pokey23
Topic Starter
Hello my pc doesn't want to work with the internet very well. Can you check out my scans logs below? I am using win xp pro with all the latest updates. with 1 gig of ram. see the OTL scans below Thank You
OTL logfile created on: 9/28/2010 11:34:05 AM - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\Larry Van Sweden\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 67.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 27.59 Gb Free Space | 74.06% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: LARRY-DD246AB59
Current User Name: Larry Van Sweden
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Larry Van Sweden\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\IncrediMail\Bin\IncMail.exe (IncrediMail, Ltd.)
PRC - C:\Program Files\IncrediMail\Bin\ImApp.exe (IncrediMail, Ltd.)
PRC - C:\Program Files\Carbonite\Carbonite Backup\CarboniteService.exe (Carbonite, Inc. (www.carbonite.com))
PRC - C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe (Carbonite, Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\VTTimer.exe (S3 Graphics, Inc.)
PRC - C:\WINDOWS\system32\Brmfrmps.exe (Brother Industries, Ltd.)
PRC - C:\WINDOWS\system32\brsvc01a.exe (brother Industries Ltd)
PRC - C:\WINDOWS\system32\brss01a.exe (brother Industries Ltd)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Larry Van Sweden\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (CarboniteService) – C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe (Carbonite, Inc. (www.carbonite.com))
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (brmfrmps) – C:\WINDOWS\System32\Brmfrmps.exe (Brother Industries, Ltd.)
SRV - (Brother XP spl Service) – C:\WINDOWS\system32\brsvc01a.exe (brother Industries Ltd)
========== Driver Services (SafeList) ==========
DRV - (cpuz132) – C:\DOCUME~1\LARRYV~1\LOCALS~1\Temp\cpuz132\cpuz132_x32.sys File not found
DRV - (avipbb) – C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) – C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (VX6000) – C:\WINDOWS\system32\drivers\VX6000Xp.sys (Microsoft Corporation
)
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (RT80x86) – C:\WINDOWS\system32\drivers\rt2860.sys (Ralink Technology, Corp.)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (RT73) – C:\WINDOWS\system32\drivers\rt73.sys (Ralink Technology, Corp.)
DRV - (BrScnUsb) – C:\WINDOWS\system32\drivers\BrScnUsb.sys (Brother Industries Ltd.)
DRV - (USR1806) – C:\WINDOWS\system32\drivers\USR1806.SYS (U.S. Robotics, Inc.)
DRV - (SetupNT) – C:\WINDOWS\system32\SetupNT.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.charter.net/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: ([2006/02/28 08:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [Carbonite Backup] C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe (Carbonite, Inc.)
O4 - HKLM..\Run: [VTTimer] C:\WINDOWS\System32\VTTimer.exe (S3 Graphics, Inc.)
O4 - HKCU..\Run: [DW6] C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe (The Weather Channel Interactive, Inc.)
O4 - HKCU..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe (IncrediMail, Ltd.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\Larry Van Sweden\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/08/10 16:12:06 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)
========== Files/Folders - Created Within 30 Days ==========
[2010/09/28 11:30:55 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Larry Van Sweden\Desktop\OTL.exe
[2010/09/27 16:15:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Larry Van Sweden\Application Data\GetRightToGo
[2010/09/27 11:30:47 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Larry Van Sweden\Recent
[2010/09/17 12:56:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Larry Van Sweden\Application Data\Avira
[2010/09/17 12:54:15 | 000,028,520 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\ssmdrv.sys
[2010/09/17 12:54:12 | 000,124,784 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avipbb.sys
[2010/09/17 12:54:12 | 000,060,936 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntflt.sys
[2010/09/17 12:54:12 | 000,045,416 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntdd.sys
[2010/09/17 12:54:12 | 000,022,360 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntmgr.sys
[2010/09/17 12:54:08 | 000,000,000 | —D | C] – C:\Program Files\Avira
[2010/09/17 12:54:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Avira
[2010/09/17 12:00:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Larry Van Sweden\Local Settings\Application Data\Threat Expert
[2010/09/17 11:00:35 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/09/17 10:55:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\PC Tools
[2010/09/14 14:19:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Larry Van Sweden\Application Data\OpenOffice.org
[2010/09/14 13:34:16 | 000,000,000 | —D | C] – C:\Program Files\JRE
[2010/09/14 13:33:39 | 000,000,000 | —D | C] – C:\Program Files\OpenOffice.org 3
[2010/09/14 13:32:32 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/09/14 13:32:32 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/09/14 13:32:32 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/09/13 18:49:02 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/09/13 18:49:02 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/09/11 13:50:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Larry Van Sweden\My Documents\My WinZip Files
[2010/09/11 13:46:08 | 000,000,000 | —D | C] – C:\Documents and Settings\Larry Van Sweden\Local Settings\Application Data\WinZip
[2010/09/11 13:45:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\WinZip
[2010/09/11 13:45:01 | 000,000,000 | —D | C] – C:\Program Files\WinZip
[2010/09/10 12:20:25 | 000,015,104 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbscan.sys
[2010/09/10 12:20:25 | 000,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusb.dll
[2010/09/10 12:20:24 | 000,159,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusd.dll
[2010/09/07 23:20:03 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/09/07 10:14:45 | 000,000,000 | —D | C] – C:\Documents and Settings\Larry Van Sweden\Local Settings\Application Data\NOS
