Dell1
Topic Starter
OTL logfile created on: 8/5/2010 12:14:13 PM - Run 1
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\Sara\My Documents\Downloads
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
502.00 Mb Total Physical Memory | 145.00 Mb Available Physical Memory | 29.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): C:\pagefile.sys 1512 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 49.80 Gb Total Space | 21.74 Gb Free Space | 43.66% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: D697QZ91
Current User Name: Sara
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Sara\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Sara\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (MskService) – File not found
SRV - (MpfService) – File not found
SRV - (mcupdmgr.exe) – File not found
SRV - (McTskshd.exe) – File not found
SRV - (McShield) – File not found
SRV - (McDetect.exe) – File not found
SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
========== Driver Services (SafeList) ==========
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\System32\DRIVERS\wanatw4.sys File not found
DRV - (cpuz132) – C:\DOCUME~1\Sara\LOCALS~1\Temp\cpuz132\cpuz132_x32.sys File not found
DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (dsunidrv) – C:\WINDOWS\system32\drivers\dsunidrv.sys (Gteko Ltd.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (SynTP) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (MPFIREWL) – C:\WINDOWS\system32\drivers\MpFirewall.sys (McAfee)
DRV - (BCM43XX) – C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corporation)
DRV - (rismxdp) – C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (APPDRV) – C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS (Dell Inc)
DRV - (NaiAvFilter1) – C:\WINDOWS\system32\drivers\naiavf5x.sys (McAfee Inc.)
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (tfsnudfa) – C:\WINDOWS\system32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (tfsnudf) – C:\WINDOWS\system32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnifs) – C:\WINDOWS\system32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsncofs) – C:\WINDOWS\system32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsnboio) – C:\WINDOWS\system32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsnopio) – C:\WINDOWS\system32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool) – C:\WINDOWS\system32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsndrct) – C:\WINDOWS\system32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres) – C:\WINDOWS\system32\dla\tfsndres.sys (Sonic Solutions)
DRV - (drvmcdb) – C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (drvnddm) – C:\WINDOWS\system32\drivers\drvnddm.sys (Sonic Solutions)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (sscdbhk5) – C:\WINDOWS\system32\drivers\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln) – C:\WINDOWS\system32\drivers\ssrtln.sys (Sonic Solutions)
DRV - (omci) – C:\WINDOWS\system32\drivers\omci.sys (Dell Inc)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (HPFECP13) – C:\WINDOWS\System32\drivers\HPFECP13.SYS ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.3
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.845
FF - prefs.js..extensions.enabledItems: {35106bca-6c78-48c7-ac28-56df30b51d2d}:1.2.4
FF - prefs.js..keyword.URL: "http://www.google.com/search?sourceid=navclient&hl;=en&q;="
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/08/04 15:22:20 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared [2010/03/26 20:59:54 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/20 19:08:12 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/10 09:09:45 | 000,000,000 | —D | M]
[2009/12/27 12:26:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\Mozilla\Extensions
[2010/08/05 11:42:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\Mozilla\Firefox\Profiles\8fryscue.default\extensions
[2010/04/24 14:23:12 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\Sara\Application Data\Mozilla\Firefox\Profiles\8fryscue.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010/05/15 18:11:05 | 000,000,000 | —D | M] (PopupMaster) – C:\Documents and Settings\Sara\Application Data\Mozilla\Firefox\Profiles\8fryscue.default\extensions\{35106bca-6c78-48c7-ac28-56df30b51d2d}
[2010/01/20 16:34:07 | 000,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\Sara\Application Data\Mozilla\Firefox\Profiles\8fryscue.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/06/07 14:28:03 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: ([2009/12/21 11:33:11 | 000,366,461 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 12612 more lines…
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll File not found
