Lucky13pinupgirl
Topic Starter
I am having problems with being re-directed to other random websites every time I try to use google! I went through all the steps listed under the Removal Instructions you had listed, rebooted and still no dice. I did all the other scans you requested and will post the results. Any help will be great! I am not so computer savvy as you can probably already see….or I would not be infected!
I am not sure which scans you are looking for, so here is the OTL logfile. If you need the other 2 I can add them later! Thank you!
OTL logfile created on: 13/09/2010 8:39:32 PM - Run 1
OTL by OldTimer - Version 3.2.12.0 Folder = C:\Users\Lucky 13\Downloads
Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.16982)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 46.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 64.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 179.50 Gb Total Space | 124.53 Gb Free Space | 69.37% Space Free | Partition Type: NTFS
Drive D: | 1011.98 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
E: Drive not present or media not loaded
Drive F: | 931.51 Gb Total Space | 275.70 Gb Free Space | 29.60% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: LUCKY13-PC
Current User Name: Lucky 13
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Users\Lucky 13\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\plugin-container.exe (Mozilla Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe (Research In Motion Limited)
PRC - C:\Program Files\Bell Mobility\Mobile Connect Basic\tscui.exe (Bell)
PRC - C:\Program Files\Novatel Wireless\NovaCore\Server\NvtlSrvr.exe ()
PRC - C:\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
PRC - C:\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
PRC - C:\Program Files\Java\jre1.6.0\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\TOSHIBA\TOSHIBA HD DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\Synaptics\SynTP\SynToshiba.exe (Synaptics, Inc.)
PRC - C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe ()
PRC - C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (Chicony)
PRC - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
PRC - C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)
PRC - C:\Program Files\ltmoh\ltmoh.exe (Agere Systems)
PRC - C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\Utilities\KeNotify.exe ()
PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)
PRC - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
PRC - C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
========== Modules (SafeList) ==========
MOD - C:\Users\Lucky 13\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.20533_none_4634c4a0218d65c1\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (NvtlService) – C:\Program Files\Novatel Wireless\Novacore\Server\NvtlSrvr.exe ()
SRV - (SBSDWSCService) – C:\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (TNaviSrv) – C:\Program Files\TOSHIBA\TOSHIBA HD DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
SRV - (TosCoSrv) – C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV - (EvtEng) Intel® – C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
SRV - (RegSrvc) Intel® – C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
SRV - (TOSHIBA Bluetooth Service) – C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
SRV - (CFSvcs) – C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
SRV - (AgereModemAudio) – C:\Windows\System32\agrsmsvc.exe (Agere Systems)
SRV - (UleadBurningHelper) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
SRV - (TODDSrv) – C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
========== Driver Services (SafeList) ==========
DRV - (TpChoice) – C:\Windows\System32\DRIVERS\TpChoice.sys File not found
DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (blbdrive) – C:\Windows\System32\drivers\blbdrive.sys File not found
DRV - (NuidFltr) – C:\Windows\System32\drivers\nuidfltr.sys (Microsoft Corporation)
DRV - (PCASp50) – C:\Windows\System32\drivers\PCASp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (NWADI) – C:\Windows\System32\drivers\NWADIenum.sys (Novatel Wireless Inc)
DRV - (NWUSBPort2) – C:\Windows\System32\drivers\nwusbser2.sys (Novatel Wireless Inc.)
DRV - (NWUSBPort) – C:\Windows\System32\drivers\nwusbser.sys (Novatel Wireless Inc.)
DRV - (NWUSBModem) – C:\Windows\System32\drivers\nwusbmdm.sys (Novatel Wireless Inc.)
DRV - (NWUSBCDFIL) – C:\Windows\System32\drivers\NwUsbCdFil.sys (Novatel Wireless Inc.)
DRV - (tos_sps32) – C:\Windows\system32\DRIVERS\tos_sps32.sys (TOSHIBA Corporation)
DRV - (igfx) – C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (SynTP) – C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (BRCMDECO) – C:\Windows\System32\drivers\BRCMHD32.sys (Broadcom Corporation)
DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation )
DRV - (NETw4v32) Intel® – C:\Windows\System32\drivers\NETw4v32.sys (Intel Corporation)
DRV - (UVCFTR) – C:\Windows\System32\drivers\UVCFTR_S.SYS (Chicony Electronics Co., Ltd.)
DRV - (iaStor) – C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (tifm21) – C:\Windows\System32\drivers\tifm21.sys (Texas Instruments)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (tosrfec) – C:\Windows\System32\drivers\tosrfec.sys (TOSHIBA Corporation)
DRV - (tdcmdpst) – C:\Windows\System32\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV - (TVALZ) – C:\Windows\system32\DRIVERS\TVALZ_O.SYS (TOSHIBA Corporation)
DRV - (LPCFilter) – C:\Windows\system32\DRIVERS\LPCFilter.sys (COMPAL ELECTRONIC INC.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.google.ca/"
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.0.3
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: {872b5b88-9db5-4310-bdd0-ac189557e5f5}:2.7.2.0
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/09/09 17:27:14 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/09/09 17:27:14 | 000,000,000 | —D | M]
[2010/06/23 19:20:06 | 000,000,000 | —D | M] – C:\Users\Lucky 13\AppData\Roaming\Mozilla\Extensions
[2010/09/12 18:25:47 | 000,000,000 | —D | M] – C:\Users\Lucky 13\AppData\Roaming\Mozilla\Firefox\Profiles\0inf5kaw.default\extensions
[2010/09/12 18:25:38 | 000,000,000 | —D | M] (NoScript) – C:\Users\Lucky 13\AppData\Roaming\Mozilla\Firefox\Profiles\0inf5kaw.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2010/08/30 12:41:07 | 000,000,000 | —D | M] (DVDVideoSoftTB Toolbar) – C:\Users\Lucky 13\AppData\Roaming\Mozilla\Firefox\Profiles\0inf5kaw.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
[2010/08/05 17:54:07 | 000,000,000 | —D | M] (No name found) – C:\Users\Lucky 13\AppData\Roaming\Mozilla\Firefox\Profiles\0inf5kaw.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2010/06/23 19:19:46 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: ([2010/09/05 15:44:04 | 000,416,890 | R— | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 14390 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Adobe PDF Link Helper) - {74E41E96-1F6A-2C83-7A24-6FFA07F64C77} - C:\Windows\System32\ccmlua.dll ()
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [00TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe (Research In Motion Limited)
O4 - HKLM..\Run: [Camera Assistant Software] C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (Chicony)
O4 - HKLM..\Run: [HSON] C:\Program Files\TOSHIBA\TBS\HSON.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [HWSetup] File not found
O4 - HKLM..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe ()
O4 - HKLM..\Run: [LtMoh] C:\Program Files\ltmoh\ltmoh.exe (Agere Systems)
O4 - HKLM..\Run: [MCStart] C:\Program Files\Bell Mobility\Mobile Connect Basic\tscui.exe (Bell)
O4 - HKLM..\Run: [NDSTray.exe] File not found
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe (TOSHIBA)
