GBS
Topic Starter
Hi. Thanks in advance.
Computer seems to be slower, also having standby and hibernating issues, whereas it's always on. Other than that, it's running "fine," except I noticed today that MBAM and Adaware would not update. Strange because I can't trace where I may have gotten infected. Let me know how it looks.
OTL results:
OTL logfile created on: 9/23/2010 1:32:31 PM - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\Shrews\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 57.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): F:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 14.51 Gb Total Space | 5.36 Gb Free Space | 36.97% Space Free | Partition Type: NTFS
Drive D: | 6.55 Gb Total Space | 1.72 Gb Free Space | 26.32% Space Free | Partition Type: NTFS
Drive E: | 6.04 Gb Total Space | 1.44 Gb Free Space | 23.77% Space Free | Partition Type: NTFS
Drive F: | 82.11 Gb Total Space | 53.13 Gb Free Space | 64.70% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: GBS-LAPTOP
Current User Name: Shrews
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Shrews\Desktop\OTL.exe (OldTimer Tools)
PRC - D:\Internet\avg\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
PRC - D:\Internet\java\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - D:\Internet\Safari\Safari.exe (Apple Inc.)
PRC - D:\Internet\avg\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - D:\Internet\avg\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - D:\System\blckarmorbackup\TimounterMonitor.exe (Seagate)
PRC - C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe (Seagate)
PRC - C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe (Seagate)
PRC - C:\Program Files\Common Files\Seagate\BlackArmorBackup\BlackArmorBackupNotify.exe (Seagate)
PRC - D:\System\blckarmorbackup\BlackArmorBackupMonitor.exe (Seagate)
PRC - C:\Program Files\Common Files\Seagate\BlackArmorBackup\BlackArmorBackupService.exe (Seagate)
PRC - D:\Internet\xampp\mysql\bin\mysqld.exe ()
PRC - D:\Internet\xampp\apache\bin\httpd.exe (Apache Software Foundation)
PRC - D:\Internet\adaware\aawservice.exe (Lavasoft)
PRC - C:\Program Files\Common Files\logishrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
PRC - C:\Program Files\Mediafour\MacDrive 7\MacDrive.exe (Mediafour Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Dell Network Assistant\hnm_svc.exe (SingleClick Systems)
PRC - C:\Program Files\Sigmatel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Mediafour\MacDrive 7\MacDriveService.exe (Mediafour Corporation)
PRC - D:\Text\Acrobat_6_prof\Distillr\acrotray.exe (Adobe Systems Inc.)
PRC - C:\WINDOWS\system32\WISPTIS.EXE (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Shrews\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (vsmon) – C:\WINDOWS\System32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (AcrSch2Svc) – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
SRV - (JavaQuickStarterService) – D:\Internet\java\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (avg8wd) – D:\Internet\avg\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Norton Ghost) – D:\System\Norton\Agent\VProSvc.exe (Symantec Corporation)
SRV - (Symantec Core LC) – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (Symantec Corporation)
SRV - (SgtSch2Svc) – C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe (Seagate)
SRV - (MySQL) – D:\Internet\xampp\mysql\bin\mysqld.exe ()
SRV - (Apache2.2) – D:\Internet\xampp\apache\bin\httpd.exe (Apache Software Foundation)
SRV - (aawservice) – D:\Internet\adaware\aawservice.exe (Lavasoft)
SRV - (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (LVSrvLauncher) – C:\Program Files\Common Files\logishrd\SrvLnch\SrvLnch.exe (Logitech Inc.)
SRV - (LicCtrlService) – C:\WINDOWS\mmfs.DLL ()
SRV - (LVPrcSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (LVCOMSer) – C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
SRV - (DellAMBrokerService) – C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe ()
SRV - (hnmsvc) – C:\Program Files\Dell Network Assistant\hnm_svc.exe (SingleClick Systems)
SRV - (MacDriveService) – C:\Program Files\Mediafour\MacDrive 7\MacDriveService.exe (Mediafour Corporation)
SRV - (GEARSecurity) – C:\WINDOWS\system32\gearsec.exe (GEAR Software)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (ccPwdSvc) – C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
========== Driver Services (SafeList) ==========
DRV - (UIUSys) – C:\WINDOWS\System32\DRIVERS\UIUSYS.SYS File not found
DRV - (srescan) – C:\WINDOWS\System32\ZoneLabs\srescan.sys File not found
DRV - (catchme) – C:\DOCUME~1\Shrews\LOCALS~1\Temp\catchme.sys File not found
DRV - (tdrpman174) Acronis Try&Decide; and Restore Points filter (build 174) – C:\WINDOWS\system32\DRIVERS\tdrpm174.sys (Acronis)
DRV - (truecrypt) – C:\WINDOWS\system32\drivers\truecrypt.sys (TrueCrypt Foundation)
DRV - (vsdatant) – C:\WINDOWS\system32\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (oreans32) – C:\WINDOWS\system32\drivers\oreans32.sys ()
DRV - (timounter) – C:\WINDOWS\system32\DRIVERS\timntr.sys (Acronis)
DRV - (tifsfilter) – C:\WINDOWS\system32\drivers\tifsfilt.sys (Acronis)
DRV - (snapman380) Acronis Snapshots Manager (Build 380) – C:\WINDOWS\system32\DRIVERS\snman380.sys (Acronis)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (VClone) – C:\WINDOWS\system32\drivers\VClone.sys (Elaborate Bytes AG)
DRV - (symlcbrd) – C:\WINDOWS\system32\drivers\symlcbrd.sys (Symantec Corporation)
DRV - (ElbyCDIO) – C:\WINDOWS\system32\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV - (LVUSBSta) – C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (PTDUWWAN) – C:\WINDOWS\system32\drivers\PTDUWWAN.sys (DEVGURU Co,LTD.)
DRV - (PTDUVsp) – C:\WINDOWS\system32\drivers\PTDUVsp.sys (DEVGURU Co,LTD.)
DRV - (PTDUMdm) – C:\WINDOWS\system32\drivers\PTDUMdm.sys (DEVGURU Co,LTD.)
DRV - (PTDUBus) – C:\WINDOWS\system32\drivers\PTDUBus.sys (DEVGURU Co,LTD.)
DRV - (PID_0928) Logitech QuickCam Express(PID_0928) – C:\WINDOWS\system32\drivers\LV561AV.SYS (Logitech Inc.)
DRV - (LVcKap) – C:\WINDOWS\system32\drivers\Lvckap.sys (Logitech Inc.)
DRV - (LVMVDrv) – C:\WINDOWS\system32\drivers\LVMVdrv.sys (Logitech Inc.)
DRV - (MDFSYSNT) – C:\WINDOWS\System32\drivers\MDFSYSNT.SYS (Mediafour Corporation)
DRV - (datunidr) – C:\WINDOWS\system32\drivers\datunidr.sys (Gteko Ltd.)
DRV - (ialm) – C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (SynTP) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (BCM43XX) – C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corporation)
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (rismxdp) – C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (iaStor) – C:\WINDOWS\system32\drivers\iaStor.sys (Intel Corporation)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (NWADI) – C:\WINDOWS\system32\drivers\NWADIenum.sys (Novatel Wireless Inc)
DRV - (NWUSBPort2) – C:\WINDOWS\system32\drivers\nwusbser2.sys (Novatel Wireless Inc.)
DRV - (NWUSBPort) – C:\WINDOWS\system32\drivers\nwusbser.sys (Novatel Wireless Inc.)
DRV - (NWUSBModem) – C:\WINDOWS\system32\drivers\nwusbmdm.sys (Novatel Wireless Inc.)
DRV - (MDPMGRNT) – C:\WINDOWS\System32\drivers\MDPMGRNT.sys (Mediafour Corporation)
DRV - (Packet) – C:\WINDOWS\system32\drivers\packet.sys (SingleClick Systems)
DRV - (DXEC02) – C:\WINDOWS\system32\drivers\dxec02.sys (Knowles Acoustics)
DRV - (PTproct) – C:\Program Files\DellAutomatedPCTuneUp\GTAction\triggers\PTproct.sys (Gteko Ltd.)
DRV - (pnetmdm) – C:\WINDOWS\system32\drivers\pnetmdm.sys (June Fabrics Technology)
DRV - (DLADResM) – C:\WINDOWS\system32\DLA\DLADResM.SYS (Roxio)
DRV - (DLABMFSM) – C:\WINDOWS\system32\DLA\DLABMFSM.SYS (Roxio)
DRV - (DLAUDF_M) – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Roxio)
DRV - (DLAUDFAM) – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Roxio)
DRV - (DLAOPIOM) – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Roxio)
DRV - (DLABOIOM) – C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Roxio)
DRV - (DLAIFS_M) – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Roxio)
DRV - (DLAPoolM) – C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Roxio)
DRV - (DRVNDDM) – C:\WINDOWS\system32\drivers\DRVNDDM.SYS (Roxio)
DRV - (DLACDBHM) – C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Roxio)
DRV - (DLARTL_M) – C:\WINDOWS\system32\drivers\DLARTL_M.SYS (Roxio)
DRV - (DRVMCDB) – C:\WINDOWS\System32\Drivers\DRVMCDB.SYS (Sonic Solutions)
DRV - (SymSnap) – C:\WINDOWS\System32\drivers\SymSnap.sys (StorageCraft)
DRV - (V2IMount) – C:\WINDOWS\System32\drivers\V2iMount.sys (Symantec Corporation)
DRV - (APPDRV) – C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS (Dell Inc)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (61883) – C:\WINDOWS\system32\drivers\61883.sys (Microsoft Corporation)
DRV - (Avc) – C:\WINDOWS\system32\drivers\avc.sys (Microsoft Corporation)
DRV - (MSDV) – C:\WINDOWS\system32\drivers\msdv.sys (Microsoft Corporation)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (Imagedrv) – C:\WINDOWS\system32\DRIVERS\imagedrv.sys (Ahead Software AG and its licensors)
DRV - (AnyDVD) – C:\WINDOWS\system32\drivers\AnyDVD.sys (SlySoft, Inc.)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (ENUM1394) – C:\WINDOWS\system32\drivers\enum1394.sys (Microsoft Corporation)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=0071211
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=0071211
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=0071211
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.newperspectivefilms.com/"
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1.6.2.63
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5.0.429
FF - prefs.js..extensions.enabledItems: [removed]:1.5.4
FF - prefs.js..extensions.enabledItems: [removed]:1.3.4
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {9458ca25-39fd-4ba8-9520-acc5c0d877b6}:1.6
FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.8
FF - prefs.js..extensions.enabledItems: [removed]:3.8.6
FF - prefs.js..extensions.enabledItems: {e968fc70-8f95-4ab9-9e79-304de2a71ee1}:0.7.2
FF - prefs.js..extensions.enabledItems: {b749fc7c-e949-447f-926c-3f4eed6accfe}:0.6.6
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: D:\Internet\avg\Firefox [2009/12/22 10:56:28 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{000a9d1c-beef-4f90-9363-039d445309b8}: C:\Program Files\Google\Google Gears\Firefox\ [2009/11/09 23:03:52 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: D:\Internet\java\lib\deploy\jqs\ff [2009/11/09 21:43:37 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: D:\Internet\Mozilla_Firefox\components [2010/07/31 12:50:03 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: D:\Internet\Mozilla_Firefox\plugins [2010/08/28 20:55:26 | 000,000,000 | —D | M]
[2010/04/28 23:42:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Mozilla\Extensions
[2010/04/28 23:42:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Mozilla\Extensions\[removed]
[2010/09/16 11:33:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Mozilla\Firefox\Profiles\ma0zn774.default\extensions
[2010/07/17 16:19:16 | 000,000,000 | —D | M] (OPML Support) – C:\Documents and Settings\Shrews\Application Data\Mozilla\Firefox\Profiles\ma0zn774.default\extensions\{9458ca25-39fd-4ba8-9520-acc5c0d877b6}
[2010/05/22 17:23:06 | 000,000,000 | —D | M] (Modify Headers) – C:\Documents and Settings\Shrews\Application Data\Mozilla\Firefox\Profiles\ma0zn774.default\extensions\{b749fc7c-e949-447f-926c-3f4eed6accfe}
[2009/07/01 00:33:46 | 000,000,000 | —D | M] (Web Developer) – C:\Documents and Settings\Shrews\Application Data\Mozilla\Firefox\Profiles\ma0zn774.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2010/04/14 01:42:03 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Documents and Settings\Shrews\Application Data\Mozilla\Firefox\Profiles\ma0zn774.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2010/05/22 16:07:35 | 000,000,000 | —D | M] (User Agent Switcher) – C:\Documents and Settings\Shrews\Application Data\Mozilla\Firefox\Profiles\ma0zn774.default\extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}
[2010/05/18 19:51:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Mozilla\Firefox\Profiles\ma0zn774.default\extensions\[removed]
[2010/08/28 20:47:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Mozilla\Firefox\Profiles\ma0zn774.default\extensions\[removed]
O1 HOSTS File: ([2004/08/04 06:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - D:\Internet\avg\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Text\Acrobat_6_prof\Acrobat\AcroIEFavClient.dll ()
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Internet\java\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Gears Helper) - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.33.0\gears.dll (Google Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Internet\java\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (ZoneAlarm Spy Blocker BHO) - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL (ZoneAlarm)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Text\Acrobat_6_prof\Acrobat\AcroIEFavClient.dll ()
O3 - HKLM\..\Toolbar: (ZoneAlarm Spy Blocker) - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL (ZoneAlarm)
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Spy Blocker) - {F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL (ZoneAlarm)
O4 - HKLM..\Run: [{B179023B-6238-4499-8F26-CD73E9D90E0A}] C:\Program Files\Mediafour\MacDrive 7\MacDrive.exe (Mediafour Corporation)
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [AcronisTimounterMonitor] D:\System\blckarmorbackup\TimounterMonitor.exe (Seagate)
O4 - HKLM..\Run: [AVG8_TRAY] D:\Internet\avg\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BlackArmorBackupMonitor.exe] D:\System\blckarmorbackup\BlackArmorBackupMonitor.exe (Seagate)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [Seagate Scheduler2 Service] C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe (Seagate)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\Sigmatel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [ZoneAlarm Client] D:\Internet\ZoneAlarm\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [EPSON Artisan 50 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIFFA.EXE (SEIKO EPSON CORPORATION)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil10i_Plugin.exe (Adobe Systems, Inc.)
