hi thanks here is the results
OTL logfile created on: 11/02/2011 13:53:10 - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\Owner\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 63.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 88.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.30 Gb Total Space | 20.08 Gb Free Space | 53.85% Space Free | Partition Type: NTFS
Drive D: | 2.52 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Computer Name: TURNER-HOME | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Owner\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\STOPzilla!\STOPzilla.exe (iS3, Inc.)
PRC - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe (iS3, Inc.)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSMonitor.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\ATKKBService.exe (ASUSTeK COMPUTER INC.)
PRC - C:\ATI-CPanel\atiptaxx.exe (ATI Technologies, Inc.)
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
PRC - C:\Program Files\Lexmark 3100 Series\lxbrbmgr.exe (Lexmark International, Inc.)
PRC - C:\Program Files\Lexmark 3100 Series\lxbrcmon.exe ()
PRC - C:\Program Files\Lexmark 3100 Series\lxbrbmon.exe (Lexmark International, Inc.)
PRC - C:\Program Files\Lexmark 3100 Series\lxbrksk.exe ( )
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Owner\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (HidServ) – File not found
SRV - (AppMgmt) – File not found
SRV - (szserver) – C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe (iS3, Inc.)
SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9emc) – C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (WPFFontCache_v0400) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (ATKKeyboardService) – C:\WINDOWS\ATKKBService.exe (ASUSTeK COMPUTER INC.)
========== Driver Services (SafeList) ==========
DRV - (AvgTdiX) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSDriverxpx) – C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilterxpx) – C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSShimxpx) – C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSErHrxpx) – C:\WINDOWS\System32\Drivers\AVGIDSxx.sys (AVG Technologies CZ, s.r.o. )
DRV - (AvgLdx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgRkx86) – C:\WINDOWS\System32\Drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (szkgfs) – C:\WINDOWS\system32\drivers\szkgfs.sys (iS3, Inc.)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (szkg5) – C:\WINDOWS\system32\DRIVERS\szkg.sys (iS3 Inc.)
DRV - (is3srv) – C:\WINDOWS\system32\drivers\is3srv.sys (iS3 Inc.)
DRV - (RTL8023xp) – C:\WINDOWS\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (EIO) – C:\WINDOWS\system32\drivers\EIO.sys (ASUSTeK Computer Inc.)
DRV - (asuskbnt) – C:\WINDOWS\system32\drivers\atkkbnt.sys (ASUSTeK COMPUTER INC.)
DRV - (RecAgent) – C:\WINDOWS\system32\DRIVERS\RecAgent.sys (Smart Link)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (ALCXSENS) – C:\WINDOWS\system32\drivers\ALCXSENS.SYS (Sensaura)
DRV - (Slntamr) – C:\WINDOWS\system32\drivers\slntamr.sys ( )
DRV - (Mtlmnt5) – C:\WINDOWS\system32\drivers\mtlmnt5.sys ( )
DRV - (Mtlstrm) – C:\WINDOWS\system32\drivers\mtlstrm.sys ( )
DRV - (SlNtHal) – C:\WINDOWS\system32\drivers\slnthal.sys ( )
DRV - (SlWdmSup) – C:\WINDOWS\system32\drivers\slwdmsup.sys (Vireo Software)
DRV - (NtMtlFax) – C:\WINDOWS\system32\drivers\ntmtlfax.sys ( )
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://uk.msn.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
[2010/07/28 21:05:30 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
O1 HOSTS File: ([2004/08/04 12:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (PlaySushi) - {21608B66-026F-4DCB-9244-0DACA328DCED} - C:\Program Files\PlaySushi\PSText.dll ()
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (STOPzilla Browser Helper Object) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll (iS3, Inc.)
O4 - HKLM..\Run: [ATIPTA] C:\ATI-CPanel\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Lexmark 3100 Series] C:\Program Files\Lexmark 3100 Series\lxbrbmgr.exe (Lexmark International, Inc.)