O4 - HKLM..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [tscui] C:\Program Files\Bell Mobility\Mobile Connect Basic\tscui.exe (Bell)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [ISUSPM] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKCU..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Lucky 13\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm ()
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Users\Lucky 13\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Lucky 13\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 15:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2009/01/31 19:51:24 | 000,000,033 | -HS- | M] () - F:\autorun.inf – [ NTFS ]
O33 - MountPoints2\{993fd453-7f2e-11df-b206-001b384af900}\Shell - "" = AutoRun
O33 - MountPoints2\{993fd453-7f2e-11df-b206-001b384af900}\Shell\AutoRun\command - "" = E:\AutoLaunch.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.dvacm - C:\Program Files\Common Files\Ulead Systems\vio\DVACM.acm (Ulead Systems, Inc.)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2010/09/09 17:25:53 | 000,000,000 | —D | C] – C:\Program Files\Golden Trails - The New Western Rush2
[2010/09/09 17:14:39 | 000,000,000 | —D | C] – C:\ProgramData\WildWestQuest2
[2010/09/08 16:11:20 | 000,000,000 | —D | C] – C:\Users\Lucky 13\AppData\Roaming\Awem
[2010/09/08 16:11:12 | 000,000,000 | —D | C] – C:\Program Files\Dream Day Couple
[2010/09/08 16:08:56 | 000,000,000 | —D | C] – C:\Program Files\Golden Trails - The New Western Rush
[2010/09/08 14:18:13 | 000,000,000 | —D | C] – C:\Users\Lucky 13\AppData\Local\WinZip
[2010/08/30 06:58:09 | 000,000,000 | —D | C] – C:\Spybot - Search & Destroy
[2010/08/30 06:58:09 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2010/08/30 06:49:20 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/08/29 19:02:35 | 000,000,000 | —D | C] – C:\Users\Lucky 13\AppData\Local\Windows Server
[2010/08/21 21:16:24 | 000,000,000 | —D | C] – C:\Program Files\Dream Day Wedding Married in Manhattan
[2010/08/19 19:04:22 | 000,000,000 | —D | C] – C:\Program Files\Games
[2010/08/18 22:14:43 | 000,000,000 | —D | C] – C:\Users\Lucky 13\AppData\Local\Oberon Games
[2010/08/18 18:12:40 | 000,000,000 | —D | C] – C:\Program Files\Hide And Secret
[2010/08/18 18:10:43 | 000,000,000 | —D | C] – C:\Program Files\Dream Day Wedding
[2010/08/16 10:54:10 | 000,000,000 | —D | C] – C:\Users\Lucky 13\AppData\Roaming\PlayFirst
[2010/08/16 10:54:10 | 000,000,000 | —D | C] – C:\ProgramData\PlayFirst
[2010/08/16 10:53:15 | 000,000,000 | —D | C] – C:\Program Files\Mystery of Shark Island
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/09/13 20:40:43 | 000,003,072 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/09/13 20:40:43 | 000,003,072 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/09/13 20:37:11 | 006,029,312 | -HS- | M] () – C:\Users\Lucky 13\NTUSER.DAT
[2010/09/13 19:05:05 | 000,000,348 | —- | M] () – C:\Windows\tasks\At3.job
[2010/09/13 18:12:36 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/09/13 17:49:33 | 000,720,952 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/09/13 17:49:33 | 000,626,246 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/09/13 17:49:33 | 000,109,370 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/09/13 17:40:45 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/09/13 17:40:31 | 2137,448,448 | -HS- | M] () – C:\hiberfil.sys
[2010/09/13 16:24:11 | 000,002,529 | —- | M] () – C:\Users\Lucky 13\Desktop\HiJackThis.lnk
[2010/09/13 16:11:40 | 000,007,647 | —- | M] () – C:\Users\Lucky 13\Desktop\hijackthis3
[2010/09/13 16:09:08 | 327,113,461 | —- | M] () – C:\Windows\MEMORY.DMP
[2010/09/13 13:21:11 | 000,000,348 | —- | M] () – C:\Windows\tasks\At2.job
[2010/09/13 01:28:08 | 000,000,348 | —- | M] () – C:\Windows\tasks\At4.job
[2010/09/10 07:49:05 | 000,000,348 | —- | M] () – C:\Windows\tasks\At1.job
[2010/09/09 23:49:52 | 000,043,008 | —- | M] () – C:\Users\Lucky 13\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/09 17:26:53 | 000,001,970 | —- | M] () – C:\Users\Lucky 13\Desktop\Golden Trails - The New Western Rush.lnk
[2010/09/09 17:13:08 | 000,001,920 | —- | M] () – C:\Users\Lucky 13\Desktop\Wild West Quest 2.lnk
[2010/09/08 14:11:42 | 000,000,913 | —- | M] () – C:\Users\Lucky 13\Desktop\Dream Day Wedding.lnk
[2010/09/05 15:44:04 | 000,416,890 | R— | M] () – C:\Windows\System32\drivers\etc\hosts
[2010/09/05 09:42:02 | 000,002,069 | —- | M] () – C:\Users\Lucky 13\Desktop\Dream Day Wedding 6 Bella Italia.lnk
[2010/08/30 08:15:20 | 000,000,875 | R— | M] () – C:\Windows\System32\drivers\etc\hosts.20100830-082415.backup
[2010/08/30 08:14:26 | 000,416,917 | R— | M] () – C:\Windows\System32\drivers\etc\hosts.20100830-081520.backup
[2010/08/30 08:09:59 | 000,000,680 | —- | M] () – C:\Users\Lucky 13\AppData\Local\d3d9caps.dat
[2010/08/30 08:07:32 | 000,000,552 | —- | M] () – C:\Users\Lucky 13\AppData\Local\d3d8caps.dat
[2010/08/30 06:58:20 | 000,000,820 | —- | M] () – C:\Users\Lucky 13\Desktop\Spybot - Search & Destroy.lnk
[2010/08/26 07:14:43 | 005,316,736 | —- | M] () – C:\Users\Lucky 13\Desktop\The Chakachas - Jungle Fever.- DJ Luis Mario 'Flaco' Orellana.mp3
[2010/08/22 17:59:52 | 000,001,185 | —- | M] () – C:\Users\Lucky 13\Desktop\Dream Day Wedding - Married in Manhattan - Shortcut.lnk
[2010/08/19 19:04:59 | 000,002,066 | —- | M] () – C:\Users\Lucky 13\Desktop\Dream Day Wedding - Viva Las Vegas.lnk
[2010/08/18 18:18:04 | 000,001,999 | —- | M] () – C:\Users\Public\Desktop\Private Eye - Greatest Unsolved Mysteries.lnk
[2010/08/18 18:18:04 | 000,001,536 | —- | M] () – C:\Users\Public\Desktop\More great games.lnk
[2010/08/16 09:53:40 | 000,000,949 | —- | M] () – C:\Users\Lucky 13\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/09/13 17:40:31 | 2137,448,448 | -HS- | C] () – C:\hiberfil.sys
[2010/09/13 16:11:40 | 000,007,647 | —- | C] () – C:\Users\Lucky 13\Desktop\hijackthis3
[2010/09/09 17:26:53 | 000,001,970 | —- | C] () – C:\Users\Lucky 13\Desktop\Golden Trails - The New Western Rush.lnk
[2010/09/09 17:13:08 | 000,001,920 | —- | C] () – C:\Users\Lucky 13\Desktop\Wild West Quest 2.lnk
[2010/09/08 14:11:42 | 000,000,913 | —- | C] () – C:\Users\Lucky 13\Desktop\Dream Day Wedding.lnk
[2010/08/30 13:24:02 | 000,002,069 | —- | C] () – C:\Users\Lucky 13\Desktop\Dream Day Wedding 6 Bella Italia.lnk
[2010/08/30 13:23:13 | 000,000,348 | —- | C] () – C:\Windows\tasks\At4.job
[2010/08/30 13:23:12 | 000,000,348 | —- | C] () – C:\Windows\tasks\At3.job
[2010/08/30 13:23:10 | 000,000,348 | —- | C] () – C:\Windows\tasks\At2.job
[2010/08/30 13:23:05 | 000,000,348 | —- | C] () – C:\Windows\tasks\At1.job
[2010/08/30 08:09:59 | 000,000,680 | —- | C] () – C:\Users\Lucky 13\AppData\Local\d3d9caps.dat
[2010/08/30 08:07:32 | 000,000,552 | —- | C] () – C:\Users\Lucky 13\AppData\Local\d3d8caps.dat
[2010/08/30 06:58:20 | 000,000,820 | —- | C] () – C:\Users\Lucky 13\Desktop\Spybot - Search & Destroy.lnk
[2010/08/30 06:49:20 | 000,002,529 | —- | C] () – C:\Users\Lucky 13\Desktop\HiJackThis.lnk
[2010/08/26 06:50:44 | 005,316,736 | —- | C] () – C:\Users\Lucky 13\Desktop\The Chakachas - Jungle Fever.- DJ Luis Mario 'Flaco' Orellana.mp3
[2010/08/22 17:59:52 | 000,001,185 | —- | C] () – C:\Users\Lucky 13\Desktop\Dream Day Wedding - Married in Manhattan - Shortcut.lnk
[2010/08/19 19:04:59 | 000,002,066 | —- | C] () – C:\Users\Lucky 13\Desktop\Dream Day Wedding - Viva Las Vegas.lnk
[2010/08/18 18:18:04 | 000,001,999 | —- | C] () – C:\Users\Public\Desktop\Private Eye - Greatest Unsolved Mysteries.lnk
[2010/08/16 09:53:40 | 000,000,949 | —- | C] () – C:\Users\Lucky 13\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2010/08/13 11:48:09 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2010/08/10 16:38:50 | 000,034,308 | —- | C] () – C:\Windows\System32\BASSMOD.dll
