S3ymour
Topic Starter
When using google or other search engines as well as some of my favorites I'm randomly being redirected to a link that appears as facebook.com/(original site linke) but appears as a myspace page. Attached below is my hijack this log and my OTL Logs:
***********************************************
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:38:46 AM, on 7/16/2010
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18928)
Boot mode: Normal
Running processes:
C:\Users\S3ymour\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files (x86)\Steam\steam.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe
C:\Program Files (x86)\AVG\AVG9\avgtray.exe
C:\Program Files (x86)\TheStubware\TheStubware.exe
C:\Users\S3ymour\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\S3ymour\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\S3ymour\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\S3ymour\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Users\S3ymour\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\S3ymour\Downloads\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?
LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common
Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)
\AVG\AVG9\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot -
Search & Destroy\SDHelper.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)
\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [HDAudDeck] "C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" -r
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Monitor] "C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe"
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~2\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [TheStubware] "C:\Program Files (x86)\TheStubware\TheStubware.exe" -Startup
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Google Update] "C:\Users\S3ymour\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [Silverlight] "C:\Users\S3ymour\AppData\Roaming\Silverlight.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL
SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-717218054-4078819399-4181070963-501\..\Run: [Sidebar] C:\Program Files\Windows
Sidebar\sidebar.exe /autoRun (User 'Guest')
O4 - S-1-5-21-717218054-4078819399-4181070963-501 Startup: OpenOffice.org 3.2.lnk = C:\Program Files (x86)
\OpenOffice.org 3\program\quickstart.exe (User 'Guest')
O4 - S-1-5-21-717218054-4078819399-4181070963-501 User Startup: OpenOffice.org 3.2.lnk = C:\Program Files (x86)
\OpenOffice.org 3\program\quickstart.exe (User 'Guest')
O4 - Startup: OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search &
Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} -
C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} -
C:\Windows\system32\browseui.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file
missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: WebEx Service Host for Support Center (atashost) - WebEx Communications, Inc. - C:\Windows\SysWOW64
\atashost.exe
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9
\avgemc.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9
\avgwdsvc.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LeapFrog Connect Device Service - LeapFrog Enterprises, Inc. - C:\Program Files (x86)
\LeapFrog\LeapFrog Connect\CommandService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe
(file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32
\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe
(file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file
missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)
\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file
missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe
(file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe
(file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common
Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32
\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file
missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file
missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32
\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program
Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
–
End of file - 8796 bytes
*******************************************************************
OTL logfile created on: 7/16/2010 10:40:38 AM - Run 1
OTL by OldTimer - Version 3.2.9.0 Folder = C:\Users\S3ymour\Downloads
64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18928)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
8.00 Gb Total Physical Memory | 6.00 Gb Available Physical Memory | 71.00% Memory free
16.00 Gb Paging File | 13.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 596.17 Gb Total Space | 459.50 Gb Free Space | 77.08% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: S3YMOUR-PC
Current User Name: S3ymour
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2010/07/16 10:40:25 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\S3ymour\Downloads\OTL.exe
PRC - [2010/07/16 10:27:38 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\S3ymour\Downloads\HiJackThis.exe
PRC - [2010/07/15 18:43:33 | 000,723,296 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG9\avgcsrvx.exe
PRC - [2010/07/15 18:43:15 | 002,065,760 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG9\avgtray.exe
PRC - [2010/07/15 18:42:54 | 000,921,440 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG9\avgemc.exe
PRC - [2010/07/15 18:42:45 | 000,308,136 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe
PRC - [2010/06/28 22:27:23 | 000,945,720 | —- | M] (Google Inc.) – C:\Users\S3ymour\AppData\Local\Google\Chrome\Application\chrome.exe
PRC - [2010/05/08 10:17:47 | 001,238,352 | —- | M] (Valve Corporation) – C:\Program Files (x86)\Steam\steam.exe
PRC - [2010/04/11 16:34:30 | 000,781,312 | —- | M] (TheStubware.com) – C:\Program Files (x86)\TheStubware\TheStubware.exe
PRC - [2010/02/02 00:10:14 | 007,418,368 | —- | M] (OpenOffice.org) – C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
PRC - [2010/02/02 00:10:10 | 007,424,000 | —- | M] (OpenOffice.org) – C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
PRC - [2010/01/11 15:21:52 | 000,490,216 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
PRC - [2009/11/10 10:14:38 | 000,443,728 | —- | M] (LeapFrog Enterprises, Inc.) – C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe
PRC - [2009/11/10 09:28:06 | 001,131,808 | —- | M] (LeapFrog Enterprises, Inc.) – C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe
PRC - [2009/03/06 12:59:12 | 000,020,376 | —- | M] (WebEx Communications, Inc.) – C:\Windows\SysWOW64\atashost.exe
PRC - [2009/01/26 15:31:16 | 002,144,088 | RHS- | M] (Safer Networking Limited) – C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2009/01/26 15:31:10 | 001,153,368 | —- | M] (Safer Networking Ltd.) – C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
========== Modules (SafeList) ==========
MOD - [2010/07/16 10:40:25 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\S3ymour\Downloads\OTL.exe
MOD - [2008/01/20 22:50:01 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\msscript.ocx
MOD - [2008/01/20 22:48:06 | 001,684,480 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2009/06/14 23:12:12 | 000,203,264 | —- | M] () [Auto | Running] – C:\Windows\SysNative\atiesrxx.exe – (AMD External Events Utility)
SRV:64bit: - [2008/01/20 22:47:32 | 000,383,544 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2010/07/15 18:42:54 | 000,921,440 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files (x86)\AVG\AVG9\avgemc.exe – (avg9emc)
SRV - [2010/07/15 18:42:45 | 000,308,136 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe – (avg9wd)
SRV - [2010/03/26 17:43:04 | 000,332,720 | —- | M] (Valve Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Steam\SteamService.exe – (Steam Client Service)
SRV - [2010/03/18 14:27:14 | 001,020,768 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe – (WPFFontCache_v0400)
SRV - [2010/03/18 14:27:14 | 000,138,576 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_64)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/11/10 09:28:06 | 001,131,808 | —- | M] (LeapFrog Enterprises, Inc.) [Auto | Running] – C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe – (LeapFrog Connect Device Service)