O4 - HKCU..\Run: [Sonic RecordNow!] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000031 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O15 - HKCU\..Trusted Domains: yahoo.com ([login] https in Trusted sites)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/9/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (C:\WINDOWS\system32\BCMLogon.dll) - C:\WINDOWS\system32\BCMLogon.dll (Broadcom Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Sara\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Sara\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/08/16 04:43:04 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{1536f12f-ca54-11dd-8136-0015c515efd7}\Shell\AutoRun\command - "" = F:\wdsync.exe – File not found
O33 - MountPoints2\{2eb575d8-cedc-11dc-807a-0015c515efd7}\Shell\AutoRun\command - "" = D:\LinksysConnectPC.exe – File not found
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun\command - "" = E:\setup.exe – File not found
O33 - MountPoints2\{4d1cb884-e94a-11dd-8144-0015c515efd7}\Shell - "" = AutoRun
O33 - MountPoints2\{4d1cb884-e94a-11dd-8144-0015c515efd7}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{4d1cb884-e94a-11dd-8144-0015c515efd7}\Shell\AutoRun\command - "" = D:\LaunchU3.exe – File not found
O33 - MountPoints2\{c760b5e0-d918-11dc-808f-0015c515efd7}\Shell - "" = AutoRun
O33 - MountPoints2\{c760b5e0-d918-11dc-808f-0015c515efd7}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{c760b5e0-d918-11dc-808f-0015c515efd7}\Shell\AutoRun\command - "" = E:\LaunchU3.exe – File not found
O33 - MountPoints2\{edb9d88d-126b-11df-86f3-0015c515efd7}\Shell\AutoRun\command - "" = D:\Setup_FlipShare.exe – File not found
O33 - MountPoints2\{edb9d88d-126b-11df-86f3-0015c515efd7}\Shell\Setup FlipShare\command - "" = D:\Setup_FlipShare.exe – File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
========== Files/Folders - Created Within 30 Days ==========
[2010/08/05 07:56:24 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Sara\Recent
[2010/07/27 01:30:35 | 008,462,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shell32.dll
[2010/07/19 14:21:40 | 000,000,000 | —D | C] – C:\WINDOWS\System32\Adobe
[2010/07/15 08:34:13 | 000,012,536 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/07/14 09:01:40 | 000,744,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\helpsvc.exe
[95 C:\*.tmp files -> C:\*.tmp -> ]
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/08/05 12:26:44 | 000,000,000 | —- | M] () – C:\Documents and Settings\Sara\Local Settings\Application Data\prvlcl.dat
[2010/08/05 12:05:04 | 000,000,420 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{5215825E-42C8-430F-9BC0-4F33662C7C32}.job
[2010/08/05 12:00:45 | 000,002,445 | —- | M] () – C:\Documents and Settings\Sara\Desktop\HiJackThis.lnk
[2010/08/05 10:55:26 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/08/05 10:54:22 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/08/05 10:54:19 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/08/05 10:54:18 | 526,843,904 | -HS- | M] () – C:\hiberfil.sys
[2010/08/05 10:52:31 | 008,126,464 | —- | M] () – C:\Documents and Settings\Sara\NTUSER.DAT
[2010/08/05 10:52:31 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Sara\ntuser.ini
[2010/08/05 08:41:16 | 062,974,081 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/08/05 08:06:43 | 004,793,568 | -H– | M] () – C:\Documents and Settings\Sara\Local Settings\Application Data\IconCache.db
[2010/08/05 07:45:06 | 000,002,495 | —- | M] () – C:\Documents and Settings\Sara\Desktop\Microsoft Office Excel 2003.lnk
[2010/07/30 14:34:12 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/07/27 01:30:35 | 008,462,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shell32.dll
[2010/07/23 14:10:47 | 000,029,696 | —- | M] () – C:\Documents and Settings\Sara\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/16 18:30:00 | 000,000,356 | —- | M] () – C:\WINDOWS\tasks\McAfee.com Scan for Viruses - My Computer (D697QZ91-Wolfgang).job
[2010/07/15 11:01:27 | 000,082,432 | —- | M] () – C:\Documents and Settings\Sara\Desktop\WolfgangBurkhardtResumeMAV_ext07042010.doc
[2010/07/15 11:00:56 | 000,082,432 | —- | M] () – C:\Documents and Settings\Sara\Desktop\WolfgangBurkhardtResumeMAV_ext06042010.doc
[2010/07/15 08:34:20 | 000,243,024 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/07/15 08:34:13 | 000,012,536 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/07/15 08:30:27 | 000,216,400 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/07/15 06:07:36 | 000,445,938 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/07/15 06:07:35 | 000,508,318 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/07/15 06:07:35 | 000,072,978 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/07/09 09:59:39 | 000,025,088 | —- | M] () – C:\Documents and Settings\Sara\Desktop\Nutone06012010.doc
[2010/07/09 09:57:36 | 000,002,497 | —- | M] () – C:\Documents and Settings\Sara\Desktop\Microsoft Office Word 2003.lnk
[95 C:\*.tmp files -> C:\*.tmp -> ]
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/07/31 10:24:10 | 003,703,009 | —- | C] () – C:\Documents and Settings\Sara\Desktop\DSC_0097.jpg
[2010/07/15 11:01:27 | 000,082,432 | —- | C] () – C:\Documents and Settings\Sara\Desktop\WolfgangBurkhardtResumeMAV_ext07042010.doc