[2010/07/08 16:50:26 | 000,043,008 | —- | C] () – C:\Users\Lucky 13\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/23 19:11:15 | 000,128,113 | —- | C] () – C:\Windows\System32\csellang.ini
[2010/06/23 19:11:15 | 000,045,056 | —- | C] () – C:\Windows\System32\csellang.dll
[2010/06/23 19:11:15 | 000,010,150 | —- | C] () – C:\Windows\System32\tosmreg.ini
[2010/06/23 19:11:15 | 000,007,671 | —- | C] () – C:\Windows\System32\cseltbl.ini
[2010/06/23 09:56:15 | 000,204,800 | —- | C] () – C:\Windows\System32\IVIresizeW7.dll
[2010/06/23 09:56:15 | 000,200,704 | —- | C] () – C:\Windows\System32\IVIresizeA6.dll
[2010/06/23 09:56:15 | 000,192,512 | —- | C] () – C:\Windows\System32\IVIresizeP6.dll
[2010/06/23 09:56:15 | 000,192,512 | —- | C] () – C:\Windows\System32\IVIresizeM6.dll
[2010/06/23 09:56:15 | 000,188,416 | —- | C] () – C:\Windows\System32\IVIresizePX.dll
[2010/06/23 09:56:15 | 000,020,480 | —- | C] () – C:\Windows\System32\IVIresize.dll
[2007/09/26 23:33:57 | 000,036,864 | —- | C] () – C:\Windows\System32\HWS_Ctrl.dll
[2007/09/26 23:15:57 | 000,000,000 | —- | C] () – C:\Windows\NDSTray.INI
[2007/09/26 21:57:53 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2007/09/26 02:25:11 | 001,238,832 | —- | C] () – C:\Windows\System32\igmedkrn.dll
[2007/09/26 02:25:11 | 000,249,856 | —- | C] () – C:\Windows\System32\igfxTMM.dll
[2007/09/26 02:25:11 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1329.dll
[2007/09/26 02:25:11 | 000,104,636 | —- | C] () – C:\Windows\System32\igmedcompkrn.dll
[2007/03/06 17:54:04 | 000,995,328 | —- | C] () – C:\Windows\System32\WLIHVUI.dll
[2006/12/05 14:05:06 | 000,114,688 | —- | C] () – C:\Windows\System32\TosBtAcc.dll
[2006/11/02 06:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 02:57:48 | 000,180,224 | —- | C] () – C:\Windows\System32\ccmlua.dll
[2006/11/02 01:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2005/11/23 15:55:42 | 000,024,576 | —- | C] () – C:\Windows\System32\SPCtl.dll
[2005/07/22 22:30:20 | 000,065,536 | —- | C] () – C:\Windows\System32\TosCommAPI.dll
========== LOP Check ==========
[2010/08/09 12:59:55 | 000,000,000 | —D | M] – C:\Users\Lucky 13\AppData\Roaming\Anarchy
[2010/09/08 16:11:20 | 000,000,000 | —D | M] – C:\Users\Lucky 13\AppData\Roaming\Awem
[2010/08/05 17:54:06 | 000,000,000 | —D | M] – C:\Users\Lucky 13\AppData\Roaming\DVDVideoSoftIEHelpers
[2010/08/11 09:52:56 | 000,000,000 | —D | M] – C:\Users\Lucky 13\AppData\Roaming\FloodLightGames
[2010/08/13 14:41:54 | 000,000,000 | —D | M] – C:\Users\Lucky 13\AppData\Roaming\Magic Academy
[2010/08/08 22:18:48 | 000,000,000 | —D | M] – C:\Users\Lucky 13\AppData\Roaming\MysteryStudio
[2010/08/16 10:54:10 | 000,000,000 | —D | M] – C:\Users\Lucky 13\AppData\Roaming\PlayFirst
[2010/06/23 21:28:30 | 000,000,000 | —D | M] – C:\Users\Lucky 13\AppData\Roaming\Research In Motion
[2010/09/10 07:49:05 | 000,000,348 | —- | M] () – C:\Windows\Tasks\At1.job
[2010/09/13 13:21:11 | 000,000,348 | —- | M] () – C:\Windows\Tasks\At2.job
[2010/09/13 19:05:05 | 000,000,348 | —- | M] () – C:\Windows\Tasks\At3.job
[2010/09/13 01:28:08 | 000,000,348 | —- | M] () – C:\Windows\Tasks\At4.job
[2010/09/05 15:38:32 | 000,032,480 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2006/09/18 15:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2006/11/02 03:53:57 | 000,438,840 | RHS- | M] () – C:\bootmgr
[2007/09/26 17:57:07 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 15:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2010/09/13 17:40:31 | 2137,448,448 | -HS- | M] () – C:\hiberfil.sys
[2010/09/13 17:40:29 | 2451,374,080 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2006/11/02 06:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 06:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 06:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2006/11/02 06:37:12 | 000,030,808 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 15:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/11/02 06:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2010/06/25 12:25:25 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2006/11/02 04:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 04:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 04:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 04:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 04:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/07/10 20:27:11 | 000,000,365 | -HS- | M] () – C:\Users\Lucky 13\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-09-03 07:36:51
========== Alternate Data Streams ==========
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:C7F08EA3
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:32A82570
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:317F7381
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:9E999B93
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:3B5038B1
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:5D59B736
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:E40EED9B
< End of report >
OTL Extras logfile created on: 13/09/2010 8:39:32 PM - Run 1
OTL by OldTimer - Version 3.2.12.0 Folder = C:\Users\Lucky 13\Downloads
Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.16982)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 46.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 64.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 179.50 Gb Total Space | 124.53 Gb Free Space | 69.37% Space Free | Partition Type: NTFS
Drive D: | 1011.98 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
E: Drive not present or media not loaded
Drive F: | 931.51 Gb Total Space | 275.70 Gb Free Space | 29.60% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: LUCKY13-PC
Current User Name: Lucky 13
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{745679E8-6D91-4C36-844E-A76183D5B83E}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{807AD8C1-C976-4FC0-BF4B-2158B3A28090}" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{FBD8C3BD-F78C-433D-AC4D-6652F1676173}" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{008D69EB-70FF-46AB-9C75-924620DF191A}" = TOSHIBA Speech System SR Engine(U.S.) Version1.0
"{07BB4D84-BE7E-45ED-B145-9A474700F590}" = Mobile Broadband Generic Drivers
"{12688FD7-CB92-4A5B-BEE4-5C8E0574434F}" = Utility Common Driver
"{12B3A009-A080-4619-9A2A-C6DB151D8D67}" = TOSHIBA Assist
"{145E18EC-4BBB-4A0C-9381-564ABB871FE9}" = Mobile Connect Basic
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java™ SE Runtime Environment 6
"{37C866E4-AA67-4725-9E95-A39968DD7960}" = Camera Assistant Software for Toshiba
"{3FBF6F99-8EC6-41B4-8527-0A32241B5496}" = TOSHIBA Speech System TTS Engine(U.S.) Version1.0
"{40A594D0-1490-4979-9382-D2B764F949C6}" = BlackBerry® Media Sync
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}" = TOSHIBA Supervisor Password
"{5279374D-87FE-4879-9385-F17278EBB9D3}" = TOSHIBA Hardware Setup
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator
"{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"{620BBA5E-F848-4D56-8BDA-584E44584C5E}" = TOSHIBA Flash Cards Support Utility
"{65D4DAA8-3611-4322-8E69-27880AFD90EC}" = reminder
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{6B9C32DB-DBCD-45A8-B901-3A92A99A2474}" = InstallVC90Support
"{6C5F3BDC-0A1B-4436-A696-5939629D5C31}" = TOSHIBA HD DVD PLAYER
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{78C6A78A-8B03-48C8-A47C-78BA1FCA2307}" = TOSHIBA ConfigFree
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{8C6BB412-D3A8-4AAE-A01B-35B681789D68}" = mHelp
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel Matrix Storage Manager
"{91120000-0031-0000-0000-0000000FF1CE}" = Microsoft Office Professional Hybrid 2007
"{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}" = CD/DVD Drive Acoustic Silencer
"{AC76BA86-7AD7-1033-7B44-A80000000002}" = Adobe Reader 8
