TL logfile created on: 12/12/2010 2:39:11 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Hills\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
224.00 Mb Total Physical Memory | 117.00 Mb Available Physical Memory | 52.00% Memory free
931.00 Mb Paging File | 768.00 Mb Available in Paging File | 82.00% Paging File free
Paging file location(s): C:\pagefile.sys 720 1440 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 7.18 Gb Free Space | 19.26% Space Free | Partition Type: NTFS
Computer Name: YEOLDINN | User Name: Hills | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Hills\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\NETGEAR\WG111v2\WG111v2.exe ()
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Hills\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (nosGetPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper_3004.dll (NOS Microsystems Ltd.)
SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (aspnet_state) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe (Microsoft Corporation)
SRV - (WPFFontCache_v0400) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (NetTcpPortSharing) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation)
SRV - (Nero BackItUp Scheduler 4.0) – C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
========== Driver Services (SafeList) ==========
DRV - (ncnvyc) – C:\WINDOWS\System32\drivers\pqnersy.sys File not found
DRV - (catchme) – C:\DOCUME~1\Hills\LOCALS~1\Temp\catchme.sys File not found
DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswSP) – C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswMon2) – C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswFsBlk) – C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (Aavmker4) – C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (USB_RNDIS) – C:\WINDOWS\system32\drivers\usb8023.sys (Microsoft Corporation)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (RTLWUSB) – C:\WINDOWS\system32\drivers\wg111v2.sys (NETGEAR Inc.)
DRV - (AN983) – C:\WINDOWS\system32\drivers\an983.sys (ADMtek Incorporated.)
DRV - (alcaudsl) – C:\WINDOWS\system32\drivers\alcaudsl.sys (THOMSON)
DRV - (alcan5ln) SpeedTouch™ USB ADSL RFC1483 Networking Driver (NDIS) – C:\WINDOWS\system32\drivers\alcan5ln.sys (THOMSON)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\SISAGPX.sys (Silicon Integrated Systems Corporation)
DRV - (SiS7012) Service for AC'97 Sample Driver (WDM) – C:\WINDOWS\system32\drivers\sis7012.sys (Silicon Integrated Systems Corporation)
DRV - (SiS315) – C:\WINDOWS\system32\drivers\sisgrp.sys (Silicon Integrated Systems Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://au.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-au
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 7E B5 1F 17 DF 2A CB 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Yahoo! Search"
FF - prefs.js..browser.search.selectedEngine: "Yahoo! Search"
FF - prefs.js..browser.startup.homepage: "
Http://ninemsn.com.au"
FF - prefs.js..extensions.enabledItems: {AA052FD6-366A-4771-A591-0D8DC551585D}:1.1.20
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20100908
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {872b5b88-9db5-4310-bdd0-ac189557e5f5}:2.7.2.0
FF - prefs.js..network.proxy.http_port: 3
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/11/18 15:23:35 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.12\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/11/20 11:27:39 | 000,000,000 | —D | M]
[2009/10/07 01:37:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Hills\Application Data\Mozilla\Extensions
[2009/10/07 01:37:43 | 000,000,000 | —D | M] – C:\Documents and Settings\Hills\Application Data\Mozilla\Extensions\[removed]
[2010/12/12 13:17:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Hills\Application Data\Mozilla\Firefox\Profiles\c5apz7ds.default\extensions
[2010/04/30 17:16:40 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Hills\Application Data\Mozilla\Firefox\Profiles\c5apz7ds.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/10/26 12:08:57 | 000,000,000 | —D | M] (DVDVideoSoftTB Toolbar) – C:\Documents and Settings\Hills\Application Data\Mozilla\Firefox\Profiles\c5apz7ds.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
[2010/09/19 18:09:41 | 000,000,000 | —D | M] (WOT) – C:\Documents and Settings\Hills\Application Data\Mozilla\Firefox\Profiles\c5apz7ds.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2010/11/02 16:55:38 | 000,000,000 | —D | M] (Calculator) – C:\Documents and Settings\Hills\Application Data\Mozilla\Firefox\Profiles\c5apz7ds.default\extensions\{AA052FD6-366A-4771-A591-0D8DC551585D}
