Hey mowman. Thanks for the help
I doubt I'll have trouble replying within 3 days.
TDSS Killer found suspicious but not malicious. I ran it twice because I couldn't find the reboot button and thought I'd missed a step. Still couldn't see it? Unless that only happens with the malicious entries after they're cured?
Anyway - here's the log
2011/02/25 15:11:02.0859 5300 TDSS rootkit removing tool 2.4.18.0 Feb 21 2011 11:08:08
2011/02/25 15:11:04.0500 5300 ================================================================================
2011/02/25 15:11:04.0500 5300 SystemInfo:
2011/02/25 15:11:04.0500 5300
2011/02/25 15:11:04.0500 5300 OS Version: 5.1.2600 ServicePack: 3.0
2011/02/25 15:11:04.0500 5300 Product type: Workstation
2011/02/25 15:11:04.0500 5300 ComputerName: SN049684320704
2011/02/25 15:11:04.0500 5300 UserName: Angel Fire
2011/02/25 15:11:04.0500 5300 Windows directory: C:\WINDOWS
2011/02/25 15:11:04.0500 5300 System windows directory: C:\WINDOWS
2011/02/25 15:11:04.0500 5300 Processor architecture: Intel x86
2011/02/25 15:11:04.0500 5300 Number of processors: 1
2011/02/25 15:11:04.0500 5300 Page size: 0x1000
2011/02/25 15:11:04.0500 5300 Boot type: Normal boot
2011/02/25 15:11:04.0500 5300 ================================================================================
2011/02/25 15:11:06.0000 5300 Initialize success
2011/02/25 15:11:09.0328 3620 ================================================================================
2011/02/25 15:11:09.0328 3620 Scan started
2011/02/25 15:11:09.0328 3620 Mode: Manual;
2011/02/25 15:11:09.0328 3620 ================================================================================
2011/02/25 15:11:11.0468 3620 2WIREPCP (6551c1cf190df3e12c435a085987fba0) C:\WINDOWS\system32\DRIVERS\2WirePCP.sys
2011/02/25 15:11:11.0562 3620 3xHybrid (c0ff161e8770f88bae6a639c56363377) C:\WINDOWS\system32\DRIVERS\3xHybrid.sys
2011/02/25 15:11:11.0671 3620 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
2011/02/25 15:11:11.0734 3620 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2011/02/25 15:11:11.0812 3620 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
2011/02/25 15:11:12.0062 3620 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys
2011/02/25 15:11:12.0125 3620 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
2011/02/25 15:11:12.0171 3620 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys
2011/02/25 15:11:12.0250 3620 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
2011/02/25 15:11:12.0281 3620 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
2011/02/25 15:11:12.0328 3620 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys
2011/02/25 15:11:12.0375 3620 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys
2011/02/25 15:11:12.0421 3620 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys
2011/02/25 15:11:12.0484 3620 alcan5wn (235ced68762538aae388cca5cdc0441a) C:\WINDOWS\system32\DRIVERS\alcan5wn.sys
2011/02/25 15:11:12.0562 3620 alcaudsl (d6652432d103b4228ffad7a754a374b5) C:\WINDOWS\system32\DRIVERS\alcaudsl.sys
2011/02/25 15:11:12.0625 3620 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys
2011/02/25 15:11:12.0671 3620 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys
2011/02/25 15:11:12.0703 3620 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys
2011/02/25 15:11:12.0750 3620 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys
2011/02/25 15:11:13.0265 3620 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
2011/02/25 15:11:13.0437 3620 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys
2011/02/25 15:11:13.0468 3620 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys
2011/02/25 15:11:13.0500 3620 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys
2011/02/25 15:11:13.0578 3620 Aspi32 (b979979ab8027f7f53fb16ec4229b7db) C:\WINDOWS\system32\drivers\Aspi32.sys
2011/02/25 15:11:13.0703 3620 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2011/02/25 15:11:13.0734 3620 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
2011/02/25 15:11:13.0796 3620 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2011/02/25 15:11:13.0843 3620 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
2011/02/25 15:11:13.0937 3620 AVGIDSDriver (0c61f066f4d94bd67063dc6691935143) C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys
2011/02/25 15:11:14.0015 3620 AVGIDSEH (84853f800cd69252c3c764fe50d0346f) C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys
2011/02/25 15:11:14.0078 3620 AVGIDSFilter (28d6adcd03e10f3838488b9b5d407dd4) C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys
2011/02/25 15:11:14.0156 3620 AVGIDSShim (0eb16f4dbbb946360af30d2b13a52d1d) C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys
2011/02/25 15:11:14.0187 3620 Avgldx86 (5fe5a2c2330c376a1d8dcff8d2680a2d) C:\WINDOWS\system32\DRIVERS\avgldx86.sys
2011/02/25 15:11:14.0218 3620 Avgmfx86 (54f1a9b4c9b540c2d8ac4baa171696b1) C:\WINDOWS\system32\DRIVERS\avgmfx86.sys
2011/02/25 15:11:14.0296 3620 Avgrkx86 (8da3b77993c5f354cc2977b7ea06d03a) C:\WINDOWS\system32\DRIVERS\avgrkx86.sys
2011/02/25 15:11:14.0359 3620 Avgtdix (660788ec46f10ece80274d564fa8b4aa) C:\WINDOWS\system32\DRIVERS\avgtdix.sys
2011/02/25 15:11:14.0453 3620 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
2011/02/25 15:11:14.0546 3620 BrScnUsb (92a964547b96d697e5e9ed43b4297f5a) C:\WINDOWS\system32\DRIVERS\BrScnUsb.sys
2011/02/25 15:11:14.0609 3620 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
2011/02/25 15:11:14.0640 3620 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2011/02/25 15:11:14.0671 3620 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
2011/02/25 15:11:14.0703 3620 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
2011/02/25 15:11:14.0750 3620 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2011/02/25 15:11:14.0984 3620 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
2011/02/25 15:11:15.0046 3620 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2011/02/25 15:11:15.0125 3620 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys
2011/02/25 15:11:15.0203 3620 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys
2011/02/25 15:11:15.0296 3620 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
2011/02/25 15:11:15.0328 3620 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys
2011/02/25 15:11:15.0390 3620 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
2011/02/25 15:11:15.0484 3620 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
2011/02/25 15:11:15.0546 3620 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
2011/02/25 15:11:15.0625 3620 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
2011/02/25 15:11:15.0750 3620 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
2011/02/25 15:11:15.0906 3620 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys
2011/02/25 15:11:16.0046 3620 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
2011/02/25 15:11:16.0140 3620 eeCtrl (e89cc1363cb7f5320ae3b41c1333d0c3) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
2011/02/25 15:11:16.0453 3620 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
2011/02/25 15:11:16.0671 3620 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
2011/02/25 15:11:16.0828 3620 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
2011/02/25 15:11:17.0156 3620 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
2011/02/25 15:11:17.0328 3620 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
2011/02/25 15:11:17.0453 3620 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2011/02/25 15:11:17.0515 3620 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2011/02/25 15:11:17.0625 3620 GEARAspiWDM (f2f431d1573ee632975c524418655b84) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
2011/02/25 15:11:17.0671 3620 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2011/02/25 15:11:17.0750 3620 HdAudAddService (2a013e7530beab6e569faa83f517e836) C:\WINDOWS\system32\drivers\HdAudio.sys
2011/02/25 15:11:17.0812 3620 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
2011/02/25 15:11:17.0875 3620 HidIr (bb1a6fb7d35a91e599973fa74a619056) C:\WINDOWS\system32\DRIVERS\hidir.sys
2011/02/25 15:11:17.0937 3620 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
2011/02/25 15:11:18.0000 3620 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys
2011/02/25 15:11:18.0046 3620 HTTP (f6aacf5bce2893e0c1754afeb672e5c9) C:\WINDOWS\system32\Drivers\HTTP.sys
2011/02/25 15:11:18.0109 3620 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys
2011/02/25 15:11:18.0218 3620 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys
2011/02/25 15:11:18.0250 3620 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
2011/02/25 15:11:18.0312 3620 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
2011/02/25 15:11:18.0484 3620 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys
2011/02/25 15:11:18.0640 3620 IntcAzAudAddService (5f2657f8781376892035976cf8122a2d) C:\WINDOWS\system32\drivers\RtkHDAud.sys
2011/02/25 15:11:18.0765 3620 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
2011/02/25 15:11:18.0812 3620 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
2011/02/25 15:11:18.0875 3620 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
2011/02/25 15:11:18.0921 3620 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