O4 - HKLM..\Run: [LXBRKsk] C:\Program Files\Lexmark 3100 Series\lxbrksk.exe ( )
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\control panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\control panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 00 02 00 00 [binary data]
O9 - Extra Button: Go to PlaySushi web site - {EBD24BD3-E272-4FA3-A8BA-C5D709757CAB} - C:\Program Files\PlaySushi\PSText.dll ()
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/microsoftu…b?1276430777812 (MUWebControl Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/06/08 16:17:32 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2010/08/16 12:57:50 | 000,000,154 | R— | M] () - D:\autorun.cfg – [ UDF ]
O32 - AutoRun File - [2010/10/05 14:53:16 | 000,214,344 | R— | M] (Sports Interactive) - D:\autorun.exe – [ UDF ]
O32 - AutoRun File - [2006/09/11 13:26:42 | 000,000,027 | R— | M] () - D:\autorun.inf – [ UDF ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – Reg Error: Key error. File not found
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax ()
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll ()
Drivers32: wave - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (56871556046913536)
========== Files/Folders - Created Within 30 Days ==========
[2011/02/11 11:45:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\STOPzilla
[2011/02/11 11:45:02 | 000,000,000 | —D | C] – C:\Program Files\STOPzilla!
[2011/02/11 11:45:02 | 000,000,000 | —D | C] – C:\Program Files\Common Files\iS3
[2011/02/11 11:45:01 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2011/02/10 18:21:38 | 000,546,256 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\SZComp5.dll
[2011/02/10 18:21:38 | 000,452,048 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\SZBase5.dll
[2011/02/10 18:21:38 | 000,132,560 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3HTUI5.dll
[2011/02/10 18:21:38 | 000,022,992 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\SZIO5.dll
[2011/02/10 18:21:36 | 000,398,800 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3DBA5.dll
[2011/02/10 18:21:36 | 000,099,792 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3Svc5.dll
[2011/02/10 18:21:36 | 000,099,792 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3Inet5.dll
[2011/02/10 18:21:36 | 000,067,024 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3Hks5.dll
[2011/02/10 18:21:36 | 000,028,624 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3XDat5.dll
[2011/02/10 18:21:34 | 000,738,768 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3Base5.dll
[2011/02/10 18:21:34 | 000,390,608 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3UI5.dll
[2011/02/10 18:21:34 | 000,230,864 | R— | C] (iS3, Inc.) – C:\WINDOWS\System32\IS3Win325.dll
[2011/02/10 10:59:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Malwarebytes
[2011/02/10 10:59:10 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/02/10 10:59:10 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/02/10 10:59:10 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/02/10 10:59:06 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/02/10 10:59:06 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/02/10 10:56:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
[2011/02/10 10:56:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2011/02/10 10:56:16 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\SUPERAntiSpyware
[2011/02/10 10:56:11 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2011/01/21 14:44:37 | 000,439,296 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shimgvw.dll
[2011/01/16 08:49:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\Lisa Work
[2011/01/15 07:04:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\End of Life Care
[2010/06/21 09:35:58 | 000,155,648 | —- | C] ( ) – C:\WINDOWS\System32\flashshl.dll
[2010/06/08 17:05:18 | 001,301,128 | —- | C] ( ) – C:\WINDOWS\System32\drivers\mtlstrm.sys
[2010/06/08 17:05:18 | 000,548,952 | —- | C] ( ) – C:\WINDOWS\System32\drivers\slntamr.sys