[2010/09/05 23:07:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Larry Van Sweden\Application Data\Malwarebytes
[2010/09/05 23:06:55 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/09/05 23:06:53 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/09/05 23:06:53 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/09/05 23:06:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/09/05 19:07:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\F-Secure
[2010/09/05 18:55:48 | 000,000,000 | —D | C] – C:\WINDOWS\Sun
[2010/09/05 18:54:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2010/09/05 18:54:52 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/09/05 18:54:16 | 000,423,656 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2010/09/05 18:54:16 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/09/05 18:51:36 | 000,000,000 | —D | C] – C:\Program Files\Java
[2010/09/05 18:49:24 | 000,000,000 | —D | C] – C:\Documents and Settings\Larry Van Sweden\Application Data\Sun
[2010/09/04 13:56:28 | 000,000,000 | —D | C] – C:\Program Files\IncrediMail
[2010/09/03 20:01:08 | 000,000,000 | -H-D | C] – C:\WINDOWS\msdownld.tmp
[2010/09/02 13:11:12 | 000,000,000 | —D | C] – C:\Documents and Settings\Larry Van Sweden\Desktop\Unused Desktop Shortcuts
[2010/09/02 12:49:23 | 000,000,000 | —D | C] – C:\Program Files\The Weather Channel FW
[2010/09/01 16:06:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Larry Van Sweden\Local Settings\Application Data\The Weather Channel
[2010/09/01 11:46:03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
[2010/08/30 20:18:17 | 000,000,000 | —D | C] – C:\WINDOWS\System32\appmgmt
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/09/28 11:30:58 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Larry Van Sweden\Desktop\OTL.exe
[2010/09/28 10:57:54 | 000,013,712 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/09/28 10:57:22 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/09/28 10:57:19 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/09/28 10:56:15 | 002,621,440 | -H– | M] () – C:\Documents and Settings\Larry Van Sweden\NTUSER.DAT
[2010/09/28 10:56:15 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Larry Van Sweden\ntuser.ini
[2010/09/27 18:26:41 | 000,000,444 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{ED2A8C3F-0BFF-4996-AEE8-E677BFB0BF1D}.job
[2010/09/27 16:21:28 | 000,000,114 | —- | M] () – C:\WINDOWS\entpack.ini
[2010/09/27 16:21:03 | 000,000,951 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/09/27 16:21:03 | 000,000,933 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Desktop\Spybot - Search & Destroy.lnk
[2010/09/26 18:35:42 | 000,196,597 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\My Documents\32 roadster from midwest hot rods.JPG
[2010/09/26 18:29:54 | 000,002,265 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Desktop\Skype.lnk
[2010/09/25 14:38:11 | 000,010,960 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\My Documents\current meds larry.odt
[2010/09/18 21:06:16 | 000,062,661 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\My Documents\Heritage Hot Rods $17780..mht
[2010/09/17 23:10:40 | 000,007,680 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/17 12:54:35 | 000,001,707 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk
[2010/09/17 11:27:33 | 000,617,722 | —- | M] () – C:\WINDOWS\System32\drivers\Cat.DB
[2010/09/14 18:59:43 | 000,018,496 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/09/14 18:57:36 | 000,118,952 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/09/14 14:21:10 | 000,000,864 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
[2010/09/10 15:35:50 | 000,000,682 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Desktop\CCleaner.lnk
[2010/09/07 23:20:12 | 000,001,734 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Desktop\HijackThis.lnk
[2010/09/06 10:30:59 | 000,000,815 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/09/05 23:07:01 | 000,000,714 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2010/09/05 23:07:01 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/09/05 18:51:43 | 000,423,656 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2010/09/05 18:51:43 | 000,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/09/05 18:51:43 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/09/05 18:51:43 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/09/05 18:51:43 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/09/04 21:56:58 | 000,000,804 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2010/09/04 14:00:05 | 000,001,750 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Application Data\Microsoft\Internet Explorer\Quick Launch\IncrediMail.lnk
[2010/09/04 13:57:05 | 000,001,736 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Application Data\Microsoft\Internet Explorer\Quick Launch\IncrediMail 2.0.lnk
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/09/27 16:21:03 | 000,000,951 | —- | C] () – C:\Documents and Settings\Larry Van Sweden\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/09/27 16:21:03 | 000,000,933 | —- | C] () – C:\Documents and Settings\Larry Van Sweden\Desktop\Spybot - Search & Destroy.lnk
[2010/09/26 18:35:42 | 000,196,597 | —- | C] () – C:\Documents and Settings\Larry Van Sweden\My Documents\32 roadster from midwest hot rods.JPG
[2010/09/18 21:06:16 | 000,062,661 | —- | C] () – C:\Documents and Settings\Larry Van Sweden\My Documents\Heritage Hot Rods $17780..mht
[2010/09/17 12:54:35 | 000,001,707 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk
[2010/09/17 11:27:27 | 000,617,722 | —- | C] () – C:\WINDOWS\System32\drivers\Cat.DB
[2010/09/14 14:21:09 | 000,000,864 | —- | C] () – C:\Documents and Settings\Larry Van Sweden\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
[2010/09/07 23:20:04 | 000,001,734 | —- | C] () – C:\Documents and Settings\Larry Van Sweden\Desktop\HijackThis.lnk
[2010/09/05 23:07:01 | 000,000,714 | —- | C] () – C:\Documents and Settings\Larry Van Sweden\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2010/09/05 23:07:00 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/09/04 14:00:05 | 000,001,750 | —- | C] () – C:\Documents and Settings\Larry Van Sweden\Application Data\Microsoft\Internet Explorer\Quick Launch\IncrediMail.lnk
