nyehus
Topic Starter
im trying to tidyup a friends laptop,
firstly it didnt have any antivirus software so i installed avira antivir and remvoed 210 trojans/viruses
im now stuck as antispysafeguard has popped up and controlling everything,
i installed latest malwarebytes which cleared several issues.
but still antispysafeguard is there and wont let me do anything
i have run otl - output logs below
OTL logfile created on: 30/09/2010 22:51:21 - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\admin\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 76.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 48.83 Gb Total Space | 40.43 Gb Free Space | 82.80% Space Free | Partition Type: NTFS
Drive D: | 97.65 Gb Total Space | 45.01 Gb Free Space | 46.09% Space Free | Partition Type: NTFS
Drive E: | 97.65 Gb Total Space | 97.30 Gb Free Space | 99.64% Space Free | Partition Type: NTFS
Drive F: | 45.20 Gb Total Space | 43.16 Gb Free Space | 95.47% Space Free | Partition Type: NTFS
Drive G: | 991.72 Mb Total Space | 196.80 Mb Free Space | 19.84% Space Free | Partition Type: FAT
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: LHD-2C1425261F2
Current User Name: admin
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\admin\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\admin\Application Data\hotfix.exe ()
PRC - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\admin\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\ebezojaz.dll ()
MOD - C:\WINDOWS\system32\opengl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\glu32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\ddraw.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\dciman32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (WMPNetworkSvc) – C:\Program Files\Windows Media Player\WMPNetwk.exe File not found
SRV - (ose) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE File not found
SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
========== Driver Services (SafeList) ==========
DRV - (RTL8187B) – C:\WINDOWS\System32\DRIVERS\RTL8187B.sys File not found
DRV - (Lbd) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (avipbb) – C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (avgntflt) – C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (rt2870) – C:\WINDOWS\system32\drivers\rt2870.sys (Ralink Technology, Corp.)
DRV - (Ambfilt) – C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)
DRV - (ialm) – C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (Monfilt) – C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.mytalktalk.co.uk
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local
FF - HKLM\software\mozilla\Firefox\Extensions\\{6E0EEBD9-61F6-4733-A1C4-D92E20296D61}: C:\Documents and Settings\admin\Local Settings\Application Data\{6E0EEBD9-61F6-4733-A1C4-D92E20296D61} [2010/09/30 21:29:23 | 000,000,000 | —D | M]
O1 HOSTS File: ([2004/08/04 13:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (C:\WINDOWS\system32\z5mdb37enf.dll) - {B1BA40A1-75F2-51BD-F313-04B03A2C8953} - C:\WINDOWS\System32\z5mdb37enf.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [RTHDCPL] File not found
O4 - HKLM..\Run: [Ssebufazemiz] C:\WINDOWS\ebezojaz.DLL ()
O4 - HKCU..\Run: [{32F3F70E-C261-4DE0-0E30-9CDD6A15D1EA}] C:\Documents and Settings\admin\Application Data\Wyohs\obaco.exe ()
O4 - HKCU..\Run: [DokterWatson.exe] C:\Documents and Settings\admin\Local Settings\Temp\DokterWatson.exe ()
O4 - HKCU..\Run: [HNUmZIXnb] C:\DOCUME~1\admin\LOCALS~1\Temp\mdm.exe File not found
O4 - HKCU..\Run: [HNUmZIXneP] C:\DOCUME~1\admin\LOCALS~1\Temp\avp32.exe File not found
O4 - HKCU..\Run: [HNUmZIXnf] C:\DOCUME~1\admin\LOCALS~1\Temp\win.exe File not found
O4 - HKCU..\Run: [HNUmZIXngP] C:\DOCUME~1\admin\LOCALS~1\Temp\win32.exe File not found
O4 - HKCU..\Run: [HNUmZIXnsb] C:\DOCUME~1\admin\LOCALS~1\Temp\drweb.exe File not found
O4 - HKCU..\Run: [HNUmZIXntg] C:\DOCUME~1\admin\LOCALS~1\Temp\wininst.exe File not found
O4 - HKCU..\Run: [HNUmZIXnvc] C:\DOCUME~1\admin\LOCALS~1\Temp\user.exe File not found
O4 - HKCU..\Run: [HNUmZIXnwaX] C:\DOCUME~1\admin\LOCALS~1\Temp\kyycej2jak.exe File not found
O4 - HKCU..\Run: [HNUmZIXnwe] C:\DOCUME~1\admin\LOCALS~1\Temp\setup.exe File not found
O4 - HKCU..\Run: [HNUmZIXnxb] C:\DOCUME~1\admin\LOCALS~1\Temp\sysedit.exe File not found
O4 - HKCU..\Run: [HNUmZIXnZP] C:\DOCUME~1\admin\LOCALS~1\Temp\gdi32.exe File not found
O4 - HKCU..\Run: [MKaoc] C:\WINDOWS\debug.exe File not found
O4 - HKCU..\Run: [MKasc] C:\WINDOWS\drweb.exe File not found
O4 - HKCU..\Run: [MKbMc] C:\WINDOWS\gdi32.exe File not found
O4 - HKCU..\Run: [MKbta] C:\WINDOWS\install.exe File not found
O4 - HKCU..\Run: [MKbtc] C:\WINDOWS\hexdump.exe File not found
O4 - HKCU..\Run: [MKbuqc] C:\WINDOWS\iexplarer.exe File not found
O4 - HKCU..\Run: [MKcZ] C:\WINDOWS\mdm.exe File not found
O4 - HKCU..\Run: [MKee] C:\WINDOWS\user.exe File not found
O4 - HKCU..\Run: [MKevc] C:\WINDOWS\setup.exe File not found
O4 - HKCU..\Run: [MKfre] C:\WINDOWS\wininst.exe File not found
O4 - HKCU..\Run: [MKZSc] C:\WINDOWS\avp32.exe File not found
O4 - HKCU..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe File not found
O4 - HKCU..\Run: [Mxofefubeq] C:\WINDOWS\MVSCDENe.DLL File not found
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [uPc+MV0NdLaXms] C:\WINDOWS\System32\xp0c5f.DLL File not found
O4 - Startup: C:\Documents and Settings\admin\Start Menu\Programs\Startup\msnmsngr.ink.lnk = C:\Documents and Settings\admin\Local Settings\Temp\DokterWatson.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O15 - HKCU\..Trusted Domains: malwarebytes.org ([]* in Trusted sites)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (C:\Documents and Settings\admin\Application Data\hotfix.exe) - C:\Documents and Settings\admin\Application Data\hotfix.exe ()
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O22 - SharedTaskScheduler: {B1BA40A1-75F2-51BD-F313-04B03A2C8953} - jsfsue98jfi8dfjijse - C:\WINDOWS\System32\z5mdb37enf.dll File not found
O24 - Desktop WallPaper: C:\Documents and Settings\admin\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\admin\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/02/25 00:53:17 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2010/05/06 11:18:32 | 000,000,000 | -H-D | M] - G:\autoruns.inf – [ FAT ]
O32 - Unable to obtain root file information for disk G:\
O33 - MountPoints2\{64c483fe-3db8-11df-ae7b-b482fe09a37a}\Shell\AutoRun\command - "" = wscript.exe .\.vbs
O33 - MountPoints2\{64c483fe-3db8-11df-ae7b-b482fe09a37a}\Shell\open\command - "" = wscript.exe .\.vbs
O33 - MountPoints2\{73898d16-3c69-11df-ae79-b482fe09a37a}\Shell - "" = AutoRun
O33 - MountPoints2\{73898d16-3c69-11df-ae79-b482fe09a37a}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{73898d16-3c69-11df-ae79-b482fe09a37a}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Error starting restore point: System Restore is disabled.