[2010/07/15 10:04:37 | 000,082,432 | —- | C] () – C:\Documents and Settings\Sara\Desktop\WolfgangBurkhardtResumeMAV_ext06042010.doc
[2010/07/09 09:59:38 | 000,025,088 | —- | C] () – C:\Documents and Settings\Sara\Desktop\Nutone06012010.doc
[2010/02/06 19:19:27 | 000,000,050 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2010/01/04 11:18:25 | 000,000,000 | —- | C] () – C:\WINDOWS\ViewNX.INI
[2008/05/17 20:26:05 | 000,000,224 | —- | C] () – C:\WINDOWS\HPFTBX13.INI
[2007/04/17 07:43:43 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2007/02/18 15:03:16 | 000,000,104 | RHS- | C] () – C:\WINDOWS\System32\29210817DF.sys
[2006/05/27 12:56:09 | 000,007,518 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2006/05/27 12:56:09 | 000,000,008 | RHS- | C] () – C:\WINDOWS\System32\DF17082129.sys
[2006/05/18 20:49:24 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/05/15 17:48:09 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/05/15 17:34:31 | 000,000,292 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/05/15 17:04:54 | 000,016,480 | —- | C] () – C:\WINDOWS\System32\rixdicon.dll
[2006/05/15 17:04:43 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\preflib.dll
[2006/05/15 17:04:39 | 000,757,760 | —- | C] () – C:\WINDOWS\System32\bcm1xsup.dll
[2006/05/15 17:03:29 | 000,000,391 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/08/16 04:37:24 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/08/05 14:01:54 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/08/14 01:54:00 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[1998/09/25 04:43:10 | 000,004,404 | —- | C] () – C:\WINDOWS\System32\HPFlnk13.ini
[1998/09/25 04:35:52 | 000,152,064 | —- | C] () – C:\WINDOWS\System32\HPFdat13.dll
[1998/09/25 04:33:44 | 000,181,248 | —- | C] () – C:\WINDOWS\System32\HPFscp13.dll
[1998/09/25 04:22:28 | 000,007,680 | —- | C] () – C:\WINDOWS\System32\HPFhrl13.dll
[1998/09/25 04:22:26 | 000,271,360 | —- | C] () – C:\WINDOWS\System32\HPFsrl13.dll
[1998/09/25 04:22:20 | 000,297,472 | —- | C] () – C:\WINDOWS\System32\HPFmrl13.dll
[1998/09/25 04:22:14 | 001,080,320 | —- | C] () – C:\WINDOWS\System32\HPFtrl13.dll
[1998/09/25 04:17:48 | 000,194,048 | —- | C] () – C:\WINDOWS\System32\HPFcps13.dll
[1998/09/25 04:17:20 | 000,076,800 | —- | C] () – C:\WINDOWS\System32\HPF24r13.dll
[1998/09/25 04:16:06 | 000,044,544 | —- | C] () – C:\WINDOWS\System32\HPFtst13.dll
[1998/09/25 04:08:42 | 000,395,264 | —- | C] () – C:\WINDOWS\System32\HPFui13.dll
[1998/09/25 04:03:08 | 000,187,904 | —- | C] () – C:\WINDOWS\System32\HPFwin13.dll
[1998/09/25 03:59:52 | 000,037,376 | —- | C] () – C:\WINDOWS\System32\HPFmon13.dll
[1998/09/25 03:59:14 | 000,033,280 | —- | C] () – C:\WINDOWS\System32\HPFcbl13.dll
[1998/09/25 03:56:58 | 000,033,384 | —- | C] () – C:\WINDOWS\System32\HPFiop13.dll
[1998/09/25 03:56:46 | 000,069,284 | —- | C] () – C:\WINDOWS\System32\HPFpml13.dll
[1998/09/25 03:56:40 | 000,137,232 | —- | C] () – C:\WINDOWS\System32\HPFmlc13.dll
[1998/09/25 03:56:32 | 000,057,240 | —- | C] () – C:\WINDOWS\System32\HPFmem13.dll
[1998/09/25 03:56:28 | 000,048,292 | —- | C] () – C:\WINDOWS\System32\HPFlpm13.dll
[1998/09/25 03:56:16 | 000,072,368 | —- | C] () – C:\WINDOWS\System32\HPFcom13.dll
[1998/09/25 03:55:24 | 000,052,800 | —- | C] () – C:\WINDOWS\System32\drivers\HPFecp13.sys
[1998/09/25 03:54:34 | 000,029,184 | —- | C] () – C:\WINDOWS\System32\HPFrsu13.dll
[1998/09/25 03:54:04 | 000,117,760 | —- | C] () – C:\WINDOWS\System32\HPFrsa13.dll
[1998/09/25 03:49:34 | 001,777,664 | —- | C] () – C:\WINDOWS\System32\HPFimg13.dll
[1998/09/25 03:46:14 | 000,124,928 | —- | C] () – C:\WINDOWS\System32\HPFcnt13.dll
========== LOP Check ==========
[2010/05/23 18:32:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2010/02/22 08:49:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2009/02/10 16:40:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2008/06/29 18:58:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2009/02/10 16:37:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nikon
[2010/03/07 19:13:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2010/02/07 16:31:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RegCure
[2010/01/26 15:35:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Seagate
[2009/07/08 15:24:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2007/04/17 07:07:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/06/03 12:58:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\UAB
[2009/02/10 16:40:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2007/05/27 15:20:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/06/11 12:54:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/06/01 10:19:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2008/08/23 20:37:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\Boomzap
[2009/07/08 15:26:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\CallingID