SRV - [2009/03/06 12:59:12 | 000,020,376 | —- | M] (WebEx Communications, Inc.) [Auto | Running] – C:\Windows\SysWOW64\atashost.exe – (atashost)
SRV - [2009/01/26 15:31:10 | 001,153,368 | —- | M] (Safer Networking Ltd.) [Auto | Running] – C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe – (SBSDWSCService)
========== Driver Services (SafeList) ==========
DRV:64bit: - File not found [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\nwlnkfwd.sys – (NwlnkFwd)
DRV:64bit: - File not found [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\nwlnkflt.sys – (NwlnkFlt)
DRV:64bit: - File not found [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\ipinip.sys – (IpInIp)
DRV:64bit: - File not found [Kernel | System | Stopped] – C:\Windows\SysNative\drivers\ActiveMonitor.SYS – (ActiveMonitor)
DRV:64bit: - [2010/07/15 18:44:31 | 000,317,520 | —- | M] () [Kernel | System | Running] – C:\Windows\SysNative\Drivers\avgtdia.sys – (AvgTdiA)
DRV:64bit: - [2010/07/15 18:44:25 | 000,269,904 | —- | M] () [Kernel | System | Running] – C:\Windows\SysNative\Drivers\avgldx64.sys – (AvgLdx64)
DRV:64bit: - [2010/07/15 18:44:23 | 000,035,536 | —- | M] () [File_System | System | Running] – C:\Windows\SysNative\Drivers\avgmfx64.sys – (AvgMfx64)
DRV:64bit: - [2009/11/10 09:27:06 | 000,024,576 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\FlyUsb.sys – (FlyUsb)
DRV:64bit: - [2009/06/14 23:48:02 | 006,031,872 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\atikmdag.sys – (atikmdag)
DRV:64bit: - [2009/06/04 08:20:48 | 000,113,168 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\AtiHdmi.sys – (AtiHdmiService)
DRV:64bit: - [2009/05/05 01:30:28 | 000,016,440 | —- | M] () [Kernel | Boot | Running] – C:\Windows\SysNative\DRIVERS\AtiPcie.sys – (AtiPcie) AMD PCI Express (3GIO)
DRV:64bit: - [2009/04/28 14:26:52 | 001,152,000 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\viahduaa.sys – (VIAHdAudAddService)
DRV:64bit: - [2008/12/12 02:41:44 | 000,188,416 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\Rtlh64.sys – (RTL8169)
DRV:64bit: - [2008/01/20 22:47:28 | 000,046,080 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\wpdusb.sys – (WpdUsb)
DRV:64bit: - [2008/01/20 22:46:57 | 000,022,528 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\WSDPrint.sys – (WSDPrintDevice)
DRV:64bit: - [2008/01/20 22:46:53 | 001,523,712 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\VSTDPV6.SYS – (VST64_DPV)
DRV:64bit: - [2008/01/20 22:46:53 | 000,724,480 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\VSTCNXT6.SYS – (winachsf)
DRV:64bit: - [2008/01/20 22:46:53 | 000,392,704 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\VSTBS26.SYS – (VST64HWBS2)
DRV:64bit: - [2006/09/18 17:36:24 | 000,000,308 | —- | M] () [File_System | On_Demand | Running] – C:\Windows\SysNative\Wbem\ntfs.mof – (Ntfs)
DRV - [2010/04/10 17:05:56 | 000,009,728 | —- | M] (TheStubware.com) [Kernel | Boot | Stopped] – C:\Windows\SysWow64\drivers\TheStubwareDriver.SYS – (TheStubwareDriver)
DRV - [2010/04/10 17:01:56 | 000,044,032 | —- | M] (TheStubware.com) [Kernel | System | Stopped] – C:\Windows\SysWOW64\drivers\ActiveMonitor.SYS – (ActiveMonitor)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: ([2006/09/18 17:37:24 | 000,000,761 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files (x86)\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4 - HKLM..\Run: [Monitor] C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe (LeapFrog Enterprises, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TheStubware] C:\Program Files (x86)\TheStubware\TheStubware.exe (TheStubware.com)
O4 - HKCU..\Run: [Silverlight] C:\Users\S3ymour\AppData\Roaming\Silverlight.exe ()
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe File not found
O4 - Startup: C:\Users\S3ymour\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed] [removed]
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - AppInit_DLLs: (avgrssta.dll) - C:\Windows\SysNative\avgrssta.dll ()
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\S3ymour\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\S3ymour\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010/07/15 19:19:19 | 000,000,000 | -H-D | C] – C:\$AVG
[2010/07/15 19:12:38 | 000,044,032 | —- | C] (TheStubware.com) – C:\Windows\SysWow64\drivers\ActiveMonitor.SYS
[2010/07/15 19:12:38 | 000,009,728 | —- | C] (TheStubware.com) – C:\Windows\SysWow64\drivers\TheStubwareDriver.SYS
[2010/07/15 19:12:38 | 000,000,000 | —D | C] – C:\Program Files (x86)\TheStubware
[2010/07/15 19:09:57 | 000,000,000 | —D | C] – C:\ProgramData\TEMP
[2010/07/15 19:09:51 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2010/07/15 19:09:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spybot - Search & Destroy
[2010/07/15 19:09:40 | 000,118,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSSTDFMT.DLL
[2010/07/15 19:09:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\SpywareBlaster
[2010/07/15 18:53:49 | 000,000,000 | —D | C] – C:\Users\S3ymour\AppData\Roaming\QuickScan
[2010/07/15 18:44:22 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\Avg
[2010/07/15 18:41:01 | 000,000,000 | —D | C] – C:\Program Files (x86)\AVG
[2010/07/15 18:40:42 | 000,000,000 | —D | C] – C:\ProgramData\avg9
[2010/06/25 03:01:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft.NET
[2010/06/23 13:28:34 | 000,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mpg2splt.ax
[2010/06/23 13:28:34 | 000,080,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSNP.ax
[2010/06/23 13:28:31 | 000,428,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\EncDec.dll
[2010/06/23 13:28:31 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisdecd.dll
[2010/06/23 13:28:31 | 000,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisrndr.ax
[2010/06/23 13:28:18 | 001,130,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dfshim.dll
[2010/06/23 13:28:18 | 000,295,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHost.exe
[2010/06/23 13:28:18 | 000,099,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHostProxy.dll
[2010/06/23 13:28:18 | 000,049,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netfxperf.dll
[2010/06/23 08:45:04 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Apphlpdm.dll
[2010/06/23 08:45:03 | 004,240,384 | —- | C] (Microsoft) – C:\Windows\SysWow64\GameUXLegacyGDFs.dll
========== Files - Modified Within 30 Days ==========
[2010/07/16 10:40:53 | 002,097,152 | -HS- | M] () – C:\Users\S3ymour\NTUSER.DAT
[2010/07/16 10:35:18 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/07/16 10:35:18 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/07/16 10:30:34 | 000,000,734 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts.new
[2010/07/16 10:13:59 | 000,000,916 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-717218054-4078819399-4181070963-1000UA.job
[2010/07/16 10:13:08 | 000,524,288 | -HS- | M] () – C:\Users\S3ymour\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TMContainer00000000000000000001.regtrans-ms
[2010/07/16 10:13:08 | 000,065,536 | -HS- | M] () – C:\Users\S3ymour\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TM.blf
[2010/07/16 09:37:33 | 062,044,352 | —- | M] () – C:\Windows\SysNative\drivers\Avg\incavi.avm
[2010/07/16 08:02:16 | 001,987,940 | -H– | M] () – C:\Users\S3ymour\AppData\Local\IconCache.db
[2010/07/16 01:14:00 | 000,000,864 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-717218054-4078819399-4181070963-1000Core.job
[2010/07/16 01:13:01 | 000,000,939 | —- | M] () – C:\Windows\SysNative\nt.bat
[2010/07/15 19:37:56 | 001,033,616 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/07/15 19:37:56 | 000,250,638 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/07/15 19:37:56 | 000,005,534 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/07/15 19:31:34 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/07/15 19:31:32 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/07/15 19:12:39 | 000,000,882 | —- | M] () – C:\Users\S3ymour\Desktop\TheStubware.lnk
[2010/07/15 19:10:11 | 000,001,121 | —- | M] () – C:\Users\S3ymour\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/07/15 19:09:44 | 000,000,842 | —- | M] () – C:\Users\S3ymour\Desktop\SpywareBlaster.lnk