[2010/07/24 16:37:08 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Hills\Application Data\Mozilla\Firefox\Profiles\c5apz7ds.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2010/12/12 13:17:09 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/05/07 12:29:16 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/24 18:41:53 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/08/24 18:41:26 | 000,423,656 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
O1 HOSTS File: ([2010/08/27 14:24:26 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR WG111v2 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v2\WG111v2.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Documents and Settings\Hills\Application Data\DVDVideoSoftIEHelpers\youtubetomp3.htm ()
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.microsoft.com/microsoftupdat…b?1248238891750 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Value error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Hills\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Hills\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/07/21 09:34:02 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (aswBoot.exe /A:"C:" /A:"*" /L:"1033" /heur:80 /pup /archives /IA:0 /KBD:2 /dir:"C:\Program Files\Alwil Software\Avast5") - C:\WINDOWS\System32\aswBoot.exe (AVAST Software)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.ac3filter - C:\WINDOWS\System32\ac3filter.acm ()
Drivers32: msacm.divxa32 - C:\WINDOWS\System32\msaud32_divx.acm (Microsoft Corporation)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\WINDOWS\System32\lameACM.acm (
http://www.mp3dev.org/)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.divx - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.ffds - C:\WINDOWS\System32\ff_vfw.dll ()
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.vp60 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.vp61 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.vp62 - C:\WINDOWS\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)
========== Files/Folders - Created Within 30 Days ==========
[2010/12/12 12:48:16 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Hills\Recent
[2010/12/11 15:40:58 | 000,272,128 | —- | C] (NETGEAR Inc.) – C:\WINDOWS\System32\drivers\wg111v2.sys
[2010/12/11 15:40:56 | 000,143,360 | —- | C] (TODO: ) – C:\WINDOWS\System32\IpLib.dll
[2010/12/11 15:40:51 | 000,000,000 | -H-D | C] – C:\Program Files\InstallShield Installation Information
[2010/12/11 15:40:51 | 000,000,000 | —D | C] – C:\Program Files\NETGEAR
[2010/12/11 15:40:37 | 000,000,000 | —D | C] – C:\Documents and Settings\Hills\Application Data\InstallShield
[2010/12/11 12:33:42 | 000,266,240 | —- | C] (WG111v2) – C:\WINDOWS\System32\WG1v2lib.dll
[2010/12/11 12:33:41 | 001,069,056 | —- | C] (The OpenSSL Project,
http://www.openssl.org/) – C:\WINDOWS\System32\libeay32.dll
[2010/12/08 17:21:48 | 000,000,000 | —D | C] – C:\Program Files\Conduit
[2010/12/07 16:04:20 | 000,000,000 | —D | C] – C:\Program Files\NOS
[2010/12/07 16:04:20 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NOS
[2010/12/05 11:26:19 | 000,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\write.exe
[2010/12/05 11:26:19 | 000,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\write.exe
[2010/12/05 11:26:12 | 000,138,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\sndvol32.exe
[2010/12/05 11:26:12 | 000,138,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sndvol32.exe
[2010/12/05 11:26:11 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\avwav.dll
[2010/12/05 11:26:11 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\avwav.dll
[2010/12/05 11:26:11 | 000,044,544 | —- | C] (Hilgraeve, Inc.) – C:\WINDOWS\System32\hticons.dll
[2010/12/05 11:26:11 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\avmeter.dll
[2010/12/05 11:26:11 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\avmeter.dll
[2010/12/05 11:26:10 | 000,227,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\avtapi.dll
[2010/12/05 11:26:10 | 000,227,840 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\avtapi.dll
[2010/12/05 11:26:10 | 000,035,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\winchat.exe
[2010/12/05 11:26:10 | 000,035,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\winchat.exe
[2010/12/05 11:26:04 | 000,605,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\getuname.dll
[2010/12/05 11:26:04 | 000,605,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\getuname.dll
[2010/12/05 11:26:04 | 000,080,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\charmap.exe
[2010/12/05 11:26:04 | 000,080,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\charmap.exe
[2010/12/05 11:26:03 | 000,126,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mshearts.exe
[2010/12/05 11:26:03 | 000,126,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mshearts.exe
[2010/12/05 11:26:03 | 000,119,808 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\winmine.exe
[2010/12/05 11:26:03 | 000,119,808 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\winmine.exe
[2010/12/05 11:26:03 | 000,114,688 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\calc.exe
[2010/12/05 11:26:03 | 000,114,688 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\calc.exe
[2010/12/05 11:26:03 | 000,056,832 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\sol.exe
[2010/12/05 11:26:03 | 000,056,832 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\sol.exe
[2010/12/05 11:26:02 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\freecell.exe
[2010/12/05 11:26:02 | 000,055,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\freecell.exe
[2010/11/26 20:05:16 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/11/21 22:52:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Hills\Application Data\Malwarebytes
[2010/11/21 22:52:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/03/31 15:47:56 | 000,812,344 | —- | C] (Trend Micro Inc.) – C:\Program Files\HJTInstall.exe
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/12/12 14:38:00 | 000,000,629 | —- | M] () – C:\Documents and Settings\Hills\Desktop\Shortcut to OTL.lnk
[2010/12/12 14:16:09 | 000,000,422 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{10E034B1-B71A-4087-9E07-C1D0A21684BB}.job
[2010/12/12 14:10:00 | 000,000,884 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/12/12 12:51:16 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2010/12/12 12:50:51 | 000,002,422 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/12/12 12:50:18 | 000,000,880 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/12/12 12:49:56 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/12/11 15:40:55 | 000,000,595 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR WG111v2 Smart Wizard.lnk
[2010/12/11 15:40:55 | 000,000,583 | —- | M] () – C:\Documents and Settings\All Users\Desktop\NETGEAR WG111v2 Smart Wizard.lnk
[2010/12/11 12:05:34 | 000,493,384 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/12/11 12:05:34 | 000,083,802 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/12/11 11:21:15 | 000,001,700 | —- | M] () – C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2010/12/11 11:21:11 | 000,002,626 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2010/12/09 23:21:46 | 000,027,136 | —- | M] () – C:\Documents and Settings\Hills\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/07 21:29:37 | 000,122,928 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/12/07 17:00:44 | 000,000,885 | —- | M] () – C:\Documents and Settings\All Users\Desktop\OpenOffice.org 3.2.lnk
[2010/12/06 15:51:38 | 000,000,104 | —- | M] () – C:\Documents and Settings\Hills\Desktop\My Network Places.lnk
[2010/12/06 15:51:31 | 000,000,104 | —- | M] () – C:\Documents and Settings\Hills\Desktop\My Computer.lnk
[2010/12/05 11:24:06 | 000,000,800 | —- | M] () – C:\Documents and Settings\Hills\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2010/11/26 20:33:21 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/11/22 14:20:31 | 000,002,447 | —- | M] () – C:\Documents and Settings\Hills\Desktop\HiJackThis.lnk
[2010/11/20 11:27:42 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/12/12 14:38:00 | 000,000,629 | —- | C] () – C:\Documents and Settings\Hills\Desktop\Shortcut to OTL.lnk
[2010/12/11 15:40:58 | 000,036,864 | —- | C] () – C:\WINDOWS\System32\RtlGina2.dll
[2010/12/11 15:40:56 | 000,966,765 | —- | C] () – C:\WINDOWS\System32\acAuth.dll
[2010/12/11 15:40:56 | 000,344,064 | —- | C] () – C:\WINDOWS\System32\SCMLib.dll
[2010/12/11 15:40:55 | 000,000,595 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR WG111v2 Smart Wizard.lnk
[2010/12/11 15:40:55 | 000,000,583 | —- | C] () – C:\Documents and Settings\All Users\Desktop\NETGEAR WG111v2 Smart Wizard.lnk
[2010/12/07 17:00:44 | 000,000,885 | —- | C] () – C:\Documents and Settings\All Users\Desktop\OpenOffice.org 3.2.lnk
[2010/12/06 15:51:38 | 000,000,104 | —- | C] () – C:\Documents and Settings\Hills\Desktop\My Network Places.lnk
[2010/12/06 15:51:31 | 000,000,104 | —- | C] () – C:\Documents and Settings\Hills\Desktop\My Computer.lnk
[2010/12/05 11:24:06 | 000,000,800 | —- | C] () – C:\Documents and Settings\Hills\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2010/08/18 23:48:36 | 000,120,178 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2010/05/25 05:33:00 | 004,670,829 | —- | C] () – C:\WINDOWS\System32\libavcodec.dll
[2010/05/25 05:33:00 | 001,529,856 | —- | C] () – C:\WINDOWS\System32\ff_samplerate.dll
[2010/05/25 05:33:00 | 001,447,921 | —- | C] () – C:\WINDOWS\System32\ffmpegmt.dll
[2010/05/25 05:33:00 | 000,877,385 | —- | C] () – C:\WINDOWS\System32\ff_x264.dll
[2010/05/25 05:33:00 | 000,810,113 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2010/05/25 05:33:00 | 000,336,384 | —- | C] () – C:\WINDOWS\System32\ff_libfaad2.dll
[2010/05/25 05:33:00 | 000,324,096 | —- | C] () – C:\WINDOWS\System32\TomsMoComp_ff.dll
[2010/05/25 05:33:00 | 000,248,320 | —- | C] () – C:\WINDOWS\System32\ff_kernelDeint.dll
[2010/05/25 05:33:00 | 000,216,576 | —- | C] () – C:\WINDOWS\System32\ff_libdts.dll
[2010/05/25 05:33:00 | 000,151,552 | —- | C] () – C:\WINDOWS\System32\ff_libmad.dll
[2010/05/25 05:33:00 | 000,145,408 | —- | C] () – C:\WINDOWS\System32\libmpeg2_ff.dll
[2010/05/25 05:33:00 | 000,139,944 | —- | C] () – C:\WINDOWS\System32\libmplayer.dll
[2010/05/25 05:33:00 | 000,121,856 | —- | C] () – C:\WINDOWS\System32\ff_liba52.dll
[2010/05/25 05:33:00 | 000,116,736 | —- | C] () – C:\WINDOWS\System32\ff_tremor.dll
[2010/05/25 05:33:00 | 000,108,032 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2010/05/25 05:33:00 | 000,100,864 | —- | C] () – C:\WINDOWS\System32\ff_wmv9.dll
[2010/05/25 05:33:00 | 000,097,792 | —- | C] () – C:\WINDOWS\System32\ff_unrar.dll
[2010/05/20 06:59:20 | 000,150,528 | —- | C] () – C:\WINDOWS\System32\mkx.dll
[2010/05/20 06:59:10 | 000,109,568 | —- | C] () – C:\WINDOWS\System32\avi.dll
[2010/05/20 06:59:02 | 000,141,824 | —- | C] () – C:\WINDOWS\System32\mp4.dll
[2010/05/20 06:58:52 | 000,123,392 | —- | C] () – C:\WINDOWS\System32\ogm.dll
[2010/05/20 06:58:18 | 000,154,112 | —- | C] () – C:\WINDOWS\System32\ts.dll
[2010/05/20 06:58:08 | 000,249,856 | —- | C] () – C:\WINDOWS\System32\dxr.dll
[2010/05/20 06:57:42 | 000,097,792 | —- | C] () – C:\WINDOWS\System32\avs.dll
[2010/05/20 06:57:26 | 000,093,184 | —- | C] () – C:\WINDOWS\System32\avss.dll
[2010/05/20 06:55:40 | 000,080,384 | —- | C] () – C:\WINDOWS\System32\mkzlib.dll
[2010/05/20 06:55:36 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\mkunicode.dll
[2010/03/30 18:41:59 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2010/01/07 15:00:23 | 000,000,205 | —- | C] () – C:\WINDOWS\youtube2mp3.ini
[2009/11/11 13:20:49 | 000,000,000 | —- | C] () – C:\Documents and Settings\Hills\Local Settings\Application Data\prvlcl.dat
[2009/11/07 10:42:49 | 000,034,915 | —- | C] () – C:\WINDOWS\System32\1_ssetup.ini
[2009/11/07 10:42:49 | 000,016,819 | —- | C] () – C:\WINDOWS\System32\sunistlog.ini
[2009/11/07 10:40:21 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\setuplib.dll
[2009/09/23 01:25:30 | 000,027,136 | —- | C] () – C:\Documents and Settings\Hills\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/07/22 10:13:14 | 000,005,606 | R— | C] () – C:\WINDOWS\System32\stci.dll
[2009/07/21 22:20:41 | 000,155,648 | R— | C] () – C:\WINDOWS\System32\TVModeLib.dll
[2009/07/21 22:20:17 | 000,121,948 | —- | C] () – C:\WINDOWS\VGAsetup.ini
[2009/07/21 22:20:00 | 000,108,562 | —- | C] () – C:\WINDOWS\System32\VGAunistlog.ini
[2009/07/21 19:18:39 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2009/06/08 02:24:04 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2009/01/11 08:15:44 | 000,159,744 | —- | C] () – C:\WINDOWS\System32\mmfinfo.dll
[2008/11/07 01:37:32 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2007/10/13 19:30:20 | 000,000,137 | —- | C] () – C:\WINDOWS\System32\Registration.ini
========== LOP Check ==========
[2010/06/20 13:28:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010/10/09 17:38:56 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DFX
[2010/02/07 14:48:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/07/24 16:37:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Hills\Application Data\DVDVideoSoftIEHelpers
[2009/07/22 00:02:20 | 000,000,000 | —D | M] – C:\Documents and Settings\Hills\Application Data\OpenOffice.org
[2010/12/09 23:05:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Hills\Application Data\uTorrent
[2010/12/12 14:16:09 | 000,000,422 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{10E034B1-B71A-4087-9E07-C1D0A21684BB}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/07/21 09:34:02 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/12/12 12:51:16 | 000,000,281 | RHS- | M] () – C:\boot.ini
[2010/11/26 20:02:18 | 000,013,486 | —- | M] () – C:\ComboFix.txt
[2009/07/21 09:34:02 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2009/07/21 09:34:02 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/08/24 18:46:51 | 000,000,444 | —- | M] () – C:\JavaRa.log
[2009/07/21 09:34:02 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2007/07/27 22:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2009/07/21 22:35:20 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/12/12 12:49:51 | 754,974,720 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/07/21 09:33:10 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 22:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 20:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010/09/08 01:12:17 | 000,038,848 | —- | M] (AVAST Software) – C:\WINDOWS\avastSS.scr
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2010/03/31 15:48:14 | 000,812,344 | —- | M] (Trend Micro Inc.) – C:\Program Files\HJTInstall.exe
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2009/07/21 19:16:17 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/07/21 19:16:17 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/07/21 19:16:17 | 000,868,352 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/07/21 22:42:38 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/07/21 22:55:49 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Hills\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2009/07/21 22:55:50 | 000,000,122 | -HS- | M] () – C:\Documents and Settings\Hills\Favorites\Desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
[2010/12/12 14:15:59 | 000,032,768 | -HS- | M] () – C:\Documents and Settings\Hills\Cookies\index.dat
< %SystemRoot%\system32\fonts\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-12-05 07:07:45
========== Alternate Data Streams ==========
@Alternate Data Stream - 16 bytes -> C:\WINDOWS\System32\mswinsck32.ocx:rsrc
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >
OTL Extras logfile created on: 12/12/2010 2:39:11 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Hills\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
224.00 Mb Total Physical Memory | 117.00 Mb Available Physical Memory | 52.00% Memory free
931.00 Mb Paging File | 768.00 Mb Available in Paging File | 82.00% Paging File free
Paging file location(s): C:\pagefile.sys 720 1440 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 7.18 Gb Free Space | 19.26% Space Free | Partition Type: NTFS
Computer Name: YEOLDINN | User Name: Hills | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Google\Google Earth\plugin\geplugin.exe" = C:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth – (Google)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{171E6C1E-B5FC-11DF-B115-005056C00008}" = Google Earth Plug-in
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java™ 6 Update 21
"{33CF58F5-48D8-4575-83D6-96F574E4D83A}" = Nero DriveSpeed
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{359CFC0A-BEB1-440D-95BA-CF63A86DA34F}" = Nero Recode
"{368BA326-73AD-4351-84ED-3C0A7A52CC53}" = Nero Rescue Agent
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{4102037D-E8E0-48E0-B203-E521D194FB71}" = NETGEAR WG111v2 wireless USB 2.0 adapter
"{43E39830-1826-415D-8BAE-86845787B54B}" = Nero Vision
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4DE3E3D9-AE81-45DE-9195-3015F7B1DBF3}" = Junk Mail filter update
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{595A3116-40BB-4E0F-A2E8-D7951DA56270}" = NeroExpress
"{62AC81F6-BDD3-4110-9D36-3E9EAAB40999}" = Nero CoverDesigner
"{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7748AC8C-18E3-43BB-959B-088FAEA16FB2}" = Nero StartSmart
"{7829DB6F-A066-4E40-8912-CB07887C20BB}" = Nero BurnRights
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{869200DB-287A-4DC0-B02B-2B6787FBCD4C}" = Nero DiscSpeed
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9E82B934-9A25-445B-B8DF-8012808074AC}" = Nero PhotoSnap
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A209525B-3377-43F4-B886-32F6B6E7356F}" = Nero WaveEditor
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.1
"{B2EC4A38-B545-4A00-8214-13FE0E915E6D}" = Advertising Center
"{B78120A0-CF84-4366-A393-4D0A59BC546C}" = Menu Templates - Starter Kit
"{BD5CA0DA-71AD-43DA-B19E-6EEE0C9ADC9A}" = Nero ControlCenter
"{BEFBEDDF-1417-4C8A-92FB-F003C0D41199}" = OpenOffice.org 3.2
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C5A7CB6C-E76D-408F-BA0E-85605420FE9D}" = SoundTrax
"{C6CA8874-5F22-4AF0-9BE3-016BF299C536}" = Windows Live Essentials
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D025A639-B9C9-417D-8531-208859000AF8}" = NeroBurningROM
"{D9DCF92E-72EB-412D-AC71-3B01276E5F8B}" = Nero ShowTime
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E498385E-1C51-459A-B45F-1721E37AA1A0}" = Movie Templates - Starter Kit
"{E8A80433-302B-4FF1-815D-FCC8EAC482FF}" = Nero Installer
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{FBCDFD61-7DCF-4E71-9226-873BA0053139}" = Nero InfoTool
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"avast5" = avast! Free Antivirus
"CCleaner" = CCleaner
"Defraggler" = Defraggler
"DFX for Windows Media Player" = DFX for Windows Media Player
"Free YouTube to MP3 Converter_is1" = Free YouTube to MP3 Converter version 3.8
"GOM Player" = GOM Player
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"Media Player - Codec Pack" = Media Player Codec Pack 3.9.6
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Mozilla Firefox (3.6.12)" = Mozilla Firefox (3.6.12)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"SiS VGA Utilities" = SiS VGA Utilities
"uTorrent" = µTorrent
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 26/11/2010 6:22:07 AM | Computer Name = YEOLDINN | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.
Error - 26/11/2010 6:22:10 AM | Computer Name = YEOLDINN | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.
Error - 26/11/2010 6:22:12 AM | Computer Name = YEOLDINN | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.
Error - 26/11/2010 6:22:15 AM | Computer Name = YEOLDINN | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.
Error - 26/11/2010 6:22:15 AM | Computer Name = YEOLDINN | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.
Error - 26/11/2010 6:22:19 AM | Computer Name = YEOLDINN | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.
Error - 26/11/2010 6:22:33 AM | Computer Name = YEOLDINN | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: The server name or address could not be resolved
Error - 4/12/2010 12:47:56 AM | Computer Name = YEOLDINN | Source = MSDTC | ID = 4163
Description = MS DTC log file not found. After ensuring that all Resource Managers
coordinated by MS DTC have no indoubt transactions, please run msdtc -resetlog
to create the log fil
Error - 4/12/2010 12:47:56 AM | Computer Name = YEOLDINN | Source = MSDTC | ID = 4185
Description = MS DTC Transaction Manager start failed. LogInit returned error 0x
Error - 4/12/2010 12:47:56 AM | Computer Name = YEOLDINN | Source = MSDTC | ID = 4112
Description = Could not start the MS DTC Transaction Manage
[ System Events ]
Error - 10/12/2010 9:21:12 PM | Computer Name = YEOLDINN | Source = Service Control Manager | ID = 7006
Description = The ScRegSetValueExW call failed for FailureActions with the following
error: %%5
Error - 10/12/2010 9:21:12 PM | Computer Name = YEOLDINN | Source = Service Control Manager | ID = 7006
Description = The ScRegSetValueExW call failed for FailureActions with the following
error: %%5
Error - 10/12/2010 10:04:22 PM | Computer Name = YEOLDINN | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)
Error - 10/12/2010 10:04:22 PM | Computer Name = YEOLDINN | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.
Error - 10/12/2010 11:12:45 PM | Computer Name = YEOLDINN | Source = DCOM | ID = 10010
Description = The server {F81CD990-910B-4BBF-9CB3-6A77F3D697B3} did not register
with DCOM within the required timeout.
Error - 10/12/2010 11:40:26 PM | Computer Name = YEOLDINN | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)
Error - 10/12/2010 11:40:26 PM | Computer Name = YEOLDINN | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.
Error - 11/12/2010 1:49:21 AM | Computer Name = YEOLDINN | Source = Service Control Manager | ID = 7006
Description = The ScRegSetValueExW call failed for Start with the following error:
%%5
Error - 11/12/2010 1:49:21 AM | Computer Name = YEOLDINN | Source = Service Control Manager | ID = 7006
Description = The ScRegSetValueExW call failed for Start with the following error:
%%5
Error - 11/12/2010 1:49:21 AM | Computer Name = YEOLDINN | Source = Service Control Manager | ID = 7006
Description = The ScRegSetValueExW call failed for Start with the following error:
%%5
< End of report >