[2010/09/04 13:57:05 | 000,001,736 | —- | C] () – C:\Documents and Settings\Larry Van Sweden\Application Data\Microsoft\Internet Explorer\Quick Launch\IncrediMail 2.0.lnk
[2010/08/28 11:31:13 | 000,000,165 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2010/08/11 11:39:09 | 000,000,114 | —- | C] () – C:\WINDOWS\entpack.ini
[2010/08/10 22:32:07 | 000,000,000 | —- | C] () – C:\WINDOWS\Brownie.ini
[2010/08/10 19:27:23 | 000,015,497 | —- | C] () – C:\WINDOWS\VX6KStd.ini
[2010/08/10 18:57:14 | 000,000,030 | —- | C] () – C:\WINDOWS\System32\brss01a.ini
[2010/08/10 18:55:50 | 000,000,419 | —- | C] () – C:\WINDOWS\brwmark.ini
[2010/08/10 18:55:50 | 000,000,234 | —- | C] () – C:\WINDOWS\Brpfx04a.ini
[2010/08/10 18:55:50 | 000,000,092 | —- | C] () – C:\WINDOWS\brpcfx.ini
[2010/08/10 18:55:50 | 000,000,079 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2010/08/10 18:54:27 | 000,027,019 | —- | C] () – C:\WINDOWS\maxlink.ini
[2010/08/10 18:49:51 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\cmirmdrv.dll
[2010/08/10 18:49:42 | 000,000,092 | —- | C] () – C:\WINDOWS\CMISETUP.INI
[2010/08/10 18:49:41 | 000,000,026 | —- | C] () – C:\WINDOWS\CMCDPLAY.INI
[2010/08/10 18:49:39 | 000,000,000 | —- | C] () – C:\WINDOWS\Wininit.ini
[2010/08/10 18:49:36 | 000,121,329 | R— | C] () – C:\WINDOWS\Cmuda.ini
[2010/08/10 18:49:33 | 000,028,672 | —- | C] () – C:\WINDOWS\CMIRmDriver.dll
[2010/08/10 18:43:10 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\vusetup.dll
[2010/08/10 18:39:07 | 000,003,000 | R— | C] () – C:\WINDOWS\System32\SetupNT.sys
[2010/08/10 16:41:52 | 000,007,680 | —- | C] () – C:\Documents and Settings\Larry Van Sweden\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/09/17 17:37:42 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\vuins32.dll
[2002/03/04 10:16:34 | 000,110,592 | R— | C] () – C:\WINDOWS\System32\Jpeg32.dll
========== LOP Check ==========
[2010/08/27 20:28:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Carbonite
[2010/09/05 19:07:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\F-Secure
[2010/08/28 11:15:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IM
[2010/08/28 11:12:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IncrediMail
[2010/08/11 12:20:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2010/08/25 21:50:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ralink Driver
[2010/08/10 18:54:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2010/09/17 18:32:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/09/11 13:46:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2010/09/27 16:16:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Larry Van Sweden\Application Data\GetRightToGo
[2010/09/14 14:19:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Larry Van Sweden\Application Data\OpenOffice.org
[2010/09/27 18:26:41 | 000,000,444 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{ED2A8C3F-0BFF-4996-AEE8-E677BFB0BF1D}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/08/10 16:12:06 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/08/11 15:42:14 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010/08/10 16:12:06 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/08/10 16:12:06 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/08/10 16:12:06 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2006/02/28 08:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/08/11 17:33:16 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/09/28 10:57:16 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2010/08/10 16:11:33 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2004/02/09 00:00:00 | 000,026,285 | —- | M] (Brother Industries ,Ltd ) – C:\WINDOWS\system32\spool\prtprocs\w32x86\brmfpp1.dll
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2001/11/20 14:37:28 | 000,047,616 | R— | M] (Black Ice Software) – C:\WINDOWS\system32\spool\prtprocs\w32x86\ppbiPr.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2010/08/10 09:48:09 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2010/08/10 09:48:08 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2010/08/10 09:48:08 | 000,884,736 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/08/11 17:38:05 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/08/10 16:21:24 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Larry Van Sweden\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/08/10 16:21:23 | 000,000,079 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2010/09/28 11:30:58 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Larry Van Sweden\Desktop\OTL.exe
[1991/09/12 19:00:16 | 000,115,056 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Desktop\TRIPEAKS.EXE
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
[2010/01/27 23:44:12 | 000,013,022 | —- | M] () – C:\WINDOWS\VX6000.src
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-09-14 22:55:57
========== Alternate Data Streams ==========
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:430C6D84
< End of report >
OTL Extras logfile created on: 9/28/2010 11:34:05 AM - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\Larry Van Sweden\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 67.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 27.59 Gb Free Space | 74.06% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: LARRY-DD246AB59
Current User Name: Larry Van Sweden
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Microsoft LifeCam\LifeExp.exe" = C:\Program Files\Microsoft LifeCam\LifeExp.exe:*:Enabled:LifeExp.exe – (Microsoft Corporation)
"C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe" = C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent – File not found
"C:\Program Files\IncrediMail\Bin\IncMail.exe" = C:\Program Files\IncrediMail\Bin\IncMail.exe:*:Enabled:IncrediMail – (IncrediMail, Ltd.)
"C:\Program Files\IncrediMail\Bin\ImApp.exe" = C:\Program Files\IncrediMail\Bin\ImApp.exe:*:Enabled:IncrediMail – (IncrediMail, Ltd.)