[2010/07/15 18:44:33 | 000,013,048 | —- | M] () – C:\Windows\SysNative\avgrssta.dll
[2010/07/15 18:44:33 | 000,001,689 | —- | M] () – C:\Users\Public\Desktop\AVG Free 9.0.lnk
[2010/07/15 18:44:31 | 000,317,520 | —- | M] () – C:\Windows\SysNative\drivers\avgtdia.sys
[2010/07/15 18:44:25 | 000,269,904 | —- | M] () – C:\Windows\SysNative\drivers\avgldx64.sys
[2010/07/15 18:44:23 | 000,035,536 | —- | M] () – C:\Windows\SysNative\drivers\avgmfx64.sys
[2010/07/15 18:44:22 | 000,113,461 | —- | M] () – C:\Windows\SysNative\drivers\Avg\iavichjw.avm
[2010/07/13 20:45:27 | 000,119,239 | —- | M] () – C:\Users\S3ymour\Documents\Verizon Wireless - Pay Bill Confirmation.pdf
[2010/07/07 22:03:06 | 000,000,680 | —- | M] () – C:\Users\S3ymour\AppData\Local\d3d9caps.dat
[2010/06/29 19:26:22 | 000,001,917 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/06/25 11:32:24 | 000,074,716 | —- | M] () – C:\Users\S3ymour\Documents\Volkswagen Credit – One-time Payment Confirmation.pdf
[2010/06/21 18:00:20 | 000,019,981 | —- | M] () – C:\Users\S3ymour\Documents\rubber band trick.odt
========== Files Created - No Company Name ==========
[2010/07/15 19:12:39 | 000,000,882 | —- | C] () – C:\Users\S3ymour\Desktop\TheStubware.lnk
[2010/07/15 19:10:11 | 000,001,121 | —- | C] () – C:\Users\S3ymour\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/07/15 19:09:44 | 000,000,842 | —- | C] () – C:\Users\S3ymour\Desktop\SpywareBlaster.lnk
[2010/07/15 18:44:33 | 000,001,689 | —- | C] () – C:\Users\Public\Desktop\AVG Free 9.0.lnk
[2010/07/15 18:44:31 | 000,013,048 | —- | C] () – C:\Windows\SysNative\avgrssta.dll
[2010/07/15 18:44:30 | 000,317,520 | —- | C] () – C:\Windows\SysNative\drivers\avgtdia.sys
[2010/07/15 18:44:24 | 000,269,904 | —- | C] () – C:\Windows\SysNative\drivers\avgldx64.sys
[2010/07/15 18:44:22 | 062,044,352 | —- | C] () – C:\Windows\SysNative\drivers\Avg\incavi.avm
[2010/07/15 18:44:22 | 000,113,461 | —- | C] () – C:\Windows\SysNative\drivers\Avg\iavichjw.avm
[2010/07/15 18:44:22 | 000,035,536 | —- | C] () – C:\Windows\SysNative\drivers\avgmfx64.sys
[2010/07/04 19:28:02 | 000,143,360 | —- | C] () – C:\Windows\STARTME.exe
[2010/07/04 19:28:02 | 000,143,360 | —- | C] () – C:\STARTME.exe
[2010/06/29 19:26:22 | 000,001,917 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/06/25 11:32:22 | 000,074,716 | —- | C] () – C:\Users\S3ymour\Documents\Volkswagen Credit – One-time Payment Confirmation.pdf
[2010/06/23 13:28:34 | 000,227,328 | —- | C] () – C:\Windows\SysNative\mpg2splt.ax
[2010/06/23 13:28:34 | 000,101,376 | —- | C] () – C:\Windows\SysNative\MSNP.ax
[2010/06/23 13:28:31 | 000,558,592 | —- | C] () – C:\Windows\SysNative\EncDec.dll
[2010/06/23 13:28:31 | 000,375,808 | —- | C] () – C:\Windows\SysNative\psisdecd.dll
[2010/06/23 13:28:31 | 000,289,792 | —- | C] () – C:\Windows\SysNative\psisrndr.ax
[2010/06/23 13:28:18 | 001,942,856 | —- | C] () – C:\Windows\SysNative\dfshim.dll
[2010/06/23 13:28:18 | 000,444,752 | —- | C] () – C:\Windows\SysNative\mscoree.dll
[2010/06/23 13:28:18 | 000,320,352 | —- | C] () – C:\Windows\SysNative\PresentationHost.exe
[2010/06/23 13:28:18 | 000,109,912 | —- | C] () – C:\Windows\SysNative\PresentationHostProxy.dll
[2010/06/23 13:28:18 | 000,048,960 | —- | C] () – C:\Windows\SysNative\netfxperf.dll
[2010/06/23 08:45:04 | 000,032,256 | —- | C] () – C:\Windows\SysNative\Apphlpdm.dll
[2010/06/23 08:45:03 | 004,240,384 | —- | C] () – C:\Windows\SysNative\GameUXLegacyGDFs.dll
[2010/06/21 18:00:17 | 000,019,981 | —- | C] () – C:\Users\S3ymour\Documents\rubber band trick.odt
[2010/05/03 19:19:31 | 000,000,110 | —- | C] () – C:\Windows\{7E7D778E-121D-4BBD-BA29-FAA81B9FBD8C}_WiseFW.ini
[2009/11/06 10:58:04 | 000,178,975 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2008/01/20 22:50:05 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2008/01/20 22:49:49 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
< End of report >
**********************************
OTL Extras logfile created on: 7/16/2010 10:40:38 AM - Run 1
OTL by OldTimer - Version 3.2.9.0 Folder = C:\Users\S3ymour\Downloads
64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18928)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
8.00 Gb Total Physical Memory | 6.00 Gb Available Physical Memory | 71.00% Memory free
16.00 Gb Paging File | 13.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 596.17 Gb Total Space | 459.50 Gb Free Space | 77.08% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: S3YMOUR-PC
Current User Name: S3ymour
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – C:\Users\S3ymour\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" File not found
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" ()
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l ()
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{02B91901-B752-4616-9D9E-D7E18A825922}" = rport=10243 | protocol=6 | dir=out | app=system |
"{071E94FF-0FB4-44ED-B528-6FDB88AC6DDC}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{09C4C23B-69D8-458F-96B2-EE1841D72673}" = rport=445 | protocol=6 | dir=out | app=system |
"{108D355C-696F-4D5C-A75B-9F9ECF5F5A3E}" = lport=2869 | protocol=6 | dir=in | app=system |
"{142C709F-8705-4B37-BFBB-6E90DFBAB9EA}" = rport=137 | protocol=17 | dir=out | app=system |
"{35CEB676-0E5B-4ABA-AEDB-B3713A4F35ED}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{3A4C7909-3742-40A6-9755-A66C197ADD75}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{40AF35A7-40D9-4BA4-95E5-64E44AB465E7}" = lport=445 | protocol=6 | dir=in | app=system |
"{44A0D924-2FD5-4A39-A72A-E3010AA36A15}" = lport=138 | protocol=17 | dir=in | app=system |
"{4B642F71-AC4B-404C-8529-1BE0A19F3FC1}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{4E0DF76F-6630-4146-83F3-CEC2A92856E7}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{57431551-B353-498B-A15E-4395C2495618}" = lport=139 | protocol=6 | dir=in | app=system |
"{5DBD489B-B578-4FEE-8E7F-A867CE0C3FB0}" = rport=139 | protocol=6 | dir=out | app=system |
"{6A23914F-183D-471F-94C5-8464A821267B}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{835E3590-4680-41AC-8DCF-82079054231A}" = rport=138 | protocol=17 | dir=out | app=system |
"{8620EF64-1D29-475A-AA63-9449321C0E61}" = lport=10243 | protocol=6 | dir=in | app=system |
"{A61984F4-86BC-4E20-97AF-538AFBCF521E}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D7481A5E-3859-4C43-B693-2D24016C4EF4}" = lport=137 | protocol=17 | dir=in | app=system |
"{F7A9A007-6B8A-4332-9785-3B8907CD9C21}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{017D7D89-99F0-462C-AF63-6BD87E5272E0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war 2\dow2.exe |
"{0289DCE7-5711-4B4F-9994-0941726FD56E}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{059F2FE0-86F1-417F-BF7E-4443EB04CA74}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{07BCD401-0932-409F-9493-9673F4346535}" = dir=in | app=c:\program files (x86)\avg\avg9\avgnsa.exe |
"{0F6FA451-2F2F-48DD-BA2E-08567D1E58A7}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{1ACBBC3C-6895-4F9E-A0FE-1A59AAB53A61}" = dir=in | app=c:\program files (x86)\avg\avg9\avgupd.exe |
"{290EC4F2-0826-45DD-91C5-E5986404B10E}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{3711A8D6-B302-4854-A766-137B3F85F198}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war 2\dow2.exe |
"{46690E88-CC63-45EA-9A48-2858716D188A}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{47048B4E-7960-4A30-A707-3037CA518CFA}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{51BBC386-2724-42EF-ADDF-6EF0F7486B2F}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{5C65390F-3907-444F-A40F-2FCF80CBDC16}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{630D8919-EB5B-484C-93EB-8193A2A8A5F4}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{73912051-FF87-4E44-91DB-7150FE30B796}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{7595F797-A7AB-478C-87AD-DEA6A878AD4B}" = protocol=6 | dir=out | app=system |