[2009/07/27 20:21:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009/12/25 13:23:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\comcasttb
[2006/11/26 16:27:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\EverAd
[2010/06/05 11:17:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\InfraRecorder
[2008/10/11 22:05:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\install_4746_MHw0MXwxMDIwMDAwMDAwfHx8fHx8fHw_(1)
[2008/10/08 10:43:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\IUpd721
[2010/04/09 23:04:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\iWin
[2008/07/07 20:42:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\Jane s Hotel
[2007/08/12 12:09:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\Leadertech
[2008/10/10 18:04:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\Logs
[2009/12/23 19:37:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\MSNInstaller
[2010/01/04 11:17:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\Nikon
[2008/10/09 17:55:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\PCPrivacyCleaner
[2010/04/11 16:56:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\PlayFirst
[2009/12/23 18:41:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\TeamViewer
[2007/05/27 15:20:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\Viewpoint
[2010/01/05 08:54:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\XnView
[2010/08/05 12:05:04 | 000,000,420 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{5215825E-42C8-430F-9BC0-4F33662C7C32}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: AGP440.SYS >
[2004/08/10 05:00:00 | 016,971,599 | —- | M] () .cab file – C:\i386\sp2.cab:AGP440.sys
[2004/08/10 05:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2009/05/19 08:10:47 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2009/05/19 08:10:47 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/03 23:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\i386\AGP440.SYS
< MD5 for: ATAPI.SYS >
[2004/08/10 05:00:00 | 016,971,599 | —- | M] () .cab file – C:\i386\sp2.cab:atapi.sys
[2004/08/10 05:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2009/05/19 08:10:47 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2009/05/19 08:10:47 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\i386\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/10 05:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\i386\eventlog.dll
< MD5 for: NETLOGON.DLL >
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2004/08/10 05:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\i386\netlogon.dll
< MD5 for: SCECLI.DLL >
[2004/08/10 05:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\i386\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2008/04/13 19:11:51 | 001,267,200 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\comsvcs.dll
[6 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2005/08/16 04:27:08 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2005/08/16 04:27:08 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2005/08/16 04:27:08 | 000,876,544 | —- | M] () – C:\WINDOWS\system32\config\system.sav
========== Alternate Data Streams ==========
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >
OTL by OldTimer - Version 3.2.9.1 Folder = C:\Documents and Settings\Sara\My Documents\Downloads
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
502.00 Mb Total Physical Memory | 145.00 Mb Available Physical Memory | 29.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): C:\pagefile.sys 1512 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 49.80 Gb Total Space | 21.74 Gb Free Space | 43.66% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: D697QZ91
Current User Name: Sara
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Sara\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Sara\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (MskService) – File not found
SRV - (MpfService) – File not found
SRV - (mcupdmgr.exe) – File not found
SRV - (McTskshd.exe) – File not found
SRV - (McShield) – File not found
SRV - (McDetect.exe) – File not found
SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
========== Driver Services (SafeList) ==========
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\System32\DRIVERS\wanatw4.sys File not found
DRV - (cpuz132) – C:\DOCUME~1\Sara\LOCALS~1\Temp\cpuz132\cpuz132_x32.sys File not found
DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (dsunidrv) – C:\WINDOWS\system32\drivers\dsunidrv.sys (Gteko Ltd.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (SynTP) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (MPFIREWL) – C:\WINDOWS\system32\drivers\MpFirewall.sys (McAfee)
DRV - (BCM43XX) – C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corporation)
DRV - (rismxdp) – C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (APPDRV) – C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS (Dell Inc)
DRV - (NaiAvFilter1) – C:\WINDOWS\system32\drivers\naiavf5x.sys (McAfee Inc.)