O4 - HKLM..\RunServices: [LicCtrl] C:\WINDOWS\mmfs.DLL ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Download all with Free Download Manager - D:\Internet\Free Download Manager\dlall.htm ()
O8 - Extra context menu item: Download selected with Free Download Manager - D:\Internet\Free Download Manager\dlselected.htm ()
O8 - Extra context menu item: Download video with Free Download Manager - D:\Internet\Free Download Manager\dlfvideo.htm ()
O8 - Extra context menu item: Download with Free Download Manager - D:\Internet\Free Download Manager\dllink.htm ()
O8 - Extra context menu item: E&xport; to Microsoft Excel - D:\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Gears; Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.33.0\gears.dll (Google Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 192.168.1.254
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\Internet\avg\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Shrews\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Shrews\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 14:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{1c0c5865-2184-11df-a86e-001d09ad8627}\Shell\AutoRun\command - "" = G:\Setup.exe – File not found
O33 - MountPoints2\{1c0c5865-2184-11df-a86e-001d09ad8627}\Shell\Install\command - "" = G:\Setup.exe – File not found
O33 - MountPoints2\{4e66e8fb-39bc-11df-a877-001d09ad8627}\Shell\AutoRun\command - "" = H:\MI.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.dfscacm - C:\WINDOWS\System32\dfscacm.dll ()
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.dfsc - C:\WINDOWS\System32\dfsc.dll ()
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.dvsd - C:\WINDOWS\System32\pdvcodec.dll (Matsushita Electric Industrial Co., Ltd.)
Drivers32: vidc.hdyc - D:\video\blackmagic codecs\BMDCodecLib.dll (Blackmagic Design)
Drivers32: VIDC.I420 - C:\WINDOWS\System32\i420vfw.dll (www.helixcommunity.org)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.MP42 - C:\WINDOWS\System32\MPG4C32.DLL (Microsoft Corporation)
Drivers32: VIDC.MPG4 - C:\WINDOWS\System32\MPG4C32.DLL (Microsoft Corporation)
Drivers32: vidc.r210 - D:\video\blackmagic codecs\BMDCodecLib.dll (Blackmagic Design)
Drivers32: vidc.v210 - D:\video\blackmagic codecs\BMDCodecLib.dll (Blackmagic Design)
Drivers32: VIDC.WMV3 - C:\WINDOWS\System32\wmv9vcm.dll (Microsoft Corporation)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\WINDOWS\System32\yv12vfw.dll (www.helixcommunity.org)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16620634377289728)
========== Files/Folders - Created Within 30 Days ==========
[2010/09/23 13:31:33 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Shrews\Desktop\OTL.exe
[2010/08/30 00:49:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Shrews\Desktop\logos
[2010/08/30 00:13:20 | 000,000,000 | —D | C] – C:\Documents and Settings\Shrews\Local Settings\Application Data\Sony
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/09/23 13:31:34 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Shrews\Desktop\OTL.exe
[2010/09/23 13:10:10 | 016,252,928 | —- | M] () – C:\Documents and Settings\Shrews\ntuser.dat
[2010/09/23 13:06:31 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/09/23 11:42:39 | 065,173,360 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/09/21 09:49:17 | 000,528,020 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/09/21 09:49:17 | 000,445,938 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/09/21 09:49:17 | 000,072,978 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/09/20 15:40:43 | 000,721,675 | —- | M] () – C:\Documents and Settings\Shrews\Desktop\Common_Gain_Stage.pdf
[2010/09/17 13:59:07 | 000,000,004 | —- | M] () – C:\WINDOWS\Twain001.Mtx
[2010/09/17 13:59:03 | 000,000,156 | —- | M] () – C:\WINDOWS\Twunk001.MTX
[2010/09/17 13:33:11 | 000,000,256 | —- | M] () – C:\WINDOWS\System32\pool.bin
[2010/09/17 13:00:05 | 002,285,676 | —- | M] () – C:\Documents and Settings\Shrews\Desktop\teesandtapes.pdf
[2010/09/15 21:51:32 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/09/15 21:51:00 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/09/15 21:50:39 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/09/15 21:50:36 | 2137,038,848 | -HS- | M] () – C:\hiberfil.sys
[2010/09/15 21:49:50 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Shrews\ntuser.ini
[2010/09/15 15:05:49 | 001,749,464 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/09/15 12:44:34 | 000,103,392 | —- | M] () – C:\Documents and Settings\Shrews\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/09/10 05:28:52 | 000,078,668 | -H– | M] () – C:\WINDOWS\System32\mlfcache.dat
[2010/09/06 23:34:30 | 000,003,584 | —- | M] () – C:\Documents and Settings\Shrews\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/01 00:24:12 | 000,019,968 | —- | M] () – C:\Documents and Settings\Shrews\Desktop\Blog.doc
[2010/08/28 21:22:04 | 000,000,202 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/08/28 18:08:16 | 000,140,752 | —- | M] () – C:\Documents and Settings\Shrews\Desktop\GBS.pdf
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/09/23 13:28:34 | 000,721,675 | —- | C] () – C:\Documents and Settings\Shrews\Desktop\Common_Gain_Stage.pdf
[2010/09/17 13:00:04 | 002,285,676 | —- | C] () – C:\Documents and Settings\Shrews\Desktop\teesandtapes.pdf
[2010/09/15 21:50:36 | 2137,038,848 | -HS- | C] () – C:\hiberfil.sys
[2010/09/01 00:24:11 | 000,019,968 | —- | C] () – C:\Documents and Settings\Shrews\Desktop\Blog.doc
[2010/08/28 18:08:15 | 000,140,752 | —- | C] () – C:\Documents and Settings\Shrews\Desktop\GBS.pdf
[2010/08/15 15:43:30 | 000,003,584 | —- | C] () – C:\Documents and Settings\Shrews\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/10 13:59:30 | 000,025,713 | —- | C] () – C:\WINDOWS\CSTBox.INI
[2010/07/23 11:47:22 | 000,024,287 | —- | C] () – C:\Documents and Settings\Shrews\Application Data\PamelaPCR_EXTRA_4_6_0_1_4C49C79A.zip
[2010/07/09 12:52:52 | 000,021,188 | —- | C] () – C:\Documents and Settings\Shrews\Application Data\PamelaPCR_EXTRA_4_6_0_1_4C3761F3.zip
[2010/07/02 16:55:16 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2010/07/02 16:52:17 | 000,000,025 | —- | C] () – C:\WINDOWS\EPART50.ini
[2010/06/24 20:19:02 | 002,463,976 | —- | C] () – C:\WINDOWS\System32\NPSWF32.dll
[2010/05/29 16:27:29 | 000,000,945 | —- | C] () – C:\WINDOWS\vista32.ini
[2010/05/29 16:01:08 | 000,000,118 | —- | C] () – C:\WINDOWS\ppdrv.ini
[2010/05/29 15:51:10 | 000,079,360 | —- | C] () – C:\WINDOWS\u1200_32.dll
[2010/05/29 15:51:10 | 000,006,932 | —- | C] () – C:\WINDOWS\System32\glscan.sys
[2010/05/29 15:51:09 | 000,030,208 | —- | C] () – C:\WINDOWS\uxmail32.dll
[2010/05/29 15:51:08 | 000,068,608 | —- | C] () – C:\WINDOWS\vufile32.dll
[2010/05/29 15:51:07 | 000,076,260 | —- | C] () – C:\WINDOWS\System32\drivers\udnt.sys
[2010/05/06 11:44:14 | 000,023,333 | —- | C] () – C:\Documents and Settings\Shrews\Application Data\PamelaPCR_EXTRA_4_6_0_1_4BE2F1DE.zip
[2010/05/05 13:44:21 | 000,020,017 | —- | C] () – C:\Documents and Settings\Shrews\Application Data\PamelaPCR_EXTRA_4_6_0_1_4BE1BC85.zip
[2010/04/18 12:14:54 | 000,033,824 | —- | C] () – C:\WINDOWS\System32\drivers\oreans32.sys
[2009/09/08 17:10:57 | 000,001,025 | —- | C] () – C:\WINDOWS\System32\clauth2.dll
[2009/09/08 17:10:57 | 000,001,025 | —- | C] () – C:\WINDOWS\System32\clauth1.dll
[2009/09/08 17:10:56 | 000,001,025 | —- | C] () – C:\WINDOWS\System32\sysprs7.dll
[2009/06/03 18:40:58 | 000,175,104 | —- | C] () – C:\WINDOWS\System32\RemoteControl.dll
[2009/04/09 21:23:03 | 000,000,347 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2009/03/30 15:41:48 | 000,000,212 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2009/03/03 13:38:58 | 000,027,211 | —- | C] () – C:\Documents and Settings\Shrews\Application Data\Personal Address Book.ADR
[2008/10/20 23:16:02 | 000,796,048 | —- | C] () – C:\WINDOWS\System32\libeay32_0.9.6l.dll
[2008/10/20 21:55:13 | 000,036,483 | —- | C] () – C:\Documents and Settings\Shrews\Application Data\Comma Separated Values (Windows).ADR
[2008/10/20 21:55:13 | 000,000,020 | —- | C] () – C:\Documents and Settings\Shrews\Application Data\Final Draft Tagger Preferences
[2008/10/18 01:16:00 | 000,000,012 | —- | C] () – C:\WINDOWS\pol32.ini
[2008/10/15 16:26:22 | 000,009,728 | —- | C] () – C:\WINDOWS\System32\BASSMOD.dll
[2008/07/04 12:51:57 | 000,001,359 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2008/06/28 17:32:09 | 000,408,576 | —- | C] () – C:\WINDOWS\System32\Smab.dll
[2008/06/28 17:32:04 | 000,027,648 | —- | C] () – C:\WINDOWS\System32\AVSredirect.dll
[2008/06/28 15:08:13 | 000,027,648 | -HS- | C] () – C:\WINDOWS\System32\Smab0.dll
[2008/04/17 00:41:55 | 000,000,040 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2008/04/10 16:55:37 | 000,000,127 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2008/04/10 16:45:21 | 000,059,904 | —- | C] () – C:\WINDOWS\System32\zlib1.dll
[2008/03/23 21:51:05 | 000,000,032 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ezsid.dat
[2008/02/20 00:55:30 | 000,000,202 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2008/01/20 14:12:49 | 000,000,026 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\.119889580931711767808769176
[2008/01/20 14:10:06 | 000,000,021 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\.24554863501262644635642126105
[2008/01/09 19:02:39 | 000,765,952 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2008/01/09 19:02:38 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2007/12/29 00:10:34 | 000,039,424 | —- | C] () – C:\WINDOWS\mmfs.dll
[2007/12/28 19:52:38 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/12/27 20:40:18 | 000,013,840 | —- | C] () – C:\WINDOWS\System32\wnaspi32.dll
[2007/12/27 20:37:04 | 003,870,720 | —- | C] () – C:\WINDOWS\System32\qt-mt323.dll
[2007/12/11 14:40:40 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2007/12/11 14:32:59 | 000,000,859 | —- | C] () – C:\WINDOWS\{0240BDFB-2995-4A3F-8C96-18D41282B716}_WiseFW.ini
[2007/12/11 14:31:06 | 000,198,144 | —- | C] () – C:\WINDOWS\System32\_psisdecd.dll
[2007/12/11 14:30:39 | 000,056,056 | —- | C] () – C:\WINDOWS\System32\DLAAPI_W.DLL
[2007/12/11 14:30:39 | 000,000,120 | —- | C] () – C:\WINDOWS\wininit.ini
[2007/12/11 14:22:53 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\preflib.dll
[2007/12/11 14:22:51 | 000,757,760 | —- | C] () – C:\WINDOWS\System32\bcm1xsup.dll
[2007/12/11 13:59:38 | 000,910,304 | —- | C] () – C:\WINDOWS\System32\igmedkrn.dll