"{76256F75-2511-46E2-96E3-9B365B8EA7A5}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{7D06721B-6648-49A1-BF5B-48E6C8A0D244}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{91BB38F7-E22A-44D9-ADFE-1B3B2EE55323}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{9AB4F3D2-155C-465A-A960-F88C21B6FACC}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{AEC5E466-7B9F-4F5C-A6E7-22C5EFD19E7A}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{B39FCD9E-CAE6-4F20-A0ED-824759AD4BFF}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{BE652749-511D-4790-80B9-39148BD94FA3}" = dir=in | app=c:\program files (x86)\avg\avg9\avgemc.exe |
"{C9AAF35E-D240-409B-93CF-46EBB52460F6}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{D94706D8-E3D6-4240-8049-83DA785D1640}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war 2\dow2.exe |
"{DF7584B8-C18B-430D-820B-0D49A01FDA59}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{E0978ACD-E440-4D9B-8133-3A5E5A4F9244}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{EDEAC8E2-5ED6-4AC5-AB99-5A2EA0567F08}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{EF30D827-2637-4BFE-AC4A-83E5B1A0BF5A}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{F20C5155-1981-4D05-9957-C5C73E88C0DA}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war 2\dow2.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{1D7F8784-001D-38D6-DCC6-5174D250C811}" = ATI Catalyst Install Manager
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{F6E2FA73-B2A7-8223-98EC-685E2E8F6CE0}" = ccc-utility64
"781745E87AFF80C0C1388CFF79D19ECAB2E9BB47" = Windows Driver Package - LeapFrog (FlyUsb) USB (11/05/2008 1.1.1.0)
"CutePDF Writer Installation" = CutePDF Writer 2.8
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{00C5F4F4-62F9-40D7-8000-AD8A9CD0C669}" = Microsoft Games for Windows - LIVE Redistributable
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0A169B94-4AF2-AD4B-1265-E1074A347418}" = Catalyst Control Center Core Implementation
"{0F15BB9F-7E5E-A355-FA8E-C2164726E577}" = CCC Help Portuguese
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java™ 6 Update 18
"{277832E3-0A34-C91C-D344-2FED4C847397}" = CCC Help German
"{279355E6-EE94-A7A5-F6B5-2903748443AE}" = Catalyst Control Center Graphics Full New
"{290AC453-D1F4-F73B-F01C-0018BC10B62B}" = ccc-core-static
"{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}" = Visual C++ 8.0 Runtime Setup Package (x64)
"{39A3C9DD-457C-5BF1-4B2D-A76927264B26}" = CCC Help Dutch
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4AA3D64E-9EC3-4B0F-AB91-5885AC55641F}" = Microsoft Games for Windows - LIVE
"{4E868D3D-6EEB-4273-926C-2287236B5B79}" = 3DVIA player 5.0
"{5AC4AE26-732F-40DE-CC6C-A4BFC2142BF8}" = CCC Help English
"{665B3CA4-DAB1-D27E-6727-0BEF6593E882}" = CCC Help Greek
"{674AD787-B463-ED3E-CCA8-4F49A9C1785D}" = Catalyst Control Center Localization All
"{6ADD0603-16EF-400D-9F9E-486432835002}" = OpenOffice.org 3.2
"{7009600B-85C8-5D83-1101-6446540F1897}" = Catalyst Control Center Graphics Previews Common
"{7305AE01-CD11-18B5-DC5F-B1A2960935C3}" = CCC Help Polish
"{7E15C4B8-85FC-4539-94F2-8280C0B213A3}" = LeapFrog Tag Plugin
"{7E7D778E-121D-4BBD-BA29-FAA81B9FBD8C}" = LeapFrog Connect
"{7FCC4EDC-6EE2-4309-ABD7-85F2667A7B90}" = WebEx Support Manager for Internet Explorer
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83BBF5E6-004F-1DBA-EC29-1033B675831B}" = CCC Help Thai
"{8508FB72-89A3-41FD-DE33-9EEBFB298947}" = CCC Help Italian
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
"{97835E04-BA21-6878-768F-1B84EA2ADAC1}" = CCC Help Norwegian
"{A192CA8A-5259-ECD5-1564-AB715B722432}" = CCC Help Japanese
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.2
"{B31327DF-2B59-F072-8B44-79CDE915D75E}" = CCC Help Danish
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B41423C9-C260-F8C8-39DD-541400ECF367}" = CCC Help French
"{C6CBE669-DDCA-DB7F-236D-18B20BEFF1B5}" = CCC Help Chinese Traditional
"{CA7D81F8-5661-3D97-F6B0-5E0993511A5D}" = CCC Help Finnish
"{D069C7EF-001B-5378-9F71-F005DE42E255}" = Catalyst Control Center Graphics Light
"{D2A7D7D8-1E27-8464-6666-44B6FB83B3FC}" = CCC Help Czech
"{D86DE1ED-9BF1-6101-6D08-2D762B28D8C8}" = CCC Help Korean
"{E1A8F958-D748-63DD-F2D2-82BE71B0F905}" = CCC Help Hungarian
"{E40A74A2-D821-2442-CCA3-75C54964D525}" = Catalyst Control Center Graphics Full Existing
"{E43ACD6B-0E7E-4F4C-0BA8-999FCB5FC5B9}" = CCC Help Chinese Standard
"{E481DB0E-52F2-4EE0-9BDA-9EE173FA6EA2}" = Catalyst Control Center - Branding
"{E9684BDD-32A6-550C-6456-0A4209EB4F3A}" = CCC Help Russian
"{F05F2DB5-4300-C318-4560-08CD9E35F512}" = CCC Help Spanish
"{F1D038D6-6229-AA2E-A8D1-43EED2CBF0BD}" = CCC Help Swedish
"{F322850C-6CCB-FC54-D36D-0F4E1CC90CBF}" = Skins
"{F527F14E-B80A-5BE7-DC85-8BF2D172067F}" = CCC Help Turkish
"{FF4F3E30-6638-6A16-2A68-139F6C613233}" = Catalyst Control Center Graphics Previews Vista
"{FFB07785-9FC3-334F-A54F-AC8D5B471EAE}" = Catalyst Control Center InstallProxy
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AVG9Uninstall" = AVG Free 9.0
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager
"SpywareBlaster_is1" = SpywareBlaster 4.3
"Steam App 15620" = Warhammer 40,000: Dawn of War II
"TagPlugin" = Use the entry named LeapFrog Connect to uninstall (LeapFrog Tag Plugin)
"TheStubware 1.7.8_is1" = TheStubware 1.7.8
"UPCShell" = LeapFrog Connect
"VLC media player" = VLC media player 1.0.1
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 6/19/2010 8:36:20 PM | Computer Name = S3ymour-PC | Source = Application Hang | ID = 1002
Description = The program chrome.exe version 0.0.0.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Problem Reports and Solutions control panel. Process
ID: 12bc Start Time: 01cb100e879e8e88 Termination Time: 22
Error - 6/19/2010 8:42:09 PM | Computer Name = S3ymour-PC | Source = Application Hang | ID = 1002
Description = The program chrome.exe version 0.0.0.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Problem Reports and Solutions control panel. Process
ID: 8a8 Start Time: 01cb1010ac242838 Termination Time: 21
Error - 6/23/2010 1:46:12 PM | Computer Name = S3ymour-PC | Source = WinMgmt | ID = 10
Description =
Error - 6/23/2010 1:51:09 PM | Computer Name = S3ymour-PC | Source = LoadPerf | ID = 3012
Description =
Error - 6/23/2010 1:51:09 PM | Computer Name = S3ymour-PC | Source = LoadPerf | ID = 3011
Description =
Error - 6/25/2010 3:04:28 AM | Computer Name = S3ymour-PC | Source = .NET Runtime Optimization Service | ID = 1101
Description =
Error - 6/29/2010 8:39:45 PM | Computer Name = S3ymour-PC | Source = WinMgmt | ID = 10
Description =
Error - 6/29/2010 8:42:26 PM | Computer Name = S3ymour-PC | Source = LoadPerf | ID = 3012
Description =
Error - 6/29/2010 8:42:26 PM | Computer Name = S3ymour-PC | Source = LoadPerf | ID = 3011
Description =
Error - 6/30/2010 1:24:42 PM | Computer Name = S3ymour-PC | Source = Application Hang | ID = 1002
Description = The program chrome.exe version 0.0.0.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Problem Reports and Solutions control panel. Process
ID: 6d0 Start Time: 01cb187845c9c3c0 Termination Time: 5
[ System Events ]
Error - 6/19/2010 9:04:58 AM | Computer Name = S3ymour-PC | Source = HTTP | ID = 15016
Description =
Error - 6/19/2010 9:06:11 AM | Computer Name = S3ymour-PC | Source = DCOM | ID = 10016
Description =
Error - 6/23/2010 1:44:59 PM | Computer Name = S3ymour-PC | Source = HTTP | ID = 15016
Description =
Error - 6/23/2010 1:46:23 PM | Computer Name = S3ymour-PC | Source = Print | ID = 54
Description = Document https://services.actstudent.org/OA_HTML/act…cdAdmTicket.jsp
failed to print and was deleted because of corruption in the spooled file. The
associated driver is: HP DeskJet 970Cxi. Try printing the document again.
Error - 6/29/2010 7:26:20 PM | Computer Name = S3ymour-PC | Source = DCOM | ID = 10005
Description =
Error - 6/29/2010 7:26:20 PM | Computer Name = S3ymour-PC | Source = Service Control Manager | ID = 7009
Description =
Error - 6/29/2010 7:26:20 PM | Computer Name = S3ymour-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 6/29/2010 8:38:08 PM | Computer Name = S3ymour-PC | Source = HTTP | ID = 15016
Description =
Error - 6/29/2010 8:39:32 PM | Computer Name = S3ymour-PC | Source = DCOM | ID = 10016
Description =
Error - 6/30/2010 1:17:48 PM | Computer Name = S3ymour-PC | Source = Service Control Manager | ID = 7011
Description =
< End of report >
*****************************************
Thanks for the help!