"{B2F3FB19-D848-479C-818E-130ABC9366DB}" = BlackBerry Device Software Updater
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B49DDCCE-BF8E-4A4C-8503-6DA24BF49D06}" = NovaCore SDK Installer
"{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser
"{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}" = TOSHIBA Recovery Disc Creator
"{B98BE95C-E76F-4246-B8E6-BEB8EE791D06}" = Roxio Media Manager
"{C53D16CC-E56F-47B8-906E-70AAF8EABB4F}" = Toshiba Registration
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240BD}" = WinZip 14.5
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE86E2F5-850C-4207-94A3-A58D647B1733}" = BlackBerry Desktop Software 5.0.1
"{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows by Toshiba
"{DB780B85-B4B5-4864-A49C-9B706B169C93}" = TIPCI
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E90C9405-DDC3-4DEB-95C8-DAAAAF69BB3E}" = Pop Art Studio 5.1
"{EBFF48F5-3CFA-436F-8FD5-94FB01D3A0A7}" = TOSHIBA SD Memory Utilities
"{EE033C1F-443E-41EC-A0E2-559B539A4E4D}" = TOSHIBA Speech System Applications
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F214EAA4-A069-4BAF-9DA4-4DB8BEEDE485}" = DVD MovieFactory for TOSHIBA
"{F5D7FAB5-A1FD-4DD3-983E-4155B09D7102}" = mCore
"{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"5 Spots II_is1" = 5 Spots II
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Agatha Christie Death On The Nile_is1" = Agatha Christie Death On The Nile
"BCM70010" = Broadcom High Definition Video Decoder [removed]
"BFGC" = Big Fish Games: Game Manager
"BFG-Murder She Wrote" = Murder, She Wrote
"BFG-Redrum - Time Lies" = Redrum: Time Lies
"Big City Adventure - San Francisco" = Big City Adventure - San Francisco (remove only)
"BlackBerry_{CE86E2F5-850C-4207-94A3-A58D647B1733}" = BlackBerry Desktop Software 5.0.1
"Dream Day Couple_is1" = Dream Day Couple
"Dream Day Wedding - Viva Las Vegas 1.00" = Dream Day Wedding - Viva Las Vegas 1.00
"Dream Day Wedding 6 Bella Italia 1.00" = Dream Day Wedding 6 Bella Italia 1.00
"Dream Day Wedding Married in Manhattan" = Dream Day Wedding Married in Manhattan
"Dream Day Wedding_is1" = Dream Day Wedding
"Free Audio CD Burner_is1" = Free Audio CD Burner version 1.4
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.7
"Golden Trails - The New Western Rush_is1" = Golden Trails - The New Western Rush
"Golden Trails - The New Western Rush1.0" = Golden Trails - The New Western Rush
"HDMI" = Intel® Graphics Media Accelerator Driver
"Hide And Secret_is1" = Hide And Secret
"InstallShield_{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}" = TOSHIBA Supervisor Password
"InstallShield_{5279374D-87FE-4879-9385-F17278EBB9D3}" = TOSHIBA Hardware Setup
"InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"InstallShield_{620BBA5E-F848-4D56-8BDA-584E44584C5E}" = TOSHIBA Flash Cards Support Utility
"InstallShield_{DB780B85-B4B5-4864-A49C-9B706B169C93}" = Texas Instruments PCIxx21/x515/xx12 drivers.
"InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"Magic Academy" = Magic Academy (remove only)
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mirror Magic_is1" = Mirror Magic
"Mobile Broadband Generic Drivers" = Mobile Broadband Generic Drivers
"Mozilla Firefox (3.6.9)" = Mozilla Firefox (3.6.9)
"Mystery Case Files - Ravenhearst" = Mystery Case Files - Ravenhearst (remove only)
"Mystery Solitaire - Secret Island" = Mystery Solitaire - Secret Island (remove only)
"OnlinePlay" = OnlinePlay 1.0
"Paparazzi" = Paparazzi (remove only)
"Private Eye - Greatest Unsolved Mysteries" = Private Eye - Greatest Unsolved Mysteries (remove only)
"PROHYBRIDR" = 2007 Microsoft Office system
"ProInst" = Intel® PROSet/Wireless Software
"REDRUM Dead Diary FINAL 1.00" = REDRUM Dead Diary FINAL 1.00
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TOSHIBA Software Modem" = TOSHIBA Software Modem
"Uninstall_is1" = Uninstall 1.0.0.1
"VLC media player" = VLC media player 1.1.0
"Wild West Quest 2 1.00" = Wild West Quest 2 1.00
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 05/09/2010 5:43:07 PM | Computer Name = Lucky13-PC | Source = EventSystem | ID = 4609
Description =
Error - 05/09/2010 5:53:18 PM | Computer Name = Lucky13-PC | Source = WerSvc | ID = 5007
Description =
Error - 07/09/2010 1:19:06 PM | Computer Name = Lucky13-PC | Source = Application Hang | ID = 1002
Description = The program plugin-container.exe version 1.9.2.3855 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 3594 Start Time: 01cb4d7bc77b16c0 Termination Time: 54
Error - 10/09/2010 1:55:03 AM | Computer Name = Lucky13-PC | Source = Application Hang | ID = 1002
Description = The program CEC_MAIN.exe version 1.7.8000.182 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 12c4 Start Time: 01cb4d4410b8dc4b Termination Time: 202
Error - 10/09/2010 7:49:39 PM | Computer Name = Lucky13-PC | Source = Application Hang | ID = 1002
Description = The program Andy.exe version 1.0.3827.20241 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 139fd0 Start Time: 01cb5142c0b0c220 Termination Time: 28
Error - 10/09/2010 7:49:46 PM | Computer Name = Lucky13-PC | Source = Application Hang | ID = 1002
Description = The program Andy.exe version 1.0.3827.20241 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 139f8c Start Time: 01cb5142bc2baf30 Termination Time: 88
Error - 11/09/2010 1:12:06 AM | Computer Name = Lucky13-PC | Source = WerSvc | ID = 5007
Description =
Error - 13/09/2010 6:09:56 PM | Computer Name = Lucky13-PC | Source = EventSystem | ID = 4609
Description =
Error - 13/09/2010 7:49:33 PM | Computer Name = Lucky13-PC | Source = WerSvc | ID = 5007
Description =
Error - 13/09/2010 10:38:17 PM | Computer Name = Lucky13-PC | Source = Application Hang | ID = 1002
Description = The program OTL.exe version 3.2.12.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Problem Reports and Solutions control panel. Process
ID: bbe0 Start Time: 01cb53b5b2bd9ce0 Termination Time: 7
[ System Events ]
Error - 16/07/2010 9:05:14 PM | Computer Name = Lucky13-PC | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.0.153 for the Network Card with network
address 0013E8C0637D has been denied by the DHCP server [removed] (The DHCP Server
sent a DHCPNACK message).
Error - 17/07/2010 9:24:15 PM | Computer Name = Lucky13-PC | Source = Dhcp | ID = 1002
Description = The IP address lease [removed] for the Network Card with network
address 0013E8C0637D has been denied by the DHCP server [removed] (The DHCP Server
sent a DHCPNACK message).
Error - 17/07/2010 9:25:07 PM | Computer Name = Lucky13-PC | Source = Dhcp | ID = 1002
Description = The IP address lease [removed] for the Network Card with network
address 0013E8C0637D has been denied by the DHCP server 192.168.168.254 (The DHCP
Server sent a DHCPNACK message).
Error - 18/07/2010 8:36:49 AM | Computer Name = Lucky13-PC | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.168.124 for the Network Card with network
address 0013E8C0637D has been denied by the DHCP server 192.168.0.1 (The DHCP Server
sent a DHCPNACK message).
Error - 19/07/2010 5:29:45 AM | Computer Name = Lucky13-PC | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 0013E8C0637D. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.
Error - 19/07/2010 5:30:49 AM | Computer Name = Lucky13-PC | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 0013E8C0637D. The following
error occurred: %%121. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.
Error - 19/07/2010 6:42:41 AM | Computer Name = Lucky13-PC | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 0013E8C0637D. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.
Error - 19/07/2010 10:13:47 AM | Computer Name = Lucky13-PC | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 0013E8C0637D. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.