[2007/12/11 13:59:38 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4831.dll
[2007/12/11 13:59:36 | 000,016,480 | —- | C] () – C:\WINDOWS\System32\rixdicon.dll
[2007/12/11 13:57:48 | 000,001,118 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2007/11/29 17:30:28 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2007/11/29 17:28:24 | 000,000,416 | —- | C] () – C:\WINDOWS\System32\dtu100.dll.manifest
[2007/11/29 17:28:24 | 000,000,416 | —- | C] () – C:\WINDOWS\System32\dpl100.dll.manifest
[2007/11/28 16:52:32 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2007/10/12 02:11:58 | 000,066,482 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2007/10/11 19:59:24 | 000,025,624 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2006/11/07 05:25:58 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2006/09/17 00:36:50 | 000,520,192 | —- | C] () – C:\WINDOWS\System32\CddbPlaylist2Roxio.dll
[2006/09/17 00:36:50 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\CddbFileTaggerRoxio.dll
[2005/07/08 23:07:46 | 000,007,168 | —- | C] () – C:\WINDOWS\System32\dfscacm.dll
[2005/07/08 23:07:44 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\dfsc.dll
[2004/08/10 14:12:05 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/10 14:01:18 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2003/01/07 10:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[1999/01/27 14:39:06 | 000,065,024 | —- | C] () – C:\WINDOWS\System32\indounin.dll
[1997/06/13 08:56:08 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\Iyvu9_32.dll
========== LOP Check ==========
[2010/02/27 14:49:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Acronis
[2010/07/02 17:18:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EPSON
[2008/01/20 14:10:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Final Draft
[2009/01/16 08:54:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FreeDownloadManager.ORG
[2007/12/28 01:21:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MailFrontier
[2008/06/28 15:21:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Mediafour
[2009/09/08 17:10:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Minnetonka Audio Software
[2010/05/04 14:46:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Research In Motion
[2010/02/27 15:11:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Seagate
[2007/12/11 14:33:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SingleClick Systems
[2008/04/17 00:42:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SlySoft
[2008/09/03 18:24:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sony
[2007/12/11 14:37:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2010/05/18 23:07:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sync App Settings
[2010/04/09 16:44:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/05/18 21:04:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TrueCrypt
[2009/05/30 21:05:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2008/10/20 21:56:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Alien Skin
[2010/08/07 18:26:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\AMPSoft
[2009/06/15 00:47:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Artisteer
[2010/05/13 21:33:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Blackberry Desktop
[2010/09/17 12:49:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Canon
[2009/06/13 13:58:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\ctpo
[2009/06/13 13:58:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\engadven
[2008/10/20 21:56:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Final Draft
[2008/10/20 21:56:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Flickr
[2009/11/15 00:33:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Foxit
[2010/02/25 14:43:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Foxit Software
[2009/08/05 10:07:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Free Download Manager
[2008/12/09 01:45:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Leadertech
[2009/05/18 20:45:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\LEAPS
[2009/05/24 15:56:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\MPEG Streamclip
[2009/03/03 01:00:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\NeoDownloader
[2008/10/20 21:55:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Opera
[2009/11/06 01:26:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Pamela
[2009/05/18 20:11:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Pegasys Inc
[2008/10/20 21:55:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Publish Providers
[2010/05/14 00:29:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Research In Motion
[2010/02/27 15:15:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Seagate
[2009/02/06 13:54:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Smith Micro
[2008/10/20 21:55:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Sony
[2008/10/20 21:55:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Sony Setup
[2010/05/18 23:07:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Sync App Settings
[2008/10/20 21:55:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Thunderbird
[2010/05/19 00:29:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\TrueCrypt
[2010/08/28 20:33:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\uTorrent
[2008/10/20 21:55:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\W Photo Studio Viewer
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2008/12/31 14:07:07 | 000,000,000 | —- | M] () – C:\asoutput.log
[2004/08/10 14:04:08 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/11/08 01:33:37 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010/05/21 11:20:12 | 000,000,281 | -HS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2009/11/09 15:48:54 | 000,015,036 | —- | M] () – C:\ComboFix.txt
[2004/08/10 14:04:08 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2007/12/11 14:02:42 | 000,006,843 | RH– | M] () – C:\dell.sdr
[2010/09/15 21:50:36 | 2137,038,848 | -HS- | M] () – C:\hiberfil.sys
[2007/12/27 18:57:09 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2004/08/10 14:04:08 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2009/12/09 21:41:38 | 000,006,508 | —- | M] () – C:\JavaRa.log
[2006/05/05 13:47:34 | 000,090,792 | —- | M] () – C:\keyfingers.jpg
[2008/04/03 00:43:27 | 000,023,224 | —- | M] () – C:\keyfingers_dell.jpg
[2009/05/09 14:31:09 | 000,300,751 | —- | M] () – C:\log_fs.log
[2004/08/10 14:04:08 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/08/04 06:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2004/08/04 06:00:00 | 000,250,032 | RHS- | M] () – C:\ntldr
[2009/04/04 17:48:40 | 000,001,760 | —- | M] () – C:\Rescued document 1.txt
[2009/04/04 17:48:34 | 000,002,741 | —- | M] () – C:\Rescued document.txt
[2009/11/06 12:00:26 | 000,007,196 | —- | M] () – C:\RootRepeal report 11-06-09 (12-00-26).txt
[2010/04/14 00:41:39 | 000,004,096 | -HS- | M] () – C:\VSNAP.IDX
[2008/04/09 18:38:22 | 000,000,252 | —- | M] () – C:\VundoFix.txt
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2004/08/10 14:03:42 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/03/28 13:57:34 | 000,274,944 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp5ha.dll
[2003/06/18 16:31:48 | 000,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
[2007/05/17 21:32:50 | 000,326,742 | —- | M] () – C:\WINDOWS\Vostro_NB_1280x864_01.jpg
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2004/08/10 13:56:48 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2004/08/10 13:56:46 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2004/08/10 13:56:46 | 000,872,448 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2004/08/10 14:04:12 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2007/12/25 14:04:38 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Shrews\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2004/08/10 14:08:38 | 000,000,079 | —- | M] () – C:\Documents and Settings\Shrews\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2010/09/23 13:31:34 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Shrews\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-07-26 16:43:20
========== Alternate Data Streams ==========
@Alternate Data Stream - 60 bytes -> C:\WINDOWS\System32\ssprs.tgz:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\WINDOWS\System32\lsprst7.tgz:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Documents and Settings\Shrews\Desktop\ROLEX AWARDS.doc:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Documents and Settings\Shrews\Desktop\cool_money.txt:AFP_AfpInfo
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:62E2D794
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:888AFB86
< End of report >
OTL Extras logfile created on: 9/23/2010 1:32:31 PM - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\Shrews\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 57.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): F:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 14.51 Gb Total Space | 5.36 Gb Free Space | 36.97% Space Free | Partition Type: NTFS
Drive D: | 6.55 Gb Total Space | 1.72 Gb Free Space | 26.32% Space Free | Partition Type: NTFS
Drive E: | 6.04 Gb Total Space | 1.44 Gb Free Space | 23.77% Space Free | Partition Type: NTFS
Drive F: | 82.11 Gb Total Space | 53.13 Gb Free Space | 64.70% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: GBS-LAPTOP
Current User Name: Shrews
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – D:\Internet\Mozilla_Firefox\firefox.exe (Mozilla Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – D:\Internet\Mozilla_Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
https [open] – "D:\Internet\Mozilla_Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
jsfile – "D:\graphics\dreamweaver\Dreamweaver 8\dreamweaver.exe" "%1" (Macromedia, Inc.)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring" = 1
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"10421:UDP" = 10421:UDP:*:Enabled:SingleClick Discovery Protocol
"10426:UDP" = 10426:UDP:*:Enabled:SingleClick ICC
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Dell Network Assistant\ezi_hnm2.exe" = C:\Program Files\Dell Network Assistant\ezi_hnm2.exe:*:Enabled:Dell Network Assistant – (SingleClick Systems)
"C:\Program Files\Dell\MediaDirect\PCMService.exe" = C:\Program Files\Dell\MediaDirect\PCMService.exe:*:Enabled:CyberLink PowerCinema Resident Program – (CyberLink Corp.)