2011/02/25 15:11:19.0000 3620 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2011/02/25 15:11:19.0046 3620 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2011/02/25 15:11:19.0109 3620 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2011/02/25 15:11:19.0171 3620 IrBus (b43b36b382aea10861f7c7a37f9d4ae2) C:\WINDOWS\system32\DRIVERS\IrBus.sys
2011/02/25 15:11:19.0234 3620 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
2011/02/25 15:11:19.0265 3620 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2011/02/25 15:11:19.0328 3620 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2011/02/25 15:11:19.0375 3620 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
2011/02/25 15:11:19.0421 3620 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
2011/02/25 15:11:19.0468 3620 KSecDD (1705745d900dabf2d89f90ebaddc7517) C:\WINDOWS\system32\drivers\KSecDD.sys
2011/02/25 15:11:19.0593 3620 massfilter (59f57b06d1e3c7a3f22d62c7c5b4c3c3) C:\WINDOWS\system32\drivers\massfilter.sys
2011/02/25 15:11:19.0671 3620 mdvrmng (4e10e84320a8ec1c12bd0d00973b22ab) C:\WINDOWS\system32\drivers\mdvrmng.sys
2011/02/25 15:11:19.0828 3620 MHNDRV (7f2f1d2815a6449d346fcccbc569fbd6) C:\WINDOWS\system32\DRIVERS\mhndrv.sys
2011/02/25 15:11:19.0921 3620 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
2011/02/25 15:11:19.0984 3620 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
2011/02/25 15:11:20.0031 3620 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2011/02/25 15:11:20.0078 3620 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
2011/02/25 15:11:20.0125 3620 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
2011/02/25 15:11:20.0187 3620 MPE (c0f8e0c2c3c0437cf37c6781896dc3ec) C:\WINDOWS\system32\DRIVERS\MPE.sys
2011/02/25 15:11:20.0234 3620 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys
2011/02/25 15:11:20.0296 3620 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2011/02/25 15:11:20.0375 3620 MRxSmb (60ae98742484e7ab80c3c1450e708148) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
2011/02/25 15:11:20.0437 3620 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
2011/02/25 15:11:20.0515 3620 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2011/02/25 15:11:20.0562 3620 Msodfcteilt (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\drivers\acpi.sys
2011/02/25 15:11:20.0625 3620 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2011/02/25 15:11:20.0671 3620 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
2011/02/25 15:11:20.0734 3620 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2011/02/25 15:11:20.0781 3620 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
2011/02/25 15:11:20.0828 3620 Mtlmnt5 (32ce8d0359672bcb720bf82c86a50d71) C:\WINDOWS\system32\DRIVERS\Mtlmnt5.sys
2011/02/25 15:11:20.0921 3620 Mtlstrm (8ada829d3d7cf2db7b1c41f3c7beaa79) C:\WINDOWS\system32\DRIVERS\Mtlstrm.sys
2011/02/25 15:11:21.0015 3620 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys
2011/02/25 15:11:21.0062 3620 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
2011/02/25 15:11:21.0125 3620 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
2011/02/25 15:11:21.0187 3620 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
2011/02/25 15:11:21.0234 3620 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
2011/02/25 15:11:21.0296 3620 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2011/02/25 15:11:21.0359 3620 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2011/02/25 15:11:21.0406 3620 NDProxy (6215023940cfd3702b46abc304e1d45a) C:\WINDOWS\system32\drivers\NDProxy.sys
2011/02/25 15:11:21.0500 3620 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
2011/02/25 15:11:21.0546 3620 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
2011/02/25 15:11:21.0640 3620 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
2011/02/25 15:11:21.0718 3620 npf (6623e51595c0076755c29c00846c4eb2) C:\WINDOWS\system32\drivers\npf.sys
2011/02/25 15:11:21.0781 3620 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
2011/02/25 15:11:21.0812 3620 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
2011/02/25 15:11:21.0953 3620 NtMtlFax (f11e04e2d0034172eb2938d0bbc7b05b) C:\WINDOWS\system32\DRIVERS\NtMtlFax.sys
2011/02/25 15:11:22.0000 3620 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
2011/02/25 15:11:22.0156 3620 nv (920d2d77a9c17dc628123d16eeea5c22) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
2011/02/25 15:11:22.0312 3620 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2011/02/25 15:11:22.0359 3620 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2011/02/25 15:11:22.0390 3620 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