Error - 19/07/2010 10:46:54 AM | Computer Name = Lucky13-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 19/07/2010 10:46:54 AM | Computer Name = Lucky13-PC | Source = Service Control Manager | ID = 7009
Description =
< End of report >
OTL logfile created on: 13/09/2010 8:39:32 PM - Run 1
OTL by OldTimer - Version 3.2.12.0 Folder = C:\Users\Lucky 13\Downloads
Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.16982)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 46.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 64.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 179.50 Gb Total Space | 124.53 Gb Free Space | 69.37% Space Free | Partition Type: NTFS
Drive D: | 1011.98 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
E: Drive not present or media not loaded
Drive F: | 931.51 Gb Total Space | 275.70 Gb Free Space | 29.60% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: LUCKY13-PC
Current User Name: Lucky 13
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Users\Lucky 13\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\plugin-container.exe (Mozilla Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe (Research In Motion Limited)
PRC - C:\Program Files\Bell Mobility\Mobile Connect Basic\tscui.exe (Bell)
PRC - C:\Program Files\Novatel Wireless\NovaCore\Server\NvtlSrvr.exe ()
PRC - C:\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
PRC - C:\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
PRC - C:\Program Files\Java\jre1.6.0\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\TOSHIBA\TOSHIBA HD DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\Synaptics\SynTP\SynToshiba.exe (Synaptics, Inc.)
PRC - C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe ()
PRC - C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (Chicony)
PRC - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
PRC - C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)
PRC - C:\Program Files\ltmoh\ltmoh.exe (Agere Systems)
PRC - C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\Utilities\KeNotify.exe ()
PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)
PRC - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
PRC - C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
========== Modules (SafeList) ==========
MOD - C:\Users\Lucky 13\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.20533_none_4634c4a0218d65c1\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (NvtlService) – C:\Program Files\Novatel Wireless\Novacore\Server\NvtlSrvr.exe ()
SRV - (SBSDWSCService) – C:\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (TNaviSrv) – C:\Program Files\TOSHIBA\TOSHIBA HD DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
SRV - (TosCoSrv) – C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV - (EvtEng) Intel® – C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
SRV - (RegSrvc) Intel® – C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
SRV - (TOSHIBA Bluetooth Service) – C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
SRV - (CFSvcs) – C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
SRV - (AgereModemAudio) – C:\Windows\System32\agrsmsvc.exe (Agere Systems)
SRV - (UleadBurningHelper) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
SRV - (TODDSrv) – C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
========== Driver Services (SafeList) ==========
DRV - (TpChoice) – C:\Windows\System32\DRIVERS\TpChoice.sys File not found
DRV - (NwlnkFwd) – C:\Windows\System32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – C:\Windows\System32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – C:\Windows\System32\DRIVERS\ipinip.sys File not found
DRV - (blbdrive) – C:\Windows\System32\drivers\blbdrive.sys File not found
DRV - (NuidFltr) – C:\Windows\System32\drivers\nuidfltr.sys (Microsoft Corporation)
DRV - (PCASp50) – C:\Windows\System32\drivers\PCASp50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (NWADI) – C:\Windows\System32\drivers\NWADIenum.sys (Novatel Wireless Inc)
DRV - (NWUSBPort2) – C:\Windows\System32\drivers\nwusbser2.sys (Novatel Wireless Inc.)
DRV - (NWUSBPort) – C:\Windows\System32\drivers\nwusbser.sys (Novatel Wireless Inc.)
DRV - (NWUSBModem) – C:\Windows\System32\drivers\nwusbmdm.sys (Novatel Wireless Inc.)
DRV - (NWUSBCDFIL) – C:\Windows\System32\drivers\NwUsbCdFil.sys (Novatel Wireless Inc.)
DRV - (tos_sps32) – C:\Windows\system32\DRIVERS\tos_sps32.sys (TOSHIBA Corporation)
DRV - (igfx) – C:\Windows\System32\drivers\igdkmd32.sys (Intel Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (SynTP) – C:\Windows\System32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (BRCMDECO) – C:\Windows\System32\drivers\BRCMHD32.sys (Broadcom Corporation)
DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation )
DRV - (NETw4v32) Intel® – C:\Windows\System32\drivers\NETw4v32.sys (Intel Corporation)
DRV - (UVCFTR) – C:\Windows\System32\drivers\UVCFTR_S.SYS (Chicony Electronics Co., Ltd.)
DRV - (iaStor) – C:\Windows\system32\DRIVERS\iaStor.sys (Intel Corporation)
DRV - (tifm21) – C:\Windows\System32\drivers\tifm21.sys (Texas Instruments)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (tosrfec) – C:\Windows\System32\drivers\tosrfec.sys (TOSHIBA Corporation)
DRV - (tdcmdpst) – C:\Windows\System32\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV - (TVALZ) – C:\Windows\system32\DRIVERS\TVALZ_O.SYS (TOSHIBA Corporation)
DRV - (LPCFilter) – C:\Windows\system32\DRIVERS\LPCFilter.sys (COMPAL ELECTRONIC INC.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.google.ca/"
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.0.3
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: {872b5b88-9db5-4310-bdd0-ac189557e5f5}:2.7.2.0
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/09/09 17:27:14 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.9\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/09/09 17:27:14 | 000,000,000 | —D | M]
[2010/06/23 19:20:06 | 000,000,000 | —D | M] – C:\Users\Lucky 13\AppData\Roaming\Mozilla\Extensions
[2010/09/12 18:25:47 | 000,000,000 | —D | M] – C:\Users\Lucky 13\AppData\Roaming\Mozilla\Firefox\Profiles\0inf5kaw.default\extensions
[2010/09/12 18:25:38 | 000,000,000 | —D | M] (NoScript) – C:\Users\Lucky 13\AppData\Roaming\Mozilla\Firefox\Profiles\0inf5kaw.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2010/08/30 12:41:07 | 000,000,000 | —D | M] (DVDVideoSoftTB Toolbar) – C:\Users\Lucky 13\AppData\Roaming\Mozilla\Firefox\Profiles\0inf5kaw.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
[2010/08/05 17:54:07 | 000,000,000 | —D | M] (No name found) – C:\Users\Lucky 13\AppData\Roaming\Mozilla\Firefox\Profiles\0inf5kaw.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2010/06/23 19:19:46 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: ([2010/09/05 15:44:04 | 000,416,890 | R— | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 14390 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Adobe PDF Link Helper) - {74E41E96-1F6A-2C83-7A24-6FFA07F64C77} - C:\Windows\System32\ccmlua.dll ()
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [00TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [BlackBerryAutoUpdate] C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe (Research In Motion Limited)
O4 - HKLM..\Run: [Camera Assistant Software] C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (Chicony)
O4 - HKLM..\Run: [HSON] C:\Program Files\TOSHIBA\TBS\HSON.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [HWSetup] File not found
O4 - HKLM..\Run: [KeNotify] C:\Program Files\TOSHIBA\Utilities\KeNotify.exe ()
O4 - HKLM..\Run: [LtMoh] C:\Program Files\ltmoh\ltmoh.exe (Agere Systems)
O4 - HKLM..\Run: [MCStart] C:\Program Files\Bell Mobility\Mobile Connect Basic\tscui.exe (Bell)
O4 - HKLM..\Run: [NDSTray.exe] File not found
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe (Sonic Solutions)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SVPWUTIL] C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe (TOSHIBA)