***********************************************
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:38:46 AM, on 7/16/2010
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18928)
Boot mode: Normal
Running processes:
C:\Users\S3ymour\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files (x86)\Steam\steam.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe
C:\Program Files (x86)\AVG\AVG9\avgtray.exe
C:\Program Files (x86)\TheStubware\TheStubware.exe
C:\Users\S3ymour\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\S3ymour\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\S3ymour\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\S3ymour\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Users\S3ymour\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\S3ymour\Downloads\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?
LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common
Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)
\AVG\AVG9\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot -
Search & Destroy\SDHelper.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)
\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [HDAudDeck] "C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" -r
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Monitor] "C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe"
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~2\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [TheStubware] "C:\Program Files (x86)\TheStubware\TheStubware.exe" -Startup
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Google Update] "C:\Users\S3ymour\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [Silverlight] "C:\Users\S3ymour\AppData\Roaming\Silverlight.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL
SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-717218054-4078819399-4181070963-501\..\Run: [Sidebar] C:\Program Files\Windows
Sidebar\sidebar.exe /autoRun (User 'Guest')
O4 - S-1-5-21-717218054-4078819399-4181070963-501 Startup: OpenOffice.org 3.2.lnk = C:\Program Files (x86)
\OpenOffice.org 3\program\quickstart.exe (User 'Guest')
O4 - S-1-5-21-717218054-4078819399-4181070963-501 User Startup: OpenOffice.org 3.2.lnk = C:\Program Files (x86)
\OpenOffice.org 3\program\quickstart.exe (User 'Guest')
O4 - Startup: OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search &
Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} -
C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} -
C:\Windows\system32\browseui.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file
missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: WebEx Service Host for Support Center (atashost) - WebEx Communications, Inc. - C:\Windows\SysWOW64
\atashost.exe
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9
\avgemc.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9
\avgwdsvc.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LeapFrog Connect Device Service - LeapFrog Enterprises, Inc. - C:\Program Files (x86)
\LeapFrog\LeapFrog Connect\CommandService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe
(file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32
\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe
(file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file
missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)
\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file
missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe
(file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe
(file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common
Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32
\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file
missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file
missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32
\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program
Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
–
End of file - 8796 bytes
*******************************************************************
OTL logfile created on: 7/16/2010 10:40:38 AM - Run 1
OTL by OldTimer - Version 3.2.9.0 Folder = C:\Users\S3ymour\Downloads
64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18928)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
8.00 Gb Total Physical Memory | 6.00 Gb Available Physical Memory | 71.00% Memory free
16.00 Gb Paging File | 13.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 596.17 Gb Total Space | 459.50 Gb Free Space | 77.08% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: S3YMOUR-PC
Current User Name: S3ymour
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2010/07/16 10:40:25 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\S3ymour\Downloads\OTL.exe
PRC - [2010/07/16 10:27:38 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\S3ymour\Downloads\HiJackThis.exe
PRC - [2010/07/15 18:43:33 | 000,723,296 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG9\avgcsrvx.exe
PRC - [2010/07/15 18:43:15 | 002,065,760 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG9\avgtray.exe
PRC - [2010/07/15 18:42:54 | 000,921,440 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG9\avgemc.exe
PRC - [2010/07/15 18:42:45 | 000,308,136 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe
PRC - [2010/06/28 22:27:23 | 000,945,720 | —- | M] (Google Inc.) – C:\Users\S3ymour\AppData\Local\Google\Chrome\Application\chrome.exe
PRC - [2010/05/08 10:17:47 | 001,238,352 | —- | M] (Valve Corporation) – C:\Program Files (x86)\Steam\steam.exe
PRC - [2010/04/11 16:34:30 | 000,781,312 | —- | M] (TheStubware.com) – C:\Program Files (x86)\TheStubware\TheStubware.exe
PRC - [2010/02/02 00:10:14 | 007,418,368 | —- | M] (OpenOffice.org) – C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
PRC - [2010/02/02 00:10:10 | 007,424,000 | —- | M] (OpenOffice.org) – C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
PRC - [2010/01/11 15:21:52 | 000,490,216 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
PRC - [2009/11/10 10:14:38 | 000,443,728 | —- | M] (LeapFrog Enterprises, Inc.) – C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe
PRC - [2009/11/10 09:28:06 | 001,131,808 | —- | M] (LeapFrog Enterprises, Inc.) – C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe
PRC - [2009/03/06 12:59:12 | 000,020,376 | —- | M] (WebEx Communications, Inc.) – C:\Windows\SysWOW64\atashost.exe
PRC - [2009/01/26 15:31:16 | 002,144,088 | RHS- | M] (Safer Networking Limited) – C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2009/01/26 15:31:10 | 001,153,368 | —- | M] (Safer Networking Ltd.) – C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
========== Modules (SafeList) ==========
MOD - [2010/07/16 10:40:25 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\S3ymour\Downloads\OTL.exe
MOD - [2008/01/20 22:50:01 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\msscript.ocx
MOD - [2008/01/20 22:48:06 | 001,684,480 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2009/06/14 23:12:12 | 000,203,264 | —- | M] () [Auto | Running] – C:\Windows\SysNative\atiesrxx.exe – (AMD External Events Utility)
SRV:64bit: - [2008/01/20 22:47:32 | 000,383,544 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2010/07/15 18:42:54 | 000,921,440 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files (x86)\AVG\AVG9\avgemc.exe – (avg9emc)
SRV - [2010/07/15 18:42:45 | 000,308,136 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe – (avg9wd)
SRV - [2010/03/26 17:43:04 | 000,332,720 | —- | M] (Valve Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Steam\SteamService.exe – (Steam Client Service)
SRV - [2010/03/18 14:27:14 | 001,020,768 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe – (WPFFontCache_v0400)
SRV - [2010/03/18 14:27:14 | 000,138,576 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_64)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/11/10 09:28:06 | 001,131,808 | —- | M] (LeapFrog Enterprises, Inc.) [Auto | Running] – C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe – (LeapFrog Connect Device Service)
SRV - [2009/03/06 12:59:12 | 000,020,376 | —- | M] (WebEx Communications, Inc.) [Auto | Running] – C:\Windows\SysWOW64\atashost.exe – (atashost)