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (tfsnudfa) – C:\WINDOWS\system32\dla\tfsnudfa.sys (Sonic Solutions)
DRV - (tfsnudf) – C:\WINDOWS\system32\dla\tfsnudf.sys (Sonic Solutions)
DRV - (tfsnifs) – C:\WINDOWS\system32\dla\tfsnifs.sys (Sonic Solutions)
DRV - (tfsncofs) – C:\WINDOWS\system32\dla\tfsncofs.sys (Sonic Solutions)
DRV - (tfsnboio) – C:\WINDOWS\system32\dla\tfsnboio.sys (Sonic Solutions)
DRV - (tfsnopio) – C:\WINDOWS\system32\dla\tfsnopio.sys (Sonic Solutions)
DRV - (tfsnpool) – C:\WINDOWS\system32\dla\tfsnpool.sys (Sonic Solutions)
DRV - (tfsndrct) – C:\WINDOWS\system32\dla\tfsndrct.sys (Sonic Solutions)
DRV - (tfsndres) – C:\WINDOWS\system32\dla\tfsndres.sys (Sonic Solutions)
DRV - (drvmcdb) – C:\WINDOWS\system32\drivers\drvmcdb.sys (Sonic Solutions)
DRV - (drvnddm) – C:\WINDOWS\system32\drivers\drvnddm.sys (Sonic Solutions)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (sscdbhk5) – C:\WINDOWS\system32\drivers\sscdbhk5.sys (Sonic Solutions)
DRV - (ssrtln) – C:\WINDOWS\system32\drivers\ssrtln.sys (Sonic Solutions)
DRV - (omci) – C:\WINDOWS\system32\drivers\omci.sys (Dell Inc)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (HPFECP13) – C:\WINDOWS\System32\drivers\HPFECP13.SYS ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.3
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.845
FF - prefs.js..extensions.enabledItems: {35106bca-6c78-48c7-ac28-56df30b51d2d}:1.2.4
FF - prefs.js..keyword.URL: "http://www.google.com/search?sourceid=navclient&hl;=en&q;="
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/08/04 15:22:20 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared [2010/03/26 20:59:54 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/20 19:08:12 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/10 09:09:45 | 000,000,000 | —D | M]
[2009/12/27 12:26:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\Mozilla\Extensions
[2010/08/05 11:42:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\Mozilla\Firefox\Profiles\8fryscue.default\extensions
[2010/04/24 14:23:12 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\Sara\Application Data\Mozilla\Firefox\Profiles\8fryscue.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010/05/15 18:11:05 | 000,000,000 | —D | M] (PopupMaster) – C:\Documents and Settings\Sara\Application Data\Mozilla\Firefox\Profiles\8fryscue.default\extensions\{35106bca-6c78-48c7-ac28-56df30b51d2d}
[2010/01/20 16:34:07 | 000,000,000 | —D | M] (Adblock Plus) – C:\Documents and Settings\Sara\Application Data\Mozilla\Firefox\Profiles\8fryscue.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/06/07 14:28:03 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: ([2009/12/21 11:33:11 | 000,366,461 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 12612 more lines…
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll File not found
O4 - HKCU..\Run: [Sonic RecordNow!] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000031 - C:\WINDOWS\System32\mclsp.dll (McAfee, Inc.)