"C:\Program Files\IncrediMail\Bin\ImpCnt.exe" = C:\Program Files\IncrediMail\Bin\ImpCnt.exe:*:Enabled:IncrediMail – (IncrediMail, Ltd.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{18DB3375-0649-4EA3-959A-44F1ACD278BA}" = IncrediMail
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216020F0}" = Java™ 6 Update 20
"{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java™ 6 Update 21
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{40A6C96D-808E-41DD-8716-617AB6B0F1F1}" = Brother MFL-Pro Suite
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5A13987D-55F4-4271-A40E-76AC9B1B38FD}" = OpenOffice.org 3.2
"{63AFACBC-4795-4A1B-8037-5085DC03FC54}" = Microsoft LifeCam
"{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}" = Ralink RT2860 Wireless LAN Card
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A17EABB6-D0C6-44E5-820C-72DC7F495064}" = PaperPort
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240BD}" = WinZip 14.5
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{DBCC73BA-C69A-4BF5-B4BF-F07501EE7039}" = AnswerWorks 5.0 English Runtime
"{ED2A3C11-3EA8-4380-B59C-F2C1832731B0}" = Quicken 2009
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"Carbonite Backup" = Carbonite
"CCleaner" = CCleaner
"C-Media Audio" = C-Media 3D Audio
"C-Media Audio Driver" = C-Media WDM Audio Driver
"HijackThis" = HijackThis 2.0.2
"ie8" = Windows Internet Explorer 8
"IncrediMail" = IncrediMail 2.0
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"S3" = UniChrome IGP Driver and Utilities
"The Weather Channel Desktop 6" = The Weather Channel Desktop 6
"VN_VUIns_Rhine_VIA" = VIA Rhine-Family Fast Ethernet Adapter
"VTDisplay" = S3 S3Display
"VTGamma2" = S3 S3Gamma2
"VTInfo2" = S3 S3Info2
"VTOverlay" = S3 S3Overlay
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 9/17/2010 8:57:52 PM | Computer Name = LARRY-DD246AB59 | Source = crypt32 | ID = 131077
Description = Failed auto update retrieval of third-party root certificate from:
<http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/323C118E1BF7B8B65254E2E2100DD6029037F096.crt>
with error: This operation returned because the timeout period expired.
Error - 9/17/2010 8:57:52 PM | Computer Name = LARRY-DD246AB59 | Source = crypt32 | ID = 131077
Description = Failed auto update retrieval of third-party root certificate from:
<http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/323C118E1BF7B8B65254E2E2100DD6029037F096.crt>
with error: The specified server cannot perform the requested operation.
Error - 9/17/2010 10:37:03 PM | Computer Name = LARRY-DD246AB59 | Source = crypt32 | ID = 131077
Description = Failed auto update retrieval of third-party root certificate from:
<http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/323C118E1BF7B8B65254E2E2100DD6029037F096.crt>
with error: This operation returned because the timeout period expired.
Error - 9/17/2010 10:37:03 PM | Computer Name = LARRY-DD246AB59 | Source = crypt32 | ID = 131077
Description = Failed auto update retrieval of third-party root certificate from:
<http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/323C118E1BF7B8B65254E2E2100DD6029037F096.crt>
with error: The specified server cannot perform the requested operation.
Error - 9/17/2010 10:37:04 PM | Computer Name = LARRY-DD246AB59 | Source = crypt32 | ID = 131077
Description = Failed auto update retrieval of third-party root certificate from:
<http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/323C118E1BF7B8B65254E2E2100DD6029037F096.crt>
with error: The specified server cannot perform the requested operation.
Error - 9/17/2010 10:37:04 PM | Computer Name = LARRY-DD246AB59 | Source = crypt32 | ID = 131077
Description = Failed auto update retrieval of third-party root certificate from:
<http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/323C118E1BF7B8B65254E2E2100DD6029037F096.crt>
with error: The specified server cannot perform the requested operation.
Error - 9/27/2010 9:49:53 AM | Computer Name = LARRY-DD246AB59 | Source = Application Hang | ID = 1002
Description = Hanging application mbam.exe, version 1.46.0.1, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 9/27/2010 9:50:01 AM | Computer Name = LARRY-DD246AB59 | Source = Application Hang | ID = 1001
Description = Fault bucket 1836621447.
Error - 9/27/2010 9:53:14 AM | Computer Name = LARRY-DD246AB59 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.
Error - 9/27/2010 12:56:45 PM | Computer Name = LARRY-DD246AB59 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
[ System Events ]
Error - 9/23/2010 6:52:15 PM | Computer Name = LARRY-DD246AB59 | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)
Error - 9/23/2010 6:52:15 PM | Computer Name = LARRY-DD246AB59 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.
Error - 9/23/2010 6:52:16 PM | Computer Name = LARRY-DD246AB59 | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)
Error - 9/23/2010 6:52:16 PM | Computer Name = LARRY-DD246AB59 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.
Error - 9/23/2010 6:53:27 PM | Computer Name = LARRY-DD246AB59 | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)
Error - 9/23/2010 6:53:27 PM | Computer Name = LARRY-DD246AB59 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.
Error - 9/23/2010 6:55:27 PM | Computer Name = LARRY-DD246AB59 | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)
Error - 9/23/2010 6:55:27 PM | Computer Name = LARRY-DD246AB59 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.
Error - 9/23/2010 6:58:55 PM | Computer Name = LARRY-DD246AB59 | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)
Error - 9/23/2010 6:58:55 PM | Computer Name = LARRY-DD246AB59 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.