SRV - [2009/01/26 15:31:10 | 001,153,368 | —- | M] (Safer Networking Ltd.) [Auto | Running] – C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe – (SBSDWSCService)
========== Driver Services (SafeList) ==========
DRV:64bit: - File not found [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\nwlnkfwd.sys – (NwlnkFwd)
DRV:64bit: - File not found [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\nwlnkflt.sys – (NwlnkFlt)
DRV:64bit: - File not found [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\ipinip.sys – (IpInIp)
DRV:64bit: - File not found [Kernel | System | Stopped] – C:\Windows\SysNative\drivers\ActiveMonitor.SYS – (ActiveMonitor)
DRV:64bit: - [2010/07/15 18:44:31 | 000,317,520 | —- | M] () [Kernel | System | Running] – C:\Windows\SysNative\Drivers\avgtdia.sys – (AvgTdiA)
DRV:64bit: - [2010/07/15 18:44:25 | 000,269,904 | —- | M] () [Kernel | System | Running] – C:\Windows\SysNative\Drivers\avgldx64.sys – (AvgLdx64)
DRV:64bit: - [2010/07/15 18:44:23 | 000,035,536 | —- | M] () [File_System | System | Running] – C:\Windows\SysNative\Drivers\avgmfx64.sys – (AvgMfx64)
DRV:64bit: - [2009/11/10 09:27:06 | 000,024,576 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\FlyUsb.sys – (FlyUsb)
DRV:64bit: - [2009/06/14 23:48:02 | 006,031,872 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\atikmdag.sys – (atikmdag)
DRV:64bit: - [2009/06/04 08:20:48 | 000,113,168 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\AtiHdmi.sys – (AtiHdmiService)
DRV:64bit: - [2009/05/05 01:30:28 | 000,016,440 | —- | M] () [Kernel | Boot | Running] – C:\Windows\SysNative\DRIVERS\AtiPcie.sys – (AtiPcie) AMD PCI Express (3GIO)
DRV:64bit: - [2009/04/28 14:26:52 | 001,152,000 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\viahduaa.sys – (VIAHdAudAddService)
DRV:64bit: - [2008/12/12 02:41:44 | 000,188,416 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\Rtlh64.sys – (RTL8169)
DRV:64bit: - [2008/01/20 22:47:28 | 000,046,080 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\wpdusb.sys – (WpdUsb)
DRV:64bit: - [2008/01/20 22:46:57 | 000,022,528 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\WSDPrint.sys – (WSDPrintDevice)
DRV:64bit: - [2008/01/20 22:46:53 | 001,523,712 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\VSTDPV6.SYS – (VST64_DPV)
DRV:64bit: - [2008/01/20 22:46:53 | 000,724,480 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\VSTCNXT6.SYS – (winachsf)
DRV:64bit: - [2008/01/20 22:46:53 | 000,392,704 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\VSTBS26.SYS – (VST64HWBS2)
DRV:64bit: - [2006/09/18 17:36:24 | 000,000,308 | —- | M] () [File_System | On_Demand | Running] – C:\Windows\SysNative\Wbem\ntfs.mof – (Ntfs)
DRV - [2010/04/10 17:05:56 | 000,009,728 | —- | M] (TheStubware.com) [Kernel | Boot | Stopped] – C:\Windows\SysWow64\drivers\TheStubwareDriver.SYS – (TheStubwareDriver)
DRV - [2010/04/10 17:01:56 | 000,044,032 | —- | M] (TheStubware.com) [Kernel | System | Stopped] – C:\Windows\SysWOW64\drivers\ActiveMonitor.SYS – (ActiveMonitor)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: ([2006/09/18 17:37:24 | 000,000,761 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files (x86)\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4 - HKLM..\Run: [Monitor] C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe (LeapFrog Enterprises, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TheStubware] C:\Program Files (x86)\TheStubware\TheStubware.exe (TheStubware.com)
O4 - HKCU..\Run: [Silverlight] C:\Users\S3ymour\AppData\Roaming\Silverlight.exe ()
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe File not found
O4 - Startup: C:\Users\S3ymour\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed] [removed]
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - AppInit_DLLs: (avgrssta.dll) - C:\Windows\SysNative\avgrssta.dll ()
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\S3ymour\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\S3ymour\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010/07/15 19:19:19 | 000,000,000 | -H-D | C] – C:\$AVG
[2010/07/15 19:12:38 | 000,044,032 | —- | C] (TheStubware.com) – C:\Windows\SysWow64\drivers\ActiveMonitor.SYS
[2010/07/15 19:12:38 | 000,009,728 | —- | C] (TheStubware.com) – C:\Windows\SysWow64\drivers\TheStubwareDriver.SYS
[2010/07/15 19:12:38 | 000,000,000 | —D | C] – C:\Program Files (x86)\TheStubware
[2010/07/15 19:09:57 | 000,000,000 | —D | C] – C:\ProgramData\TEMP
[2010/07/15 19:09:51 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2010/07/15 19:09:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spybot - Search & Destroy
[2010/07/15 19:09:40 | 000,118,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSSTDFMT.DLL
[2010/07/15 19:09:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\SpywareBlaster
[2010/07/15 18:53:49 | 000,000,000 | —D | C] – C:\Users\S3ymour\AppData\Roaming\QuickScan
[2010/07/15 18:44:22 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\Avg
[2010/07/15 18:41:01 | 000,000,000 | —D | C] – C:\Program Files (x86)\AVG
[2010/07/15 18:40:42 | 000,000,000 | —D | C] – C:\ProgramData\avg9
[2010/06/25 03:01:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft.NET
[2010/06/23 13:28:34 | 000,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mpg2splt.ax
[2010/06/23 13:28:34 | 000,080,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSNP.ax
[2010/06/23 13:28:31 | 000,428,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\EncDec.dll
[2010/06/23 13:28:31 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisdecd.dll
[2010/06/23 13:28:31 | 000,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisrndr.ax
[2010/06/23 13:28:18 | 001,130,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dfshim.dll
[2010/06/23 13:28:18 | 000,295,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHost.exe
[2010/06/23 13:28:18 | 000,099,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHostProxy.dll
[2010/06/23 13:28:18 | 000,049,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netfxperf.dll
[2010/06/23 08:45:04 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Apphlpdm.dll
[2010/06/23 08:45:03 | 004,240,384 | —- | C] (Microsoft) – C:\Windows\SysWow64\GameUXLegacyGDFs.dll
========== Files - Modified Within 30 Days ==========
[2010/07/16 10:40:53 | 002,097,152 | -HS- | M] () – C:\Users\S3ymour\NTUSER.DAT
[2010/07/16 10:35:18 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/07/16 10:35:18 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/07/16 10:30:34 | 000,000,734 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts.new
[2010/07/16 10:13:59 | 000,000,916 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-717218054-4078819399-4181070963-1000UA.job
[2010/07/16 10:13:08 | 000,524,288 | -HS- | M] () – C:\Users\S3ymour\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TMContainer00000000000000000001.regtrans-ms
[2010/07/16 10:13:08 | 000,065,536 | -HS- | M] () – C:\Users\S3ymour\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TM.blf
[2010/07/16 09:37:33 | 062,044,352 | —- | M] () – C:\Windows\SysNative\drivers\Avg\incavi.avm
[2010/07/16 08:02:16 | 001,987,940 | -H– | M] () – C:\Users\S3ymour\AppData\Local\IconCache.db
[2010/07/16 01:14:00 | 000,000,864 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-717218054-4078819399-4181070963-1000Core.job
[2010/07/16 01:13:01 | 000,000,939 | —- | M] () – C:\Windows\SysNative\nt.bat
[2010/07/15 19:37:56 | 001,033,616 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/07/15 19:37:56 | 000,250,638 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/07/15 19:37:56 | 000,005,534 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/07/15 19:31:34 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/07/15 19:31:32 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/07/15 19:12:39 | 000,000,882 | —- | M] () – C:\Users\S3ymour\Desktop\TheStubware.lnk
[2010/07/15 19:10:11 | 000,001,121 | —- | M] () – C:\Users\S3ymour\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/07/15 19:09:44 | 000,000,842 | —- | M] () – C:\Users\S3ymour\Desktop\SpywareBlaster.lnk
[2010/07/15 18:44:33 | 000,013,048 | —- | M] () – C:\Windows\SysNative\avgrssta.dll