O15 - HKCU\..Trusted Domains: yahoo.com ([login] https in Trusted sites)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/9/b…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (C:\WINDOWS\system32\BCMLogon.dll) - C:\WINDOWS\system32\BCMLogon.dll (Broadcom Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Sara\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Sara\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/08/16 04:43:04 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{1536f12f-ca54-11dd-8136-0015c515efd7}\Shell\AutoRun\command - "" = F:\wdsync.exe – File not found
O33 - MountPoints2\{2eb575d8-cedc-11dc-807a-0015c515efd7}\Shell\AutoRun\command - "" = D:\LinksysConnectPC.exe – File not found
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun\command - "" = E:\setup.exe – File not found
O33 - MountPoints2\{4d1cb884-e94a-11dd-8144-0015c515efd7}\Shell - "" = AutoRun
O33 - MountPoints2\{4d1cb884-e94a-11dd-8144-0015c515efd7}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{4d1cb884-e94a-11dd-8144-0015c515efd7}\Shell\AutoRun\command - "" = D:\LaunchU3.exe – File not found
O33 - MountPoints2\{c760b5e0-d918-11dc-808f-0015c515efd7}\Shell - "" = AutoRun
O33 - MountPoints2\{c760b5e0-d918-11dc-808f-0015c515efd7}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{c760b5e0-d918-11dc-808f-0015c515efd7}\Shell\AutoRun\command - "" = E:\LaunchU3.exe – File not found
O33 - MountPoints2\{edb9d88d-126b-11df-86f3-0015c515efd7}\Shell\AutoRun\command - "" = D:\Setup_FlipShare.exe – File not found
O33 - MountPoints2\{edb9d88d-126b-11df-86f3-0015c515efd7}\Shell\Setup FlipShare\command - "" = D:\Setup_FlipShare.exe – File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
========== Files/Folders - Created Within 30 Days ==========
[2010/08/05 07:56:24 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Sara\Recent
[2010/07/27 01:30:35 | 008,462,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shell32.dll
[2010/07/19 14:21:40 | 000,000,000 | —D | C] – C:\WINDOWS\System32\Adobe
[2010/07/15 08:34:13 | 000,012,536 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/07/14 09:01:40 | 000,744,448 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\helpsvc.exe
[95 C:\*.tmp files -> C:\*.tmp -> ]
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/08/05 12:26:44 | 000,000,000 | —- | M] () – C:\Documents and Settings\Sara\Local Settings\Application Data\prvlcl.dat
[2010/08/05 12:05:04 | 000,000,420 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{5215825E-42C8-430F-9BC0-4F33662C7C32}.job
[2010/08/05 12:00:45 | 000,002,445 | —- | M] () – C:\Documents and Settings\Sara\Desktop\HiJackThis.lnk
[2010/08/05 10:55:26 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/08/05 10:54:22 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/08/05 10:54:19 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/08/05 10:54:18 | 526,843,904 | -HS- | M] () – C:\hiberfil.sys
[2010/08/05 10:52:31 | 008,126,464 | —- | M] () – C:\Documents and Settings\Sara\NTUSER.DAT
[2010/08/05 10:52:31 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Sara\ntuser.ini
[2010/08/05 08:41:16 | 062,974,081 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/08/05 08:06:43 | 004,793,568 | -H– | M] () – C:\Documents and Settings\Sara\Local Settings\Application Data\IconCache.db
[2010/08/05 07:45:06 | 000,002,495 | —- | M] () – C:\Documents and Settings\Sara\Desktop\Microsoft Office Excel 2003.lnk
[2010/07/30 14:34:12 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/07/27 01:30:35 | 008,462,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shell32.dll
[2010/07/23 14:10:47 | 000,029,696 | —- | M] () – C:\Documents and Settings\Sara\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/16 18:30:00 | 000,000,356 | —- | M] () – C:\WINDOWS\tasks\McAfee.com Scan for Viruses - My Computer (D697QZ91-Wolfgang).job
[2010/07/15 11:01:27 | 000,082,432 | —- | M] () – C:\Documents and Settings\Sara\Desktop\WolfgangBurkhardtResumeMAV_ext07042010.doc
[2010/07/15 11:00:56 | 000,082,432 | —- | M] () – C:\Documents and Settings\Sara\Desktop\WolfgangBurkhardtResumeMAV_ext06042010.doc
[2010/07/15 08:34:20 | 000,243,024 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2010/07/15 08:34:13 | 000,012,536 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2010/07/15 08:30:27 | 000,216,400 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2010/07/15 06:07:36 | 000,445,938 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/07/15 06:07:35 | 000,508,318 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/07/15 06:07:35 | 000,072,978 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/07/09 09:59:39 | 000,025,088 | —- | M] () – C:\Documents and Settings\Sara\Desktop\Nutone06012010.doc