O4 - HKLM..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [tscui] C:\Program Files\Bell Mobility\Mobile Connect Basic\tscui.exe (Bell)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [ISUSPM] C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKCU..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Lucky 13\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm ()
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Users\Lucky 13\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Lucky 13\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 15:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2009/01/31 19:51:24 | 000,000,033 | -HS- | M] () - F:\autorun.inf – [ NTFS ]
O33 - MountPoints2\{993fd453-7f2e-11df-b206-001b384af900}\Shell - "" = AutoRun
O33 - MountPoints2\{993fd453-7f2e-11df-b206-001b384af900}\Shell\AutoRun\command - "" = E:\AutoLaunch.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.dvacm - C:\Program Files\Common Files\Ulead Systems\vio\DVACM.acm (Ulead Systems, Inc.)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2010/09/09 17:25:53 | 000,000,000 | —D | C] – C:\Program Files\Golden Trails - The New Western Rush2
[2010/09/09 17:14:39 | 000,000,000 | —D | C] – C:\ProgramData\WildWestQuest2
[2010/09/08 16:11:20 | 000,000,000 | —D | C] – C:\Users\Lucky 13\AppData\Roaming\Awem
[2010/09/08 16:11:12 | 000,000,000 | —D | C] – C:\Program Files\Dream Day Couple
[2010/09/08 16:08:56 | 000,000,000 | —D | C] – C:\Program Files\Golden Trails - The New Western Rush
[2010/09/08 14:18:13 | 000,000,000 | —D | C] – C:\Users\Lucky 13\AppData\Local\WinZip
[2010/08/30 06:58:09 | 000,000,000 | —D | C] – C:\Spybot - Search & Destroy
[2010/08/30 06:58:09 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2010/08/30 06:49:20 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/08/29 19:02:35 | 000,000,000 | —D | C] – C:\Users\Lucky 13\AppData\Local\Windows Server
[2010/08/21 21:16:24 | 000,000,000 | —D | C] – C:\Program Files\Dream Day Wedding Married in Manhattan
[2010/08/19 19:04:22 | 000,000,000 | —D | C] – C:\Program Files\Games
[2010/08/18 22:14:43 | 000,000,000 | —D | C] – C:\Users\Lucky 13\AppData\Local\Oberon Games
[2010/08/18 18:12:40 | 000,000,000 | —D | C] – C:\Program Files\Hide And Secret
[2010/08/18 18:10:43 | 000,000,000 | —D | C] – C:\Program Files\Dream Day Wedding
[2010/08/16 10:54:10 | 000,000,000 | —D | C] – C:\Users\Lucky 13\AppData\Roaming\PlayFirst
[2010/08/16 10:54:10 | 000,000,000 | —D | C] – C:\ProgramData\PlayFirst
[2010/08/16 10:53:15 | 000,000,000 | —D | C] – C:\Program Files\Mystery of Shark Island
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/09/13 20:40:43 | 000,003,072 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/09/13 20:40:43 | 000,003,072 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/09/13 20:37:11 | 006,029,312 | -HS- | M] () – C:\Users\Lucky 13\NTUSER.DAT
[2010/09/13 19:05:05 | 000,000,348 | —- | M] () – C:\Windows\tasks\At3.job
[2010/09/13 18:12:36 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/09/13 17:49:33 | 000,720,952 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/09/13 17:49:33 | 000,626,246 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/09/13 17:49:33 | 000,109,370 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/09/13 17:40:45 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/09/13 17:40:31 | 2137,448,448 | -HS- | M] () – C:\hiberfil.sys
[2010/09/13 16:24:11 | 000,002,529 | —- | M] () – C:\Users\Lucky 13\Desktop\HiJackThis.lnk
[2010/09/13 16:11:40 | 000,007,647 | —- | M] () – C:\Users\Lucky 13\Desktop\hijackthis3
[2010/09/13 16:09:08 | 327,113,461 | —- | M] () – C:\Windows\MEMORY.DMP
[2010/09/13 13:21:11 | 000,000,348 | —- | M] () – C:\Windows\tasks\At2.job
[2010/09/13 01:28:08 | 000,000,348 | —- | M] () – C:\Windows\tasks\At4.job
[2010/09/10 07:49:05 | 000,000,348 | —- | M] () – C:\Windows\tasks\At1.job
[2010/09/09 23:49:52 | 000,043,008 | —- | M] () – C:\Users\Lucky 13\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/09 17:26:53 | 000,001,970 | —- | M] () – C:\Users\Lucky 13\Desktop\Golden Trails - The New Western Rush.lnk
[2010/09/09 17:13:08 | 000,001,920 | —- | M] () – C:\Users\Lucky 13\Desktop\Wild West Quest 2.lnk
[2010/09/08 14:11:42 | 000,000,913 | —- | M] () – C:\Users\Lucky 13\Desktop\Dream Day Wedding.lnk
[2010/09/05 15:44:04 | 000,416,890 | R— | M] () – C:\Windows\System32\drivers\etc\hosts
[2010/09/05 09:42:02 | 000,002,069 | —- | M] () – C:\Users\Lucky 13\Desktop\Dream Day Wedding 6 Bella Italia.lnk
[2010/08/30 08:15:20 | 000,000,875 | R— | M] () – C:\Windows\System32\drivers\etc\hosts.20100830-082415.backup
[2010/08/30 08:14:26 | 000,416,917 | R— | M] () – C:\Windows\System32\drivers\etc\hosts.20100830-081520.backup
[2010/08/30 08:09:59 | 000,000,680 | —- | M] () – C:\Users\Lucky 13\AppData\Local\d3d9caps.dat
[2010/08/30 08:07:32 | 000,000,552 | —- | M] () – C:\Users\Lucky 13\AppData\Local\d3d8caps.dat
[2010/08/30 06:58:20 | 000,000,820 | —- | M] () – C:\Users\Lucky 13\Desktop\Spybot - Search & Destroy.lnk
[2010/08/26 07:14:43 | 005,316,736 | —- | M] () – C:\Users\Lucky 13\Desktop\The Chakachas - Jungle Fever.- DJ Luis Mario 'Flaco' Orellana.mp3
[2010/08/22 17:59:52 | 000,001,185 | —- | M] () – C:\Users\Lucky 13\Desktop\Dream Day Wedding - Married in Manhattan - Shortcut.lnk
[2010/08/19 19:04:59 | 000,002,066 | —- | M] () – C:\Users\Lucky 13\Desktop\Dream Day Wedding - Viva Las Vegas.lnk
[2010/08/18 18:18:04 | 000,001,999 | —- | M] () – C:\Users\Public\Desktop\Private Eye - Greatest Unsolved Mysteries.lnk
[2010/08/18 18:18:04 | 000,001,536 | —- | M] () – C:\Users\Public\Desktop\More great games.lnk
[2010/08/16 09:53:40 | 000,000,949 | —- | M] () – C:\Users\Lucky 13\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/09/13 17:40:31 | 2137,448,448 | -HS- | C] () – C:\hiberfil.sys
[2010/09/13 16:11:40 | 000,007,647 | —- | C] () – C:\Users\Lucky 13\Desktop\hijackthis3
[2010/09/09 17:26:53 | 000,001,970 | —- | C] () – C:\Users\Lucky 13\Desktop\Golden Trails - The New Western Rush.lnk
[2010/09/09 17:13:08 | 000,001,920 | —- | C] () – C:\Users\Lucky 13\Desktop\Wild West Quest 2.lnk
[2010/09/08 14:11:42 | 000,000,913 | —- | C] () – C:\Users\Lucky 13\Desktop\Dream Day Wedding.lnk
[2010/08/30 13:24:02 | 000,002,069 | —- | C] () – C:\Users\Lucky 13\Desktop\Dream Day Wedding 6 Bella Italia.lnk
[2010/08/30 13:23:13 | 000,000,348 | —- | C] () – C:\Windows\tasks\At4.job
[2010/08/30 13:23:12 | 000,000,348 | —- | C] () – C:\Windows\tasks\At3.job
[2010/08/30 13:23:10 | 000,000,348 | —- | C] () – C:\Windows\tasks\At2.job
[2010/08/30 13:23:05 | 000,000,348 | —- | C] () – C:\Windows\tasks\At1.job
[2010/08/30 08:09:59 | 000,000,680 | —- | C] () – C:\Users\Lucky 13\AppData\Local\d3d9caps.dat
[2010/08/30 08:07:32 | 000,000,552 | —- | C] () – C:\Users\Lucky 13\AppData\Local\d3d8caps.dat
[2010/08/30 06:58:20 | 000,000,820 | —- | C] () – C:\Users\Lucky 13\Desktop\Spybot - Search & Destroy.lnk
[2010/08/30 06:49:20 | 000,002,529 | —- | C] () – C:\Users\Lucky 13\Desktop\HiJackThis.lnk
[2010/08/26 06:50:44 | 005,316,736 | —- | C] () – C:\Users\Lucky 13\Desktop\The Chakachas - Jungle Fever.- DJ Luis Mario 'Flaco' Orellana.mp3
[2010/08/22 17:59:52 | 000,001,185 | —- | C] () – C:\Users\Lucky 13\Desktop\Dream Day Wedding - Married in Manhattan - Shortcut.lnk
[2010/08/19 19:04:59 | 000,002,066 | —- | C] () – C:\Users\Lucky 13\Desktop\Dream Day Wedding - Viva Las Vegas.lnk
[2010/08/18 18:18:04 | 000,001,999 | —- | C] () – C:\Users\Public\Desktop\Private Eye - Greatest Unsolved Mysteries.lnk
[2010/08/16 09:53:40 | 000,000,949 | —- | C] () – C:\Users\Lucky 13\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2010/08/13 11:48:09 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2010/08/10 16:38:50 | 000,034,308 | —- | C] () – C:\Windows\System32\BASSMOD.dll
[2010/07/08 16:50:26 | 000,043,008 | —- | C] () – C:\Users\Lucky 13\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/23 19:11:15 | 000,128,113 | —- | C] () – C:\Windows\System32\csellang.ini