[2010/06/08 17:05:18 | 000,221,736 | —- | C] ( ) – C:\WINDOWS\System32\drivers\mtlmnt5.sys
[2010/06/08 17:05:18 | 000,167,384 | —- | C] ( ) – C:\WINDOWS\System32\drivers\ntmtlfax.sys
[2010/06/08 17:05:18 | 000,086,128 | —- | C] ( ) – C:\WINDOWS\System32\drivers\slnthal.sys
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/02/11 12:17:30 | 000,481,000 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/02/11 12:17:30 | 000,079,074 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/02/11 11:54:55 | 000,000,310 | -HS- | M] () – C:\WINDOWS\tasks\Octomntob.job
[2011/02/11 11:54:38 | 000,000,240 | —- | M] () – C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2011/02/11 11:53:31 | 000,000,022 | —- | M] () – C:\WINDOWS\FLASHKSK.INI
[2011/02/11 11:53:25 | 000,003,206 | —- | M] () – C:\WINDOWS\LXBRCAH.ini
[2011/02/11 11:53:21 | 000,013,688 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/02/11 11:53:14 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/02/10 18:21:38 | 000,546,256 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\SZComp5.dll
[2011/02/10 18:21:38 | 000,452,048 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\SZBase5.dll
[2011/02/10 18:21:38 | 000,132,560 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3HTUI5.dll
[2011/02/10 18:21:38 | 000,022,992 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\SZIO5.dll
[2011/02/10 18:21:36 | 000,398,800 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3DBA5.dll
[2011/02/10 18:21:36 | 000,099,792 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3Svc5.dll
[2011/02/10 18:21:36 | 000,099,792 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3Inet5.dll
[2011/02/10 18:21:36 | 000,067,024 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3Hks5.dll
[2011/02/10 18:21:36 | 000,028,624 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3XDat5.dll
[2011/02/10 18:21:34 | 000,738,768 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3Base5.dll
[2011/02/10 18:21:34 | 000,390,608 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3UI5.dll
[2011/02/10 18:21:34 | 000,230,864 | R— | M] (iS3, Inc.) – C:\WINDOWS\System32\IS3Win325.dll
[2011/02/10 18:12:56 | 000,026,112 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Monday.doc
[2011/02/10 17:46:56 | 000,133,280 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/02/10 11:12:47 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/02/10 10:59:10 | 000,000,784 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/02/10 10:56:17 | 000,001,678 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/02/10 10:47:37 | 000,001,729 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2011/02/09 05:22:51 | 000,050,688 | —- | M] () – C:\Documents and Settings\Owner\My Documents\Resident Bath Preferences & Record[1].xls
[2011/02/05 15:26:48 | 000,002,201 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\FMRTE.lnk
[2011/02/03 17:44:02 | 000,026,624 | —- | M] () – C:\Documents and Settings\Owner\My Documents\266349_cv current 3[1].doc
[2011/01/26 21:52:14 | 000,069,632 | RHS- | M] () – C:\WINDOWS\System32\CatRootf.dll
[2011/01/26 17:14:50 | 007,586,816 | —- | M] () – C:\Documents and Settings\Owner\My Documents\1st Choice Pre Jan 2011 vista[1].ppt
[2011/01/21 14:44:37 | 008,462,336 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shell32.dll
[2011/01/21 14:44:37 | 000,439,296 | —- | M] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shimgvw.dll
[2011/01/14 20:29:00 | 000,000,324 | —- | M] () – C:\WINDOWS\lexstat.ini
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/02/11 11:54:38 | 000,000,240 | —- | C] () – C:\WINDOWS\System32\drivers\kgpcpy.cfg
[2011/02/10 18:12:56 | 000,026,112 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Monday.doc
[2011/02/10 10:59:10 | 000,000,784 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/02/10 10:56:17 | 000,001,678 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/02/09 05:22:51 | 000,050,688 | —- | C] () – C:\Documents and Settings\Owner\My Documents\Resident Bath Preferences & Record[1].xls