[2010/07/09 09:57:36 | 000,002,497 | —- | M] () – C:\Documents and Settings\Sara\Desktop\Microsoft Office Word 2003.lnk
[95 C:\*.tmp files -> C:\*.tmp -> ]
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/07/31 10:24:10 | 003,703,009 | —- | C] () – C:\Documents and Settings\Sara\Desktop\DSC_0097.jpg
[2010/07/15 11:01:27 | 000,082,432 | —- | C] () – C:\Documents and Settings\Sara\Desktop\WolfgangBurkhardtResumeMAV_ext07042010.doc
[2010/07/15 10:04:37 | 000,082,432 | —- | C] () – C:\Documents and Settings\Sara\Desktop\WolfgangBurkhardtResumeMAV_ext06042010.doc
[2010/07/09 09:59:38 | 000,025,088 | —- | C] () – C:\Documents and Settings\Sara\Desktop\Nutone06012010.doc
[2010/02/06 19:19:27 | 000,000,050 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2010/01/04 11:18:25 | 000,000,000 | —- | C] () – C:\WINDOWS\ViewNX.INI
[2008/05/17 20:26:05 | 000,000,224 | —- | C] () – C:\WINDOWS\HPFTBX13.INI
[2007/04/17 07:43:43 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2007/02/18 15:03:16 | 000,000,104 | RHS- | C] () – C:\WINDOWS\System32\29210817DF.sys
[2006/05/27 12:56:09 | 000,007,518 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2006/05/27 12:56:09 | 000,000,008 | RHS- | C] () – C:\WINDOWS\System32\DF17082129.sys
[2006/05/18 20:49:24 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/05/15 17:48:09 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2006/05/15 17:34:31 | 000,000,292 | —- | C] () – C:\WINDOWS\wininit.ini
[2006/05/15 17:04:54 | 000,016,480 | —- | C] () – C:\WINDOWS\System32\rixdicon.dll
[2006/05/15 17:04:43 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\preflib.dll
[2006/05/15 17:04:39 | 000,757,760 | —- | C] () – C:\WINDOWS\System32\bcm1xsup.dll
[2006/05/15 17:03:29 | 000,000,391 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/08/16 04:37:24 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005/08/05 14:01:54 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/08/14 01:54:00 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[1998/09/25 04:43:10 | 000,004,404 | —- | C] () – C:\WINDOWS\System32\HPFlnk13.ini
[1998/09/25 04:35:52 | 000,152,064 | —- | C] () – C:\WINDOWS\System32\HPFdat13.dll
[1998/09/25 04:33:44 | 000,181,248 | —- | C] () – C:\WINDOWS\System32\HPFscp13.dll
[1998/09/25 04:22:28 | 000,007,680 | —- | C] () – C:\WINDOWS\System32\HPFhrl13.dll
[1998/09/25 04:22:26 | 000,271,360 | —- | C] () – C:\WINDOWS\System32\HPFsrl13.dll
[1998/09/25 04:22:20 | 000,297,472 | —- | C] () – C:\WINDOWS\System32\HPFmrl13.dll
[1998/09/25 04:22:14 | 001,080,320 | —- | C] () – C:\WINDOWS\System32\HPFtrl13.dll
[1998/09/25 04:17:48 | 000,194,048 | —- | C] () – C:\WINDOWS\System32\HPFcps13.dll
[1998/09/25 04:17:20 | 000,076,800 | —- | C] () – C:\WINDOWS\System32\HPF24r13.dll
[1998/09/25 04:16:06 | 000,044,544 | —- | C] () – C:\WINDOWS\System32\HPFtst13.dll
[1998/09/25 04:08:42 | 000,395,264 | —- | C] () – C:\WINDOWS\System32\HPFui13.dll
[1998/09/25 04:03:08 | 000,187,904 | —- | C] () – C:\WINDOWS\System32\HPFwin13.dll
[1998/09/25 03:59:52 | 000,037,376 | —- | C] () – C:\WINDOWS\System32\HPFmon13.dll
[1998/09/25 03:59:14 | 000,033,280 | —- | C] () – C:\WINDOWS\System32\HPFcbl13.dll
[1998/09/25 03:56:58 | 000,033,384 | —- | C] () – C:\WINDOWS\System32\HPFiop13.dll
[1998/09/25 03:56:46 | 000,069,284 | —- | C] () – C:\WINDOWS\System32\HPFpml13.dll
[1998/09/25 03:56:40 | 000,137,232 | —- | C] () – C:\WINDOWS\System32\HPFmlc13.dll
[1998/09/25 03:56:32 | 000,057,240 | —- | C] () – C:\WINDOWS\System32\HPFmem13.dll
[1998/09/25 03:56:28 | 000,048,292 | —- | C] () – C:\WINDOWS\System32\HPFlpm13.dll
[1998/09/25 03:56:16 | 000,072,368 | —- | C] () – C:\WINDOWS\System32\HPFcom13.dll
[1998/09/25 03:55:24 | 000,052,800 | —- | C] () – C:\WINDOWS\System32\drivers\HPFecp13.sys
[1998/09/25 03:54:34 | 000,029,184 | —- | C] () – C:\WINDOWS\System32\HPFrsu13.dll
[1998/09/25 03:54:04 | 000,117,760 | —- | C] () – C:\WINDOWS\System32\HPFrsa13.dll
[1998/09/25 03:49:34 | 001,777,664 | —- | C] () – C:\WINDOWS\System32\HPFimg13.dll
[1998/09/25 03:46:14 | 000,124,928 | —- | C] () – C:\WINDOWS\System32\HPFcnt13.dll
========== LOP Check ==========
[2010/05/23 18:32:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2010/02/22 08:49:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2009/02/10 16:40:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2008/06/29 18:58:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2009/02/10 16:37:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Nikon