< End of report >
OTL logfile created on: 9/28/2010 11:34:05 AM - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\Larry Van Sweden\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 67.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 27.59 Gb Free Space | 74.06% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: LARRY-DD246AB59
Current User Name: Larry Van Sweden
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Larry Van Sweden\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\IncrediMail\Bin\IncMail.exe (IncrediMail, Ltd.)
PRC - C:\Program Files\IncrediMail\Bin\ImApp.exe (IncrediMail, Ltd.)
PRC - C:\Program Files\Carbonite\Carbonite Backup\CarboniteService.exe (Carbonite, Inc. (www.carbonite.com))
PRC - C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe (Carbonite, Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\VTTimer.exe (S3 Graphics, Inc.)
PRC - C:\WINDOWS\system32\Brmfrmps.exe (Brother Industries, Ltd.)
PRC - C:\WINDOWS\system32\brsvc01a.exe (brother Industries Ltd)
PRC - C:\WINDOWS\system32\brss01a.exe (brother Industries Ltd)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Larry Van Sweden\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (CarboniteService) – C:\Program Files\Carbonite\Carbonite Backup\carboniteservice.exe (Carbonite, Inc. (www.carbonite.com))
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (brmfrmps) – C:\WINDOWS\System32\Brmfrmps.exe (Brother Industries, Ltd.)
SRV - (Brother XP spl Service) – C:\WINDOWS\system32\brsvc01a.exe (brother Industries Ltd)
========== Driver Services (SafeList) ==========
DRV - (cpuz132) – C:\DOCUME~1\LARRYV~1\LOCALS~1\Temp\cpuz132\cpuz132_x32.sys File not found
DRV - (avipbb) – C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) – C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (VX6000) – C:\WINDOWS\system32\drivers\VX6000Xp.sys (Microsoft Corporation
)
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (RT80x86) – C:\WINDOWS\system32\drivers\rt2860.sys (Ralink Technology, Corp.)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\USBAUDIO.sys (Microsoft Corporation)
DRV - (RT73) – C:\WINDOWS\system32\drivers\rt73.sys (Ralink Technology, Corp.)
DRV - (BrScnUsb) – C:\WINDOWS\system32\drivers\BrScnUsb.sys (Brother Industries Ltd.)
DRV - (USR1806) – C:\WINDOWS\system32\drivers\USR1806.SYS (U.S. Robotics, Inc.)
DRV - (SetupNT) – C:\WINDOWS\system32\SetupNT.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.charter.net/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: ([2006/02/28 08:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [Carbonite Backup] C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe (Carbonite, Inc.)
O4 - HKLM..\Run: [VTTimer] C:\WINDOWS\System32\VTTimer.exe (S3 Graphics, Inc.)
O4 - HKCU..\Run: [DW6] C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe (The Weather Channel Interactive, Inc.)
O4 - HKCU..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe (IncrediMail, Ltd.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\Larry Van Sweden\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/08/10 16:12:06 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)
========== Files/Folders - Created Within 30 Days ==========
[2010/09/28 11:30:55 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Larry Van Sweden\Desktop\OTL.exe
[2010/09/27 16:15:22 | 000,000,000 | —D | C] – C:\Documents and Settings\Larry Van Sweden\Application Data\GetRightToGo
[2010/09/27 11:30:47 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Larry Van Sweden\Recent
[2010/09/17 12:56:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Larry Van Sweden\Application Data\Avira
[2010/09/17 12:54:15 | 000,028,520 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\ssmdrv.sys
[2010/09/17 12:54:12 | 000,124,784 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avipbb.sys
[2010/09/17 12:54:12 | 000,060,936 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntflt.sys
[2010/09/17 12:54:12 | 000,045,416 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntdd.sys
[2010/09/17 12:54:12 | 000,022,360 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntmgr.sys
[2010/09/17 12:54:08 | 000,000,000 | —D | C] – C:\Program Files\Avira
[2010/09/17 12:54:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Avira
[2010/09/17 12:00:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Larry Van Sweden\Local Settings\Application Data\Threat Expert
[2010/09/17 11:00:35 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/09/17 10:55:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\PC Tools
[2010/09/14 14:19:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Larry Van Sweden\Application Data\OpenOffice.org
[2010/09/14 13:34:16 | 000,000,000 | —D | C] – C:\Program Files\JRE
[2010/09/14 13:33:39 | 000,000,000 | —D | C] – C:\Program Files\OpenOffice.org 3
[2010/09/14 13:32:32 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/09/14 13:32:32 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/09/14 13:32:32 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/09/13 18:49:02 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/09/13 18:49:02 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/09/11 13:50:11 | 000,000,000 | —D | C] – C:\Documents and Settings\Larry Van Sweden\My Documents\My WinZip Files
[2010/09/11 13:46:08 | 000,000,000 | —D | C] – C:\Documents and Settings\Larry Van Sweden\Local Settings\Application Data\WinZip
[2010/09/11 13:45:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\WinZip
[2010/09/11 13:45:01 | 000,000,000 | —D | C] – C:\Program Files\WinZip
[2010/09/10 12:20:25 | 000,015,104 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbscan.sys
[2010/09/10 12:20:25 | 000,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusb.dll
[2010/09/10 12:20:24 | 000,159,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusd.dll
[2010/09/07 23:20:03 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/09/07 10:14:45 | 000,000,000 | —D | C] – C:\Documents and Settings\Larry Van Sweden\Local Settings\Application Data\NOS
[2010/09/05 23:07:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Larry Van Sweden\Application Data\Malwarebytes