"D:\Internet\avg\avgupd.exe" = D:\Internet\avg\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
"D:\Internet\utorrent\uTorrent.exe" = D:\Internet\utorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour – File not found
"C:\WINDOWS\system32\ZoneLabs\vsmon.exe" = C:\WINDOWS\system32\ZoneLabs\vsmon.exe:*:Enabled:vsmon – (Check Point Software Technologies LTD)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0240BDFB-2995-4A3F-8C96-18D41282B716}" = Dell Network Assistant
"{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime
"{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
"{06A1BE8A-4CA4-4A39-B9E4-E815AA8FE05C}" = Sony Noise Reduction Plug-In 2.0h
"{0837A661-FEC3-48B3-876C-91E7D32048A9}" = Macromedia Dreamweaver 8
"{0D2E80C8-0875-43EB-9623-47118E2DFBCA}" = Quicken 2007
"{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{13515135-48BB-4184-8C1F-2FAE0138E200}" = TBS WMP Plug-in
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{190D0C6E-C8A7-4019-8FB5-FD041EC1F2D2}" = Mobile Broadband Drivers
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 18
"{26D77DBB-E7BF-4B2F-8C02-E731F2E224C0}_is1" = JoomlaPack Native Tools 2009.3
"{2715D1D6-2B81-4DD5-A9DC-6EFF4D5E0993}" = Ahead Nero Burning Rom PlugIn Pack 2.0.2 by MadHacker2k4
"{2BD5C305-1B27-4D41-B690-7A61172D2FEB}" = Macromedia Flash 8
"{2F28B3C9-2C89-4206-8B33-8ADC9577C49B}" = Scan
"{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}" = Roxio Drag-to-Disc
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{31228E31-2BFF-11D2-8866-00805F0D9D40}" = QPST
"{32F720F5-2D0D-4245-A2B0-9EB3CECF8101}" = Norton Ghost 10.0
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{40A594D0-1490-4979-9382-D2B764F949C6}" = BlackBerry® Media Sync
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4AEA9A23-D627-4699-8A0F-FC474308C2E6}" = Sony Sound Forge 9.0
"{4C24A8C1-7CFA-4650-AF15-732F5BD7B46D}" = Macromedia Fireworks 8
"{5546CDB5-2CE2-498B-B059-5B3BF81FC41F}" = Macromedia Extension Manager
"{5BACA8C1-909F-4AA4-90EB-6CAE5241FA96}" = MacDrive 7
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.6
"{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{62230596-37E5-4618-A329-0D21F529A86F}" = Browser Address Error Redirector
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
"{78D62D17-D970-42DA-B8CF-5E5576293B33}" = Final Draft 7
"{7B4174E8-FE92-4269-808A-3B8D116D9538}" = Advanced Security for Outlook
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7C9AD221-994C-45B2-B46D-26F5735158CF}" = Sony Vegas Pro 8.0
"{7DD9A065-2C86-4A9F-A5FF-796EC1B99DCA}" = AnswerWorks 4.0 Runtime - English
"{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
"{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}" = Roxio Creator BDAV Plugin
"{885A63EA-382B-4DD4-A755-14809B8557D6}" = Macromedia Flash Player 8
"{88908767-B7AD-4b0d-ACBC-FBCCF2761D31}" = HP Photosmart All-In-One Software 9.0
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8BF2C401-02CE-424D-BC26-6C4F9FB446B6}" = Macromedia Flash 8 Video Encoder
"{8D55AC33-2CB4-4A4D-93A9-F5C76124BBC3}" = BlackBerry Device Software v5.0.0 for the BlackBerry 8530 smartphone
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{945AC98B-3DC8-45BE-BAE0-22CEEE37A103}" = Logitech QuickCam
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{9BDEF074-020E-458D-ADC5-8FF68E0C9B56}" = OutlookAddinSetup
"{9C6978E8-B6D0-4AB7-A7A0-D81A74FBF745}" = MediaDirect
"{9DF6EC22-733E-4EDC-AC88-54CAD4BF4E7B}" = BlackArmor Backup
"{A040AC77-C1AA-4CC9-8931-9F648AF178F6}" = VC 9.0 Runtime
"{A14F7508-B784-40B8-B11A-E0E2EEB7229F}" = Adobe Premiere Pro 1.5
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-1033-0000-7760-000000000001}" = Adobe Acrobat 6.0 Professional
"{AF7FC1CA-79DF-43c3-90A3-33EFEB9294CE}" = AIO_Scan
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B74D4E10-1033-0000-0000-000000000001}" = Adobe Bridge 1.0
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BC2FE771-EDBE-3087-A676-2B6C45A2BF7E}" = Google Gears
"{BCE46757-7674-4416-BEDB-68205A60409E}" = Canon CanoScan Toolbox 4.1
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C13AF9C7-8E06-4354-B629-DF6192CE4A66}" = PANTECH UM175 Driver
"{C5074CC4-0E26-4716-A307-960272A90040}" = QuickSet
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE
"{C99C0593-3B48-41D9-B42F-6E035B320449}" = Broadcom Management Programs
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240B8}" = WinZip 12.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE86E2F5-850C-4207-94A3-A58D647B1733}" = BlackBerry Desktop Software 5.0.1
"{D050D7362D214723AD585B541FFB6C11}" = DivX Content Uploader
"{D16A31F9-276D-4968-A753-FFEAC56995D0}" = Epson Print CD
"{D1B5E9C8-4CCF-44E3-87D6-7C00D7DA5370}" = IntelliSonic Speech Enhancement
"{D26F7C78-E2D7-49AB-8E64-53CB8AE99074}" = XDCAM EX Clip Browser
"{D639085F-4B6E-4105-9F37-A0DBB023E2FB}" = Roxio MyDVD DE
"{D6E4E5D6-7693-4BB4-95BA-21F38FAFEE90}" = Safari
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E28750A2-45F2-4b63-99F7-9F81A94B1E2D}" = PS_AIO_Software_min
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{E76CDDCE-EFC0-4FE5-9972-9489CE49AA55}_is1" = NeoDownloader 2.2
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"{E9C18EBD-85BE-47D0-AA73-3FEDCC976B04}" = Toolbox
"{ED80F174-B621-4B8F-BBB9-3E031A59555A}" = TMPGEnc 4.0 XPress
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F5A6583A-3051-45ED-BE87-10CF079CB6B4}" = Blackmagic Codecs
"{F63A3748-B93D-4360-9AD4-B064481A5C7B}" = Modem Diagnostic Tool
"{FA61D601-A0FC-48BD-AE7A-54946BCD7FB6}_is1" = BitPim 1.0.6
"{FE34691C-4298-4667-9758-D7F534DD0B94}" = Dell Automated PC TuneUp
"7-Zip" = 7-Zip 4.65
"ABC Amber vCard Converter" = ABC Amber vCard Converter
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"Allway Sync_is1" = Allway Sync version 10.3.8
"AMP Font Viewer" = AMP Font Viewer
"AnyDVD" = AnyDVD
"AVG8Uninstall" = AVG Free 8.5
"BBE Sonic Maximizer Plugin" = BBE Sonic Maximizer Plugin
"BlackBerry_{CE86E2F5-850C-4207-94A3-A58D647B1733}" = BlackBerry Desktop Software 5.0.1
"Blow Up" = Alien Skin Blow Up
"Broadcom 802.11b Network Adapter" = Dell Wireless WLAN Card
"CCleaner" = CCleaner (remove only)
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV;_2C06&SUBSYS;_14F1000F" = Conexant HDA D330 MDC V.92 Modem
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"DebugMode FrameServer" = DebugMode FrameServer
"Easy Duplicate Finder_is1" = Easy Duplicate Finder v. 2.2.1
"EPSON Artisan 50 Series" = EPSON Artisan 50 Series Printer Uninstall
"EPSON Printer and Utilities" = EPSON Printer Software
"ERUNT_is1" = ERUNT 1.1j
"Exposure 2" = Alien Skin Exposure 2
"FileZilla" = FileZilla (remove only)
"Flickr Uploadr" = Flickr Uploadr 3.0.5
"Foxit PDF Editor" = Foxit PDF Editor
"Foxit Reader" = Foxit Reader
"Free Download Manager_is1" = Free Download Manager 3.0
"FriendBlasterPro_is1" = FriendBlasterPro
"HardlinkShellExt" = Link Shell Extension
"HDMI" = Intel® Graphics Media Accelerator Driver
"ie7" = Windows Internet Explorer 7
"InstallShield_{13515135-48BB-4184-8C1F-2FAE0138E200}" = TBS WMP Plug-in
"IrfanView" = IrfanView (remove only)
"LiveReg" = LiveReg (Symantec Corporation)
"lvdrivers_11.50" = Logitech QuickCam Driver Package
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Moleskinsoft Clone Remover 3.8_is1" = Moleskinsoft Clone Remover 3.8
"Mozilla Firefox (3.6.8)" = Mozilla Firefox (3.6.8)
"Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition
"NeroVision!UninstallKey" = Nero Digital
"Pamela" = Pamela Pro 4.5
"PandoraSaver (standalone)_is1" = PandoraSaver 1.008e (standalone)
"PdaNet_is1" = PdaNet for BlackBerry 1.30
"Picasa 3" = Picasa 3
"SpywareBlaster_is1" = SpywareBlaster 4.2
"SUPER ©" = SUPER © Version 2008.bld.30 (Mar 22, 2008)
"SynTPDeinstKey" = Dell Touchpad
"The Rosetta Stone" = The Rosetta Stone
"TrueCrypt" = TrueCrypt
"Tweak UI 2.10" = Tweak UI
"VirtualCloneDrive" = VirtualCloneDrive
"Web Album Maker" = Web Album Maker 2.20
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinRAR archiver" = WinRAR archiver
"WinZip" = WinZip
"xampp" = XAMPP 1.7.1
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Xvid_is1" = Xvid 1.1.3 final uninstall
"ZoneAlarm" = ZoneAlarm
"ZoneAlarmSB Uninstall" = ZoneAlarm Spy Blocker
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 9/22/2010 11:47:10 PM | Computer Name = GBS-LAPTOP | Source = Google Update | ID = 20
Description =
Error - 9/23/2010 12:06:30 AM | Computer Name = GBS-LAPTOP | Source = Google Update | ID = 20
Description =
Error - 9/23/2010 12:47:09 AM | Computer Name = GBS-LAPTOP | Source = Google Update | ID = 20
Description =
Error - 9/23/2010 1:06:29 AM | Computer Name = GBS-LAPTOP | Source = Google Update | ID = 20
Description =
Error - 9/23/2010 1:47:09 AM | Computer Name = GBS-LAPTOP | Source = Google Update | ID = 20
Description =
Error - 9/23/2010 2:06:28 AM | Computer Name = GBS-LAPTOP | Source = Google Update | ID = 20
Description =
Error - 9/23/2010 12:40:47 PM | Computer Name = GBS-LAPTOP | Source = Google Update | ID = 20
Description =
Error - 9/23/2010 1:06:35 PM | Computer Name = GBS-LAPTOP | Source = Google Update | ID = 20
Description =
Error - 9/23/2010 1:43:44 PM | Computer Name = GBS-LAPTOP | Source = Google Update | ID = 20
Description =
Error - 9/23/2010 2:06:30 PM | Computer Name = GBS-LAPTOP | Source = Google Update | ID = 20
Description =
[ System Events ]
Error - 9/15/2010 7:04:49 PM | Computer Name = GBS-LAPTOP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
Error - 9/15/2010 7:05:26 PM | Computer Name = GBS-LAPTOP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 9/15/2010 7:06:18 PM | Computer Name = GBS-LAPTOP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 9/15/2010 7:06:27 PM | Computer Name = GBS-LAPTOP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 9/15/2010 7:06:27 PM | Computer Name = GBS-LAPTOP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 9/15/2010 10:49:48 PM | Computer Name = GBS-LAPTOP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 9/15/2010 10:52:30 PM | Computer Name = GBS-LAPTOP | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the LicCtrl Service service
to connect.
Error - 9/15/2010 10:52:30 PM | Computer Name = GBS-LAPTOP | Source = Service Control Manager | ID = 7000
Description = The LicCtrl Service service failed to start due to the following error:
%%1053
Error - 9/20/2010 2:33:48 AM | Computer Name = GBS-LAPTOP | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.1.105 on
the Network Card with network address 001E8C317C52.
Error - 9/22/2010 3:43:41 PM | Computer Name = GBS-LAPTOP | Source = ipnathlp | ID = 32003
Description = The Network Address Translator (NAT) was unable to request an operation
of
the kernel-mode translation module. This may indicate misconfiguration, insufficient
resources, or an internal error. The data is the error code.
< End of report >
Computer seems to be slower, also having standby and hibernating issues, whereas it's always on. Other than that, it's running "fine," except I noticed today that MBAM and Adaware would not update. Strange because I can't trace where I may have gotten infected. Let me know how it looks.