[2010/06/23 19:11:15 | 000,045,056 | —- | C] () – C:\Windows\System32\csellang.dll
[2010/06/23 19:11:15 | 000,010,150 | —- | C] () – C:\Windows\System32\tosmreg.ini
[2010/06/23 19:11:15 | 000,007,671 | —- | C] () – C:\Windows\System32\cseltbl.ini
[2010/06/23 09:56:15 | 000,204,800 | —- | C] () – C:\Windows\System32\IVIresizeW7.dll
[2010/06/23 09:56:15 | 000,200,704 | —- | C] () – C:\Windows\System32\IVIresizeA6.dll
[2010/06/23 09:56:15 | 000,192,512 | —- | C] () – C:\Windows\System32\IVIresizeP6.dll
[2010/06/23 09:56:15 | 000,192,512 | —- | C] () – C:\Windows\System32\IVIresizeM6.dll
[2010/06/23 09:56:15 | 000,188,416 | —- | C] () – C:\Windows\System32\IVIresizePX.dll
[2010/06/23 09:56:15 | 000,020,480 | —- | C] () – C:\Windows\System32\IVIresize.dll
[2007/09/26 23:33:57 | 000,036,864 | —- | C] () – C:\Windows\System32\HWS_Ctrl.dll
[2007/09/26 23:15:57 | 000,000,000 | —- | C] () – C:\Windows\NDSTray.INI
[2007/09/26 21:57:53 | 001,060,424 | —- | C] () – C:\Windows\System32\WdfCoInstaller01000.dll
[2007/09/26 02:25:11 | 001,238,832 | —- | C] () – C:\Windows\System32\igmedkrn.dll
[2007/09/26 02:25:11 | 000,249,856 | —- | C] () – C:\Windows\System32\igfxTMM.dll
[2007/09/26 02:25:11 | 000,147,456 | —- | C] () – C:\Windows\System32\igfxCoIn_v1329.dll
[2007/09/26 02:25:11 | 000,104,636 | —- | C] () – C:\Windows\System32\igmedcompkrn.dll
[2007/03/06 17:54:04 | 000,995,328 | —- | C] () – C:\Windows\System32\WLIHVUI.dll
[2006/12/05 14:05:06 | 000,114,688 | —- | C] () – C:\Windows\System32\TosBtAcc.dll
[2006/11/02 06:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 02:57:48 | 000,180,224 | —- | C] () – C:\Windows\System32\ccmlua.dll
[2006/11/02 01:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
[2005/11/23 15:55:42 | 000,024,576 | —- | C] () – C:\Windows\System32\SPCtl.dll
[2005/07/22 22:30:20 | 000,065,536 | —- | C] () – C:\Windows\System32\TosCommAPI.dll
========== LOP Check ==========
[2010/08/09 12:59:55 | 000,000,000 | —D | M] – C:\Users\Lucky 13\AppData\Roaming\Anarchy
[2010/09/08 16:11:20 | 000,000,000 | —D | M] – C:\Users\Lucky 13\AppData\Roaming\Awem
[2010/08/05 17:54:06 | 000,000,000 | —D | M] – C:\Users\Lucky 13\AppData\Roaming\DVDVideoSoftIEHelpers
[2010/08/11 09:52:56 | 000,000,000 | —D | M] – C:\Users\Lucky 13\AppData\Roaming\FloodLightGames
[2010/08/13 14:41:54 | 000,000,000 | —D | M] – C:\Users\Lucky 13\AppData\Roaming\Magic Academy
[2010/08/08 22:18:48 | 000,000,000 | —D | M] – C:\Users\Lucky 13\AppData\Roaming\MysteryStudio
[2010/08/16 10:54:10 | 000,000,000 | —D | M] – C:\Users\Lucky 13\AppData\Roaming\PlayFirst
[2010/06/23 21:28:30 | 000,000,000 | —D | M] – C:\Users\Lucky 13\AppData\Roaming\Research In Motion
[2010/09/10 07:49:05 | 000,000,348 | —- | M] () – C:\Windows\Tasks\At1.job
[2010/09/13 13:21:11 | 000,000,348 | —- | M] () – C:\Windows\Tasks\At2.job
[2010/09/13 19:05:05 | 000,000,348 | —- | M] () – C:\Windows\Tasks\At3.job
[2010/09/13 01:28:08 | 000,000,348 | —- | M] () – C:\Windows\Tasks\At4.job
[2010/09/05 15:38:32 | 000,032,480 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2006/09/18 15:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2006/11/02 03:53:57 | 000,438,840 | RHS- | M] () – C:\bootmgr
[2007/09/26 17:57:07 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 15:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2010/09/13 17:40:31 | 2137,448,448 | -HS- | M] () – C:\hiberfil.sys
[2010/09/13 17:40:29 | 2451,374,080 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2006/11/02 06:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 06:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 06:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2006/11/02 06:37:12 | 000,030,808 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 15:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/11/02 06:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2010/06/25 12:25:25 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2006/11/02 04:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 04:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 04:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 04:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 04:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/07/10 20:27:11 | 000,000,365 | -HS- | M] () – C:\Users\Lucky 13\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-09-03 07:36:51
========== Alternate Data Streams ==========
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:C7F08EA3
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:32A82570
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:317F7381
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:9E999B93
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:3B5038B1
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:5D59B736
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:E40EED9B
< End of report >
OTL Extras logfile created on: 13/09/2010 8:39:32 PM - Run 1
OTL by OldTimer - Version 3.2.12.0 Folder = C:\Users\Lucky 13\Downloads
Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.16982)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 46.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 64.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 179.50 Gb Total Space | 124.53 Gb Free Space | 69.37% Space Free | Partition Type: NTFS
Drive D: | 1011.98 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
E: Drive not present or media not loaded
Drive F: | 931.51 Gb Total Space | 275.70 Gb Free Space | 29.60% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: LUCKY13-PC
Current User Name: Lucky 13
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{745679E8-6D91-4C36-844E-A76183D5B83E}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{807AD8C1-C976-4FC0-BF4B-2158B3A28090}" = protocol=6 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
"{FBD8C3BD-F78C-433D-AC4D-6652F1676173}" = protocol=17 | dir=in | app=c:\program files\bittorrent\bittorrent.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{008D69EB-70FF-46AB-9C75-924620DF191A}" = TOSHIBA Speech System SR Engine(U.S.) Version1.0
"{07BB4D84-BE7E-45ED-B145-9A474700F590}" = Mobile Broadband Generic Drivers
"{12688FD7-CB92-4A5B-BEE4-5C8E0574434F}" = Utility Common Driver
"{12B3A009-A080-4619-9A2A-C6DB151D8D67}" = TOSHIBA Assist
"{145E18EC-4BBB-4A0C-9381-564ABB871FE9}" = Mobile Connect Basic
"{3248F0A8-6813-11D6-A77B-00B0D0160000}" = Java™ SE Runtime Environment 6
"{37C866E4-AA67-4725-9E95-A39968DD7960}" = Camera Assistant Software for Toshiba
"{3FBF6F99-8EC6-41B4-8527-0A32241B5496}" = TOSHIBA Speech System TTS Engine(U.S.) Version1.0
"{40A594D0-1490-4979-9382-D2B764F949C6}" = BlackBerry® Media Sync
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}" = TOSHIBA Supervisor Password
"{5279374D-87FE-4879-9385-F17278EBB9D3}" = TOSHIBA Hardware Setup
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator
"{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"{620BBA5E-F848-4D56-8BDA-584E44584C5E}" = TOSHIBA Flash Cards Support Utility
"{65D4DAA8-3611-4322-8E69-27880AFD90EC}" = reminder
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{6B9C32DB-DBCD-45A8-B901-3A92A99A2474}" = InstallVC90Support
"{6C5F3BDC-0A1B-4436-A696-5939629D5C31}" = TOSHIBA HD DVD PLAYER
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{78C6A78A-8B03-48C8-A47C-78BA1FCA2307}" = TOSHIBA ConfigFree
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{8C6BB412-D3A8-4AAE-A01B-35B681789D68}" = mHelp
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel Matrix Storage Manager
"{91120000-0031-0000-0000-0000000FF1CE}" = Microsoft Office Professional Hybrid 2007
"{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}" = CD/DVD Drive Acoustic Silencer
"{AC76BA86-7AD7-1033-7B44-A80000000002}" = Adobe Reader 8
"{B2F3FB19-D848-479C-818E-130ABC9366DB}" = BlackBerry Device Software Updater