[2010/09/05 23:06:55 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/09/05 23:06:53 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/09/05 23:06:53 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/09/05 23:06:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/09/05 19:07:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\F-Secure
[2010/09/05 18:55:48 | 000,000,000 | —D | C] – C:\WINDOWS\Sun
[2010/09/05 18:54:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2010/09/05 18:54:52 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/09/05 18:54:16 | 000,423,656 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2010/09/05 18:54:16 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/09/05 18:51:36 | 000,000,000 | —D | C] – C:\Program Files\Java
[2010/09/05 18:49:24 | 000,000,000 | —D | C] – C:\Documents and Settings\Larry Van Sweden\Application Data\Sun
[2010/09/04 13:56:28 | 000,000,000 | —D | C] – C:\Program Files\IncrediMail
[2010/09/03 20:01:08 | 000,000,000 | -H-D | C] – C:\WINDOWS\msdownld.tmp
[2010/09/02 13:11:12 | 000,000,000 | —D | C] – C:\Documents and Settings\Larry Van Sweden\Desktop\Unused Desktop Shortcuts
[2010/09/02 12:49:23 | 000,000,000 | —D | C] – C:\Program Files\The Weather Channel FW
[2010/09/01 16:06:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Larry Van Sweden\Local Settings\Application Data\The Weather Channel
[2010/09/01 11:46:03 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
[2010/08/30 20:18:17 | 000,000,000 | —D | C] – C:\WINDOWS\System32\appmgmt
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/09/28 11:30:58 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Larry Van Sweden\Desktop\OTL.exe
[2010/09/28 10:57:54 | 000,013,712 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/09/28 10:57:22 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/09/28 10:57:19 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/09/28 10:56:15 | 002,621,440 | -H– | M] () – C:\Documents and Settings\Larry Van Sweden\NTUSER.DAT
[2010/09/28 10:56:15 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Larry Van Sweden\ntuser.ini
[2010/09/27 18:26:41 | 000,000,444 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{ED2A8C3F-0BFF-4996-AEE8-E677BFB0BF1D}.job
[2010/09/27 16:21:28 | 000,000,114 | —- | M] () – C:\WINDOWS\entpack.ini
[2010/09/27 16:21:03 | 000,000,951 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/09/27 16:21:03 | 000,000,933 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Desktop\Spybot - Search & Destroy.lnk
[2010/09/26 18:35:42 | 000,196,597 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\My Documents\32 roadster from midwest hot rods.JPG
[2010/09/26 18:29:54 | 000,002,265 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Desktop\Skype.lnk
[2010/09/25 14:38:11 | 000,010,960 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\My Documents\current meds larry.odt
[2010/09/18 21:06:16 | 000,062,661 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\My Documents\Heritage Hot Rods $17780..mht
[2010/09/17 23:10:40 | 000,007,680 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/17 12:54:35 | 000,001,707 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk
[2010/09/17 11:27:33 | 000,617,722 | —- | M] () – C:\WINDOWS\System32\drivers\Cat.DB
[2010/09/14 18:59:43 | 000,018,496 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/09/14 18:57:36 | 000,118,952 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/09/14 14:21:10 | 000,000,864 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
[2010/09/10 15:35:50 | 000,000,682 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Desktop\CCleaner.lnk
[2010/09/07 23:20:12 | 000,001,734 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Desktop\HijackThis.lnk
[2010/09/06 10:30:59 | 000,000,815 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/09/05 23:07:01 | 000,000,714 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2010/09/05 23:07:01 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/09/05 18:51:43 | 000,423,656 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2010/09/05 18:51:43 | 000,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/09/05 18:51:43 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/09/05 18:51:43 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/09/05 18:51:43 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/09/04 21:56:58 | 000,000,804 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2010/09/04 14:00:05 | 000,001,750 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Application Data\Microsoft\Internet Explorer\Quick Launch\IncrediMail.lnk
[2010/09/04 13:57:05 | 000,001,736 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Application Data\Microsoft\Internet Explorer\Quick Launch\IncrediMail 2.0.lnk
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/09/27 16:21:03 | 000,000,951 | —- | C] () – C:\Documents and Settings\Larry Van Sweden\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/09/27 16:21:03 | 000,000,933 | —- | C] () – C:\Documents and Settings\Larry Van Sweden\Desktop\Spybot - Search & Destroy.lnk
[2010/09/26 18:35:42 | 000,196,597 | —- | C] () – C:\Documents and Settings\Larry Van Sweden\My Documents\32 roadster from midwest hot rods.JPG
[2010/09/18 21:06:16 | 000,062,661 | —- | C] () – C:\Documents and Settings\Larry Van Sweden\My Documents\Heritage Hot Rods $17780..mht
[2010/09/17 12:54:35 | 000,001,707 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk
[2010/09/17 11:27:27 | 000,617,722 | —- | C] () – C:\WINDOWS\System32\drivers\Cat.DB
[2010/09/14 14:21:09 | 000,000,864 | —- | C] () – C:\Documents and Settings\Larry Van Sweden\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
[2010/09/07 23:20:04 | 000,001,734 | —- | C] () – C:\Documents and Settings\Larry Van Sweden\Desktop\HijackThis.lnk
[2010/09/05 23:07:01 | 000,000,714 | —- | C] () – C:\Documents and Settings\Larry Van Sweden\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2010/09/05 23:07:00 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/09/04 14:00:05 | 000,001,750 | —- | C] () – C:\Documents and Settings\Larry Van Sweden\Application Data\Microsoft\Internet Explorer\Quick Launch\IncrediMail.lnk