[2010/07/15 18:44:33 | 000,001,689 | —- | M] () – C:\Users\Public\Desktop\AVG Free 9.0.lnk
[2010/07/15 18:44:31 | 000,317,520 | —- | M] () – C:\Windows\SysNative\drivers\avgtdia.sys
[2010/07/15 18:44:25 | 000,269,904 | —- | M] () – C:\Windows\SysNative\drivers\avgldx64.sys
[2010/07/15 18:44:23 | 000,035,536 | —- | M] () – C:\Windows\SysNative\drivers\avgmfx64.sys
[2010/07/15 18:44:22 | 000,113,461 | —- | M] () – C:\Windows\SysNative\drivers\Avg\iavichjw.avm
[2010/07/13 20:45:27 | 000,119,239 | —- | M] () – C:\Users\S3ymour\Documents\Verizon Wireless - Pay Bill Confirmation.pdf
[2010/07/07 22:03:06 | 000,000,680 | —- | M] () – C:\Users\S3ymour\AppData\Local\d3d9caps.dat
[2010/06/29 19:26:22 | 000,001,917 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/06/25 11:32:24 | 000,074,716 | —- | M] () – C:\Users\S3ymour\Documents\Volkswagen Credit – One-time Payment Confirmation.pdf
[2010/06/21 18:00:20 | 000,019,981 | —- | M] () – C:\Users\S3ymour\Documents\rubber band trick.odt
========== Files Created - No Company Name ==========
[2010/07/15 19:12:39 | 000,000,882 | —- | C] () – C:\Users\S3ymour\Desktop\TheStubware.lnk
[2010/07/15 19:10:11 | 000,001,121 | —- | C] () – C:\Users\S3ymour\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/07/15 19:09:44 | 000,000,842 | —- | C] () – C:\Users\S3ymour\Desktop\SpywareBlaster.lnk
[2010/07/15 18:44:33 | 000,001,689 | —- | C] () – C:\Users\Public\Desktop\AVG Free 9.0.lnk
[2010/07/15 18:44:31 | 000,013,048 | —- | C] () – C:\Windows\SysNative\avgrssta.dll
[2010/07/15 18:44:30 | 000,317,520 | —- | C] () – C:\Windows\SysNative\drivers\avgtdia.sys
[2010/07/15 18:44:24 | 000,269,904 | —- | C] () – C:\Windows\SysNative\drivers\avgldx64.sys
[2010/07/15 18:44:22 | 062,044,352 | —- | C] () – C:\Windows\SysNative\drivers\Avg\incavi.avm
[2010/07/15 18:44:22 | 000,113,461 | —- | C] () – C:\Windows\SysNative\drivers\Avg\iavichjw.avm
[2010/07/15 18:44:22 | 000,035,536 | —- | C] () – C:\Windows\SysNative\drivers\avgmfx64.sys
[2010/07/04 19:28:02 | 000,143,360 | —- | C] () – C:\Windows\STARTME.exe
[2010/07/04 19:28:02 | 000,143,360 | —- | C] () – C:\STARTME.exe
[2010/06/29 19:26:22 | 000,001,917 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/06/25 11:32:22 | 000,074,716 | —- | C] () – C:\Users\S3ymour\Documents\Volkswagen Credit – One-time Payment Confirmation.pdf
[2010/06/23 13:28:34 | 000,227,328 | —- | C] () – C:\Windows\SysNative\mpg2splt.ax
[2010/06/23 13:28:34 | 000,101,376 | —- | C] () – C:\Windows\SysNative\MSNP.ax
[2010/06/23 13:28:31 | 000,558,592 | —- | C] () – C:\Windows\SysNative\EncDec.dll
[2010/06/23 13:28:31 | 000,375,808 | —- | C] () – C:\Windows\SysNative\psisdecd.dll
[2010/06/23 13:28:31 | 000,289,792 | —- | C] () – C:\Windows\SysNative\psisrndr.ax
[2010/06/23 13:28:18 | 001,942,856 | —- | C] () – C:\Windows\SysNative\dfshim.dll
[2010/06/23 13:28:18 | 000,444,752 | —- | C] () – C:\Windows\SysNative\mscoree.dll
[2010/06/23 13:28:18 | 000,320,352 | —- | C] () – C:\Windows\SysNative\PresentationHost.exe
[2010/06/23 13:28:18 | 000,109,912 | —- | C] () – C:\Windows\SysNative\PresentationHostProxy.dll
[2010/06/23 13:28:18 | 000,048,960 | —- | C] () – C:\Windows\SysNative\netfxperf.dll
[2010/06/23 08:45:04 | 000,032,256 | —- | C] () – C:\Windows\SysNative\Apphlpdm.dll
[2010/06/23 08:45:03 | 004,240,384 | —- | C] () – C:\Windows\SysNative\GameUXLegacyGDFs.dll
[2010/06/21 18:00:17 | 000,019,981 | —- | C] () – C:\Users\S3ymour\Documents\rubber band trick.odt
[2010/05/03 19:19:31 | 000,000,110 | —- | C] () – C:\Windows\{7E7D778E-121D-4BBD-BA29-FAA81B9FBD8C}_WiseFW.ini
[2009/11/06 10:58:04 | 000,178,975 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2008/01/20 22:50:05 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2008/01/20 22:49:49 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
< End of report >
**********************************
OTL Extras logfile created on: 7/16/2010 10:40:38 AM - Run 1
OTL by OldTimer - Version 3.2.9.0 Folder = C:\Users\S3ymour\Downloads
64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18928)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
8.00 Gb Total Physical Memory | 6.00 Gb Available Physical Memory | 71.00% Memory free
16.00 Gb Paging File | 13.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 596.17 Gb Total Space | 459.50 Gb Free Space | 77.08% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: S3YMOUR-PC
Current User Name: S3ymour
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – C:\Users\S3ymour\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" File not found
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" ()
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l ()
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{02B91901-B752-4616-9D9E-D7E18A825922}" = rport=10243 | protocol=6 | dir=out | app=system |
"{071E94FF-0FB4-44ED-B528-6FDB88AC6DDC}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{09C4C23B-69D8-458F-96B2-EE1841D72673}" = rport=445 | protocol=6 | dir=out | app=system |
"{108D355C-696F-4D5C-A75B-9F9ECF5F5A3E}" = lport=2869 | protocol=6 | dir=in | app=system |
"{142C709F-8705-4B37-BFBB-6E90DFBAB9EA}" = rport=137 | protocol=17 | dir=out | app=system |
"{35CEB676-0E5B-4ABA-AEDB-B3713A4F35ED}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{3A4C7909-3742-40A6-9755-A66C197ADD75}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{40AF35A7-40D9-4BA4-95E5-64E44AB465E7}" = lport=445 | protocol=6 | dir=in | app=system |
"{44A0D924-2FD5-4A39-A72A-E3010AA36A15}" = lport=138 | protocol=17 | dir=in | app=system |
"{4B642F71-AC4B-404C-8529-1BE0A19F3FC1}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{4E0DF76F-6630-4146-83F3-CEC2A92856E7}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{57431551-B353-498B-A15E-4395C2495618}" = lport=139 | protocol=6 | dir=in | app=system |
"{5DBD489B-B578-4FEE-8E7F-A867CE0C3FB0}" = rport=139 | protocol=6 | dir=out | app=system |
"{6A23914F-183D-471F-94C5-8464A821267B}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{835E3590-4680-41AC-8DCF-82079054231A}" = rport=138 | protocol=17 | dir=out | app=system |
"{8620EF64-1D29-475A-AA63-9449321C0E61}" = lport=10243 | protocol=6 | dir=in | app=system |
"{A61984F4-86BC-4E20-97AF-538AFBCF521E}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D7481A5E-3859-4C43-B693-2D24016C4EF4}" = lport=137 | protocol=17 | dir=in | app=system |
"{F7A9A007-6B8A-4332-9785-3B8907CD9C21}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{017D7D89-99F0-462C-AF63-6BD87E5272E0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war 2\dow2.exe |
"{0289DCE7-5711-4B4F-9994-0941726FD56E}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{059F2FE0-86F1-417F-BF7E-4443EB04CA74}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{07BCD401-0932-409F-9493-9673F4346535}" = dir=in | app=c:\program files (x86)\avg\avg9\avgnsa.exe |
"{0F6FA451-2F2F-48DD-BA2E-08567D1E58A7}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{1ACBBC3C-6895-4F9E-A0FE-1A59AAB53A61}" = dir=in | app=c:\program files (x86)\avg\avg9\avgupd.exe |
"{290EC4F2-0826-45DD-91C5-E5986404B10E}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{3711A8D6-B302-4854-A766-137B3F85F198}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war 2\dow2.exe |
"{46690E88-CC63-45EA-9A48-2858716D188A}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{47048B4E-7960-4A30-A707-3037CA518CFA}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{51BBC386-2724-42EF-ADDF-6EF0F7486B2F}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{5C65390F-3907-444F-A40F-2FCF80CBDC16}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{630D8919-EB5B-484C-93EB-8193A2A8A5F4}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{73912051-FF87-4E44-91DB-7150FE30B796}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{7595F797-A7AB-478C-87AD-DEA6A878AD4B}" = protocol=6 | dir=out | app=system |
"{76256F75-2511-46E2-96E3-9B365B8EA7A5}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{7D06721B-6648-49A1-BF5B-48E6C8A0D244}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{91BB38F7-E22A-44D9-ADFE-1B3B2EE55323}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{9AB4F3D2-155C-465A-A960-F88C21B6FACC}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{AEC5E466-7B9F-4F5C-A6E7-22C5EFD19E7A}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{B39FCD9E-CAE6-4F20-A0ED-824759AD4BFF}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{BE652749-511D-4790-80B9-39148BD94FA3}" = dir=in | app=c:\program files (x86)\avg\avg9\avgemc.exe |
"{C9AAF35E-D240-409B-93CF-46EBB52460F6}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{D94706D8-E3D6-4240-8049-83DA785D1640}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war 2\dow2.exe |
"{DF7584B8-C18B-430D-820B-0D49A01FDA59}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{E0978ACD-E440-4D9B-8133-3A5E5A4F9244}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{EDEAC8E2-5ED6-4AC5-AB99-5A2EA0567F08}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{EF30D827-2637-4BFE-AC4A-83E5B1A0BF5A}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{F20C5155-1981-4D05-9957-C5C73E88C0DA}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war 2\dow2.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{1D7F8784-001D-38D6-DCC6-5174D250C811}" = ATI Catalyst Install Manager
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{F6E2FA73-B2A7-8223-98EC-685E2E8F6CE0}" = ccc-utility64
"781745E87AFF80C0C1388CFF79D19ECAB2E9BB47" = Windows Driver Package - LeapFrog (FlyUsb) USB (11/05/2008 1.1.1.0)
"CutePDF Writer Installation" = CutePDF Writer 2.8
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{00C5F4F4-62F9-40D7-8000-AD8A9CD0C669}" = Microsoft Games for Windows - LIVE Redistributable
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0A169B94-4AF2-AD4B-1265-E1074A347418}" = Catalyst Control Center Core Implementation
"{0F15BB9F-7E5E-A355-FA8E-C2164726E577}" = CCC Help Portuguese
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java™ 6 Update 18
"{277832E3-0A34-C91C-D344-2FED4C847397}" = CCC Help German
"{279355E6-EE94-A7A5-F6B5-2903748443AE}" = Catalyst Control Center Graphics Full New
"{290AC453-D1F4-F73B-F01C-0018BC10B62B}" = ccc-core-static
"{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}" = Visual C++ 8.0 Runtime Setup Package (x64)
"{39A3C9DD-457C-5BF1-4B2D-A76927264B26}" = CCC Help Dutch
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4AA3D64E-9EC3-4B0F-AB91-5885AC55641F}" = Microsoft Games for Windows - LIVE
"{4E868D3D-6EEB-4273-926C-2287236B5B79}" = 3DVIA player 5.0
"{5AC4AE26-732F-40DE-CC6C-A4BFC2142BF8}" = CCC Help English
"{665B3CA4-DAB1-D27E-6727-0BEF6593E882}" = CCC Help Greek
"{674AD787-B463-ED3E-CCA8-4F49A9C1785D}" = Catalyst Control Center Localization All
"{6ADD0603-16EF-400D-9F9E-486432835002}" = OpenOffice.org 3.2
"{7009600B-85C8-5D83-1101-6446540F1897}" = Catalyst Control Center Graphics Previews Common
"{7305AE01-CD11-18B5-DC5F-B1A2960935C3}" = CCC Help Polish
"{7E15C4B8-85FC-4539-94F2-8280C0B213A3}" = LeapFrog Tag Plugin
"{7E7D778E-121D-4BBD-BA29-FAA81B9FBD8C}" = LeapFrog Connect
"{7FCC4EDC-6EE2-4309-ABD7-85F2667A7B90}" = WebEx Support Manager for Internet Explorer
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83BBF5E6-004F-1DBA-EC29-1033B675831B}" = CCC Help Thai
"{8508FB72-89A3-41FD-DE33-9EEBFB298947}" = CCC Help Italian
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
"{97835E04-BA21-6878-768F-1B84EA2ADAC1}" = CCC Help Norwegian
"{A192CA8A-5259-ECD5-1564-AB715B722432}" = CCC Help Japanese
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.2
"{B31327DF-2B59-F072-8B44-79CDE915D75E}" = CCC Help Danish
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B41423C9-C260-F8C8-39DD-541400ECF367}" = CCC Help French
"{C6CBE669-DDCA-DB7F-236D-18B20BEFF1B5}" = CCC Help Chinese Traditional
"{CA7D81F8-5661-3D97-F6B0-5E0993511A5D}" = CCC Help Finnish
"{D069C7EF-001B-5378-9F71-F005DE42E255}" = Catalyst Control Center Graphics Light
"{D2A7D7D8-1E27-8464-6666-44B6FB83B3FC}" = CCC Help Czech
"{D86DE1ED-9BF1-6101-6D08-2D762B28D8C8}" = CCC Help Korean
"{E1A8F958-D748-63DD-F2D2-82BE71B0F905}" = CCC Help Hungarian
"{E40A74A2-D821-2442-CCA3-75C54964D525}" = Catalyst Control Center Graphics Full Existing
"{E43ACD6B-0E7E-4F4C-0BA8-999FCB5FC5B9}" = CCC Help Chinese Standard
"{E481DB0E-52F2-4EE0-9BDA-9EE173FA6EA2}" = Catalyst Control Center - Branding
"{E9684BDD-32A6-550C-6456-0A4209EB4F3A}" = CCC Help Russian
"{F05F2DB5-4300-C318-4560-08CD9E35F512}" = CCC Help Spanish
"{F1D038D6-6229-AA2E-A8D1-43EED2CBF0BD}" = CCC Help Swedish
"{F322850C-6CCB-FC54-D36D-0F4E1CC90CBF}" = Skins
"{F527F14E-B80A-5BE7-DC85-8BF2D172067F}" = CCC Help Turkish
"{FF4F3E30-6638-6A16-2A68-139F6C613233}" = Catalyst Control Center Graphics Previews Vista
"{FFB07785-9FC3-334F-A54F-AC8D5B471EAE}" = Catalyst Control Center InstallProxy
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AVG9Uninstall" = AVG Free 9.0
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager
"SpywareBlaster_is1" = SpywareBlaster 4.3
"Steam App 15620" = Warhammer 40,000: Dawn of War II
"TagPlugin" = Use the entry named LeapFrog Connect to uninstall (LeapFrog Tag Plugin)
"TheStubware 1.7.8_is1" = TheStubware 1.7.8
"UPCShell" = LeapFrog Connect
"VLC media player" = VLC media player 1.0.1
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 6/19/2010 8:36:20 PM | Computer Name = S3ymour-PC | Source = Application Hang | ID = 1002
Description = The program chrome.exe version 0.0.0.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Problem Reports and Solutions control panel. Process
ID: 12bc Start Time: 01cb100e879e8e88 Termination Time: 22
Error - 6/19/2010 8:42:09 PM | Computer Name = S3ymour-PC | Source = Application Hang | ID = 1002
Description = The program chrome.exe version 0.0.0.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Problem Reports and Solutions control panel. Process
ID: 8a8 Start Time: 01cb1010ac242838 Termination Time: 21
Error - 6/23/2010 1:46:12 PM | Computer Name = S3ymour-PC | Source = WinMgmt | ID = 10
Description =
Error - 6/23/2010 1:51:09 PM | Computer Name = S3ymour-PC | Source = LoadPerf | ID = 3012
Description =
Error - 6/23/2010 1:51:09 PM | Computer Name = S3ymour-PC | Source = LoadPerf | ID = 3011
Description =
Error - 6/25/2010 3:04:28 AM | Computer Name = S3ymour-PC | Source = .NET Runtime Optimization Service | ID = 1101
Description =
Error - 6/29/2010 8:39:45 PM | Computer Name = S3ymour-PC | Source = WinMgmt | ID = 10
Description =
Error - 6/29/2010 8:42:26 PM | Computer Name = S3ymour-PC | Source = LoadPerf | ID = 3012
Description =
Error - 6/29/2010 8:42:26 PM | Computer Name = S3ymour-PC | Source = LoadPerf | ID = 3011
Description =
Error - 6/30/2010 1:24:42 PM | Computer Name = S3ymour-PC | Source = Application Hang | ID = 1002
Description = The program chrome.exe version 0.0.0.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Problem Reports and Solutions control panel. Process
ID: 6d0 Start Time: 01cb187845c9c3c0 Termination Time: 5
[ System Events ]
Error - 6/19/2010 9:04:58 AM | Computer Name = S3ymour-PC | Source = HTTP | ID = 15016
Description =
Error - 6/19/2010 9:06:11 AM | Computer Name = S3ymour-PC | Source = DCOM | ID = 10016
Description =
Error - 6/23/2010 1:44:59 PM | Computer Name = S3ymour-PC | Source = HTTP | ID = 15016
Description =
Error - 6/23/2010 1:46:23 PM | Computer Name = S3ymour-PC | Source = Print | ID = 54
Description = Document https://services.actstudent.org/OA_HTML/act…cdAdmTicket.jsp
failed to print and was deleted because of corruption in the spooled file. The
associated driver is: HP DeskJet 970Cxi. Try printing the document again.
Error - 6/29/2010 7:26:20 PM | Computer Name = S3ymour-PC | Source = DCOM | ID = 10005
Description =
Error - 6/29/2010 7:26:20 PM | Computer Name = S3ymour-PC | Source = Service Control Manager | ID = 7009
Description =
Error - 6/29/2010 7:26:20 PM | Computer Name = S3ymour-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 6/29/2010 8:38:08 PM | Computer Name = S3ymour-PC | Source = HTTP | ID = 15016
Description =
Error - 6/29/2010 8:39:32 PM | Computer Name = S3ymour-PC | Source = DCOM | ID = 10016
Description =
Error - 6/30/2010 1:17:48 PM | Computer Name = S3ymour-PC | Source = Service Control Manager | ID = 7011
Description =
< End of report >
*****************************************
Thanks for the help!