[2011/02/03 17:44:02 | 000,026,624 | —- | C] () – C:\Documents and Settings\Owner\My Documents\266349_cv current 3[1].doc
[2011/01/26 21:52:14 | 000,069,632 | RHS- | C] () – C:\WINDOWS\System32\CatRootf.dll
[2011/01/26 21:52:14 | 000,000,310 | -HS- | C] () – C:\WINDOWS\tasks\Octomntob.job
[2011/01/26 17:14:50 | 007,586,816 | —- | C] () – C:\Documents and Settings\Owner\My Documents\1st Choice Pre Jan 2011 vista[1].ppt
[2010/12/12 17:28:17 | 000,124,362 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-1547161642-115176313-725345543-1003-0.dat
[2010/12/03 12:24:56 | 000,124,362 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2010/07/27 16:13:12 | 000,078,344 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010/06/21 09:35:58 | 000,000,022 | —- | C] () – C:\WINDOWS\FLASHKSK.INI
[2010/06/21 09:35:57 | 000,000,468 | —- | C] () – C:\WINDOWS\LXBRFMT.INI
[2010/06/21 09:35:55 | 000,003,206 | —- | C] () – C:\WINDOWS\LXBRCAH.ini
[2010/06/21 09:35:53 | 000,002,178 | —- | C] () – C:\WINDOWS\System32\LXBRSET.INI
[2010/06/21 09:34:00 | 000,000,324 | —- | C] () – C:\WINDOWS\lexstat.ini
[2010/06/21 09:33:24 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\lxbrvs.dll
[2010/06/21 09:32:53 | 000,000,181 | —- | C] () – C:\WINDOWS\System32\lxbrcoin.ini
[2010/06/19 11:04:39 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2010/06/13 17:50:43 | 000,155,648 | R— | C] () – C:\WINDOWS\System32\RTLCPAPI.dll
[2010/06/08 17:05:18 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\slextspk.dll
[2010/06/08 17:05:18 | 000,159,744 | —- | C] () – C:\WINDOWS\System32\SLGen.dll
[2010/06/08 17:03:30 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2010/06/08 16:28:52 | 000,046,592 | —- | C] () – C:\WINDOWS\System32\asfrench.dll
[2010/06/08 16:28:52 | 000,046,080 | —- | C] () – C:\WINDOWS\System32\asrussian.dll
[2010/06/08 16:28:52 | 000,046,080 | —- | C] () – C:\WINDOWS\System32\asgerman.dll
[2010/06/08 16:28:52 | 000,046,080 | —- | C] () – C:\WINDOWS\System32\aseng.dll
[2010/06/08 16:28:52 | 000,045,568 | —- | C] () – C:\WINDOWS\System32\askorean.dll
[2010/06/08 16:28:52 | 000,045,568 | —- | C] () – C:\WINDOWS\System32\asjapan.dll
[2010/06/08 16:28:52 | 000,045,568 | —- | C] () – C:\WINDOWS\System32\ASCHT.dll
[2010/06/08 16:28:52 | 000,045,568 | —- | C] () – C:\WINDOWS\System32\aschs.dll
[2010/06/08 16:28:52 | 000,010,496 | —- | C] () – C:\WINDOWS\System32\ATKOSDMini.DLL
[2010/06/08 16:28:52 | 000,000,018 | —- | C] () – C:\WINDOWS\System32\atkid.ini
[2006/08/11 13:45:20 | 000,581,632 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2006/08/11 13:43:10 | 000,196,608 | —- | C] () – C:\WINDOWS\System32\nvapi.dll
[2006/08/11 13:43:00 | 001,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2006/08/11 13:43:00 | 001,470,464 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2006/08/11 13:43:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2006/08/11 13:43:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2006/08/11 13:43:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2006/05/03 16:44:54 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\ati2evxx.dll
[2004/08/04 12:00:00 | 000,755,200 | —- | C] () – C:\WINDOWS\System32\ir50_32.dll
[2004/08/04 12:00:00 | 000,338,432 | —- | C] () – C:\WINDOWS\System32\ir41_qcx.dll
[2004/08/04 12:00:00 | 000,200,192 | —- | C] () – C:\WINDOWS\System32\ir50_qc.dll
[2004/08/04 12:00:00 | 000,183,808 | —- | C] () – C:\WINDOWS\System32\ir50_qcx.dll
[2004/08/04 12:00:00 | 000,120,320 | —- | C] () – C:\WINDOWS\System32\ir41_qc.dll
[2003/07/02 16:04:32 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\coinst.dll
[1999/01/22 10:46:58 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
========== LOP Check ==========
[2010/06/13 13:28:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2010/12/19 08:30:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2010/06/19 11:46:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sports Interactive
[2011/02/11 13:51:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\STOPzilla!