Error closing restore point: System Restore is disabled.
========== Files/Folders - Created Within 30 Days ==========
[2010/10/01 05:20:53 | 000,000,000 | —D | C] – C:\Documents and Settings\admin\Application Data\Avira
[2010/10/01 04:59:22 | 000,000,000 | —D | C] – D:\My Documents\Downloads
[2010/10/01 04:52:19 | 000,000,000 | —D | C] – D:\My Documents\final student reports
[2010/10/01 04:52:10 | 000,000,000 | —D | C] – D:\My Documents\Cafe ideas
[2010/10/01 04:51:57 | 000,000,000 | —D | C] – D:\My Documents\anya's work
[2010/10/01 04:47:00 | 000,000,000 | R–D | C] – D:\My Documents\My Music
[2010/10/01 04:41:26 | 000,000,000 | —D | C] – C:\WINDOWS\System32\NtmsData
[2010/10/01 04:38:02 | 000,028,520 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\ssmdrv.sys
[2010/10/01 04:37:59 | 000,124,784 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avipbb.sys
[2010/10/01 04:37:59 | 000,060,936 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntflt.sys
[2010/10/01 04:37:59 | 000,045,416 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntdd.sys
[2010/10/01 04:37:59 | 000,022,360 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntmgr.sys
[2010/10/01 04:37:58 | 000,000,000 | —D | C] – C:\Program Files\Avira
[2010/10/01 04:37:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Avira
[2010/10/01 04:35:42 | 000,000,000 | —D | C] – C:\Documents and Settings\admin\Desktop\New Folder
[2010/10/01 04:33:18 | 000,000,000 | R–D | C] – D:\My Documents\My Pictures
[2010/10/01 04:33:17 | 000,000,000 | R–D | C] – D:\My Documents\My Videos
[2010/09/30 22:48:55 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Documents and Settings\admin\Desktop\OTL.exe
[2010/09/30 22:48:55 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\admin\Desktop\HiJackThis.exe
[2010/09/30 22:27:46 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/09/30 22:27:44 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/09/30 22:27:44 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/09/30 22:03:25 | 000,064,288 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2010/09/30 22:02:48 | 000,000,000 | —D | C] – C:\Program Files\Lavasoft
[2010/09/30 22:02:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2010/09/30 21:29:23 | 000,000,000 | —D | C] – C:\Documents and Settings\admin\Local Settings\Application Data\{6E0EEBD9-61F6-4733-A1C4-D92E20296D61}
[2010/09/30 21:14:10 | 000,000,000 | —D | C] – C:\Documents and Settings\admin\Application Data\vlc
[2010/09/30 10:41:06 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Wise Installation Wizard
[2010/09/30 10:27:36 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}
[2010/09/30 09:58:48 | 000,000,000 | —D | C] – C:\Documents and Settings\admin\Application Data\Malwarebytes
[2010/09/30 09:58:40 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/09/23 05:08:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2010/09/23 05:08:42 | 000,000,000 | —D | C] – C:\Documents and Settings\admin\Application Data\SUPERAntiSpyware.com
[2010/09/23 05:08:35 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2010/09/23 04:53:23 | 000,000,000 | —D | C] – C:\WINDOWS\System32\msmq
[2010/09/23 04:53:22 | 000,000,000 | —D | C] – C:\Inetpub
[2010/09/22 16:44:46 | 000,000,000 | —D | C] – C:\WINDOWS\System32\MpEngineStore
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/10/01 04:46:51 | 001,826,816 | —- | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\SkyTel.exe
[2010/10/01 04:46:51 | 001,200,128 | —- | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\RtlUpd.exe
[2010/10/01 04:46:50 | 009,715,200 | —- | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\RTLCPL.EXE
[2010/10/01 04:46:46 | 002,168,320 | —- | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\MicCal.exe
[2010/10/01 04:46:46 | 000,122,880 | —- | M] (Realtek Semiconductor) – C:\WINDOWS\RtkAudioService.exe
[2010/10/01 04:46:45 | 002,808,832 | —- | M] (RealTek Semicoductor Corp.) – C:\WINDOWS\ALCWZRD.EXE
[2010/10/01 04:38:23 | 000,001,707 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk
[2010/09/30 22:53:36 | 000,843,776 | —- | M] () – C:\WINDOWS\System32\drivers\zrxstpd.sys
[2010/09/30 22:47:54 | 000,359,929 | —- | M] () – C:\Documents and Settings\admin\Desktop\dds.scr
[2010/09/30 22:47:06 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\admin\Desktop\OTL.exe
[2010/09/30 22:44:26 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\admin\Desktop\HiJackThis.exe
[2010/09/30 22:35:18 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/09/30 22:34:51 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/09/30 22:34:48 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/09/30 22:33:48 | 007,602,176 | —- | M] () – C:\Documents and Settings\admin\ntuser.dat
[2010/09/30 22:33:48 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\admin\ntuser.ini
[2010/09/30 22:27:49 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/09/30 22:14:34 | 005,887,284 | -H– | M] () – C:\Documents and Settings\admin\Local Settings\Application Data\IconCache.db
[2010/09/30 22:03:04 | 000,000,885 | —- | M] () – C:\Documents and Settings\admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2010/09/30 22:03:04 | 000,000,867 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2010/09/30 21:43:04 | 000,730,112 | —- | M] () – C:\Documents and Settings\admin\Application Data\hotfix.exe
[2010/09/30 21:43:04 | 000,000,141 | —- | M] () – C:\Documents and Settings\admin\Application Data\jsdfgs.bat
[2010/09/30 21:29:24 | 000,000,120 | —- | M] () – C:\WINDOWS\Qxepacibisovuniw.dat
[2010/09/30 21:29:24 | 000,000,000 | —- | M] () – C:\WINDOWS\Elobutiyayiyohuy.bin
[2010/09/30 21:14:06 | 000,000,719 | —- | M] () – C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
[2010/09/30 21:11:41 | 000,508,956 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/09/30 21:11:41 | 000,432,924 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/09/30 21:11:41 | 000,067,714 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/09/30 12:35:48 | 000,154,112 | —- | M] () – C:\Documents and Settings\admin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/30 08:02:08 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/09/23 05:49:38 | 000,000,790 | —- | M] () – C:\Documents and Settings\admin\Start Menu\Programs\Startup\msnmsngr.ink.lnk
[2010/09/23 05:08:37 | 000,001,678 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/09/23 04:53:39 | 000,009,418 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/09/22 16:44:47 | 000,006,669 | —- | M] () – C:\WINDOWS\System32\MRT.INI
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/10/01 04:38:23 | 000,001,707 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk
[2010/09/30 22:48:55 | 000,359,929 | —- | C] () – C:\Documents and Settings\admin\Desktop\dds.scr
[2010/09/30 22:27:49 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/09/30 22:05:12 | 000,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/09/30 22:03:04 | 000,000,885 | —- | C] () – C:\Documents and Settings\admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2010/09/30 22:03:04 | 000,000,867 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2010/09/30 21:29:24 | 000,000,000 | —- | C] () – C:\WINDOWS\Elobutiyayiyohuy.bin
[2010/09/30 10:50:16 | 000,000,141 | —- | C] () – C:\Documents and Settings\admin\Application Data\jsdfgs.bat
[2010/09/30 10:50:15 | 000,730,112 | —- | C] () – C:\Documents and Settings\admin\Application Data\hotfix.exe
[2010/09/23 05:24:53 | 000,843,776 | —- | C] () – C:\WINDOWS\System32\drivers\zrxstpd.sys
[2010/09/23 05:08:37 | 000,001,678 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/09/22 16:44:47 | 000,006,669 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2010/02/25 06:26:34 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2010/02/25 05:58:02 | 000,154,112 | —- | C] () – C:\Documents and Settings\admin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/02/25 01:31:55 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/02/25 01:18:27 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2010/02/25 01:10:24 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4953.dll
[2004/08/04 13:00:00 | 000,200,192 | —- | C] () – C:\WINDOWS\ebezojaz.dll
[2003/01/08 00:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
========== LOP Check ==========
[2010/09/30 08:06:16 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\MSNInstaller
[2010/09/30 22:48:20 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\Muif
[2010/05/17 03:20:15 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\Uniblue
[2010/02/25 01:00:25 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\WinBatch
[2010/06/07 06:49:25 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\Wyohs
[2010/09/30 22:03:07 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}
[2010/09/30 22:35:18 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/02/25 00:53:17 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/02/25 00:48:08 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010/02/25 00:53:17 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/02/25 00:53:17 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/02/25 00:53:17 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 13:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/05/13 20:43:49 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/09/30 22:34:45 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2006/04/19 00:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 23:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/19 00:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 23:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2010/02/25 00:52:55 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 13:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2003/06/19 02:31:48 | 000,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 11:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2010/08/01 04:08:02 | 000,001,754 | -H– | M] () – C:\Documents and Settings\admin\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2010/02/24 16:37:54 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2010/02/24 16:37:54 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2010/02/24 16:37:53 | 000,901,120 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/05/13 20:48:33 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/02/25 00:57:41 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\admin\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/02/25 00:57:40 | 000,000,079 | —- | M] () – C:\Documents and Settings\admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2010/09/30 22:44:26 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\admin\Desktop\HiJackThis.exe
[2010/09/30 22:47:06 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\admin\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-09-22 15:45:10
< End of report >
OTL Extras logfile created on: 30/09/2010 22:51:21 - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\admin\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 76.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 48.83 Gb Total Space | 40.43 Gb Free Space | 82.80% Space Free | Partition Type: NTFS
Drive D: | 97.65 Gb Total Space | 45.01 Gb Free Space | 46.09% Space Free | Partition Type: NTFS
Drive E: | 97.65 Gb Total Space | 97.30 Gb Free Space | 99.64% Space Free | Partition Type: NTFS
Drive F: | 45.20 Gb Total Space | 43.16 Gb Free Space | 95.47% Space Free | Partition Type: NTFS
Drive G: | 991.72 Mb Total Space | 196.80 Mb Free Space | 19.84% Space Free | Partition Type: FAT
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: LHD-2C1425261F2
Current User Name: admin
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 File not found
htmlfile [print] – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 File not found
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"ANTIVIRUSDISABLENOTIFY" = 0
"FIREWALLDISABLENOTIFY" = 0
"UPDATESDISABLENOTIFY" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]
"DisableSR" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 4
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Documents and Settings\admin\Local Settings\Temp\Rar$EX01.265\FreeU13.exe" = C:\Documents and Settings\admin\Local Settings\Temp\Rar$EX01.265\FreeU13.exe:*:Enabled:Fast and Secure Gateway to Internet Freedom – File not found
"C:\Program Files\WinRAR\WinRAR.exe" = C:\Program Files\WinRAR\WinRAR.exe:*:Enabled:WinRAR – File not found
"C:\Documents and Settings\admin\Local Settings\Temp\Rar$EX01.734\FreeU13.exe" = C:\Documents and Settings\admin\Local Settings\Temp\Rar$EX01.734\FreeU13.exe:*:Enabled:Fast and Secure Gateway to Internet Freedom – File not found
"C:\Documents and Settings\admin\Local Settings\Temp\Rar$EX00.515\FreeU13.exe" = C:\Documents and Settings\admin\Local Settings\Temp\Rar$EX00.515\FreeU13.exe:*:Enabled:Fast and Secure Gateway to Internet Freedom – File not found
"C:\Documents and Settings\admin\Local Settings\Temp\Rar$EX01.843\FreeU13.exe" = C:\Documents and Settings\admin\Local Settings\Temp\Rar$EX01.843\FreeU13.exe:*:Enabled:Fast and Secure Gateway to Internet Freedom – File not found
"C:\Documents and Settings\admin\Local Settings\Temp\Rar$EX03.937\FreeU13.exe" = C:\Documents and Settings\admin\Local Settings\Temp\Rar$EX03.937\FreeU13.exe:*:Enabled:Fast and Secure Gateway to Internet Freedom – File not found
"C:\Documents and Settings\admin\Local Settings\Temp\Rar$EX02.640\u995.exe" = C:\Documents and Settings\admin\Local Settings\Temp\Rar$EX02.640\u995.exe:*:Enabled:u995 – File not found
"C:\Documents and Settings\admin\Local Settings\Temp\Rar$EX00.546\u995.exe" = C:\Documents and Settings\admin\Local Settings\Temp\Rar$EX00.546\u995.exe:*:Enabled:u995 – File not found
"C:\Documents and Settings\admin\Local Settings\Temp\Rar$EX00.625\u995.exe" = C:\Documents and Settings\admin\Local Settings\Temp\Rar$EX00.625\u995.exe:*:Enabled:u995 – File not found
"C:\Documents and Settings\admin\Local Settings\Temp\Rar$EX00.906\u995.exe" = C:\Documents and Settings\admin\Local Settings\Temp\Rar$EX00.906\u995.exe:*:Enabled:u995 – File not found
"C:\Program Files\Skype\Plugin Manager\skypePM.exe" = C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager – File not found
"C:\WINDOWS\explorer.exe" = C:\WINDOWS\explorer.exe:*:Disabled:Windows Explorer – (Microsoft Corporation)
"C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" = C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe:*:Enabled:Malwarebytes' Anti-Malware – (Malwarebytes Corporation)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"Ad-Aware" = Ad-Aware
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"All ATI Software" = ATI - Software Uninstall Utility
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"HDMI" = Intel® Graphics Media Accelerator Driver
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"VLC media player" = VLC media player 1.1.4
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 30/09/2010 16:51:22 | Computer Name = LHD-2C1425261F2 | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 3.0.12.38, faulting module
unknown, version 0.0.0.0, fault address 0x24017c1e.
Error - 30/09/2010 16:51:22 | Computer Name = LHD-2C1425261F2 | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 3.0.12.38, faulting module
unknown, version 0.0.0.0, fault address 0x24017c1e.
Error - 30/09/2010 17:03:15 | Computer Name = LHD-2C1425261F2 | Source = Lavasoft Ad-Aware Service | ID = 0
Description =
Error - 30/09/2010 17:08:04 | Computer Name = LHD-2C1425261F2 | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 3.0.12.38, faulting module
unknown, version 0.0.0.0, fault address 0x24017c1e.
Error - 30/09/2010 17:12:37 | Computer Name = LHD-2C1425261F2 | Source = MsiInstaller | ID = 10005
Description = Product: Microsoft Office Professional Edition 2003 – Error 25090.
Office Setup encountered a problem with the Office Source Engine, system error:
-2147024894. Please open C:\Program Files\Microsoft Office\OFFICE11\1033\SETUP.CHM
and look for "Office Source Engine" for information on how to resolve this problem.
Error - 30/09/2010 17:12:42 | Computer Name = LHD-2C1425261F2 | Source = MsiInstaller | ID = 10005
Description = Product: Microsoft Office Professional Edition 2003 – Error 25090.
Office Setup encountered a problem with the Office Source Engine, system error:
-2147024894. Please open C:\Program Files\Microsoft Office\OFFICE11\1033\SETUP.CHM
and look for "Office Source Engine" for information on how to resolve this problem.
Error - 30/09/2010 17:26:48 | Computer Name = LHD-2C1425261F2 | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 3.0.12.38, faulting module
unknown, version 0.0.0.0, fault address 0x24017c1e.
Error - 30/09/2010 17:26:48 | Computer Name = LHD-2C1425261F2 | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 3.0.12.38, faulting module
unknown, version 0.0.0.0, fault address 0x24017c1e.
Error - 30/09/2010 17:26:48 | Computer Name = LHD-2C1425261F2 | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 3.0.12.38, faulting module
unknown, version 0.0.0.0, fault address 0x24017c1e.
Error - 30/09/2010 17:26:48 | Computer Name = LHD-2C1425261F2 | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 3.0.12.38, faulting module
unknown, version 0.0.0.0, fault address 0x24087c1e.
[ System Events ]
Error - 30/09/2010 17:17:41 | Computer Name = LHD-2C1425261F2 | Source = Service Control Manager | ID = 7001
Description = The DNS Client service depends on the TCP/IP Protocol Driver service
which failed to start because of the following error: %%31
Error - 30/09/2010 17:17:41 | Computer Name = LHD-2C1425261F2 | Source = Service Control Manager | ID = 7001
Description = The TCP/IP NetBIOS Helper service depends on the AFD service which
failed to start because of the following error: %%31
Error - 30/09/2010 17:17:41 | Computer Name = LHD-2C1425261F2 | Source = Service Control Manager | ID = 7001
Description = The IPSEC Services service depends on the IPSEC driver service which
failed to start because of the following error: %%31
Error - 30/09/2010 17:17:41 | Computer Name = LHD-2C1425261F2 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AFD avgio avipbb Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss SASDIFSV SASKUTIL ssmdrv
Tcpip
Error - 30/09/2010 17:18:08 | Computer Name = LHD-2C1425261F2 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 30/09/2010 17:21:56 | Computer Name = LHD-2C1425261F2 | Source = Service Control Manager | ID = 7031
Description = The Lavasoft Ad-Aware Service service terminated unexpectedly. It
has done this 1 time(s). The following corrective action will be taken in 5000
milliseconds: Restart the service.
Error - 30/09/2010 17:22:20 | Computer Name = LHD-2C1425261F2 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 30/09/2010 17:23:00 | Computer Name = LHD-2C1425261F2 | Source = Print | ID = 19
Description = Sharing printer failed + 1722, Printer Microsoft XPS Document Writer
share name Printer.
Error - 30/09/2010 17:51:31 | Computer Name = LHD-2C1425261F2 | Source = SRService | ID = 104
Description = The System Restore initialization process failed.
Error - 30/09/2010 17:51:32 | Computer Name = LHD-2C1425261F2 | Source = Service Control Manager | ID = 7023
Description = The System Restore Service service terminated with the following error:
%%2
< End of report >
firstly it didnt have any antivirus software so i installed avira antivir and remvoed 210 trojans/viruses
im now stuck as antispysafeguard has popped up and controlling everything,
i installed latest malwarebytes which cleared several issues.
but still antispysafeguard is there and wont let me do anything
i have run otl - output logs below
OTL logfile created on: 30/09/2010 22:51:21 - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\admin\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 76.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 48.83 Gb Total Space | 40.43 Gb Free Space | 82.80% Space Free | Partition Type: NTFS
Drive D: | 97.65 Gb Total Space | 45.01 Gb Free Space | 46.09% Space Free | Partition Type: NTFS
Drive E: | 97.65 Gb Total Space | 97.30 Gb Free Space | 99.64% Space Free | Partition Type: NTFS
Drive F: | 45.20 Gb Total Space | 43.16 Gb Free Space | 95.47% Space Free | Partition Type: NTFS
Drive G: | 991.72 Mb Total Space | 196.80 Mb Free Space | 19.84% Space Free | Partition Type: FAT
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: LHD-2C1425261F2
Current User Name: admin
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\admin\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\admin\Application Data\hotfix.exe ()
PRC - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\admin\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\ebezojaz.dll ()
MOD - C:\WINDOWS\system32\opengl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\glu32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\ddraw.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\dciman32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (WMPNetworkSvc) – C:\Program Files\Windows Media Player\WMPNetwk.exe File not found
SRV - (ose) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE File not found
SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
========== Driver Services (SafeList) ==========
DRV - (RTL8187B) – C:\WINDOWS\System32\DRIVERS\RTL8187B.sys File not found
DRV - (Lbd) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (avipbb) – C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (avgntflt) – C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (rt2870) – C:\WINDOWS\system32\drivers\rt2870.sys (Ralink Technology, Corp.)
DRV - (Ambfilt) – C:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)
DRV - (ialm) – C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (Monfilt) – C:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.mytalktalk.co.uk
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local
FF - HKLM\software\mozilla\Firefox\Extensions\\{6E0EEBD9-61F6-4733-A1C4-D92E20296D61}: C:\Documents and Settings\admin\Local Settings\Application Data\{6E0EEBD9-61F6-4733-A1C4-D92E20296D61} [2010/09/30 21:29:23 | 000,000,000 | —D | M]
O1 HOSTS File: ([2004/08/04 13:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (C:\WINDOWS\system32\z5mdb37enf.dll) - {B1BA40A1-75F2-51BD-F313-04B03A2C8953} - C:\WINDOWS\System32\z5mdb37enf.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [RTHDCPL] File not found
O4 - HKLM..\Run: [Ssebufazemiz] C:\WINDOWS\ebezojaz.DLL ()
O4 - HKCU..\Run: [{32F3F70E-C261-4DE0-0E30-9CDD6A15D1EA}] C:\Documents and Settings\admin\Application Data\Wyohs\obaco.exe ()
O4 - HKCU..\Run: [DokterWatson.exe] C:\Documents and Settings\admin\Local Settings\Temp\DokterWatson.exe ()
O4 - HKCU..\Run: [HNUmZIXnb] C:\DOCUME~1\admin\LOCALS~1\Temp\mdm.exe File not found
O4 - HKCU..\Run: [HNUmZIXneP] C:\DOCUME~1\admin\LOCALS~1\Temp\avp32.exe File not found
O4 - HKCU..\Run: [HNUmZIXnf] C:\DOCUME~1\admin\LOCALS~1\Temp\win.exe File not found
O4 - HKCU..\Run: [HNUmZIXngP] C:\DOCUME~1\admin\LOCALS~1\Temp\win32.exe File not found
O4 - HKCU..\Run: [HNUmZIXnsb] C:\DOCUME~1\admin\LOCALS~1\Temp\drweb.exe File not found
O4 - HKCU..\Run: [HNUmZIXntg] C:\DOCUME~1\admin\LOCALS~1\Temp\wininst.exe File not found
O4 - HKCU..\Run: [HNUmZIXnvc] C:\DOCUME~1\admin\LOCALS~1\Temp\user.exe File not found
O4 - HKCU..\Run: [HNUmZIXnwaX] C:\DOCUME~1\admin\LOCALS~1\Temp\kyycej2jak.exe File not found
O4 - HKCU..\Run: [HNUmZIXnwe] C:\DOCUME~1\admin\LOCALS~1\Temp\setup.exe File not found
O4 - HKCU..\Run: [HNUmZIXnxb] C:\DOCUME~1\admin\LOCALS~1\Temp\sysedit.exe File not found
O4 - HKCU..\Run: [HNUmZIXnZP] C:\DOCUME~1\admin\LOCALS~1\Temp\gdi32.exe File not found
O4 - HKCU..\Run: [MKaoc] C:\WINDOWS\debug.exe File not found
O4 - HKCU..\Run: [MKasc] C:\WINDOWS\drweb.exe File not found
O4 - HKCU..\Run: [MKbMc] C:\WINDOWS\gdi32.exe File not found
O4 - HKCU..\Run: [MKbta] C:\WINDOWS\install.exe File not found
O4 - HKCU..\Run: [MKbtc] C:\WINDOWS\hexdump.exe File not found
O4 - HKCU..\Run: [MKbuqc] C:\WINDOWS\iexplarer.exe File not found
O4 - HKCU..\Run: [MKcZ] C:\WINDOWS\mdm.exe File not found
O4 - HKCU..\Run: [MKee] C:\WINDOWS\user.exe File not found
O4 - HKCU..\Run: [MKevc] C:\WINDOWS\setup.exe File not found
O4 - HKCU..\Run: [MKfre] C:\WINDOWS\wininst.exe File not found
O4 - HKCU..\Run: [MKZSc] C:\WINDOWS\avp32.exe File not found
O4 - HKCU..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe File not found
O4 - HKCU..\Run: [Mxofefubeq] C:\WINDOWS\MVSCDENe.DLL File not found
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [uPc+MV0NdLaXms] C:\WINDOWS\System32\xp0c5f.DLL File not found
O4 - Startup: C:\Documents and Settings\admin\Start Menu\Programs\Startup\msnmsngr.ink.lnk = C:\Documents and Settings\admin\Local Settings\Temp\DokterWatson.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O15 - HKCU\..Trusted Domains: malwarebytes.org ([]* in Trusted sites)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (C:\Documents and Settings\admin\Application Data\hotfix.exe) - C:\Documents and Settings\admin\Application Data\hotfix.exe ()
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O22 - SharedTaskScheduler: {B1BA40A1-75F2-51BD-F313-04B03A2C8953} - jsfsue98jfi8dfjijse - C:\WINDOWS\System32\z5mdb37enf.dll File not found
O24 - Desktop WallPaper: C:\Documents and Settings\admin\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\admin\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/02/25 00:53:17 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2010/05/06 11:18:32 | 000,000,000 | -H-D | M] - G:\autoruns.inf – [ FAT ]
O32 - Unable to obtain root file information for disk G:\
O33 - MountPoints2\{64c483fe-3db8-11df-ae7b-b482fe09a37a}\Shell\AutoRun\command - "" = wscript.exe .\.vbs
O33 - MountPoints2\{64c483fe-3db8-11df-ae7b-b482fe09a37a}\Shell\open\command - "" = wscript.exe .\.vbs
O33 - MountPoints2\{73898d16-3c69-11df-ae79-b482fe09a37a}\Shell - "" = AutoRun
O33 - MountPoints2\{73898d16-3c69-11df-ae79-b482fe09a37a}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{73898d16-3c69-11df-ae79-b482fe09a37a}\Shell\AutoRun\command - "" = G:\LaunchU3.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Error starting restore point: System Restore is disabled.
Error closing restore point: System Restore is disabled.
========== Files/Folders - Created Within 30 Days ==========
[2010/10/01 05:20:53 | 000,000,000 | —D | C] – C:\Documents and Settings\admin\Application Data\Avira
[2010/10/01 04:59:22 | 000,000,000 | —D | C] – D:\My Documents\Downloads
[2010/10/01 04:52:19 | 000,000,000 | —D | C] – D:\My Documents\final student reports
[2010/10/01 04:52:10 | 000,000,000 | —D | C] – D:\My Documents\Cafe ideas
[2010/10/01 04:51:57 | 000,000,000 | —D | C] – D:\My Documents\anya's work
[2010/10/01 04:47:00 | 000,000,000 | R–D | C] – D:\My Documents\My Music
[2010/10/01 04:41:26 | 000,000,000 | —D | C] – C:\WINDOWS\System32\NtmsData
[2010/10/01 04:38:02 | 000,028,520 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\ssmdrv.sys
[2010/10/01 04:37:59 | 000,124,784 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avipbb.sys
[2010/10/01 04:37:59 | 000,060,936 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntflt.sys
[2010/10/01 04:37:59 | 000,045,416 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntdd.sys
[2010/10/01 04:37:59 | 000,022,360 | —- | C] (Avira GmbH) – C:\WINDOWS\System32\drivers\avgntmgr.sys
[2010/10/01 04:37:58 | 000,000,000 | —D | C] – C:\Program Files\Avira
[2010/10/01 04:37:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Avira
[2010/10/01 04:35:42 | 000,000,000 | —D | C] – C:\Documents and Settings\admin\Desktop\New Folder
[2010/10/01 04:33:18 | 000,000,000 | R–D | C] – D:\My Documents\My Pictures
[2010/10/01 04:33:17 | 000,000,000 | R–D | C] – D:\My Documents\My Videos
[2010/09/30 22:48:55 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Documents and Settings\admin\Desktop\OTL.exe
[2010/09/30 22:48:55 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\admin\Desktop\HiJackThis.exe
[2010/09/30 22:27:46 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/09/30 22:27:44 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/09/30 22:27:44 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/09/30 22:03:25 | 000,064,288 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2010/09/30 22:02:48 | 000,000,000 | —D | C] – C:\Program Files\Lavasoft
[2010/09/30 22:02:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2010/09/30 21:29:23 | 000,000,000 | —D | C] – C:\Documents and Settings\admin\Local Settings\Application Data\{6E0EEBD9-61F6-4733-A1C4-D92E20296D61}
[2010/09/30 21:14:10 | 000,000,000 | —D | C] – C:\Documents and Settings\admin\Application Data\vlc
[2010/09/30 10:41:06 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Wise Installation Wizard
[2010/09/30 10:27:36 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}
[2010/09/30 09:58:48 | 000,000,000 | —D | C] – C:\Documents and Settings\admin\Application Data\Malwarebytes
[2010/09/30 09:58:40 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/09/23 05:08:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2010/09/23 05:08:42 | 000,000,000 | —D | C] – C:\Documents and Settings\admin\Application Data\SUPERAntiSpyware.com
[2010/09/23 05:08:35 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2010/09/23 04:53:23 | 000,000,000 | —D | C] – C:\WINDOWS\System32\msmq
[2010/09/23 04:53:22 | 000,000,000 | —D | C] – C:\Inetpub
[2010/09/22 16:44:46 | 000,000,000 | —D | C] – C:\WINDOWS\System32\MpEngineStore
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/10/01 04:46:51 | 001,826,816 | —- | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\SkyTel.exe
[2010/10/01 04:46:51 | 001,200,128 | —- | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\RtlUpd.exe
[2010/10/01 04:46:50 | 009,715,200 | —- | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\RTLCPL.EXE
[2010/10/01 04:46:46 | 002,168,320 | —- | M] (Realtek Semiconductor Corp.) – C:\WINDOWS\MicCal.exe
[2010/10/01 04:46:46 | 000,122,880 | —- | M] (Realtek Semiconductor) – C:\WINDOWS\RtkAudioService.exe
[2010/10/01 04:46:45 | 002,808,832 | —- | M] (RealTek Semicoductor Corp.) – C:\WINDOWS\ALCWZRD.EXE
[2010/10/01 04:38:23 | 000,001,707 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk
[2010/09/30 22:53:36 | 000,843,776 | —- | M] () – C:\WINDOWS\System32\drivers\zrxstpd.sys
[2010/09/30 22:47:54 | 000,359,929 | —- | M] () – C:\Documents and Settings\admin\Desktop\dds.scr
[2010/09/30 22:47:06 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\admin\Desktop\OTL.exe
[2010/09/30 22:44:26 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\admin\Desktop\HiJackThis.exe
[2010/09/30 22:35:18 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/09/30 22:34:51 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/09/30 22:34:48 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/09/30 22:33:48 | 007,602,176 | —- | M] () – C:\Documents and Settings\admin\ntuser.dat
[2010/09/30 22:33:48 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\admin\ntuser.ini
[2010/09/30 22:27:49 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/09/30 22:14:34 | 005,887,284 | -H– | M] () – C:\Documents and Settings\admin\Local Settings\Application Data\IconCache.db
[2010/09/30 22:03:04 | 000,000,885 | —- | M] () – C:\Documents and Settings\admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2010/09/30 22:03:04 | 000,000,867 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2010/09/30 21:43:04 | 000,730,112 | —- | M] () – C:\Documents and Settings\admin\Application Data\hotfix.exe
[2010/09/30 21:43:04 | 000,000,141 | —- | M] () – C:\Documents and Settings\admin\Application Data\jsdfgs.bat
[2010/09/30 21:29:24 | 000,000,120 | —- | M] () – C:\WINDOWS\Qxepacibisovuniw.dat
[2010/09/30 21:29:24 | 000,000,000 | —- | M] () – C:\WINDOWS\Elobutiyayiyohuy.bin
[2010/09/30 21:14:06 | 000,000,719 | —- | M] () – C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
[2010/09/30 21:11:41 | 000,508,956 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/09/30 21:11:41 | 000,432,924 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/09/30 21:11:41 | 000,067,714 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/09/30 12:35:48 | 000,154,112 | —- | M] () – C:\Documents and Settings\admin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/30 08:02:08 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/09/23 05:49:38 | 000,000,790 | —- | M] () – C:\Documents and Settings\admin\Start Menu\Programs\Startup\msnmsngr.ink.lnk
[2010/09/23 05:08:37 | 000,001,678 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/09/23 04:53:39 | 000,009,418 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/09/22 16:44:47 | 000,006,669 | —- | M] () – C:\WINDOWS\System32\MRT.INI
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/10/01 04:38:23 | 000,001,707 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk
[2010/09/30 22:48:55 | 000,359,929 | —- | C] () – C:\Documents and Settings\admin\Desktop\dds.scr
[2010/09/30 22:27:49 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/09/30 22:05:12 | 000,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/09/30 22:03:04 | 000,000,885 | —- | C] () – C:\Documents and Settings\admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Ad-Aware.lnk
[2010/09/30 22:03:04 | 000,000,867 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2010/09/30 21:29:24 | 000,000,000 | —- | C] () – C:\WINDOWS\Elobutiyayiyohuy.bin
[2010/09/30 10:50:16 | 000,000,141 | —- | C] () – C:\Documents and Settings\admin\Application Data\jsdfgs.bat
[2010/09/30 10:50:15 | 000,730,112 | —- | C] () – C:\Documents and Settings\admin\Application Data\hotfix.exe
[2010/09/23 05:24:53 | 000,843,776 | —- | C] () – C:\WINDOWS\System32\drivers\zrxstpd.sys
[2010/09/23 05:08:37 | 000,001,678 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/09/22 16:44:47 | 000,006,669 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2010/02/25 06:26:34 | 000,000,000 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2010/02/25 05:58:02 | 000,154,112 | —- | C] () – C:\Documents and Settings\admin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/02/25 01:31:55 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/02/25 01:18:27 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2010/02/25 01:10:24 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4953.dll
[2004/08/04 13:00:00 | 000,200,192 | —- | C] () – C:\WINDOWS\ebezojaz.dll
[2003/01/08 00:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
========== LOP Check ==========
[2010/09/30 08:06:16 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\MSNInstaller
[2010/09/30 22:48:20 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\Muif
[2010/05/17 03:20:15 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\Uniblue
[2010/02/25 01:00:25 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\WinBatch
[2010/06/07 06:49:25 | 000,000,000 | —D | M] – C:\Documents and Settings\admin\Application Data\Wyohs
[2010/09/30 22:03:07 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}
[2010/09/30 22:35:18 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/02/25 00:53:17 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/02/25 00:48:08 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2010/02/25 00:53:17 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/02/25 00:53:17 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/02/25 00:53:17 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 13:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/05/13 20:43:49 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/09/30 22:34:45 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2006/04/19 00:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 23:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/19 00:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 23:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2010/02/25 00:52:55 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 13:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2003/06/19 02:31:48 | 000,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 11:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2010/08/01 04:08:02 | 000,001,754 | -H– | M] () – C:\Documents and Settings\admin\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2010/02/24 16:37:54 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2010/02/24 16:37:54 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2010/02/24 16:37:53 | 000,901,120 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/05/13 20:48:33 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/02/25 00:57:41 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\admin\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/02/25 00:57:40 | 000,000,079 | —- | M] () – C:\Documents and Settings\admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2010/09/30 22:44:26 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\admin\Desktop\HiJackThis.exe
[2010/09/30 22:47:06 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\admin\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-09-22 15:45:10
< End of report >
OTL Extras logfile created on: 30/09/2010 22:51:21 - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\admin\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 76.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 48.83 Gb Total Space | 40.43 Gb Free Space | 82.80% Space Free | Partition Type: NTFS
Drive D: | 97.65 Gb Total Space | 45.01 Gb Free Space | 46.09% Space Free | Partition Type: NTFS
Drive E: | 97.65 Gb Total Space | 97.30 Gb Free Space | 99.64% Space Free | Partition Type: NTFS
Drive F: | 45.20 Gb Total Space | 43.16 Gb Free Space | 95.47% Space Free | Partition Type: NTFS
Drive G: | 991.72 Mb Total Space | 196.80 Mb Free Space | 19.84% Space Free | Partition Type: FAT
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: LHD-2C1425261F2
Current User Name: admin
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 File not found
htmlfile [print] – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 File not found
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"ANTIVIRUSDISABLENOTIFY" = 0
"FIREWALLDISABLENOTIFY" = 0
"UPDATESDISABLENOTIFY" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]
"DisableSR" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 4
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Documents and Settings\admin\Local Settings\Temp\Rar$EX01.265\FreeU13.exe" = C:\Documents and Settings\admin\Local Settings\Temp\Rar$EX01.265\FreeU13.exe:*:Enabled:Fast and Secure Gateway to Internet Freedom – File not found
"C:\Program Files\WinRAR\WinRAR.exe" = C:\Program Files\WinRAR\WinRAR.exe:*:Enabled:WinRAR – File not found
"C:\Documents and Settings\admin\Local Settings\Temp\Rar$EX01.734\FreeU13.exe" = C:\Documents and Settings\admin\Local Settings\Temp\Rar$EX01.734\FreeU13.exe:*:Enabled:Fast and Secure Gateway to Internet Freedom – File not found
"C:\Documents and Settings\admin\Local Settings\Temp\Rar$EX00.515\FreeU13.exe" = C:\Documents and Settings\admin\Local Settings\Temp\Rar$EX00.515\FreeU13.exe:*:Enabled:Fast and Secure Gateway to Internet Freedom – File not found
"C:\Documents and Settings\admin\Local Settings\Temp\Rar$EX01.843\FreeU13.exe" = C:\Documents and Settings\admin\Local Settings\Temp\Rar$EX01.843\FreeU13.exe:*:Enabled:Fast and Secure Gateway to Internet Freedom – File not found
"C:\Documents and Settings\admin\Local Settings\Temp\Rar$EX03.937\FreeU13.exe" = C:\Documents and Settings\admin\Local Settings\Temp\Rar$EX03.937\FreeU13.exe:*:Enabled:Fast and Secure Gateway to Internet Freedom – File not found
"C:\Documents and Settings\admin\Local Settings\Temp\Rar$EX02.640\u995.exe" = C:\Documents and Settings\admin\Local Settings\Temp\Rar$EX02.640\u995.exe:*:Enabled:u995 – File not found
"C:\Documents and Settings\admin\Local Settings\Temp\Rar$EX00.546\u995.exe" = C:\Documents and Settings\admin\Local Settings\Temp\Rar$EX00.546\u995.exe:*:Enabled:u995 – File not found
"C:\Documents and Settings\admin\Local Settings\Temp\Rar$EX00.625\u995.exe" = C:\Documents and Settings\admin\Local Settings\Temp\Rar$EX00.625\u995.exe:*:Enabled:u995 – File not found
"C:\Documents and Settings\admin\Local Settings\Temp\Rar$EX00.906\u995.exe" = C:\Documents and Settings\admin\Local Settings\Temp\Rar$EX00.906\u995.exe:*:Enabled:u995 – File not found
"C:\Program Files\Skype\Plugin Manager\skypePM.exe" = C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager – File not found
"C:\WINDOWS\explorer.exe" = C:\WINDOWS\explorer.exe:*:Disabled:Windows Explorer – (Microsoft Corporation)
"C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" = C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe:*:Enabled:Malwarebytes' Anti-Malware – (Malwarebytes Corporation)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"Ad-Aware" = Ad-Aware
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"All ATI Software" = ATI - Software Uninstall Utility
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"HDMI" = Intel® Graphics Media Accelerator Driver
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"VLC media player" = VLC media player 1.1.4
"WIC" = Windows Imaging Component
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 30/09/2010 16:51:22 | Computer Name = LHD-2C1425261F2 | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 3.0.12.38, faulting module
unknown, version 0.0.0.0, fault address 0x24017c1e.
Error - 30/09/2010 16:51:22 | Computer Name = LHD-2C1425261F2 | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 3.0.12.38, faulting module
unknown, version 0.0.0.0, fault address 0x24017c1e.
Error - 30/09/2010 17:03:15 | Computer Name = LHD-2C1425261F2 | Source = Lavasoft Ad-Aware Service | ID = 0
Description =
Error - 30/09/2010 17:08:04 | Computer Name = LHD-2C1425261F2 | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 3.0.12.38, faulting module
unknown, version 0.0.0.0, fault address 0x24017c1e.
Error - 30/09/2010 17:12:37 | Computer Name = LHD-2C1425261F2 | Source = MsiInstaller | ID = 10005
Description = Product: Microsoft Office Professional Edition 2003 – Error 25090.
Office Setup encountered a problem with the Office Source Engine, system error:
-2147024894. Please open C:\Program Files\Microsoft Office\OFFICE11\1033\SETUP.CHM
and look for "Office Source Engine" for information on how to resolve this problem.
Error - 30/09/2010 17:12:42 | Computer Name = LHD-2C1425261F2 | Source = MsiInstaller | ID = 10005
Description = Product: Microsoft Office Professional Edition 2003 – Error 25090.
Office Setup encountered a problem with the Office Source Engine, system error:
-2147024894. Please open C:\Program Files\Microsoft Office\OFFICE11\1033\SETUP.CHM
and look for "Office Source Engine" for information on how to resolve this problem.
Error - 30/09/2010 17:26:48 | Computer Name = LHD-2C1425261F2 | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 3.0.12.38, faulting module
unknown, version 0.0.0.0, fault address 0x24017c1e.
Error - 30/09/2010 17:26:48 | Computer Name = LHD-2C1425261F2 | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 3.0.12.38, faulting module
unknown, version 0.0.0.0, fault address 0x24017c1e.
Error - 30/09/2010 17:26:48 | Computer Name = LHD-2C1425261F2 | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 3.0.12.38, faulting module
unknown, version 0.0.0.0, fault address 0x24017c1e.
Error - 30/09/2010 17:26:48 | Computer Name = LHD-2C1425261F2 | Source = Application Error | ID = 1000
Description = Faulting application svchost.exe, version 3.0.12.38, faulting module
unknown, version 0.0.0.0, fault address 0x24087c1e.
[ System Events ]
Error - 30/09/2010 17:17:41 | Computer Name = LHD-2C1425261F2 | Source = Service Control Manager | ID = 7001
Description = The DNS Client service depends on the TCP/IP Protocol Driver service
which failed to start because of the following error: %%31
Error - 30/09/2010 17:17:41 | Computer Name = LHD-2C1425261F2 | Source = Service Control Manager | ID = 7001
Description = The TCP/IP NetBIOS Helper service depends on the AFD service which
failed to start because of the following error: %%31
Error - 30/09/2010 17:17:41 | Computer Name = LHD-2C1425261F2 | Source = Service Control Manager | ID = 7001
Description = The IPSEC Services service depends on the IPSEC driver service which
failed to start because of the following error: %%31
Error - 30/09/2010 17:17:41 | Computer Name = LHD-2C1425261F2 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AFD avgio avipbb Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss SASDIFSV SASKUTIL ssmdrv
Tcpip
Error - 30/09/2010 17:18:08 | Computer Name = LHD-2C1425261F2 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 30/09/2010 17:21:56 | Computer Name = LHD-2C1425261F2 | Source = Service Control Manager | ID = 7031
Description = The Lavasoft Ad-Aware Service service terminated unexpectedly. It
has done this 1 time(s). The following corrective action will be taken in 5000
milliseconds: Restart the service.
Error - 30/09/2010 17:22:20 | Computer Name = LHD-2C1425261F2 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 30/09/2010 17:23:00 | Computer Name = LHD-2C1425261F2 | Source = Print | ID = 19
Description = Sharing printer failed + 1722, Printer Microsoft XPS Document Writer
share name Printer.
Error - 30/09/2010 17:51:31 | Computer Name = LHD-2C1425261F2 | Source = SRService | ID = 104
Description = The System Restore initialization process failed.
Error - 30/09/2010 17:51:32 | Computer Name = LHD-2C1425261F2 | Source = Service Control Manager | ID = 7023
Description = The System Restore Service service terminated with the following error:
%%2
< End of report >