OTL results:
OTL logfile created on: 9/23/2010 1:32:31 PM - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\Shrews\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 57.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): F:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 14.51 Gb Total Space | 5.36 Gb Free Space | 36.97% Space Free | Partition Type: NTFS
Drive D: | 6.55 Gb Total Space | 1.72 Gb Free Space | 26.32% Space Free | Partition Type: NTFS
Drive E: | 6.04 Gb Total Space | 1.44 Gb Free Space | 23.77% Space Free | Partition Type: NTFS
Drive F: | 82.11 Gb Total Space | 53.13 Gb Free Space | 64.70% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: GBS-LAPTOP
Current User Name: Shrews
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Shrews\Desktop\OTL.exe (OldTimer Tools)
PRC - D:\Internet\avg\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
PRC - D:\Internet\java\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - D:\Internet\Safari\Safari.exe (Apple Inc.)
PRC - D:\Internet\avg\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - D:\Internet\avg\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - D:\System\blckarmorbackup\TimounterMonitor.exe (Seagate)
PRC - C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe (Seagate)
PRC - C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe (Seagate)
PRC - C:\Program Files\Common Files\Seagate\BlackArmorBackup\BlackArmorBackupNotify.exe (Seagate)
PRC - D:\System\blckarmorbackup\BlackArmorBackupMonitor.exe (Seagate)
PRC - C:\Program Files\Common Files\Seagate\BlackArmorBackup\BlackArmorBackupService.exe (Seagate)
PRC - D:\Internet\xampp\mysql\bin\mysqld.exe ()
PRC - D:\Internet\xampp\apache\bin\httpd.exe (Apache Software Foundation)
PRC - D:\Internet\adaware\aawservice.exe (Lavasoft)
PRC - C:\Program Files\Common Files\logishrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
PRC - C:\Program Files\Mediafour\MacDrive 7\MacDrive.exe (Mediafour Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Dell Network Assistant\hnm_svc.exe (SingleClick Systems)
PRC - C:\Program Files\Sigmatel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
PRC - C:\Program Files\Mediafour\MacDrive 7\MacDriveService.exe (Mediafour Corporation)
PRC - D:\Text\Acrobat_6_prof\Distillr\acrotray.exe (Adobe Systems Inc.)
PRC - C:\WINDOWS\system32\WISPTIS.EXE (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Shrews\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (vsmon) – C:\WINDOWS\System32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (AcrSch2Svc) – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
SRV - (JavaQuickStarterService) – D:\Internet\java\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (avg8wd) – D:\Internet\avg\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Norton Ghost) – D:\System\Norton\Agent\VProSvc.exe (Symantec Corporation)
SRV - (Symantec Core LC) – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (Symantec Corporation)
SRV - (SgtSch2Svc) – C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe (Seagate)
SRV - (MySQL) – D:\Internet\xampp\mysql\bin\mysqld.exe ()
SRV - (Apache2.2) – D:\Internet\xampp\apache\bin\httpd.exe (Apache Software Foundation)
SRV - (aawservice) – D:\Internet\adaware\aawservice.exe (Lavasoft)
SRV - (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (LVSrvLauncher) – C:\Program Files\Common Files\logishrd\SrvLnch\SrvLnch.exe (Logitech Inc.)
SRV - (LicCtrlService) – C:\WINDOWS\mmfs.DLL ()
SRV - (LVPrcSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (LVCOMSer) – C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
SRV - (DellAMBrokerService) – C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe ()
SRV - (hnmsvc) – C:\Program Files\Dell Network Assistant\hnm_svc.exe (SingleClick Systems)
SRV - (MacDriveService) – C:\Program Files\Mediafour\MacDrive 7\MacDriveService.exe (Mediafour Corporation)
SRV - (GEARSecurity) – C:\WINDOWS\system32\gearsec.exe (GEAR Software)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (ccPwdSvc) – C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
========== Driver Services (SafeList) ==========
DRV - (UIUSys) – C:\WINDOWS\System32\DRIVERS\UIUSYS.SYS File not found
DRV - (srescan) – C:\WINDOWS\System32\ZoneLabs\srescan.sys File not found
DRV - (catchme) – C:\DOCUME~1\Shrews\LOCALS~1\Temp\catchme.sys File not found
DRV - (tdrpman174) Acronis Try&Decide; and Restore Points filter (build 174) – C:\WINDOWS\system32\DRIVERS\tdrpm174.sys (Acronis)
DRV - (truecrypt) – C:\WINDOWS\system32\drivers\truecrypt.sys (TrueCrypt Foundation)
DRV - (vsdatant) – C:\WINDOWS\system32\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (oreans32) – C:\WINDOWS\system32\drivers\oreans32.sys ()
DRV - (timounter) – C:\WINDOWS\system32\DRIVERS\timntr.sys (Acronis)
DRV - (tifsfilter) – C:\WINDOWS\system32\drivers\tifsfilt.sys (Acronis)
DRV - (snapman380) Acronis Snapshots Manager (Build 380) – C:\WINDOWS\system32\DRIVERS\snman380.sys (Acronis)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (VClone) – C:\WINDOWS\system32\drivers\VClone.sys (Elaborate Bytes AG)
DRV - (symlcbrd) – C:\WINDOWS\system32\drivers\symlcbrd.sys (Symantec Corporation)
DRV - (ElbyCDIO) – C:\WINDOWS\system32\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV - (LVUSBSta) – C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (PTDUWWAN) – C:\WINDOWS\system32\drivers\PTDUWWAN.sys (DEVGURU Co,LTD.)
DRV - (PTDUVsp) – C:\WINDOWS\system32\drivers\PTDUVsp.sys (DEVGURU Co,LTD.)
DRV - (PTDUMdm) – C:\WINDOWS\system32\drivers\PTDUMdm.sys (DEVGURU Co,LTD.)
DRV - (PTDUBus) – C:\WINDOWS\system32\drivers\PTDUBus.sys (DEVGURU Co,LTD.)
DRV - (PID_0928) Logitech QuickCam Express(PID_0928) – C:\WINDOWS\system32\drivers\LV561AV.SYS (Logitech Inc.)
DRV - (LVcKap) – C:\WINDOWS\system32\drivers\Lvckap.sys (Logitech Inc.)
DRV - (LVMVDrv) – C:\WINDOWS\system32\drivers\LVMVdrv.sys (Logitech Inc.)
DRV - (MDFSYSNT) – C:\WINDOWS\System32\drivers\MDFSYSNT.SYS (Mediafour Corporation)
DRV - (datunidr) – C:\WINDOWS\system32\drivers\datunidr.sys (Gteko Ltd.)
DRV - (ialm) – C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (SynTP) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (BCM43XX) – C:\WINDOWS\system32\drivers\BCMWL5.SYS (Broadcom Corporation)
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (rismxdp) – C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (iaStor) – C:\WINDOWS\system32\drivers\iaStor.sys (Intel Corporation)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (NWADI) – C:\WINDOWS\system32\drivers\NWADIenum.sys (Novatel Wireless Inc)
DRV - (NWUSBPort2) – C:\WINDOWS\system32\drivers\nwusbser2.sys (Novatel Wireless Inc.)
DRV - (NWUSBPort) – C:\WINDOWS\system32\drivers\nwusbser.sys (Novatel Wireless Inc.)
DRV - (NWUSBModem) – C:\WINDOWS\system32\drivers\nwusbmdm.sys (Novatel Wireless Inc.)
DRV - (MDPMGRNT) – C:\WINDOWS\System32\drivers\MDPMGRNT.sys (Mediafour Corporation)
DRV - (Packet) – C:\WINDOWS\system32\drivers\packet.sys (SingleClick Systems)
DRV - (DXEC02) – C:\WINDOWS\system32\drivers\dxec02.sys (Knowles Acoustics)
DRV - (PTproct) – C:\Program Files\DellAutomatedPCTuneUp\GTAction\triggers\PTproct.sys (Gteko Ltd.)
DRV - (pnetmdm) – C:\WINDOWS\system32\drivers\pnetmdm.sys (June Fabrics Technology)
DRV - (DLADResM) – C:\WINDOWS\system32\DLA\DLADResM.SYS (Roxio)
DRV - (DLABMFSM) – C:\WINDOWS\system32\DLA\DLABMFSM.SYS (Roxio)
DRV - (DLAUDF_M) – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Roxio)
DRV - (DLAUDFAM) – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Roxio)
DRV - (DLAOPIOM) – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Roxio)
DRV - (DLABOIOM) – C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Roxio)
DRV - (DLAIFS_M) – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Roxio)
DRV - (DLAPoolM) – C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Roxio)
DRV - (DRVNDDM) – C:\WINDOWS\system32\drivers\DRVNDDM.SYS (Roxio)
DRV - (DLACDBHM) – C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Roxio)
DRV - (DLARTL_M) – C:\WINDOWS\system32\drivers\DLARTL_M.SYS (Roxio)
DRV - (DRVMCDB) – C:\WINDOWS\System32\Drivers\DRVMCDB.SYS (Sonic Solutions)
DRV - (SymSnap) – C:\WINDOWS\System32\drivers\SymSnap.sys (StorageCraft)
DRV - (V2IMount) – C:\WINDOWS\System32\drivers\V2iMount.sys (Symantec Corporation)
DRV - (APPDRV) – C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS (Dell Inc)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\Hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (61883) – C:\WINDOWS\system32\drivers\61883.sys (Microsoft Corporation)
DRV - (Avc) – C:\WINDOWS\system32\drivers\avc.sys (Microsoft Corporation)
DRV - (MSDV) – C:\WINDOWS\system32\drivers\msdv.sys (Microsoft Corporation)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (Imagedrv) – C:\WINDOWS\system32\DRIVERS\imagedrv.sys (Ahead Software AG and its licensors)
DRV - (AnyDVD) – C:\WINDOWS\system32\drivers\AnyDVD.sys (SlySoft, Inc.)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (ENUM1394) – C:\WINDOWS\system32\drivers\enum1394.sys (Microsoft Corporation)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=0071211
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=0071211
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=0071211
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.newperspectivefilms.com/"
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1.6.2.63
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5.0.429
FF - prefs.js..extensions.enabledItems: [removed]:1.5.4
FF - prefs.js..extensions.enabledItems: [removed]:1.3.4
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {9458ca25-39fd-4ba8-9520-acc5c0d877b6}:1.6
FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.8
FF - prefs.js..extensions.enabledItems: [removed]:3.8.6
FF - prefs.js..extensions.enabledItems: {e968fc70-8f95-4ab9-9e79-304de2a71ee1}:0.7.2
FF - prefs.js..extensions.enabledItems: {b749fc7c-e949-447f-926c-3f4eed6accfe}:0.6.6
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: D:\Internet\avg\Firefox [2009/12/22 10:56:28 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{000a9d1c-beef-4f90-9363-039d445309b8}: C:\Program Files\Google\Google Gears\Firefox\ [2009/11/09 23:03:52 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: D:\Internet\java\lib\deploy\jqs\ff [2009/11/09 21:43:37 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: D:\Internet\Mozilla_Firefox\components [2010/07/31 12:50:03 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: D:\Internet\Mozilla_Firefox\plugins [2010/08/28 20:55:26 | 000,000,000 | —D | M]
[2010/04/28 23:42:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Mozilla\Extensions
[2010/04/28 23:42:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Mozilla\Extensions\[removed]
[2010/09/16 11:33:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Mozilla\Firefox\Profiles\ma0zn774.default\extensions
[2010/07/17 16:19:16 | 000,000,000 | —D | M] (OPML Support) – C:\Documents and Settings\Shrews\Application Data\Mozilla\Firefox\Profiles\ma0zn774.default\extensions\{9458ca25-39fd-4ba8-9520-acc5c0d877b6}
[2010/05/22 17:23:06 | 000,000,000 | —D | M] (Modify Headers) – C:\Documents and Settings\Shrews\Application Data\Mozilla\Firefox\Profiles\ma0zn774.default\extensions\{b749fc7c-e949-447f-926c-3f4eed6accfe}
[2009/07/01 00:33:46 | 000,000,000 | —D | M] (Web Developer) – C:\Documents and Settings\Shrews\Application Data\Mozilla\Firefox\Profiles\ma0zn774.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2010/04/14 01:42:03 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Documents and Settings\Shrews\Application Data\Mozilla\Firefox\Profiles\ma0zn774.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2010/05/22 16:07:35 | 000,000,000 | —D | M] (User Agent Switcher) – C:\Documents and Settings\Shrews\Application Data\Mozilla\Firefox\Profiles\ma0zn774.default\extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}
[2010/05/18 19:51:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Mozilla\Firefox\Profiles\ma0zn774.default\extensions\[removed]
[2010/08/28 20:47:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Mozilla\Firefox\Profiles\ma0zn774.default\extensions\[removed]
O1 HOSTS File: ([2004/08/04 06:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - D:\Internet\avg\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AcroIEToolbarHelper Class) - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Text\Acrobat_6_prof\Acrobat\AcroIEFavClient.dll ()
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Internet\java\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Google Gears Helper) - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.33.0\gears.dll (Google Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - D:\Internet\java\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (ZoneAlarm Spy Blocker BHO) - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL (ZoneAlarm)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Text\Acrobat_6_prof\Acrobat\AcroIEFavClient.dll ()
O3 - HKLM\..\Toolbar: (ZoneAlarm Spy Blocker) - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL (ZoneAlarm)
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Spy Blocker) - {F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL (ZoneAlarm)
O4 - HKLM..\Run: [{B179023B-6238-4499-8F26-CD73E9D90E0A}] C:\Program Files\Mediafour\MacDrive 7\MacDrive.exe (Mediafour Corporation)
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [AcronisTimounterMonitor] D:\System\blckarmorbackup\TimounterMonitor.exe (Seagate)
O4 - HKLM..\Run: [AVG8_TRAY] D:\Internet\avg\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BlackArmorBackupMonitor.exe] D:\System\blckarmorbackup\BlackArmorBackupMonitor.exe (Seagate)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [Seagate Scheduler2 Service] C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe (Seagate)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\Sigmatel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [ZoneAlarm Client] D:\Internet\ZoneAlarm\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [EPSON Artisan 50 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIFFA.EXE (SEIKO EPSON CORPORATION)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\FlashUtil10i_Plugin.exe (Adobe Systems, Inc.)
O4 - HKLM..\RunServices: [LicCtrl] C:\WINDOWS\mmfs.DLL ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Download all with Free Download Manager - D:\Internet\Free Download Manager\dlall.htm ()
O8 - Extra context menu item: Download selected with Free Download Manager - D:\Internet\Free Download Manager\dlselected.htm ()
O8 - Extra context menu item: Download video with Free Download Manager - D:\Internet\Free Download Manager\dlfvideo.htm ()
O8 - Extra context menu item: Download with Free Download Manager - D:\Internet\Free Download Manager\dllink.htm ()
O8 - Extra context menu item: E&xport; to Microsoft Excel - D:\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Gears; Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.33.0\gears.dll (Google Inc.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 192.168.1.254
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\Internet\avg\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Shrews\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Shrews\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 14:04:08 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{1c0c5865-2184-11df-a86e-001d09ad8627}\Shell\AutoRun\command - "" = G:\Setup.exe – File not found
O33 - MountPoints2\{1c0c5865-2184-11df-a86e-001d09ad8627}\Shell\Install\command - "" = G:\Setup.exe – File not found
O33 - MountPoints2\{4e66e8fb-39bc-11df-a877-001d09ad8627}\Shell\AutoRun\command - "" = H:\MI.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.dfscacm - C:\WINDOWS\System32\dfscacm.dll ()
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.dfsc - C:\WINDOWS\System32\dfsc.dll ()
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.dvsd - C:\WINDOWS\System32\pdvcodec.dll (Matsushita Electric Industrial Co., Ltd.)
Drivers32: vidc.hdyc - D:\video\blackmagic codecs\BMDCodecLib.dll (Blackmagic Design)
Drivers32: VIDC.I420 - C:\WINDOWS\System32\i420vfw.dll (www.helixcommunity.org)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.MP42 - C:\WINDOWS\System32\MPG4C32.DLL (Microsoft Corporation)
Drivers32: VIDC.MPG4 - C:\WINDOWS\System32\MPG4C32.DLL (Microsoft Corporation)
Drivers32: vidc.r210 - D:\video\blackmagic codecs\BMDCodecLib.dll (Blackmagic Design)
Drivers32: vidc.v210 - D:\video\blackmagic codecs\BMDCodecLib.dll (Blackmagic Design)
Drivers32: VIDC.WMV3 - C:\WINDOWS\System32\wmv9vcm.dll (Microsoft Corporation)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\WINDOWS\System32\yv12vfw.dll (www.helixcommunity.org)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16620634377289728)
========== Files/Folders - Created Within 30 Days ==========
[2010/09/23 13:31:33 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Shrews\Desktop\OTL.exe
[2010/08/30 00:49:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Shrews\Desktop\logos
[2010/08/30 00:13:20 | 000,000,000 | —D | C] – C:\Documents and Settings\Shrews\Local Settings\Application Data\Sony
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/09/23 13:31:34 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Shrews\Desktop\OTL.exe
[2010/09/23 13:10:10 | 016,252,928 | —- | M] () – C:\Documents and Settings\Shrews\ntuser.dat
[2010/09/23 13:06:31 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/09/23 11:42:39 | 065,173,360 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/09/21 09:49:17 | 000,528,020 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/09/21 09:49:17 | 000,445,938 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/09/21 09:49:17 | 000,072,978 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/09/20 15:40:43 | 000,721,675 | —- | M] () – C:\Documents and Settings\Shrews\Desktop\Common_Gain_Stage.pdf
[2010/09/17 13:59:07 | 000,000,004 | —- | M] () – C:\WINDOWS\Twain001.Mtx
[2010/09/17 13:59:03 | 000,000,156 | —- | M] () – C:\WINDOWS\Twunk001.MTX
[2010/09/17 13:33:11 | 000,000,256 | —- | M] () – C:\WINDOWS\System32\pool.bin
[2010/09/17 13:00:05 | 002,285,676 | —- | M] () – C:\Documents and Settings\Shrews\Desktop\teesandtapes.pdf
[2010/09/15 21:51:32 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/09/15 21:51:00 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/09/15 21:50:39 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/09/15 21:50:36 | 2137,038,848 | -HS- | M] () – C:\hiberfil.sys
[2010/09/15 21:49:50 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Shrews\ntuser.ini
[2010/09/15 15:05:49 | 001,749,464 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/09/15 12:44:34 | 000,103,392 | —- | M] () – C:\Documents and Settings\Shrews\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/09/10 05:28:52 | 000,078,668 | -H– | M] () – C:\WINDOWS\System32\mlfcache.dat
[2010/09/06 23:34:30 | 000,003,584 | —- | M] () – C:\Documents and Settings\Shrews\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/01 00:24:12 | 000,019,968 | —- | M] () – C:\Documents and Settings\Shrews\Desktop\Blog.doc
[2010/08/28 21:22:04 | 000,000,202 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/08/28 18:08:16 | 000,140,752 | —- | M] () – C:\Documents and Settings\Shrews\Desktop\GBS.pdf
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/09/23 13:28:34 | 000,721,675 | —- | C] () – C:\Documents and Settings\Shrews\Desktop\Common_Gain_Stage.pdf
[2010/09/17 13:00:04 | 002,285,676 | —- | C] () – C:\Documents and Settings\Shrews\Desktop\teesandtapes.pdf
[2010/09/15 21:50:36 | 2137,038,848 | -HS- | C] () – C:\hiberfil.sys
[2010/09/01 00:24:11 | 000,019,968 | —- | C] () – C:\Documents and Settings\Shrews\Desktop\Blog.doc
[2010/08/28 18:08:15 | 000,140,752 | —- | C] () – C:\Documents and Settings\Shrews\Desktop\GBS.pdf
[2010/08/15 15:43:30 | 000,003,584 | —- | C] () – C:\Documents and Settings\Shrews\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/10 13:59:30 | 000,025,713 | —- | C] () – C:\WINDOWS\CSTBox.INI
[2010/07/23 11:47:22 | 000,024,287 | —- | C] () – C:\Documents and Settings\Shrews\Application Data\PamelaPCR_EXTRA_4_6_0_1_4C49C79A.zip
[2010/07/09 12:52:52 | 000,021,188 | —- | C] () – C:\Documents and Settings\Shrews\Application Data\PamelaPCR_EXTRA_4_6_0_1_4C3761F3.zip
[2010/07/02 16:55:16 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2010/07/02 16:52:17 | 000,000,025 | —- | C] () – C:\WINDOWS\EPART50.ini
[2010/06/24 20:19:02 | 002,463,976 | —- | C] () – C:\WINDOWS\System32\NPSWF32.dll
[2010/05/29 16:27:29 | 000,000,945 | —- | C] () – C:\WINDOWS\vista32.ini
[2010/05/29 16:01:08 | 000,000,118 | —- | C] () – C:\WINDOWS\ppdrv.ini
[2010/05/29 15:51:10 | 000,079,360 | —- | C] () – C:\WINDOWS\u1200_32.dll
[2010/05/29 15:51:10 | 000,006,932 | —- | C] () – C:\WINDOWS\System32\glscan.sys
[2010/05/29 15:51:09 | 000,030,208 | —- | C] () – C:\WINDOWS\uxmail32.dll
[2010/05/29 15:51:08 | 000,068,608 | —- | C] () – C:\WINDOWS\vufile32.dll
[2010/05/29 15:51:07 | 000,076,260 | —- | C] () – C:\WINDOWS\System32\drivers\udnt.sys
[2010/05/06 11:44:14 | 000,023,333 | —- | C] () – C:\Documents and Settings\Shrews\Application Data\PamelaPCR_EXTRA_4_6_0_1_4BE2F1DE.zip
[2010/05/05 13:44:21 | 000,020,017 | —- | C] () – C:\Documents and Settings\Shrews\Application Data\PamelaPCR_EXTRA_4_6_0_1_4BE1BC85.zip
[2010/04/18 12:14:54 | 000,033,824 | —- | C] () – C:\WINDOWS\System32\drivers\oreans32.sys
[2009/09/08 17:10:57 | 000,001,025 | —- | C] () – C:\WINDOWS\System32\clauth2.dll
[2009/09/08 17:10:57 | 000,001,025 | —- | C] () – C:\WINDOWS\System32\clauth1.dll
[2009/09/08 17:10:56 | 000,001,025 | —- | C] () – C:\WINDOWS\System32\sysprs7.dll
[2009/06/03 18:40:58 | 000,175,104 | —- | C] () – C:\WINDOWS\System32\RemoteControl.dll
[2009/04/09 21:23:03 | 000,000,347 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2009/03/30 15:41:48 | 000,000,212 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2009/03/03 13:38:58 | 000,027,211 | —- | C] () – C:\Documents and Settings\Shrews\Application Data\Personal Address Book.ADR
[2008/10/20 23:16:02 | 000,796,048 | —- | C] () – C:\WINDOWS\System32\libeay32_0.9.6l.dll
[2008/10/20 21:55:13 | 000,036,483 | —- | C] () – C:\Documents and Settings\Shrews\Application Data\Comma Separated Values (Windows).ADR
[2008/10/20 21:55:13 | 000,000,020 | —- | C] () – C:\Documents and Settings\Shrews\Application Data\Final Draft Tagger Preferences
[2008/10/18 01:16:00 | 000,000,012 | —- | C] () – C:\WINDOWS\pol32.ini
[2008/10/15 16:26:22 | 000,009,728 | —- | C] () – C:\WINDOWS\System32\BASSMOD.dll
[2008/07/04 12:51:57 | 000,001,359 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2008/06/28 17:32:09 | 000,408,576 | —- | C] () – C:\WINDOWS\System32\Smab.dll
[2008/06/28 17:32:04 | 000,027,648 | —- | C] () – C:\WINDOWS\System32\AVSredirect.dll
[2008/06/28 15:08:13 | 000,027,648 | -HS- | C] () – C:\WINDOWS\System32\Smab0.dll
[2008/04/17 00:41:55 | 000,000,040 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\.zreglib
[2008/04/10 16:55:37 | 000,000,127 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2008/04/10 16:45:21 | 000,059,904 | —- | C] () – C:\WINDOWS\System32\zlib1.dll
[2008/03/23 21:51:05 | 000,000,032 | —- | C] () – C:\Documents and Settings\All Users\Application Data\ezsid.dat
[2008/02/20 00:55:30 | 000,000,202 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2008/01/20 14:12:49 | 000,000,026 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\.119889580931711767808769176
[2008/01/20 14:10:06 | 000,000,021 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\.24554863501262644635642126105
[2008/01/09 19:02:39 | 000,765,952 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2008/01/09 19:02:38 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2007/12/29 00:10:34 | 000,039,424 | —- | C] () – C:\WINDOWS\mmfs.dll
[2007/12/28 19:52:38 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/12/27 20:40:18 | 000,013,840 | —- | C] () – C:\WINDOWS\System32\wnaspi32.dll
[2007/12/27 20:37:04 | 003,870,720 | —- | C] () – C:\WINDOWS\System32\qt-mt323.dll
[2007/12/11 14:40:40 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2007/12/11 14:32:59 | 000,000,859 | —- | C] () – C:\WINDOWS\{0240BDFB-2995-4A3F-8C96-18D41282B716}_WiseFW.ini
[2007/12/11 14:31:06 | 000,198,144 | —- | C] () – C:\WINDOWS\System32\_psisdecd.dll
[2007/12/11 14:30:39 | 000,056,056 | —- | C] () – C:\WINDOWS\System32\DLAAPI_W.DLL
[2007/12/11 14:30:39 | 000,000,120 | —- | C] () – C:\WINDOWS\wininit.ini
[2007/12/11 14:22:53 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\preflib.dll
[2007/12/11 14:22:51 | 000,757,760 | —- | C] () – C:\WINDOWS\System32\bcm1xsup.dll
[2007/12/11 13:59:38 | 000,910,304 | —- | C] () – C:\WINDOWS\System32\igmedkrn.dll
[2007/12/11 13:59:38 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4831.dll
[2007/12/11 13:59:36 | 000,016,480 | —- | C] () – C:\WINDOWS\System32\rixdicon.dll
[2007/12/11 13:57:48 | 000,001,118 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2007/11/29 17:30:28 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2007/11/29 17:28:24 | 000,000,416 | —- | C] () – C:\WINDOWS\System32\dtu100.dll.manifest
[2007/11/29 17:28:24 | 000,000,416 | —- | C] () – C:\WINDOWS\System32\dpl100.dll.manifest
[2007/11/28 16:52:32 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2007/10/12 02:11:58 | 000,066,482 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2007/10/11 19:59:24 | 000,025,624 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2006/11/07 05:25:58 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2006/09/17 00:36:50 | 000,520,192 | —- | C] () – C:\WINDOWS\System32\CddbPlaylist2Roxio.dll
[2006/09/17 00:36:50 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\CddbFileTaggerRoxio.dll
[2005/07/08 23:07:46 | 000,007,168 | —- | C] () – C:\WINDOWS\System32\dfscacm.dll
[2005/07/08 23:07:44 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\dfsc.dll
[2004/08/10 14:12:05 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/10 14:01:18 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2003/01/07 10:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[1999/01/27 14:39:06 | 000,065,024 | —- | C] () – C:\WINDOWS\System32\indounin.dll
[1997/06/13 08:56:08 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\Iyvu9_32.dll
========== LOP Check ==========
[2010/02/27 14:49:22 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Acronis
[2010/07/02 17:18:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EPSON
[2008/01/20 14:10:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Final Draft
[2009/01/16 08:54:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FreeDownloadManager.ORG
[2007/12/28 01:21:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MailFrontier
[2008/06/28 15:21:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Mediafour
[2009/09/08 17:10:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Minnetonka Audio Software
[2010/05/04 14:46:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Research In Motion
[2010/02/27 15:11:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Seagate
[2007/12/11 14:33:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SingleClick Systems
[2008/04/17 00:42:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SlySoft
[2008/09/03 18:24:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sony
[2007/12/11 14:37:07 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2010/05/18 23:07:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sync App Settings
[2010/04/09 16:44:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/05/18 21:04:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TrueCrypt
[2009/05/30 21:05:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2008/10/20 21:56:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Alien Skin
[2010/08/07 18:26:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\AMPSoft
[2009/06/15 00:47:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Artisteer
[2010/05/13 21:33:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Blackberry Desktop
[2010/09/17 12:49:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Canon
[2009/06/13 13:58:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\ctpo
[2009/06/13 13:58:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\engadven
[2008/10/20 21:56:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Final Draft
[2008/10/20 21:56:04 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Flickr
[2009/11/15 00:33:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Foxit
[2010/02/25 14:43:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Foxit Software
[2009/08/05 10:07:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Free Download Manager
[2008/12/09 01:45:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Leadertech
[2009/05/18 20:45:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\LEAPS
[2009/05/24 15:56:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\MPEG Streamclip
[2009/03/03 01:00:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\NeoDownloader
[2008/10/20 21:55:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Opera
[2009/11/06 01:26:05 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Pamela
[2009/05/18 20:11:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Pegasys Inc
[2008/10/20 21:55:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Publish Providers
[2010/05/14 00:29:57 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Research In Motion
[2010/02/27 15:15:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Seagate
[2009/02/06 13:54:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Smith Micro
[2008/10/20 21:55:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Sony
[2008/10/20 21:55:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Sony Setup
[2010/05/18 23:07:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Sync App Settings
[2008/10/20 21:55:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\Thunderbird
[2010/05/19 00:29:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\TrueCrypt
[2010/08/28 20:33:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\uTorrent
[2008/10/20 21:55:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Shrews\Application Data\W Photo Studio Viewer
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2008/12/31 14:07:07 | 000,000,000 | —- | M] () – C:\asoutput.log
[2004/08/10 14:04:08 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2009/11/08 01:33:37 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010/05/21 11:20:12 | 000,000,281 | -HS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2009/11/09 15:48:54 | 000,015,036 | —- | M] () – C:\ComboFix.txt
[2004/08/10 14:04:08 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2007/12/11 14:02:42 | 000,006,843 | RH– | M] () – C:\dell.sdr
[2010/09/15 21:50:36 | 2137,038,848 | -HS- | M] () – C:\hiberfil.sys
[2007/12/27 18:57:09 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2004/08/10 14:04:08 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2009/12/09 21:41:38 | 000,006,508 | —- | M] () – C:\JavaRa.log
[2006/05/05 13:47:34 | 000,090,792 | —- | M] () – C:\keyfingers.jpg
[2008/04/03 00:43:27 | 000,023,224 | —- | M] () – C:\keyfingers_dell.jpg
[2009/05/09 14:31:09 | 000,300,751 | —- | M] () – C:\log_fs.log
[2004/08/10 14:04:08 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2004/08/04 06:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2004/08/04 06:00:00 | 000,250,032 | RHS- | M] () – C:\ntldr
[2009/04/04 17:48:40 | 000,001,760 | —- | M] () – C:\Rescued document 1.txt
[2009/04/04 17:48:34 | 000,002,741 | —- | M] () – C:\Rescued document.txt
[2009/11/06 12:00:26 | 000,007,196 | —- | M] () – C:\RootRepeal report 11-06-09 (12-00-26).txt
[2010/04/14 00:41:39 | 000,004,096 | -HS- | M] () – C:\VSNAP.IDX
[2008/04/09 18:38:22 | 000,000,252 | —- | M] () – C:\VundoFix.txt
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2004/08/10 14:03:42 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/03/28 13:57:34 | 000,274,944 | —- | M] (Hewlett-Packard Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp5ha.dll
[2003/06/18 16:31:48 | 000,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\msonpppr.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
[2007/05/17 21:32:50 | 000,326,742 | —- | M] () – C:\WINDOWS\Vostro_NB_1280x864_01.jpg
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2004/08/10 13:56:48 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2004/08/10 13:56:46 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2004/08/10 13:56:46 | 000,872,448 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2004/08/10 14:04:12 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2007/12/25 14:04:38 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Shrews\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2004/08/10 14:08:38 | 000,000,079 | —- | M] () – C:\Documents and Settings\Shrews\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2010/09/23 13:31:34 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Shrews\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-07-26 16:43:20
========== Alternate Data Streams ==========
@Alternate Data Stream - 60 bytes -> C:\WINDOWS\System32\ssprs.tgz:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\WINDOWS\System32\lsprst7.tgz:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Documents and Settings\Shrews\Desktop\ROLEX AWARDS.doc:AFP_AfpInfo
@Alternate Data Stream - 60 bytes -> C:\Documents and Settings\Shrews\Desktop\cool_money.txt:AFP_AfpInfo
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 113 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:62E2D794
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:888AFB86
< End of report >
OTL Extras logfile created on: 9/23/2010 1:32:31 PM - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\Shrews\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 57.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): F:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 14.51 Gb Total Space | 5.36 Gb Free Space | 36.97% Space Free | Partition Type: NTFS
Drive D: | 6.55 Gb Total Space | 1.72 Gb Free Space | 26.32% Space Free | Partition Type: NTFS
Drive E: | 6.04 Gb Total Space | 1.44 Gb Free Space | 23.77% Space Free | Partition Type: NTFS
Drive F: | 82.11 Gb Total Space | 53.13 Gb Free Space | 64.70% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: GBS-LAPTOP
Current User Name: Shrews
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – D:\Internet\Mozilla_Firefox\firefox.exe (Mozilla Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – D:\Internet\Mozilla_Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
https [open] – "D:\Internet\Mozilla_Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
jsfile – "D:\graphics\dreamweaver\Dreamweaver 8\dreamweaver.exe" "%1" (Macromedia, Inc.)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring" = 1
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"10421:UDP" = 10421:UDP:*:Enabled:SingleClick Discovery Protocol
"10426:UDP" = 10426:UDP:*:Enabled:SingleClick ICC
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Dell Network Assistant\ezi_hnm2.exe" = C:\Program Files\Dell Network Assistant\ezi_hnm2.exe:*:Enabled:Dell Network Assistant – (SingleClick Systems)
"C:\Program Files\Dell\MediaDirect\PCMService.exe" = C:\Program Files\Dell\MediaDirect\PCMService.exe:*:Enabled:CyberLink PowerCinema Resident Program – (CyberLink Corp.)
"D:\Internet\avg\avgupd.exe" = D:\Internet\avg\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
"D:\Internet\utorrent\uTorrent.exe" = D:\Internet\utorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\Program Files\Bonjour\mDNSResponder.exe" = C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour – File not found
"C:\WINDOWS\system32\ZoneLabs\vsmon.exe" = C:\WINDOWS\system32\ZoneLabs\vsmon.exe:*:Enabled:vsmon – (Check Point Software Technologies LTD)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0240BDFB-2995-4A3F-8C96-18D41282B716}" = Dell Network Assistant
"{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime
"{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
"{06A1BE8A-4CA4-4A39-B9E4-E815AA8FE05C}" = Sony Noise Reduction Plug-In 2.0h
"{0837A661-FEC3-48B3-876C-91E7D32048A9}" = Macromedia Dreamweaver 8
"{0D2E80C8-0875-43EB-9623-47118E2DFBCA}" = Quicken 2007
"{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
"{121634B0-2F4B-11D3-ADA3-00C04F52DD52}" = Windows Installer Clean Up
"{13515135-48BB-4184-8C1F-2FAE0138E200}" = TBS WMP Plug-in
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{190D0C6E-C8A7-4019-8FB5-FD041EC1F2D2}" = Mobile Broadband Drivers
"{236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 18
"{26D77DBB-E7BF-4B2F-8C02-E731F2E224C0}_is1" = JoomlaPack Native Tools 2009.3
"{2715D1D6-2B81-4DD5-A9DC-6EFF4D5E0993}" = Ahead Nero Burning Rom PlugIn Pack 2.0.2 by MadHacker2k4
"{2BD5C305-1B27-4D41-B690-7A61172D2FEB}" = Macromedia Flash 8
"{2F28B3C9-2C89-4206-8B33-8ADC9577C49B}" = Scan
"{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}" = Roxio Drag-to-Disc
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{31228E31-2BFF-11D2-8866-00805F0D9D40}" = QPST
"{32F720F5-2D0D-4245-A2B0-9EB3CECF8101}" = Norton Ghost 10.0
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{40A594D0-1490-4979-9382-D2B764F949C6}" = BlackBerry® Media Sync
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4AEA9A23-D627-4699-8A0F-FC474308C2E6}" = Sony Sound Forge 9.0
"{4C24A8C1-7CFA-4650-AF15-732F5BD7B46D}" = Macromedia Fireworks 8
"{5546CDB5-2CE2-498B-B059-5B3BF81FC41F}" = Macromedia Extension Manager
"{5BACA8C1-909F-4AA4-90EB-6CAE5241FA96}" = MacDrive 7
"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype™ 3.6
"{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{62230596-37E5-4618-A329-0D21F529A86F}" = Browser Address Error Redirector
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{786C5747-1033-0000-B58E-000000000001}" = Adobe Stock Photos 1.0
"{78D62D17-D970-42DA-B8CF-5E5576293B33}" = Final Draft 7
"{7B4174E8-FE92-4269-808A-3B8D116D9538}" = Advanced Security for Outlook
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{7C9AD221-994C-45B2-B46D-26F5735158CF}" = Sony Vegas Pro 8.0
"{7DD9A065-2C86-4A9F-A5FF-796EC1B99DCA}" = AnswerWorks 4.0 Runtime - English
"{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
"{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}" = Roxio Creator BDAV Plugin
"{885A63EA-382B-4DD4-A755-14809B8557D6}" = Macromedia Flash Player 8
"{88908767-B7AD-4b0d-ACBC-FBCCF2761D31}" = HP Photosmart All-In-One Software 9.0
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8BF2C401-02CE-424D-BC26-6C4F9FB446B6}" = Macromedia Flash 8 Video Encoder
"{8D55AC33-2CB4-4A4D-93A9-F5C76124BBC3}" = BlackBerry Device Software v5.0.0 for the BlackBerry 8530 smartphone
"{8EDBA74D-0686-4C99-BFDD-F894678E5B39}" = Adobe Common File Installer
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{945AC98B-3DC8-45BE-BAE0-22CEEE37A103}" = Logitech QuickCam
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{9BDEF074-020E-458D-ADC5-8FF68E0C9B56}" = OutlookAddinSetup
"{9C6978E8-B6D0-4AB7-A7A0-D81A74FBF745}" = MediaDirect
"{9DF6EC22-733E-4EDC-AC88-54CAD4BF4E7B}" = BlackArmor Backup
"{A040AC77-C1AA-4CC9-8931-9F648AF178F6}" = VC 9.0 Runtime
"{A14F7508-B784-40B8-B11A-E0E2EEB7229F}" = Adobe Premiere Pro 1.5
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A429C2AE-EBF1-4F81-A221-1C115CAADDAD}" = QuickTime
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = SigmaTel Audio
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-1033-0000-7760-000000000001}" = Adobe Acrobat 6.0 Professional
"{AF7FC1CA-79DF-43c3-90A3-33EFEB9294CE}" = AIO_Scan
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B74D4E10-1033-0000-0000-000000000001}" = Adobe Bridge 1.0
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BC2FE771-EDBE-3087-A676-2B6C45A2BF7E}" = Google Gears
"{BCE46757-7674-4416-BEDB-68205A60409E}" = Canon CanoScan Toolbox 4.1
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C13AF9C7-8E06-4354-B629-DF6192CE4A66}" = PANTECH UM175 Driver
"{C5074CC4-0E26-4716-A307-960272A90040}" = QuickSet
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE
"{C99C0593-3B48-41D9-B42F-6E035B320449}" = Broadcom Management Programs
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240B8}" = WinZip 12.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE86E2F5-850C-4207-94A3-A58D647B1733}" = BlackBerry Desktop Software 5.0.1
"{D050D7362D214723AD585B541FFB6C11}" = DivX Content Uploader
"{D16A31F9-276D-4968-A753-FFEAC56995D0}" = Epson Print CD
"{D1B5E9C8-4CCF-44E3-87D6-7C00D7DA5370}" = IntelliSonic Speech Enhancement
"{D26F7C78-E2D7-49AB-8E64-53CB8AE99074}" = XDCAM EX Clip Browser
"{D639085F-4B6E-4105-9F37-A0DBB023E2FB}" = Roxio MyDVD DE
"{D6E4E5D6-7693-4BB4-95BA-21F38FAFEE90}" = Safari
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E28750A2-45F2-4b63-99F7-9F81A94B1E2D}" = PS_AIO_Software_min
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E3BFEE55-39E2-4BE0-B966-89FE583822C1}" = Dell Support Center (Support Software)
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{E76CDDCE-EFC0-4FE5-9972-9489CE49AA55}_is1" = NeoDownloader 2.2
"{E9787678-1033-0000-8E67-000000000001}" = Adobe Help Center 1.0
"{E9C18EBD-85BE-47D0-AA73-3FEDCC976B04}" = Toolbox
"{ED80F174-B621-4B8F-BBB9-3E031A59555A}" = TMPGEnc 4.0 XPress
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F5A6583A-3051-45ED-BE87-10CF079CB6B4}" = Blackmagic Codecs
"{F63A3748-B93D-4360-9AD4-B064481A5C7B}" = Modem Diagnostic Tool
"{FA61D601-A0FC-48BD-AE7A-54946BCD7FB6}_is1" = BitPim 1.0.6
"{FE34691C-4298-4667-9758-D7F534DD0B94}" = Dell Automated PC TuneUp
"7-Zip" = 7-Zip 4.65
"ABC Amber vCard Converter" = ABC Amber vCard Converter
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}" = Adobe Photoshop CS2
"Allway Sync_is1" = Allway Sync version 10.3.8
"AMP Font Viewer" = AMP Font Viewer
"AnyDVD" = AnyDVD
"AVG8Uninstall" = AVG Free 8.5
"BBE Sonic Maximizer Plugin" = BBE Sonic Maximizer Plugin
"BlackBerry_{CE86E2F5-850C-4207-94A3-A58D647B1733}" = BlackBerry Desktop Software 5.0.1
"Blow Up" = Alien Skin Blow Up
"Broadcom 802.11b Network Adapter" = Dell Wireless WLAN Card
"CCleaner" = CCleaner (remove only)
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV;_2C06&SUBSYS;_14F1000F" = Conexant HDA D330 MDC V.92 Modem
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"DebugMode FrameServer" = DebugMode FrameServer
"Easy Duplicate Finder_is1" = Easy Duplicate Finder v. 2.2.1
"EPSON Artisan 50 Series" = EPSON Artisan 50 Series Printer Uninstall
"EPSON Printer and Utilities" = EPSON Printer Software
"ERUNT_is1" = ERUNT 1.1j
"Exposure 2" = Alien Skin Exposure 2
"FileZilla" = FileZilla (remove only)
"Flickr Uploadr" = Flickr Uploadr 3.0.5
"Foxit PDF Editor" = Foxit PDF Editor
"Foxit Reader" = Foxit Reader
"Free Download Manager_is1" = Free Download Manager 3.0
"FriendBlasterPro_is1" = FriendBlasterPro
"HardlinkShellExt" = Link Shell Extension
"HDMI" = Intel® Graphics Media Accelerator Driver
"ie7" = Windows Internet Explorer 7
"InstallShield_{13515135-48BB-4184-8C1F-2FAE0138E200}" = TBS WMP Plug-in
"IrfanView" = IrfanView (remove only)
"LiveReg" = LiveReg (Symantec Corporation)
"lvdrivers_11.50" = Logitech QuickCam Driver Package
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Moleskinsoft Clone Remover 3.8_is1" = Moleskinsoft Clone Remover 3.8
"Mozilla Firefox (3.6.8)" = Mozilla Firefox (3.6.8)
"Nero - Burning Rom!UninstallKey" = Nero 6 Ultra Edition
"NeroVision!UninstallKey" = Nero Digital
"Pamela" = Pamela Pro 4.5
"PandoraSaver (standalone)_is1" = PandoraSaver 1.008e (standalone)
"PdaNet_is1" = PdaNet for BlackBerry 1.30
"Picasa 3" = Picasa 3
"SpywareBlaster_is1" = SpywareBlaster 4.2
"SUPER ©" = SUPER © Version 2008.bld.30 (Mar 22, 2008)
"SynTPDeinstKey" = Dell Touchpad
"The Rosetta Stone" = The Rosetta Stone
"TrueCrypt" = TrueCrypt
"Tweak UI 2.10" = Tweak UI
"VirtualCloneDrive" = VirtualCloneDrive
"Web Album Maker" = Web Album Maker 2.20
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinRAR archiver" = WinRAR archiver
"WinZip" = WinZip
"xampp" = XAMPP 1.7.1
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"Xvid_is1" = Xvid 1.1.3 final uninstall
"ZoneAlarm" = ZoneAlarm
"ZoneAlarmSB Uninstall" = ZoneAlarm Spy Blocker
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 9/22/2010 11:47:10 PM | Computer Name = GBS-LAPTOP | Source = Google Update | ID = 20
Description =
Error - 9/23/2010 12:06:30 AM | Computer Name = GBS-LAPTOP | Source = Google Update | ID = 20
Description =
Error - 9/23/2010 12:47:09 AM | Computer Name = GBS-LAPTOP | Source = Google Update | ID = 20
Description =
Error - 9/23/2010 1:06:29 AM | Computer Name = GBS-LAPTOP | Source = Google Update | ID = 20
Description =
Error - 9/23/2010 1:47:09 AM | Computer Name = GBS-LAPTOP | Source = Google Update | ID = 20
Description =
Error - 9/23/2010 2:06:28 AM | Computer Name = GBS-LAPTOP | Source = Google Update | ID = 20
Description =
Error - 9/23/2010 12:40:47 PM | Computer Name = GBS-LAPTOP | Source = Google Update | ID = 20
Description =
Error - 9/23/2010 1:06:35 PM | Computer Name = GBS-LAPTOP | Source = Google Update | ID = 20
Description =
Error - 9/23/2010 1:43:44 PM | Computer Name = GBS-LAPTOP | Source = Google Update | ID = 20
Description =
Error - 9/23/2010 2:06:30 PM | Computer Name = GBS-LAPTOP | Source = Google Update | ID = 20
Description =
[ System Events ]
Error - 9/15/2010 7:04:49 PM | Computer Name = GBS-LAPTOP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
Error - 9/15/2010 7:05:26 PM | Computer Name = GBS-LAPTOP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 9/15/2010 7:06:18 PM | Computer Name = GBS-LAPTOP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 9/15/2010 7:06:27 PM | Computer Name = GBS-LAPTOP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 9/15/2010 7:06:27 PM | Computer Name = GBS-LAPTOP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
Error - 9/15/2010 10:49:48 PM | Computer Name = GBS-LAPTOP | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 9/15/2010 10:52:30 PM | Computer Name = GBS-LAPTOP | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the LicCtrl Service service
to connect.
Error - 9/15/2010 10:52:30 PM | Computer Name = GBS-LAPTOP | Source = Service Control Manager | ID = 7000
Description = The LicCtrl Service service failed to start due to the following error:
%%1053
Error - 9/20/2010 2:33:48 AM | Computer Name = GBS-LAPTOP | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.1.105 on
the Network Card with network address 001E8C317C52.
Error - 9/22/2010 3:43:41 PM | Computer Name = GBS-LAPTOP | Source = ipnathlp | ID = 32003
Description = The Network Address Translator (NAT) was unable to request an operation
of
the kernel-mode translation module. This may indicate misconfiguration, insufficient
resources, or an internal error. The data is the error code.
< End of report >