[2010/12/19 08:55:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/11/28 12:09:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Vivitar
[2010/11/28 12:09:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Vivitar Experience Image Manager
[2010/06/15 18:02:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\AVG9
[2010/07/11 10:18:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\My Games
[2010/11/05 10:43:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Sports Interactive
[2011/02/11 12:00:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\uTorrent
[2010/06/19 12:42:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Windows Search
[2011/02/11 11:54:55 | 000,000,310 | -HS- | M] () – C:\WINDOWS\Tasks\Octomntob.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/06/08 16:17:32 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/06/14 08:54:54 | 000,000,210 | -HS- | M] () – C:\boot.ini
[2010/06/08 16:17:32 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/06/13 18:30:28 | 000,000,040 | —- | M] () – C:\CTJINI.INI
[2010/06/13 18:30:43 | 000,001,319 | —- | M] () – C:\drvpnp.dat
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2007/11/07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 08:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2010/06/08 16:17:32 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/06/08 16:17:32 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/04 12:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/06/13 12:55:08 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/02/11 11:53:11 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2010/06/13 18:30:41 | 000,000,657 | —- | M] () – C:\pnpID.dat
[2011/02/11 13:49:12 | 000,038,528 | —- | M] () – C:\TDSSKiller.2.4.17.0_11.02.2011_13.48.35_log.txt
[2011/02/11 13:50:07 | 000,038,528 | —- | M] () – C:\TDSSKiller.2.4.17.0_11.02.2011_13.49.41_log.txt
[2010/06/13 18:33:10 | 000,000,091 | —- | M] () – C:\temp.log
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI
< %systemroot%\Fonts\*.com >
[2006/04/18 14:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 13:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 14:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 13:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2010/06/08 16:17:04 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 12:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2003/07/29 09:45:10 | 000,078,336 | —- | M] () – C:\WINDOWS\system32\spool\prtprocs\w32x86\LXBRPP5C.DLL
[2008/07/06 10:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2010/09/22 17:10:37 | 000,001,666 | -H– | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2010/06/08 17:00:49 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2010/06/08 17:00:49 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2010/06/08 17:00:49 | 000,901,120 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010/06/13 12:59:53 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/06/13 13:10:29 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/06/08 16:23:31 | 000,000,079 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
[2010/10/16 09:49:31 | 023,458,816 | —- | M] () – C:\Documents and Settings\Owner\My Documents\242.exe
[2010/06/19 12:37:21 | 000,889,416 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Owner\My Documents\dotNetFx40_Full_setup.exe
[2010/11/20 10:22:01 | 180,137,984 | —- | M] () – C:\Documents and Settings\Owner\My Documents\fm2011v11.1.1_pc_dit_patch.exe
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2010/06/13 13:10:29 | 000,000,122 | -HS- | M] () – C:\Documents and Settings\Owner\Favorites\Desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
[2011/02/11 13:53:08 | 000,065,536 | —- | M] () – C:\Documents and Settings\Owner\Cookies\index.dat
< %SystemRoot%\system32\fonts\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-02-10 11:12:47
< >
========== Alternate Data Streams ==========
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:59846E5E
< End of report >
OTL Extras logfile created on: 11/02/2011 13:53:10 - Run 1
OTL by OldTimer - Version 3.2.20.6 Folder = C:\Documents and Settings\Owner\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 63.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 88.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.30 Gb Total Space | 20.08 Gb Free Space | 53.85% Space Free | Partition Type: NTFS
Drive D: | 2.52 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Computer Name: TURNER-HOME | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.exe [@ = exefile] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:TCP" = 1900:TCP:LocalSubNet:Enabled:UDP 1900
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Sports Interactive\Football Manager 2010\fm.exe" = C:\Program Files\Sports Interactive\Football Manager 2010\fm.exe:*:Enabled:Football Manager 2010 – (Sports Interactive)
"C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Civilization4.exe" = C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Civilization4.exe:*:Enabled:Sid Meier's Civilization 4 – (Firaxis Games)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\Program Files\Sports Interactive\Football Manager 2011\fm.exe" = C:\Program Files\Sports Interactive\Football Manager 2011\fm.exe:*:Enabled:Football Manager 2011 – (Sports Interactive)
"C:\Program Files\AVG\AVG9\avgam.exe" = C:\Program Files\AVG\AVG9\avgam.exe:*:Disabled:avgam.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgdiagex.exe" = C:\Program Files\AVG\AVG9\avgdiagex.exe:*:Disabled:avgdiagex.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgemc.exe" = C:\Program Files\AVG\AVG9\avgemc.exe:*:Disabled:avgemc.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Disabled:avgnsx.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Disabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00000409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Premium
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{22C29E59-2EF5-4B64-9B7F-9F7A69BC7D1A}" = FMRTE
"{315ACD04-BCEB-478B-9B1D-5431D0E6CB11}" = ASUS Enhanced Display Driver
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{4377F918-E6C9-4ECA-A7F5-754B310B7ED8}" = Sid Meier's Civilization 4
"{73CB01A1-A9D0-41CA-B490-348880975F48}" = STOPzilla
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.2
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CFBCE791-2D53-4FCE-B3FB-D6E01F4112E8}" = Sid Meier's Civilization 4
"{D1696920-9794-4BBC-8A30-7A88763DE5A2}" = ABBYY FineReader 5.0 Sprint
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{F8131A35-47FD-27AD-116D-0E79AF5DE5EE}" = Acrobat.com
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"All ATI Software" = ATI - Software Uninstall Utility
"ATI Display Driver" = ATI Display Driver
"AVG9Uninstall" = AVG 9.0
"BFG-Luxor 3" = Luxor 3
"Championship Manager 01-02" = Championship Manager 01-02
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Football Manager 2010" = Football Manager 2010
"Football Manager 2011" = Football Manager 2011
"ie8" = Windows Internet Explorer 8
"Lexmark 3100 Series" = Lexmark 3100 Series
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NVIDIA Drivers" = NVIDIA Drivers
"Playsushi" = Playsushi
"uTorrent" = µTorrent
"Vivitar Experience Image Manager" = Vivitar Experience Image Manager
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
========== Last 10 Event Log Errors ==========
[ System Events ]
Error - 11/02/2011 08:15:43 | Computer Name = TURNER-HOME | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 11/02/2011 08:15:43 | Computer Name = TURNER-HOME | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 11/02/2011 08:15:43 | Computer Name = TURNER-HOME | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 11/02/2011 08:15:43 | Computer Name = TURNER-HOME | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 11/02/2011 08:15:44 | Computer Name = TURNER-HOME | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 11/02/2011 08:15:44 | Computer Name = TURNER-HOME | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 11/02/2011 08:15:44 | Computer Name = TURNER-HOME | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 11/02/2011 08:15:44 | Computer Name = TURNER-HOME | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 11/02/2011 08:15:44 | Computer Name = TURNER-HOME | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126
Error - 11/02/2011 08:17:22 | Computer Name = TURNER-HOME | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service WSearch with
arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
< End of report >