[2010/09/04 13:57:05 | 000,001,736 | —- | C] () – C:\Documents and Settings\Larry Van Sweden\Application Data\Microsoft\Internet Explorer\Quick Launch\IncrediMail 2.0.lnk
[2010/08/28 11:31:13 | 000,000,165 | —- | C] () – C:\WINDOWS\QUICKEN.INI
[2010/08/11 11:39:09 | 000,000,114 | —- | C] () – C:\WINDOWS\entpack.ini
[2010/08/10 22:32:07 | 000,000,000 | —- | C] () – C:\WINDOWS\Brownie.ini
[2010/08/10 19:27:23 | 000,015,497 | —- | C] () – C:\WINDOWS\VX6KStd.ini
[2010/08/10 18:57:14 | 000,000,030 | —- | C] () – C:\WINDOWS\System32\brss01a.ini
[2010/08/10 18:55:50 | 000,000,419 | —- | C] () – C:\WINDOWS\brwmark.ini
[2010/08/10 18:55:50 | 000,000,234 | —- | C] () – C:\WINDOWS\Brpfx04a.ini
[2010/08/10 18:55:50 | 000,000,092 | —- | C] () – C:\WINDOWS\brpcfx.ini
[2010/08/10 18:55:50 | 000,000,079 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2010/08/10 18:54:27 | 000,027,019 | —- | C] () – C:\WINDOWS\maxlink.ini
[2010/08/10 18:49:51 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\cmirmdrv.dll
[2010/08/10 18:49:42 | 000,000,092 | —- | C] () – C:\WINDOWS\CMISETUP.INI
[2010/08/10 18:49:41 | 000,000,026 | —- | C] () – C:\WINDOWS\CMCDPLAY.INI
[2010/08/10 18:49:39 | 000,000,000 | —- | C] () – C:\WINDOWS\Wininit.ini
[2010/08/10 18:49:36 | 000,121,329 | R— | C] () – C:\WINDOWS\Cmuda.ini
[2010/08/10 18:49:33 | 000,028,672 | —- | C] () – C:\WINDOWS\CMIRmDriver.dll
[2010/08/10 18:43:10 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\vusetup.dll
[2010/08/10 18:39:07 | 000,003,000 | R— | C] () – C:\WINDOWS\System32\SetupNT.sys
[2010/08/10 16:41:52 | 000,007,680 | —- | C] () – C:\Documents and Settings\Larry Van Sweden\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2004/09/17 17:37:42 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\vuins32.dll
[2002/03/04 10:16:34 | 000,110,592 | R— | C] () – C:\WINDOWS\System32\Jpeg32.dll
========== LOP Check ==========
[2010/08/27 20:28:44 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Carbonite
[2010/09/05 19:07:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\F-Secure
[2010/08/28 11:15:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IM
[2010/08/28 11:12:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IncrediMail
[2010/08/11 12:20:18 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2010/08/25 21:50:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ralink Driver
[2010/08/10 18:54:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2010/09/17 18:32:29 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/09/11 13:46:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2010/09/27 16:16:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Larry Van Sweden\Application Data\GetRightToGo
[2010/09/14 14:19:51 | 000,000,000 | —D | M] – C:\Documents and Settings\Larry Van Sweden\Application Data\OpenOffice.org
[2010/09/27 18:26:41 | 000,000,444 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{ED2A8C3F-0BFF-4996-AEE8-E677BFB0BF1D}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/08/10 16:12:06 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/08/11 15:42:14 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010/08/10 16:12:06 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/08/10 16:12:06 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/08/10 16:12:06 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2006/02/28 08:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/08/11 17:33:16 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/09/28 10:57:16 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2010/08/10 16:11:33 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2004/02/09 00:00:00 | 000,026,285 | —- | M] (Brother Industries ,Ltd ) – C:\WINDOWS\system32\spool\prtprocs\w32x86\brmfpp1.dll
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2001/11/20 14:37:28 | 000,047,616 | R— | M] (Black Ice Software) – C:\WINDOWS\system32\spool\prtprocs\w32x86\ppbiPr.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2010/08/10 09:48:09 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2010/08/10 09:48:08 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2010/08/10 09:48:08 | 000,884,736 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/08/11 17:38:05 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/08/10 16:21:24 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Larry Van Sweden\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/08/10 16:21:23 | 000,000,079 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2010/09/28 11:30:58 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Larry Van Sweden\Desktop\OTL.exe
[1991/09/12 19:00:16 | 000,115,056 | —- | M] () – C:\Documents and Settings\Larry Van Sweden\Desktop\TRIPEAKS.EXE
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
[2010/01/27 23:44:12 | 000,013,022 | —- | M] () – C:\WINDOWS\VX6000.src
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-09-14 22:55:57
========== Alternate Data Streams ==========
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 102 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:430C6D84
< End of report >
OTL Extras logfile created on: 9/28/2010 11:34:05 AM - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\Larry Van Sweden\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 67.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 27.59 Gb Free Space | 74.06% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: LARRY-DD246AB59
Current User Name: Larry Van Sweden
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Microsoft LifeCam\LifeExp.exe" = C:\Program Files\Microsoft LifeCam\LifeExp.exe:*:Enabled:LifeExp.exe – (Microsoft Corporation)
"C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe" = C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent – File not found
"C:\Program Files\IncrediMail\Bin\IncMail.exe" = C:\Program Files\IncrediMail\Bin\IncMail.exe:*:Enabled:IncrediMail – (IncrediMail, Ltd.)
"C:\Program Files\IncrediMail\Bin\ImApp.exe" = C:\Program Files\IncrediMail\Bin\ImApp.exe:*:Enabled:IncrediMail – (IncrediMail, Ltd.)