[2010/03/07 19:13:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2010/02/07 16:31:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\RegCure
[2010/01/26 15:35:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Seagate
[2009/07/08 15:24:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2007/04/17 07:07:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/06/03 12:58:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\UAB
[2009/02/10 16:40:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2007/05/27 15:20:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2010/06/11 12:54:49 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/06/01 10:19:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2008/08/23 20:37:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\Boomzap
[2009/07/08 15:26:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\CallingID
[2009/07/27 20:21:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009/12/25 13:23:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\comcasttb
[2006/11/26 16:27:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\EverAd
[2010/06/05 11:17:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\InfraRecorder
[2008/10/11 22:05:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\install_4746_MHw0MXwxMDIwMDAwMDAwfHx8fHx8fHw_(1)
[2008/10/08 10:43:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\IUpd721
[2010/04/09 23:04:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\iWin
[2008/07/07 20:42:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\Jane s Hotel
[2007/08/12 12:09:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\Leadertech
[2008/10/10 18:04:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\Logs
[2009/12/23 19:37:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\MSNInstaller
[2010/01/04 11:17:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\Nikon
[2008/10/09 17:55:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\PCPrivacyCleaner
[2010/04/11 16:56:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\PlayFirst
[2009/12/23 18:41:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\TeamViewer
[2007/05/27 15:20:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\Viewpoint
[2010/01/05 08:54:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Sara\Application Data\XnView
[2010/08/05 12:05:04 | 000,000,420 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{5215825E-42C8-430F-9BC0-4F33662C7C32}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: AGP440.SYS >
[2004/08/10 05:00:00 | 016,971,599 | —- | M] () .cab file – C:\i386\sp2.cab:AGP440.sys
[2004/08/10 05:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2009/05/19 08:10:47 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2009/05/19 08:10:47 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 13:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/03 23:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\i386\AGP440.SYS
< MD5 for: ATAPI.SYS >
[2004/08/10 05:00:00 | 016,971,599 | —- | M] () .cab file – C:\i386\sp2.cab:atapi.sys
[2004/08/10 05:00:00 | 016,971,599 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2009/05/19 08:10:47 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2009/05/19 08:10:47 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 13:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\i386\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 19:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/10 05:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\i386\eventlog.dll
< MD5 for: NETLOGON.DLL >
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 19:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2004/08/10 05:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\i386\netlogon.dll
< MD5 for: SCECLI.DLL >
[2004/08/10 05:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\i386\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 19:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2008/04/13 19:11:51 | 001,267,200 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\system32\comsvcs.dll
[6 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2005/08/16 04:27:08 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2005/08/16 04:27:08 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2005/08/16 04:27:08 | 000,876,544 | —- | M] () – C:\WINDOWS\system32\config\system.sav
========== Alternate Data Streams ==========
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >