- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\System32\DRIVERS\sparrow.sys – (Sparrow)
DRV - [2001/08/17 14:07:42 | 000,030,688 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\WINDOWS\System32\DRIVERS\sym_u3.sys – (sym_u3)
DRV - [2001/08/17 14:07:40 | 000,028,384 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\WINDOWS\System32\DRIVERS\sym_hi.sys – (sym_hi)
DRV - [2001/08/17 14:07:36 | 000,032,640 | —- | M] (LSI Logic) [Kernel | Disabled | Stopped] – C:\WINDOWS\System32\DRIVERS\symc8xx.sys – (symc8xx)
DRV - [2001/08/17 14:07:34 | 000,016,256 | —- | M] (Symbios Logic Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\System32\DRIVERS\symc810.sys – (symc810)
DRV - [2001/08/17 13:57:38 | 000,016,128 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\SYSTEM32\DRIVERS\MODEMCSA.sys – (MODEMCSA)
DRV - [2001/08/17 13:52:22 | 000,036,736 | —- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\System32\DRIVERS\ultra.sys – (ultra)
DRV - [2001/08/17 13:52:20 | 000,045,312 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\System32\DRIVERS\ql12160.sys – (ql12160)
DRV - [2001/08/17 13:52:20 | 000,040,320 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\System32\DRIVERS\ql1080.sys – (ql1080)
DRV - [2001/08/17 13:52:18 | 000,049,024 | —- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\System32\DRIVERS\ql1280.sys – (ql1280)
DRV - [2001/08/17 13:52:16 | 000,179,584 | —- | M] (Mylex Corporation) [Kernel | Disabled | Stopped] – C:\WINDOWS\System32\DRIVERS\dac2w2k.sys – (dac2w2k)
DRV - [2001/08/17 13:52:12 | 000,017,280 | —- | M] (American Megatrends Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\System32\DRIVERS\mraid35x.sys – (mraid35x)
DRV - [2001/08/17 13:52:00 | 000,026,496 | —- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\System32\DRIVERS\asc.sys – (asc)
DRV - [2001/08/17 13:51:58 | 000,014,848 | —- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\System32\DRIVERS\asc3550.sys – (asc3550)
DRV - [2001/08/17 13:51:56 | 000,005,248 | —- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\System32\DRIVERS\aliide.sys – (AliIde)
DRV - [2001/08/17 13:51:54 | 000,006,656 | —- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] – C:\WINDOWS\System32\DRIVERS\cmdide.sys – (CmdIde)
DRV - [2001/08/17 12:11:06 | 000,066,591 | —- | M] (3Com Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\SYSTEM32\DRIVERS\EL90XBC5.SYS – (EL90XBC)
DRV - [1999/12/17 01:00:00 | 000,006,752 | —- | M] (Creative Technology Ltd.) [Kernel | Auto | Running] – C:\WINDOWS\SYSTEM32\PFMODNT.SYS – (PfModNT)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:5555



O1 HOSTS File: ([2010/06/09 15:38:14 | 000,000,098 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx ()
O2 - BHO: (SpywareBlock Class) - {0A87E45F-537A-40B4-B812-E2544C21A09F} - C:\Program Files\SpyCatcher\SCActiveBlock.dll File not found
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (PCTools Site Guard) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll File not found
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\SYSTEM32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar3.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (PCTools Browser Monitor) - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll File not found
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No CLSID value found.
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar3.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar3.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [diagent] C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
O4 - HKLM..\Run: [HelpCenter4.1] C:\Program Files\Bellsouth\HelpCenter40b\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [LifeScape Media Detector] C:\Program Files\Picasa\PicasaMediaDetector.exe ()
O4 - HKLM..\Run: [mm_server] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_server.exe (Musicmatch Inc.)
O4 - HKLM..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe (Musicmatch, Inc.)
O4 - HKLM..\Run: [ReminderApp] C:\Program Files\Nova Development\Greeting Card Factory Deluxe\ReminderApp.exe ()
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdateManager] C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe (Sonic Solutions)
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKCU..\Run: [MoneyAgent] C:\Program Files\Microsoft Money\System\mnyexpr.exe (Microsoft Corp.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe (Hewlett-Packard)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\officejet 6100.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Pervasive.SQL Workgroup Engine.lnk = C:\pvsw\bin\w3dbsmgr.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe (Yahoo! Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: google.com ([mail] http in Trusted sites)
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Domains: yahoo.com ([login] https in Trusted sites)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1229632777906 (WUWebControl Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2)
O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/flas…ent/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://www.popcap.com/webgames/popcaploader_v10.cab (PopCapLoader Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\508\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\508\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Hunter\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Hunter\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/09/03 08:59:58 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\SYSTEM32\IAS [2004/05/11 22:50:04 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\SYSTEM32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.ctmp3 - C:\WINDOWS\SYSTEM32\ctmp3.acm (Creative Technology Ltd.)
Drivers32: msacm.iac2 - C:\WINDOWS\System32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\SYSTEM32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\TSSOFT32.ACM (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\IR32_32.DLL ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\IR32_32.DLL ()
Drivers32: vidc.iv41 - ir41_32.dll File not found
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.yvu9 - iyvu9_32.dll File not found
Drivers32: wave1 - C:\WINDOWS\System32\SERWVDRV.DLL (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17746534284132352)

========== Files/Folders - Created Within 30 Days ==========

[2010/06/09 15:34:23 | 000,000,000 | —D | C] – C:\_OTL
[2010/06/08 09:44:48 | 000,571,904 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Hunter\Desktop\OTL.exe
[2010/06/04 10:26:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Hunter\Application Data\Malwarebytes
[2010/06/04 10:24:53 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/06/04 10:24:51 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/06/04 10:24:50 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/06/04 10:24:50 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/06/02 16:29:26 | 000,000,000 | -H-D | C] – C:\$AVG
[2010/06/02 15:06:59 | 000,012,464 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/06/02 15:06:56 | 000,242,896 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/06/02 15:06:55 | 000,216,200 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/06/02 15:06:49 | 000,029,584 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/06/02 15:06:33 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\Avg
[2010/06/02 15:06:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2010/06/02 15:02:48 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2010/06/02 15:02:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\avg9
[2010/06/02 10:03:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Hunter\Local Settings\Application Data\uaisauqes
[2010/05/28 10:15:03 | 000,000,000 | —D | C] – C:\Program Files\Alwil Software
[2010/05/28 10:15:03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010/05/28 09:20:28 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Windows Server
[2010/05/26 08:16:54 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/05/26 08:16:33 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/05/25 16:06:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Hunter\Local Settings\Application Data\Windows Server
[2010/05/25 07:56:41 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Hunter\Recent
[2010/05/25 07:42:56 | 000,000,000 | —D | C] – C:\Config.Msi
[2004/05/11 23:27:03 | 000,065,536 | —- | C] ( ) – C:\WINDOWS\System32\A3d.dll
[1 C:\Documents and Settings\Hunter\My Documents\*.tmp files -> C:\Documents and Settings\Hunter\My Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/06/10 15:13:12 | 000,000,494 | —- | M] () – C:\hpfr5550.xml
[2010/06/10 14:59:33 | 000,002,497 | —- | M] () – C:\Documents and Settings\Hunter\Desktop\Word.lnk
[2010/06/10 14:49:04 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/06/10 14:11:12 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2010/06/10 12:30:59 | 000,001,170 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2010/06/10 12:28:23 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/06/10 12:28:17 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/06/10 12:28:11 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2010/06/10 12:28:10 | 535,891,968 | -HS- | M] () – C:\hiberfil.sys
[2010/06/10 12:27:07 | 007,634,944 | —- | M] () – C:\Documents and Settings\Hunter\ntuser.dat
[2010/06/10 12:27:07 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Hunter\NTUSER.INI
[2010/06/10 09:10:53 | 060,896,297 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/06/10 09:03:40 | 000,002,521 | —- | M] () – C:\Documents and Settings\Hunter\Desktop\Outlook.lnk
[2010/06/09 15:38:14 | 000,000,098 | —- | M] () – C:\WINDOWS\System32\drivers\ETC\Hosts
[2010/06/09 13:22:21 | 000,013,824 | —- | M] () – C:\Documents and Settings\Hunter\My Documents\CanDo Rent Roll.xls
[2010/06/08 09:43:50 | 000,571,904 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Hunter\Desktop\OTL.exe
[2010/06/08 09:31:48 | 000,002,449 | —- | M] () – C:\Documents and Settings\Hunter\Desktop\HiJackThis.lnk
[2010/06/04 10:24:58 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/06/03 09:53:22 | 000,242,896 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/06/03 09:53:19 | 000,029,584 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2010/06/02 23:44:00 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/06/02 15:07:03 | 000,113,461 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2010/06/02 15:07:02 | 000,001,507 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG Free 9.0.lnk
[2010/06/02 15:07:01 | 000,012,464 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/06/02 15:06:55 | 000,216,200 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/06/02 14:46:44 | 000,002,577 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2010/05/26 16:26:33 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/05/25 08:57:26 | 000,001,915 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2010/05/18 16:22:25 | 003,178,178 | -H– | M] () – C:\Documents and Settings\Hunter\Local Settings\Application Data\IconCache.db