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B49DDCCE-BF8E-4A4C-8503-6DA24BF49D06}" = NovaCore SDK Installer
"{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser
"{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}" = TOSHIBA Recovery Disc Creator
"{B98BE95C-E76F-4246-B8E6-BEB8EE791D06}" = Roxio Media Manager
"{C53D16CC-E56F-47B8-906E-70AAF8EABB4F}" = Toshiba Registration
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240BD}" = WinZip 14.5
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE86E2F5-850C-4207-94A3-A58D647B1733}" = BlackBerry Desktop Software 5.0.1
"{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}" = Bluetooth Stack for Windows by Toshiba
"{DB780B85-B4B5-4864-A49C-9B706B169C93}" = TIPCI
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E90C9405-DDC3-4DEB-95C8-DAAAAF69BB3E}" = Pop Art Studio 5.1
"{EBFF48F5-3CFA-436F-8FD5-94FB01D3A0A7}" = TOSHIBA SD Memory Utilities
"{EE033C1F-443E-41EC-A0E2-559B539A4E4D}" = TOSHIBA Speech System Applications
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F214EAA4-A069-4BAF-9DA4-4DB8BEEDE485}" = DVD MovieFactory for TOSHIBA
"{F5D7FAB5-A1FD-4DD3-983E-4155B09D7102}" = mCore
"{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"5 Spots II_is1" = 5 Spots II
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Agatha Christie Death On The Nile_is1" = Agatha Christie Death On The Nile
"BCM70010" = Broadcom High Definition Video Decoder [removed]
"BFGC" = Big Fish Games: Game Manager
"BFG-Murder She Wrote" = Murder, She Wrote
"BFG-Redrum - Time Lies" = Redrum: Time Lies
"Big City Adventure - San Francisco" = Big City Adventure - San Francisco (remove only)
"BlackBerry_{CE86E2F5-850C-4207-94A3-A58D647B1733}" = BlackBerry Desktop Software 5.0.1
"Dream Day Couple_is1" = Dream Day Couple
"Dream Day Wedding - Viva Las Vegas 1.00" = Dream Day Wedding - Viva Las Vegas 1.00
"Dream Day Wedding 6 Bella Italia 1.00" = Dream Day Wedding 6 Bella Italia 1.00
"Dream Day Wedding Married in Manhattan" = Dream Day Wedding Married in Manhattan
"Dream Day Wedding_is1" = Dream Day Wedding
"Free Audio CD Burner_is1" = Free Audio CD Burner version 1.4
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.7
"Golden Trails - The New Western Rush_is1" = Golden Trails - The New Western Rush
"Golden Trails - The New Western Rush1.0" = Golden Trails - The New Western Rush
"HDMI" = Intel® Graphics Media Accelerator Driver
"Hide And Secret_is1" = Hide And Secret
"InstallShield_{51B4E156-14A5-4904-9AE4-B1AA2A0E46BE}" = TOSHIBA Supervisor Password
"InstallShield_{5279374D-87FE-4879-9385-F17278EBB9D3}" = TOSHIBA Hardware Setup
"InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"InstallShield_{620BBA5E-F848-4D56-8BDA-584E44584C5E}" = TOSHIBA Flash Cards Support Utility
"InstallShield_{DB780B85-B4B5-4864-A49C-9B706B169C93}" = Texas Instruments PCIxx21/x515/xx12 drivers.
"InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"Magic Academy" = Magic Academy (remove only)
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mirror Magic_is1" = Mirror Magic
"Mobile Broadband Generic Drivers" = Mobile Broadband Generic Drivers
"Mozilla Firefox (3.6.9)" = Mozilla Firefox (3.6.9)
"Mystery Case Files - Ravenhearst" = Mystery Case Files - Ravenhearst (remove only)
"Mystery Solitaire - Secret Island" = Mystery Solitaire - Secret Island (remove only)
"OnlinePlay" = OnlinePlay 1.0
"Paparazzi" = Paparazzi (remove only)
"Private Eye - Greatest Unsolved Mysteries" = Private Eye - Greatest Unsolved Mysteries (remove only)
"PROHYBRIDR" = 2007 Microsoft Office system
"ProInst" = Intel® PROSet/Wireless Software
"REDRUM Dead Diary FINAL 1.00" = REDRUM Dead Diary FINAL 1.00
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TOSHIBA Software Modem" = TOSHIBA Software Modem
"Uninstall_is1" = Uninstall 1.0.0.1
"VLC media player" = VLC media player 1.1.0
"Wild West Quest 2 1.00" = Wild West Quest 2 1.00
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 05/09/2010 5:43:07 PM | Computer Name = Lucky13-PC | Source = EventSystem | ID = 4609
Description =
Error - 05/09/2010 5:53:18 PM | Computer Name = Lucky13-PC | Source = WerSvc | ID = 5007
Description =
Error - 07/09/2010 1:19:06 PM | Computer Name = Lucky13-PC | Source = Application Hang | ID = 1002
Description = The program plugin-container.exe version 1.9.2.3855 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 3594 Start Time: 01cb4d7bc77b16c0 Termination Time: 54
Error - 10/09/2010 1:55:03 AM | Computer Name = Lucky13-PC | Source = Application Hang | ID = 1002
Description = The program CEC_MAIN.exe version 1.7.8000.182 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 12c4 Start Time: 01cb4d4410b8dc4b Termination Time: 202
Error - 10/09/2010 7:49:39 PM | Computer Name = Lucky13-PC | Source = Application Hang | ID = 1002
Description = The program Andy.exe version 1.0.3827.20241 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 139fd0 Start Time: 01cb5142c0b0c220 Termination Time: 28
Error - 10/09/2010 7:49:46 PM | Computer Name = Lucky13-PC | Source = Application Hang | ID = 1002
Description = The program Andy.exe version 1.0.3827.20241 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 139f8c Start Time: 01cb5142bc2baf30 Termination Time: 88
Error - 11/09/2010 1:12:06 AM | Computer Name = Lucky13-PC | Source = WerSvc | ID = 5007
Description =
Error - 13/09/2010 6:09:56 PM | Computer Name = Lucky13-PC | Source = EventSystem | ID = 4609
Description =
Error - 13/09/2010 7:49:33 PM | Computer Name = Lucky13-PC | Source = WerSvc | ID = 5007
Description =
Error - 13/09/2010 10:38:17 PM | Computer Name = Lucky13-PC | Source = Application Hang | ID = 1002
Description = The program OTL.exe version 3.2.12.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Problem Reports and Solutions control panel. Process
ID: bbe0 Start Time: 01cb53b5b2bd9ce0 Termination Time: 7
[ System Events ]
Error - 16/07/2010 9:05:14 PM | Computer Name = Lucky13-PC | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.0.153 for the Network Card with network
address 0013E8C0637D has been denied by the DHCP server [removed] (The DHCP Server
sent a DHCPNACK message).
Error - 17/07/2010 9:24:15 PM | Computer Name = Lucky13-PC | Source = Dhcp | ID = 1002
Description = The IP address lease [removed] for the Network Card with network
address 0013E8C0637D has been denied by the DHCP server [removed] (The DHCP Server
sent a DHCPNACK message).
Error - 17/07/2010 9:25:07 PM | Computer Name = Lucky13-PC | Source = Dhcp | ID = 1002
Description = The IP address lease [removed] for the Network Card with network
address 0013E8C0637D has been denied by the DHCP server 192.168.168.254 (The DHCP
Server sent a DHCPNACK message).
Error - 18/07/2010 8:36:49 AM | Computer Name = Lucky13-PC | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.168.124 for the Network Card with network
address 0013E8C0637D has been denied by the DHCP server 192.168.0.1 (The DHCP Server
sent a DHCPNACK message).
Error - 19/07/2010 5:29:45 AM | Computer Name = Lucky13-PC | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 0013E8C0637D. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.
Error - 19/07/2010 5:30:49 AM | Computer Name = Lucky13-PC | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 0013E8C0637D. The following
error occurred: %%121. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.
Error - 19/07/2010 6:42:41 AM | Computer Name = Lucky13-PC | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 0013E8C0637D. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.
Error - 19/07/2010 10:13:47 AM | Computer Name = Lucky13-PC | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 0013E8C0637D. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.
Error - 19/07/2010 10:46:54 AM | Computer Name = Lucky13-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 19/07/2010 10:46:54 AM | Computer Name = Lucky13-PC | Source = Service Control Manager | ID = 7009
Description =
< End of report >