"C:\Program Files\IncrediMail\Bin\ImpCnt.exe" = C:\Program Files\IncrediMail\Bin\ImpCnt.exe:*:Enabled:IncrediMail – (IncrediMail, Ltd.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{18DB3375-0649-4EA3-959A-44F1ACD278BA}" = IncrediMail
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216020F0}" = Java™ 6 Update 20
"{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java™ 6 Update 21
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{40A6C96D-808E-41DD-8716-617AB6B0F1F1}" = Brother MFL-Pro Suite
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{5A13987D-55F4-4271-A40E-76AC9B1B38FD}" = OpenOffice.org 3.2
"{63AFACBC-4795-4A1B-8037-5085DC03FC54}" = Microsoft LifeCam
"{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}" = Ralink RT2860 Wireless LAN Card
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A17EABB6-D0C6-44E5-820C-72DC7F495064}" = PaperPort
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240BD}" = WinZip 14.5
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{DBCC73BA-C69A-4BF5-B4BF-F07501EE7039}" = AnswerWorks 5.0 English Runtime
"{ED2A3C11-3EA8-4380-B59C-F2C1832731B0}" = Quicken 2009
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"Carbonite Backup" = Carbonite
"CCleaner" = CCleaner
"C-Media Audio" = C-Media 3D Audio
"C-Media Audio Driver" = C-Media WDM Audio Driver
"HijackThis" = HijackThis 2.0.2
"ie8" = Windows Internet Explorer 8
"IncrediMail" = IncrediMail 2.0
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"S3" = UniChrome IGP Driver and Utilities
"The Weather Channel Desktop 6" = The Weather Channel Desktop 6
"VN_VUIns_Rhine_VIA" = VIA Rhine-Family Fast Ethernet Adapter
"VTDisplay" = S3 S3Display
"VTGamma2" = S3 S3Gamma2
"VTInfo2" = S3 S3Info2
"VTOverlay" = S3 S3Overlay
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 9/17/2010 8:57:52 PM | Computer Name = LARRY-DD246AB59 | Source = crypt32 | ID = 131077
Description = Failed auto update retrieval of third-party root certificate from:
<http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/323C118E1BF7B8B65254E2E2100DD6029037F096.crt>
with error: This operation returned because the timeout period expired.
Error - 9/17/2010 8:57:52 PM | Computer Name = LARRY-DD246AB59 | Source = crypt32 | ID = 131077
Description = Failed auto update retrieval of third-party root certificate from:
<http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/323C118E1BF7B8B65254E2E2100DD6029037F096.crt>
with error: The specified server cannot perform the requested operation.
Error - 9/17/2010 10:37:03 PM | Computer Name = LARRY-DD246AB59 | Source = crypt32 | ID = 131077
Description = Failed auto update retrieval of third-party root certificate from:
<http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/323C118E1BF7B8B65254E2E2100DD6029037F096.crt>
with error: This operation returned because the timeout period expired.
Error - 9/17/2010 10:37:03 PM | Computer Name = LARRY-DD246AB59 | Source = crypt32 | ID = 131077
Description = Failed auto update retrieval of third-party root certificate from:
<http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/323C118E1BF7B8B65254E2E2100DD6029037F096.crt>
with error: The specified server cannot perform the requested operation.
Error - 9/17/2010 10:37:04 PM | Computer Name = LARRY-DD246AB59 | Source = crypt32 | ID = 131077
Description = Failed auto update retrieval of third-party root certificate from:
<http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/323C118E1BF7B8B65254E2E2100DD6029037F096.crt>
with error: The specified server cannot perform the requested operation.
Error - 9/17/2010 10:37:04 PM | Computer Name = LARRY-DD246AB59 | Source = crypt32 | ID = 131077
Description = Failed auto update retrieval of third-party root certificate from:
<http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/323C118E1BF7B8B65254E2E2100DD6029037F096.crt>
with error: The specified server cannot perform the requested operation.
Error - 9/27/2010 9:49:53 AM | Computer Name = LARRY-DD246AB59 | Source = Application Hang | ID = 1002
Description = Hanging application mbam.exe, version 1.46.0.1, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 9/27/2010 9:50:01 AM | Computer Name = LARRY-DD246AB59 | Source = Application Hang | ID = 1001
Description = Fault bucket 1836621447.
Error - 9/27/2010 9:53:14 AM | Computer Name = LARRY-DD246AB59 | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.
Error - 9/27/2010 12:56:45 PM | Computer Name = LARRY-DD246AB59 | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
[ System Events ]
Error - 9/23/2010 6:52:15 PM | Computer Name = LARRY-DD246AB59 | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)
Error - 9/23/2010 6:52:15 PM | Computer Name = LARRY-DD246AB59 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.
Error - 9/23/2010 6:52:16 PM | Computer Name = LARRY-DD246AB59 | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)
Error - 9/23/2010 6:52:16 PM | Computer Name = LARRY-DD246AB59 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.
Error - 9/23/2010 6:53:27 PM | Computer Name = LARRY-DD246AB59 | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)
Error - 9/23/2010 6:53:27 PM | Computer Name = LARRY-DD246AB59 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.
Error - 9/23/2010 6:55:27 PM | Computer Name = LARRY-DD246AB59 | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)
Error - 9/23/2010 6:55:27 PM | Computer Name = LARRY-DD246AB59 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.
Error - 9/23/2010 6:58:55 PM | Computer Name = LARRY-DD246AB59 | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)
Error - 9/23/2010 6:58:55 PM | Computer Name = LARRY-DD246AB59 | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.
< End of report >