[1 C:\Documents and Settings\Hunter\My Documents\*.tmp files -> C:\Documents and Settings\Hunter\My Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/06/09 13:22:21 | 000,013,824 | —- | C] () – C:\Documents and Settings\Hunter\My Documents\CanDo Rent Roll.xls
[2010/06/07 09:21:12 | 000,002,449 | —- | C] () – C:\Documents and Settings\Hunter\Desktop\HiJackThis.lnk
[2010/06/04 14:51:29 | 535,891,968 | -HS- | C] () – C:\hiberfil.sys
[2010/06/04 10:24:58 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/06/02 15:07:03 | 000,113,461 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2010/06/02 15:07:02 | 000,001,507 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AVG Free 9.0.lnk
[2010/06/02 15:06:33 | 060,896,297 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/05/26 16:25:58 | 007,634,944 | —- | C] () – C:\Documents and Settings\Hunter\ntuser.dat
[2010/05/25 17:03:17 | 000,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2010/05/25 08:57:26 | 000,001,915 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2009/12/17 15:03:30 | 000,000,148 | —- | C] () – C:\WINDOWS\dellstat.ini
[2009/12/17 15:02:47 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\dlbcvs.dll
[2009/12/17 15:02:44 | 000,000,373 | —- | C] () – C:\WINDOWS\System32\dlbccoin.ini
[2008/06/16 15:34:50 | 000,240,595 | -HS- | C] () – C:\WINDOWS\System32\AIhggfii.ini
[2008/06/16 09:38:29 | 000,244,397 | -HS- | C] () – C:\WINDOWS\System32\cMSrrBeg.ini
[2008/06/16 08:32:32 | 000,238,549 | -HS- | C] () – C:\WINDOWS\System32\EhhjQXbc.ini
[2008/05/19 08:47:54 | 000,000,118 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2007/12/06 11:47:01 | 000,000,080 | RHS- | C] () – C:\WINDOWS\System32\5D520C8D8C.dll
[2007/11/27 09:41:45 | 000,785,250 | -HS- | C] () – C:\WINDOWS\System32\bdadxhvn.ini
[2007/11/26 09:39:02 | 000,785,190 | -HS- | C] () – C:\WINDOWS\System32\fagngxji.ini
[2007/11/21 14:14:00 | 000,780,363 | -HS- | C] () – C:\WINDOWS\System32\dnnnllpm.ini
[2007/11/20 14:04:30 | 000,689,223 | -HS- | C] () – C:\WINDOWS\System32\uuglggoi.ini
[2007/11/20 13:43:44 | 000,689,181 | -HS- | C] () – C:\WINDOWS\System32\qqrkkjca.ini
[2007/11/19 13:09:42 | 000,685,703 | -HS- | C] () – C:\WINDOWS\System32\ephckuls.ini
[2007/11/16 14:11:59 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\sys_dll.dll
[2007/11/16 10:51:12 | 000,675,260 | -HS- | C] () – C:\WINDOWS\System32\ulegnsuc.ini
[2007/11/16 08:49:46 | 000,675,587 | -HS- | C] () – C:\WINDOWS\System32\yydrvoue.ini
[2007/11/15 08:47:39 | 000,675,440 | -HS- | C] () – C:\WINDOWS\System32\gfhxdkqb.ini
[2007/11/14 08:51:33 | 000,670,544 | -HS- | C] () – C:\WINDOWS\System32\iubuvsdn.ini
[2006/07/24 15:15:14 | 000,040,448 | —- | C] () – C:\WINDOWS\System32\BJAXSecurityManager.dll
[2006/07/24 15:15:08 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\BJInstaller.dll
[2006/05/10 16:06:34 | 000,001,724 | —- | C] () – C:\WINDOWS\PCW140.ini
[2005/10/13 13:43:39 | 000,001,370 | —- | C] () – C:\WINDOWS\FASPEACH.INI
[2005/05/10 07:39:47 | 000,044,544 | —- | C] () – C:\WINDOWS\System32\gif89.dll
[2005/05/10 07:39:38 | 000,000,525 | —- | C] () – C:\WINDOWS\SIERRA.INI
[2004/07/13 15:35:48 | 000,001,598 | —- | C] () – C:\WINDOWS\PCW130.INI_upg2007
[2004/06/04 15:00:10 | 000,004,019 | —- | C] () – C:\WINDOWS\BPGLLINK.INI
[2004/05/24 13:23:02 | 000,018,250 | —- | C] () – C:\WINDOWS\cdPlayer.ini
[2004/05/24 09:48:08 | 000,172,032 | —- | C] () – C:\WINDOWS\System32\rsUtil.dll
[2004/05/11 23:44:44 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2004/05/11 23:34:29 | 000,000,588 | —- | C] () – C:\WINDOWS\ODBC.INI
[2004/05/11 23:27:16 | 000,000,231 | —- | C] () – C:\WINDOWS\AC3API.INI
[2004/05/11 23:27:03 | 000,047,616 | —- | C] () – C:\WINDOWS\System32\P16X.dll
[2004/05/11 23:27:03 | 000,002,158 | —- | C] () – C:\WINDOWS\System32\P16X.ini
[2004/05/11 23:27:03 | 000,000,026 | —- | C] () – C:\WINDOWS\System32\ctzapxx.ini
[2004/05/11 23:27:02 | 000,002,572 | —- | C] () – C:\WINDOWS\MIXDEF.INI
[2004/05/11 23:27:02 | 000,000,064 | —- | C] () – C:\WINDOWS\P16x.ini
[2004/05/11 23:26:34 | 000,000,245 | —- | C] () – C:\WINDOWS\SBWIN.INI
[2004/05/11 23:25:52 | 000,000,701 | —- | C] () – C:\WINDOWS\wininit.ini
[2004/05/11 23:22:50 | 000,000,882 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/05/11 23:09:17 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2004/05/11 22:54:48 | 000,000,547 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2003/11/20 13:39:58 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2003/03/08 23:31:04 | 000,561,152 | R— | C] () – C:\WINDOWS\System32\hpotscl.dll
[2003/02/18 09:27:58 | 000,003,521 | —- | C] () – C:\WINDOWS\PFA110.ini
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2000/10/25 20:15:00 | 000,017,920 | —- | C] () – C:\WINDOWS\System32\Implode.dll
[1999/03/30 09:53:50 | 000,000,793 | —- | C] () – C:\WINDOWS\BTI.INI
[1999/03/11 23:00:00 | 000,299,008 | —- | C] () – C:\WINDOWS\System32\Crutl14.dll
[1980/01/01 00:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll

========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2002/09/03 08:59:58 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2006/07/24 15:15:27 | 022,091,050 | —- | M] () – C:\BellSouthIW.re~
[2007/09/04 08:32:09 | 000,000,211 | RHS- | M] () – C:\BOOT.INI
[2002/09/03 08:38:46 | 000,000,512 | -HS- | M] () – C:\BOOTSECT.DOS
[2007/11/27 10:43:00 | 000,012,760 | —- | M] () – C:\ComboFix.txt
[2002/09/03 08:59:58 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2004/05/11 22:59:36 | 000,005,679 | RH– | M] () – C:\DELL.SDR
[2007/04/11 09:52:48 | 000,000,101 | —- | M] () – C:\DownloadLog.txt
[2010/05/28 09:29:23 | 000,000,270 | —- | M] () – C:\feed.txt
[2010/06/10 12:28:10 | 535,891,968 | -HS- | M] () – C:\hiberfil.sys
[2010/06/10 15:13:12 | 000,000,494 | —- | M] () – C:\hpfr5550.xml
[2002/09/03 08:59:58 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2004/05/11 23:28:32 | 000,000,864 | -H– | M] () – C:\IPH.PH
[2002/01/05 04:48:16 | 000,974,848 | —- | M] (Microsoft Corporation) – C:\mfc70.dll
[2002/01/05 04:36:38 | 000,964,608 | —- | M] (Microsoft Corporation) – C:\mfc70u.dll
[2002/09/03 08:59:58 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/08/23 09:07:17 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/12/22 09:04:19 | 000,250,048 | RHS- | M] () – C:\NTLDR
[2007/02/07 15:44:00 | 000,040,105 | —- | M] () – C:\P9install.log
[2010/06/10 12:28:08 | 805,306,368 | -HS- | M] () – C:\pagefile.sys
[2007/11/19 13:03:12 | 000,004,427 | —- | M] () – C:\rapport.txt
[2010/06/04 10:22:38 | 000,000,427 | —- | M] () – C:\rkill.log
[2007/11/21 14:31:34 | 000,000,810 | —- | M] () – C:\VundoFix.txt
[2008/01/30 08:31:09 | 000,000,150 | —- | M] () – C:\YServer.txt

< %systemroot%\system32\Spool\prtprocs\w32x86\*.dll >
[2003/07/29 08:27:40 | 000,078,336 | —- | M] () – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\DLBCPP5C.DLL
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\filterpipelineprintproc.dll
[2007/04/09 14:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\mdippr.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2002/09/03 08:47:18 | 000,094,208 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.SAV
[2002/09/03 08:47:18 | 000,602,112 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.SAV
[2002/09/03 08:47:18 | 000,380,928 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.SAV

< %systemroot%\system32\user32.dll /md5 >
[2008/04/13 19:12:08 | 000,578,560 | —- | M] (Microsoft Corporation) MD5=B26B135FF1B9F60C9388B4A7D16F600B – C:\WINDOWS\SYSTEM32\user32.dll

< %systemroot%\system32\ws2_32.dll /md5 >
[2008/04/13 19:12:10 | 000,082,432 | —- | M] (Microsoft Corporation) MD5=2CCC474EB85CEAA3E1FA1726580A3E5A – C:\WINDOWS\SYSTEM32\ws2_32.dll

========== Alternate Data Streams ==========

@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI