hi mowman,
OTL logfile created on: 02/01/2011 19:14:00 - Run 2
OTL by OldTimer - Version 3.2.18.1 Folder = C:\Documents and Settings\P Compton\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 69.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): c:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 40.00 Gb Total Space | 6.10 Gb Free Space | 15.26% Space Free | Partition Type: NTFS
Drive D: | 146.31 Gb Total Space | 113.81 Gb Free Space | 77.79% Space Free | Partition Type: NTFS
Computer Name: EDITMACHINE | User Name: P Compton | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\P Compton\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Searchqu Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\WINDOWS\system32\hasplms.exe (SafeNet Inc.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe (ATI Technologies Inc.)
PRC - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe ()
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\P Compton\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (SNMPTRAP) – C:\WINDOWS\System32\snmptrap.exe File not found
SRV - (SNMP) – C:\WINDOWS\System32\snmp.exe File not found
SRV - (NBService) – C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe File not found
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe File not found
SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (gusvc) – File not found
SRV - (Fun4IM Coordinator) – C:\PROGRA~1\Fun4IM\Bandoo.exe File not found
SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe File not found
SRV - (avg9emc) – C:\Program Files\AVG\AVG9\avgemc.exe File not found
SRV - (MsMpSvc) – C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (hasplms) – C:\WINDOWS\System32\hasplms.exe (SafeNet Inc.)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (BlueSoleil Hid Service) – C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe ()
SRV - (AutoExNT) – C:\WINDOWS\system32\Autoexnt.exe ()
========== Driver Services (SafeList) ==========
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys File not found
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS File not found
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS File not found
DRV - (Lbd) – C:\WINDOWS\System32\DRIVERS\Lbd.sys File not found
DRV - (cpuz132) – C:\DOCUME~1\PCOMPT~1\LOCALS~1\Temp\cpuz132\cpuz132_x32.sys File not found
DRV - (AvgTdiX) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (NCHSSVAD) SoundTap Recorder (32 Bit) – C:\WINDOWS\system32\drivers\nchssvad.sys (NCH Swift Sound)
DRV - (aksfridge) – C:\WINDOWS\system32\drivers\aksfridge.sys (Aladdin Knowledge Systems Ltd.)
DRV - (akshasp) – C:\WINDOWS\system32\drivers\akshasp.sys (Aladdin Knowledge Systems Ltd.)
DRV - (Hardlock) – C:\WINDOWS\system32\drivers\hardlock.sys (SafeNet Inc.)
DRV - (aksusb) – C:\WINDOWS\system32\drivers\aksusb.sys (Aladdin Knowledge Systems Ltd.)
DRV - (akshhl) – C:\WINDOWS\system32\drivers\akshhl.sys (Aladdin Knowledge Systems Ltd.)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (NSCIRDA) – C:\WINDOWS\system32\drivers\nscirda.sys (National Semiconductor Corporation)
DRV - (61883) – C:\WINDOWS\system32\drivers\61883.sys (Microsoft Corporation)
DRV - (Avc) – C:\WINDOWS\system32\drivers\avc.sys (Microsoft Corporation)
DRV - (MSDV) – C:\WINDOWS\system32\drivers\msdv.sys (Microsoft Corporation)
DRV - (MSTAPE) – C:\WINDOWS\system32\drivers\mstape.sys (Microsoft Corporation)
DRV - (AVCSTRM) – C:\WINDOWS\system32\drivers\avcstrm.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (cdrblock) – C:\WINDOWS\system32\drivers\cdrblock.sys (Canopus Co,. Ltd.)
DRV - (Haspnt) – C:\WINDOWS\system32\drivers\Haspnt.sys (Aladdin Knowledge Systems)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (SiFilter) – C:\WINDOWS\system32\DRIVERS\SiWinAcc.sys (Silicon Image, Inc)
DRV - (SiRemFil) – C:\WINDOWS\system32\DRIVERS\SiRemFil.sys (Silicon Image, Inc)
DRV - (SI3132) – C:\WINDOWS\system32\DRIVERS\SI3132.sys (Silicon Image, Inc)
DRV - (n558) – C:\WINDOWS\system32\drivers\n558.sys ()
DRV - (motmodem) – C:\WINDOWS\system32\drivers\motmodem.sys (Motorola)
DRV - (MotDev) – C:\WINDOWS\system32\drivers\motodrv.sys (Motorola Inc)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (w39n51) Intel® – C:\WINDOWS\system32\drivers\w39n51.sys (Intel® Corporation)
DRV - (SynTP) – C:\WINDOWS\system32\drivers\SynTP.sys (Synaptics, Inc.)
DRV - (tifm21) – C:\WINDOWS\system32\drivers\tifm21.sys (Texas Instruments)
DRV - (Btcsrusb) – C:\WINDOWS\system32\drivers\btcusb.sys (IVT Corporation)
DRV - (BlueletAudio) – C:\WINDOWS\system32\drivers\blueletaudio.sys (IVT Corporation)
DRV - (VcommMgr) – C:\WINDOWS\system32\drivers\VcommMgr.sys (IVT Corporation)
DRV - (BT) – C:\WINDOWS\system32\drivers\BtNetDrv.sys (IVT Corporation)
DRV - (Cam5603D) – C:\WINDOWS\system32\drivers\BisonCam.sys (Bison Electronics. Inc. )
DRV - (Ktp) – C:\WINDOWS\system32\drivers\Ktp.sys (ELANTECH Devices Corp.)
DRV - (w810obex) – C:\WINDOWS\system32\drivers\w810obex.sys (MCCI)
DRV - (w810mgmt) Sony Ericsson W810 USB WMC Device Management Drivers (WDM) – C:\WINDOWS\system32\drivers\w810mgmt.sys (MCCI)
DRV - (w810mdm) – C:\WINDOWS\system32\drivers\w810mdm.sys (MCCI)
DRV - (w810mdfl) – C:\WINDOWS\system32\drivers\w810mdfl.sys (MCCI)
DRV - (w810bus) Sony Ericsson W810 Driver driver (WDM) – C:\WINDOWS\system32\drivers\w810bus.sys (MCCI)
DRV - (BlueletSCOAudio) – C:\WINDOWS\system32\drivers\BlueletSCOAudio.sys (IVT Corporation)
DRV - (BTHidEnum) – C:\WINDOWS\system32\drivers\vbtenum.sys ()
DRV - (BTHidMgr) – C:\WINDOWS\System32\Drivers\BTHidMgr.sys (IVT Corporation)
DRV - (cdrport) – C:\WINDOWS\system32\drivers\cdrport.sys (Canopus Co,. Ltd.)
DRV - (Afc) – C:\WINDOWS\system32\drivers\afc.sys (Arcsoft, Inc.)
DRV - (VComm) – C:\WINDOWS\system32\drivers\VComm.sys (IVT Corporation)
DRV - (PhilCam8116) Logitech QuickCam Pro 3000(PID_08B0) – C:\WINDOWS\system32\drivers\CamDrL21.sys (Philips Semiconductors)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://uk.search.yahoo.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://uk.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
http://www.bing.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.co.uk/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://uk.yahoo.com"
FF - prefs.js..keyword.URL: "
http://uk.search.yahoo.com/search?fr=ffds1&p="
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.search.defaulturl: "
http://uk.search.yahoo.com/search?fr=ffsp1&p="
FF - prefs.js..extensions.enabledItems: {000a9d1c-beef-4f90-9363-039d445309b8}:0.5.16.0
[2009/04/25 12:12:33 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\P Compton\Application Data\Mozilla\Extensions
[2009/01/19 13:07:28 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\P Compton\Application Data\Mozilla\Extensions\[removed]
[2010/04/13 11:35:55 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\P Compton\Application Data\Mozilla\Firefox\Profiles\jorb9q2r.default\extensions
[2010/04/13 11:35:55 | 000,000,000 | —D | M] (Vuze Remote Toolbar) – C:\Documents and Settings\P Compton\Application Data\Mozilla\Firefox\Profiles\jorb9q2r.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
File not found (No name found) – C:\PROGRAM FILES\GOOGLE\GOOGLE GEARS\FIREFOX
O1 HOSTS File: ([2010/05/24 18:55:47 | 000,000,027 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll File not found
O2 - BHO: (Searchqu Toolbar) - {7FF99715-3016-4381-84CE-E4E4C9673020} - C:\Program Files\Windows Searchqu Toolbar\ToolBar\SearchquDx.dll ()
O2 - BHO: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuz1.dll (Conduit Ltd.)
O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (Sopcast Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1203.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {7FF99715-3016-4381-84CE-E4E4C9673020} - C:\Program Files\Windows Searchqu Toolbar\ToolBar\SearchquDx.dll ()
O3 - HKLM\..\Toolbar: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\tbVuz1.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Sopcast Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Vuze Remote Toolbar) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Program Files\Vuze_Remote\tbVuz1.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Sopcast Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe File not found
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe ()
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [DATAMNGR] C:\Program Files\Windows Searchqu Toolbar\Datamngr\datamngrUI.exe (Discordia, LTD)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [KTPWare] C:\Program Files\Elantech\Ktp.exe (ELANTECH Devices Corp.)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe File not found
O4 - Startup: C:\Documents and Settings\P Compton\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.microsoft.com/windowsupdate/…b?1263498871678 (WUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {8FEFF364-6A5F-4966-A917-A3AC28411659}
http://download.sopcast.com/download/SOPCORE.CAB (SopCore Control)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll File not found
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\x-sdch {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - Reg Error: Value error. File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL File not found
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\WgaLogon: DllName - WgaLogon.dll - C:\WINDOWS\System32\WgaLogon.dll ()
O24 - Desktop WallPaper: C:\Documents and Settings\P Compton\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\P Compton\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/11/20 15:39:48 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2009/05/01 21:08:11 | 000,000,000 | R–D | M] - C:\autorun.inf – [ NTFS ]
O32 - AutoRun File - [2009/05/01 21:08:11 | 000,000,000 | R–D | M] - D:\autorun.inf – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - File not found
O34 - HKLM BootExecute: (sprestrt) - C:\WINDOWS\System32\sprestrt.exe (Microsoft Corporation)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found
========== Files/Folders - Created Within 30 Days ==========
[2011/01/02 16:05:30 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/01/02 15:42:35 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/01/02 15:42:33 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/01/02 15:42:33 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/12/29 12:24:50 | 000,601,600 | —- | C] (OldTimer Tools) – C:\Documents and Settings\P Compton\Desktop\OTL.exe
[2010/12/28 23:58:20 | 000,014,640 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\spmsg.dll
[2010/12/28 23:42:30 | 000,000,000 | —D | C] – C:\Documents and Settings\P Compton\Application Data\Bandoo
[2010/12/28 23:42:17 | 000,000,000 | —D | C] – C:\Documents and Settings\P Compton\Application Data\searchqutb
[2010/12/28 23:42:14 | 000,000,000 | —D | C] – C:\Program Files\Windows Searchqu Toolbar
[2010/12/28 23:42:13 | 000,000,000 | —D | C] – C:\Program Files\Fun4IM
[2010/12/28 18:02:15 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2010/12/28 17:51:57 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/12/28 17:51:45 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/12/28 17:51:45 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/12/28 17:51:45 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/12/28 17:04:25 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Conduit
[2010/12/28 17:04:22 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Vuze_Remote
[2010/12/28 15:37:20 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2010/12/28 15:37:20 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2010/12/28 14:25:11 | 000,000,000 | RH-D | C] – C:\Documents and Settings\P Compton\Recent
[2010/12/28 13:40:12 | 000,000,000 | —D | C] – C:\Documents and Settings\P Compton\Local Settings\Application Data\{033964CD-4C22-4505-A7A9-BD9546940F05}
[2010/12/28 13:18:28 | 000,000,000 | —D | C] – C:\Program Files\WOT
[2010/12/27 19:43:31 | 000,000,000 | —D | C] – C:\Program Files\Veetle
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/01/02 19:12:08 | 000,000,430 | -H– | M] () – C:\WINDOWS\tasks\User_Feed_Synchronization-{682B6A91-0EC6-4D3F-A3F5-E62BA9D4F6B4}.job
[2011/01/02 19:01:00 | 000,000,242 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2011/01/02 17:08:22 | 000,000,424 | -H– | M] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011/01/02 16:00:17 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/01/02 15:42:38 | 000,000,754 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/01/01 17:38:46 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/01/01 17:37:44 | 001,232,020 | —- | M] () – C:\Documents and Settings\P Compton\Desktop\tdsskiller.zip
[2010/12/31 17:32:12 | 000,001,252 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/12/30 18:38:48 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2010/12/30 18:38:24 | 000,000,840 | —- | M] () – C:\Documents and Settings\P Compton\Desktop\Windows Media Player.lnk
[2010/12/29 12:44:13 | 000,288,107 | —- | M] () – C:\Documents and Settings\P Compton\Desktop\gmer.zip
[2010/12/29 12:25:04 | 000,601,600 | —- | M] (OldTimer Tools) – C:\Documents and Settings\P Compton\Desktop\OTL.exe
[2010/12/28 23:58:04 | 000,023,392 | —- | M] () – C:\WINDOWS\System32\nscompat.tlb
[2010/12/28 23:58:04 | 000,016,832 | —- | M] () – C:\WINDOWS\System32\amcompat.tlb
[2010/12/28 23:42:02 | 000,001,730 | —- | M] () – C:\Documents and Settings\P Compton\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch WhiteSmoke.lnk
[2010/12/28 18:03:15 | 000,001,945 | —- | M] () – C:\WINDOWS\epplauncher.mif
[2010/12/28 17:55:25 | 007,864,320 | —- | M] () – C:\Documents and Settings\P Compton\ntuser.bak
[2010/12/28 17:49:02 | 000,464,140 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/12/28 17:49:02 | 000,079,562 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/12/28 17:38:54 | 000,002,187 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2010/12/28 13:40:14 | 000,000,120 | —- | M] () – C:\WINDOWS\Yvagejivuluyet.dat
[2010/12/28 13:40:14 | 000,000,000 | —- | M] () – C:\WINDOWS\Pkacovoxadosex.bin
[2010/12/27 20:01:20 | 000,000,724 | —- | M] () – C:\Documents and Settings\P Compton\Desktop\SopCast.lnk
[2010/12/20 18:09:00 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/12/20 18:08:40 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/12/19 14:30:30 | 002,207,840 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/12/18 17:23:00 | 000,001,393 | —- | M] () – C:\WINDOWS\imsins.BAK
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/01/02 15:42:38 | 000,000,754 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/01/01 17:37:28 | 001,232,020 | —- | C] () – C:\Documents and Settings\P Compton\Desktop\tdsskiller.zip
[2010/12/29 13:16:18 | 000,026,762 | —- | C] () – C:\Documents and Settings\P Compton\Desktop\gmer.text
[2010/12/29 12:44:12 | 000,288,107 | —- | C] () – C:\Documents and Settings\P Compton\Desktop\gmer.zip
[2010/12/28 23:42:02 | 000,001,730 | —- | C] () – C:\Documents and Settings\P Compton\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch WhiteSmoke.lnk
[2010/12/28 18:07:47 | 000,000,424 | -H– | C] () – C:\WINDOWS\tasks\MP Scheduled Scan.job
[2010/12/28 17:59:39 | 000,001,945 | —- | C] () – C:\WINDOWS\epplauncher.mif
[2010/12/28 13:40:14 | 000,000,120 | —- | C] () – C:\WINDOWS\Yvagejivuluyet.dat
[2010/12/28 13:40:14 | 000,000,000 | —- | C] () – C:\WINDOWS\Pkacovoxadosex.bin
[2010/06/03 11:37:47 | 000,000,576 | —- | C] () – C:\Documents and Settings\All Users\Application Data\afl.log
[2010/05/19 09:08:13 | 000,000,132 | —- | C] () – C:\Documents and Settings\P Compton\Local Settings\Application Data\fusioncache.dat
[2010/04/10 17:21:31 | 000,002,320 | —- | C] () – C:\WINDOWS\System32\Servmess.dll
[2010/04/09 01:09:00 | 000,017,182 | -HS- | C] () – C:\Documents and Settings\P Compton\Local Settings\Application Data\8O3lJ
[2010/04/09 01:09:00 | 000,017,182 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\8O3lJ
[2010/04/08 23:07:35 | 000,001,690 | -HS- | C] () – C:\Documents and Settings\P Compton\Local Settings\Application Data\1474v
[2010/04/08 23:07:35 | 000,001,690 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\1474v
[2009/08/03 14:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/02 12:21:43 | 000,819,200 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2009/08/02 12:21:43 | 000,180,224 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2009/07/23 10:52:45 | 000,000,241 | —- | C] () – C:\WINDOWS\QSync.INI
[2009/07/23 10:51:06 | 000,000,544 | —- | C] () – C:\WINDOWS\_delis32.ini
[2009/07/23 10:50:51 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\MimicICM.dll
[2009/07/23 10:38:15 | 000,005,187 | R— | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2009/04/24 22:34:25 | 001,122,304 | —- | C] () – C:\WINDOWS\System32\Boris TTK Renderer.dll
[2009/04/24 22:34:25 | 000,813,056 | —- | C] () – C:\WINDOWS\System32\Boris TTK Scene.dll
[2009/04/24 22:34:25 | 000,208,896 | —- | C] () – C:\WINDOWS\System32\Boris TTK Utilities.dll
[2009/04/24 22:34:25 | 000,094,720 | —- | C] () – C:\WINDOWS\System32\Boris TTK Render Node.dll
[2009/04/24 22:34:22 | 000,000,000 | —- | C] () – C:\WINDOWS\ScriptTO6.0.ini
[2009/04/24 22:34:22 | 000,000,000 | —- | C] () – C:\WINDOWS\ScriptLD6.0.ini
[2009/04/24 22:34:22 | 000,000,000 | —- | C] () – C:\WINDOWS\ScriptET6.0.ini
[2009/04/24 22:34:22 | 000,000,000 | —- | C] () – C:\WINDOWS\ScriptES6.0.ini
[2009/04/24 22:34:17 | 018,619,392 | —- | C] () – C:\WINDOWS\System32\BCC6_AE_16Bit.dll
[2009/04/24 22:33:59 | 018,531,840 | —- | C] () – C:\WINDOWS\System32\BCC6_AE_8Bit.dll
[2009/04/24 22:22:18 | 000,000,000 | —- | C] () – C:\WINDOWS\BorisFX BCC6.ini
[2009/04/17 20:10:52 | 000,000,302 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2008/09/05 23:30:42 | 000,003,584 | —- | C] () – C:\WINDOWS\System32\WgaLogon.dll
[2008/07/21 16:14:10 | 000,073,728 | —- | C] () – C:\WINDOWS\System32\RtNicProp32.dll
[2008/06/21 19:01:02 | 000,000,000 | —- | C] () – C:\WINDOWS\mngui.INI
[2008/05/16 09:11:23 | 000,000,118 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2008/01/23 11:53:38 | 000,237,568 | R— | C] () – C:\WINDOWS\System32\qtmlClient.dll
[2007/12/30 18:03:45 | 000,001,755 | —- | C] () – C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2007/12/01 22:25:20 | 000,117,248 | —- | C] () – C:\Documents and Settings\P Compton\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/12/01 17:17:13 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/11/30 17:39:17 | 000,000,383 | —- | C] () – C:\WINDOWS\System32\haspdos.sys
[2007/11/30 17:38:37 | 000,002,098 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2007/11/30 17:06:41 | 000,000,034 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2007/11/29 23:33:06 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2007/11/27 14:12:18 | 000,000,103 | —- | C] () – C:\WINDOWS\canopus.ini
[2007/11/21 11:42:51 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\pavedius4db.dll
[2007/11/21 11:42:51 | 000,057,344 | —- | C] () – C:\WINDOWS\System32\pavedius.dll
[2007/11/21 11:07:21 | 000,172,032 | —- | C] () – C:\WINDOWS\System32\tifmicon.dll
[2007/11/21 11:05:52 | 000,532,544 | —- | C] () – C:\WINDOWS\PIC.dll
[2007/11/21 11:05:52 | 000,024,576 | —- | C] () – C:\WINDOWS\HKNTDLL.dll
[2007/11/21 10:41:36 | 000,015,190 | —- | C] () – C:\WINDOWS\M2000Twn.ini
[2007/11/20 15:28:35 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2007/09/27 10:51:02 | 000,020,698 | —- | C] () – C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | —- | C] () – C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | —- | C] () – C:\WINDOWS\System32\gthrctr.ini
[2007/08/15 07:27:18 | 000,009,600 | —- | C] () – C:\WINDOWS\System32\drivers\n558.sys
[2006/04/14 09:14:12 | 000,014,312 | —- | C] () – C:\WINDOWS\System32\drivers\BTNetFilter.sys
[2005/08/12 21:57:09 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2005/07/30 07:21:32 | 000,011,988 | —- | C] () – C:\WINDOWS\System32\drivers\vbtenum.sys
[1999/01/27 12:39:06 | 000,065,024 | —- | C] () – C:\WINDOWS\System32\indounin.dll
[1997/06/13 06:56:08 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\Iyvu9_32.dll
========== LOP Check ==========
[2010/05/29 22:58:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2008/02/03 21:59:31 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Azureus
[2007/11/29 23:47:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Bluetooth
[2009/08/04 19:25:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Canopus
[2009/08/04 19:25:34 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DriverScanner
[2007/11/30 17:45:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grass Valley
[2009/10/06 08:54:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Juicer3
[2010/11/15 14:09:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2010/04/08 18:15:09 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2010/10/06 12:05:59 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\proDAD
[2010/02/21 23:57:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/01/22 13:32:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TomTom
[2009/06/28 09:54:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2010/04/11 19:06:19 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009/12/29 14:20:11 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/07/28 13:09:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2010/02/13 18:47:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}
[2010/05/20 22:13:47 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\AVG9
[2010/12/19 21:44:46 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Azureus
[2010/12/28 23:42:30 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Bandoo
[2007/11/29 23:36:51 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Canopus
[2010/10/03 17:20:45 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\FileZilla
[2007/12/23 15:59:04 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Grass Valley
[2009/01/21 22:38:28 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Inscriber
[2008/10/10 11:53:33 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\LimeWire
[2008/06/21 18:45:51 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Motorola
[2010/11/15 14:16:51 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\NCH Swift Sound
[2009/05/22 19:12:47 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\OpenCandy
[2010/02/05 16:53:31 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Recordpad
[2010/03/22 19:16:54 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Red Kawa
[2010/12/30 19:13:00 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\searchqutb
[2008/06/21 18:48:00 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Teleca
[2009/01/19 13:07:24 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\TomTom
[2009/08/04 19:25:35 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Uniblue
[2008/11/06 11:17:45 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Windows Desktop Search
[2008/11/07 15:54:16 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\Windows Search
[2007/12/04 18:00:20 | 000,000,000 | —D | M] – C:\Documents and Settings\P Compton\Application Data\WinPatrol
[2010/11/28 09:40:00 | 000,000,472 | —- | M] () – C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2010/11/15 14:07:38 | 000,000,302 | —- | M] () – C:\WINDOWS\Tasks\expressripDowngrade.job
[2010/11/21 14:07:00 | 000,000,302 | —- | M] () – C:\WINDOWS\Tasks\expressripShakeIcon.job
[2011/01/02 17:08:22 | 000,000,424 | -H– | M] () – C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2011/01/02 19:01:00 | 000,000,242 | —- | M] () – C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
[2011/01/02 19:12:08 | 000,000,430 | -H– | M] () – C:\WINDOWS\Tasks\User_Feed_Synchronization-{682B6A91-0EC6-4D3F-A3F5-E62BA9D4F6B4}.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >
the computer is running ok now , no redirects at all so far