2011/02/25 15:11:22.0453 3620 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
2011/02/25 15:11:22.0515 3620 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
2011/02/25 15:11:22.0562 3620 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
2011/02/25 15:11:22.0625 3620 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
2011/02/25 15:11:22.0703 3620 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
2011/02/25 15:11:22.0765 3620 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
2011/02/25 15:11:23.0046 3620 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys
2011/02/25 15:11:23.0093 3620 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys
2011/02/25 15:11:23.0203 3620 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2011/02/25 15:11:23.0250 3620 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys
2011/02/25 15:11:23.0296 3620 prodrv06 (0dfd0df9ab7a227cedf97fadee60f793) C:\WINDOWS\System32\drivers\prodrv06.sys
2011/02/25 15:11:23.0468 3620 prohlp02 (f2e44d17ea6334b39f35cc42251b2aca) C:\WINDOWS\system32\drivers\prohlp02.sys
2011/02/25 15:11:23.0593 3620 prosync1 (f3471e7971ee62420451d958da635064) C:\WINDOWS\system32\drivers\prosync1.sys
2011/02/25 15:11:23.0718 3620 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
2011/02/25 15:11:23.0750 3620 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
2011/02/25 15:11:23.0812 3620 PxHelp20 (0c8da0a8b0d227319c285e0eae65defd) C:\WINDOWS\system32\Drivers\PxHelp20.sys
2011/02/25 15:11:23.0984 3620 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys
2011/02/25 15:11:24.0046 3620 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
2011/02/25 15:11:24.0078 3620 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys
2011/02/25 15:11:24.0109 3620 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys
2011/02/25 15:11:24.0140 3620 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys
2011/02/25 15:11:24.0203 3620 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
2011/02/25 15:11:24.0250 3620 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
2011/02/25 15:11:24.0281 3620 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
2011/02/25 15:11:24.0343 3620 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
2011/02/25 15:11:24.0390 3620 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
2011/02/25 15:11:24.0437 3620 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2011/02/25 15:11:24.0515 3620 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
2011/02/25 15:11:24.0578 3620 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
2011/02/25 15:11:24.0671 3620 RecAgent (e9aaa0092d74a9d371659c4c38882e12) C:\WINDOWS\system32\DRIVERS\RecAgent.sys
2011/02/25 15:11:24.0765 3620 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
2011/02/25 15:11:24.0875 3620 RTL8023 (31c3ebb3a71fe56b8109bfb4ed20ae69) C:\WINDOWS\system32\DRIVERS\Rtlnic51.sys
2011/02/25 15:11:24.0984 3620 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
2011/02/25 15:11:25.0046 3620 Serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
2011/02/25 15:11:25.0093 3620 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
2011/02/25 15:11:25.0156 3620 sfhlp01 (462aee0ea0481ea8bd45cac876a4ccc4) C:\WINDOWS\system32\drivers\sfhlp01.sys
2011/02/25 15:11:25.0328 3620 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
2011/02/25 15:11:25.0453 3620 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys
2011/02/25 15:11:25.0515 3620 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
2011/02/25 15:11:25.0609 3620 Slntamr (c1a825aef40774bab5bed0e64022b089) C:\WINDOWS\system32\DRIVERS\slntamr.sys
2011/02/25 15:11:25.0656 3620 SlNtHal (d84ce5182f7d9f3e7e4ff0c36b16a466) C:\WINDOWS\system32\DRIVERS\Slnthal.sys
2011/02/25 15:11:25.0718 3620 SlWdmSup (4a35904e8ee6c103c815ee269cc7a7b9) C:\WINDOWS\system32\DRIVERS\SlWdmSup.sys
2011/02/25 15:11:25.0781 3620 snpstd2 (6db1737f710860c1685bface72798535) C:\WINDOWS\system32\DRIVERS\snpstd2.sys
2011/02/25 15:11:25.0859 3620 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys
2011/02/25 15:11:25.0906 3620 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
2011/02/25 15:11:26.0015 3620 sptd (0d8d6a7156888de1601c25913d8a3b17) C:\WINDOWS\system32\Drivers\sptd.sys
2011/02/25 15:11:26.0015 3620 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: 0d8d6a7156888de1601c25913d8a3b17
2011/02/25 15:11:26.0031 3620 sptd - detected Locked file (1)
2011/02/25 15:11:26.0140 3620 SQTECH905C (545a8412a9349074132330ad5b30e09a) C:\WINDOWS\system32\Drivers\Capt905c.sys
2011/02/25 15:11:26.0250 3620 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
2011/02/25 15:11:26.0328 3620 Srv (3bb03f2ba89d2be417206c373d2af17c) C:\WINDOWS\system32\DRIVERS\srv.sys
2011/02/25 15:11:26.0390 3620 STEC3 (e4ebf293d1f612bda19b646c36715b20) C:\WINDOWS\system32\STEC3.sys
2011/02/25 15:11:26.0531 3620 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
2011/02/25 15:11:26.0609 3620 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
2011/02/25 15:11:26.0656 3620 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
2011/02/25 15:11:26.0718 3620 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys
2011/02/25 15:11:26.0765 3620 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys
2011/02/25 15:11:26.0812 3620 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys
2011/02/25 15:11:26.0843 3620 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys
2011/02/25 15:11:26.0890 3620 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
2011/02/25 15:11:26.0984 3620 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
2011/02/25 15:11:27.0046 3620 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
2011/02/25 15:11:27.0125 3620 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
2011/02/25 15:11:27.0203 3620 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
2011/02/25 15:11:27.0265 3620 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys
2011/02/25 15:11:27.0312 3620 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
2011/02/25 15:11:27.0421 3620 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys
2011/02/25 15:11:27.0500 3620 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
2011/02/25 15:11:27.0578 3620 usbaudio (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
2011/02/25 15:11:27.0625 3620 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
2011/02/25 15:11:27.0656 3620 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
2011/02/25 15:11:27.0703 3620 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
2011/02/25 15:11:27.0750 3620 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys
2011/02/25 15:11:27.0812 3620 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
2011/02/25 15:11:27.0859 3620 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
2011/02/25 15:11:27.0921 3620 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
2011/02/25 15:11:28.0000 3620 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
2011/02/25 15:11:28.0062 3620 vaxscsi (92cebc2bc7be2c8d49391b365569f306) C:\WINDOWS\System32\Drivers\vaxscsi.sys
2011/02/25 15:11:28.0093 3620 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
2011/02/25 15:11:28.0156 3620 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys
2011/02/25 15:11:28.0203 3620 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys
2011/02/25 15:11:28.0234 3620 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
2011/02/25 15:11:28.0328 3620 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
2011/02/25 15:11:28.0421 3620 wanatw (0a716c08cb13c3a8f4f51e882dbf7416) C:\WINDOWS\system32\DRIVERS\wanatw4.sys
2011/02/25 15:11:28.0656 3620 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
2011/02/25 15:11:28.0984 3620 WmBEnum (bc3ecbcb40147bdae3ad2fd0b4b346d8) C:\WINDOWS\system32\drivers\WmBEnum.sys
2011/02/25 15:11:29.0140 3620 WmFilter (19f9881d8b3484fedb605d0216876898) C:\WINDOWS\system32\drivers\WmFilter.sys
2011/02/25 15:11:29.0390 3620 WmVirHid (7a51545a6409a25eedbdbd97d019e8cc) C:\WINDOWS\system32\drivers\WmVirHid.sys
2011/02/25 15:11:29.0453 3620 WmXlCore (1f083b3bc73017e60c3ca85cf4a70753) C:\WINDOWS\system32\drivers\WmXlCore.sys
2011/02/25 15:11:29.0625 3620 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
2011/02/25 15:11:29.0703 3620 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
2011/02/25 15:11:29.0750 3620 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
2011/02/25 15:11:29.0843 3620 ZTEusbmdm6k (d169ecbde1291b7d720441550d15d104) C:\WINDOWS\system32\DRIVERS\ZTEusbmdm6k.sys
2011/02/25 15:11:29.0890 3620 ZTEusbnmea (d169ecbde1291b7d720441550d15d104) C:\WINDOWS\system32\DRIVERS\ZTEusbnmea.sys
2011/02/25 15:11:30.0359 3620 ZTEusbser6k (d169ecbde1291b7d720441550d15d104) C:\WINDOWS\system32\DRIVERS\ZTEusbser6k.sys
2011/02/25 15:11:30.0578 3620 ================================================================================
2011/02/25 15:11:30.0578 3620 Scan finished
2011/02/25 15:11:30.0578 3620 ================================================================================
2011/02/25 15:11:30.0609 0764 Detected object count: 1
2011/02/25 15:11:43.0750 0764 Locked file(sptd) - User select action: Skip
2011/02/25 15:11:47.0546 4656 Deinitialize success
and the OTL ones
OTL logfile created on: 25/02/2011 15:16:09 - Run 1
OTL by OldTimer - Version 3.2.21.0 Folder = D:\Documents and Settings\Angel Fire\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
511.00 Mb Total Physical Memory | 174.00 Mb Available Physical Memory | 34.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 43.00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 29.99 Gb Total Space | 10.81 Gb Free Space | 36.05% Space Free | Partition Type: NTFS
Drive D: | 111.24 Gb Total Space | 44.41 Gb Free Space | 39.93% Space Free | Partition Type: NTFS
Drive G: | 21.97 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: SN049684320704 | User Name: Angel Fire | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - D:\Documents and Settings\Angel Fire\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG10\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation)
PRC - C:\Program Files\3 Mobile Broadband\3Connect\BecHelperService.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe (Nikon Corporation)
PRC - C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe (Brother Industries, Ltd.)
PRC - C:\Program Files\Brother\ControlCenter3\BrccMCtl.exe (Brother Industries, Ltd.)
PRC - C:\Program Files\Brother\Brmfcmon\BrMfcMon.exe (Brother Industries, Ltd.)
PRC - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Winamp\winampa.exe ()
PRC - C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
PRC - C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Canon\Memory Card Utility\iP6210D\PDUiP6210DMon.exe (CANON INC.)
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FATIAHE.EXE (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\Common Files\Ulead Systems\AutoDetector\Monitor.exe (Ulead Systems, Inc.)
PRC - C:\Program Files\Simple Star\PhotoShow Deluxe 3\data\Xtras\mssysmgr.exe (Simple Star, Inc.)
PRC - C:\Program Files\Logitech\Profiler\LWEMon.exe (Logitech Inc.)
PRC - C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (America Online, Inc.)
PRC - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
PRC - C:\WINDOWS\vsnpstd2.exe ()
PRC - C:\WINDOWS\system32\slserv.exe ( )
PRC - C:\APPS\ABOARD\ABOARD.EXE (NEC Computers International)
PRC - C:\APPS\ABOARD\AOSD.EXE (NEC Computers International)
PRC - C:\Program Files\Alcatel\SpeedTouch USB\dragdiag.exe (THOMSON multimedia)
========== Modules (SafeList) ==========
MOD - D:\Documents and Settings\Angel Fire\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\MsgPlusLoader.dll (Patchou)
MOD - C:\Program Files\Logitech\Profiler\LWEHook.dll (Logitech Inc.)
========== Win32 Services (SafeList) ==========
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG10\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (BecHelperService) – C:\Program Files\3 Mobile Broadband\3Connect\BecHelperService.exe ()
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_0.EXE (Symantec Corporation)
SRV - (Automatic LiveUpdate Scheduler) – C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (Symantec Corporation)
SRV - (AOL ACS) – C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (America Online, Inc.)
SRV - (UleadBurningHelper) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
SRV - (SLService) – C:\WINDOWS\System32\slserv.exe ( )
========== Driver Services (SafeList) ==========
DRV - (Avgldx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSEH) – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgmfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\WINDOWS\system32\DRIVERS\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) – C:\WINDOWS\system32\drivers\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSDriver) – C:\WINDOWS\system32\drivers\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilter) – C:\WINDOWS\system32\drivers\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (mdvrmng) – C:\WINDOWS\system32\drivers\mdvrmng.sys ()
DRV - (ZTEusbser6k) – C:\WINDOWS\system32\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV - (ZTEusbnmea) – C:\WINDOWS\system32\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV - (ZTEusbmdm6k) – C:\WINDOWS\system32\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV - (massfilter) – C:\WINDOWS\system32\drivers\massfilter.sys (ZTE Incorporated)
DRV - (eeCtrl) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (MPE) – C:\WINDOWS\system32\drivers\mpe.sys (Microsoft Corporation)
DRV - (IrBus) – C:\WINDOWS\system32\drivers\irbus.sys (Microsoft Corporation)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (npf) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies)
DRV - (2WIREPCP) – C:\WINDOWS\system32\drivers\2WirePCP.sys (2Wire, Inc.)
DRV - (vaxscsi) – C:\WINDOWS\System32\Drivers\vaxscsi.sys (Alcohol Soft Co., Ltd.)
DRV - (sptd) – C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (STEC3) – C:\WINDOWS\system32\STEC3.sys (AntiCracking)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (3xHybrid) – C:\WINDOWS\system32\drivers\3xHybrid.sys (Philips Semiconductors GmbH)
DRV - (HdAudAddService) – C:\WINDOWS\system32\drivers\Hdaudio.sys (Windows ® Server 2003 DDK provider)
DRV - (SQTECH905C) – C:\WINDOWS\system32\drivers\Capt905c.sys (Service & Quality Technology.)
DRV - (BrScnUsb) – C:\WINDOWS\system32\drivers\BrScnUsb.sys (Brother Industries Ltd.)
DRV - (RecAgent) – C:\WINDOWS\system32\drivers\recagent.sys (Smart Link)
DRV - (WmXlCore) – C:\WINDOWS\system32\drivers\WmXlCore.sys (Logitech Inc.)
DRV - (WmFilter) – C:\WINDOWS\system32\drivers\WmFilter.sys (Logitech Inc.)
DRV - (WmBEnum) – C:\WINDOWS\system32\drivers\WmBEnum.sys (Logitech Inc.)
DRV - (WmVirHid) – C:\WINDOWS\system32\drivers\WmVirHid.sys (Logitech Inc.)
DRV - (snpstd2) USB PC Camera (SN9C103) – C:\WINDOWS\system32\drivers\snpstd2.sys ()
DRV - (RTL8023) – C:\WINDOWS\system32\drivers\Rtlnic51.sys (Realtek Semiconductor Corporation )
DRV - (sfhlp01) – C:\WINDOWS\System32\drivers\sfhlp01.sys (Protection Technology)
DRV - (prohlp02) – C:\WINDOWS\System32\drivers\prohlp02.sys (Protection Technology)
DRV - (prodrv06) – C:\WINDOWS\System32\drivers\prodrv06.sys (Protection Technology)
DRV - (prosync1) – C:\WINDOWS\System32\drivers\prosync1.sys (Protection Technology)
DRV - (Slntamr) – C:\WINDOWS\system32\drivers\slntamr.sys ( )
DRV - (Mtlmnt5) – C:\WINDOWS\system32\drivers\mtlmnt5.sys ( )
DRV - (Mtlstrm) – C:\WINDOWS\system32\drivers\mtlstrm.sys ( )
DRV - (SlNtHal) – C:\WINDOWS\system32\drivers\slnthal.sys ( )
DRV - (SlWdmSup) – C:\WINDOWS\system32\drivers\slwdmsup.sys (Vireo Software)
DRV - (NtMtlFax) – C:\WINDOWS\system32\drivers\ntmtlfax.sys ( )
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (alcan5wn) Alcatel SpeedTouch USB ADSL PPP Networking Driver (NDISWAN) – C:\WINDOWS\system32\drivers\alcan5wn.sys (THOMSON multimedia)
DRV - (alcaudsl) – C:\WINDOWS\system32\drivers\alcaudsl.sys (THOMSON multimedia)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (Aspi32) – C:\WINDOWS\System32\drivers\ASPI32.sys (Adaptec)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://uk.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.btbroadbandoffice.com
IE - HKCU\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\7.bin\MWSSRCAS.DLL (MyWebSearch.com)
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:10.0.0.1178
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "
http://search.avg.com/?d=4d5cec20&i;=23&tp;=ab&nt;=1&q;="
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\ [2011/02/17 09:32:14 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/01/19 14:00:23 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/12/11 15:45:04 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Netscape Browser 8.1.0.0\Extensions\\Components: C:\Program Files\\Netscape\\Netscape Browser\Components [2007/06/18 15:07:04 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Netscape Browser 8.1.0.0\Extensions\\Plugins: C:\Program Files\\Netscape\\Netscape Browser\Plugins [2010/08/24 09:12:28 | 000,000,000 | —D | M]
[2010/03/06 18:28:19 | 000,000,000 | —D | M] (No name found) – D:\Documents and Settings\Angel Fire\Application Data\Mozilla\Extensions
[2011/02/25 15:14:26 | 000,000,000 | —D | M] (No name found) – D:\Documents and Settings\Angel Fire\Application Data\Mozilla\Firefox\Profiles\xr9oftax.default\extensions
[2006/09/09 12:58:32 | 000,000,000 | —D | M] ("Yahoo! Toolbar") – D:\Documents and Settings\Angel Fire\Application Data\Mozilla\Firefox\Profiles\xr9oftax.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/02/24 09:44:28 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/11/16 10:24:54 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/11/25 09:52:46 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/02/24 09:43:32 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/02/17 09:32:14 | 000,000,000 | —D | M] (AVG Safe Search) – C:\PROGRAM FILES\AVG\AVG10\FIREFOX
[2010/11/16 10:24:18 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011/02/02 21:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2003/11/18 13:37:32 | 000,241,664 | —- | M] (Musicnotes, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npmusicn.dll
[2007/07/03 19:20:18 | 000,024,673 | —- | M] (MyWebSearch.com) – C:\Program Files\Mozilla Firefox\plugins\NPMyWebS.dll
[2010/09/10 12:27:23 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/09/10 12:27:23 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/09/10 12:27:23 | 000,000,769 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/09/10 12:27:23 | 000,001,135 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: ([2009/05/03 04:52:05 | 000,000,075 | -HS- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 82.98.231.89 url.adtrgt.com
O1 - Hosts: 82.98.231.89 googleads2.gdoubleclick.net
O2 - BHO: (MyWebSearch Search Assistant BHO) - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\7.bin\MWSSRCAS.DLL (MyWebSearch.com)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {4a1b12a9-3b13-44c8-a941-f6a6fe45daaa} - File not found
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (EpsonToolBandKicker Class) - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - File not found
O2 - BHO: (Nothing) - {edbf1bc8-39ab-48eb-a0a9-c75078eb7c8e} - File not found
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - File not found
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {5D956A61-05E7-427B-A2B1-BF32FB18B1BE} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - File not found
O4 - HKLM..\Run: [19091254] File not found
O4 - HKLM..\Run: [ACTIVBOARD] c:\APPS\ABOARD\ABOARD.EXE (NEC Computers International)
O4 - HKLM..\Run: [Adobe Photo Downloader] C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [CPMcfa0e8de] File not found
O4 - HKLM..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [EPSON Stylus Photo R240 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAHE.EXE (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [hajomoyipu] File not found
O4 - HKLM..\Run: [High Definition Audio Property Page Shortcut] C:\WINDOWS\System32\HdAShCut.exe (Windows ® Server 2003 DDK provider)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [My Web Search Bar Search Scope Monitor] File not found
O4 - HKLM..\Run: [MyWebSearch Email Plugin] File not found
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [PDUiP6210DMon] C:\Program Files\Canon\Memory Card Utility\iP6210D\PDUiP6210DMon.exe (CANON INC.)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PromoReg] File not found
O4 - HKLM..\Run: [services] File not found
O4 - HKLM..\Run: [SNPSTD2] C:\WINDOWS\vsnpstd2.exe ()
O4 - HKLM..\Run: [SpeedTouch USB Diagnostics] C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe (THOMSON multimedia)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Ulead AutoDetector v2] C:\Program Files\Common Files\Ulead Systems\AutoDetector\Monitor.exe (Ulead Systems, Inc.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe ()
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [MyWebSearch Email Plugin] File not found
O4 - HKCU..\Run: [PhotoShow Deluxe Media Manager] C:\Program Files\Simple Star\PhotoShow Deluxe 3\data\Xtras\mssysmgr.exe (Simple Star, Inc.)
O4 - HKCU..\Run: [services] File not found
O4 - HKCU..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Profiler\lwemon.exe (Logitech Inc.)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\System32\Macromed\Flash\NPSWF32_FlashUtil.exe (Adobe Systems, Inc.)
O4 - Startup: D:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: D:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: D:\Documents and Settings\All Users\Start Menu\Programs\Startup\Nikon Monitor.lnk = C:\Program Files\Common Files\Nikon\Monitor\NkMonitor.exe (Nikon Corporation)
O4 - Startup: D:\Documents and Settings\Angel Fire\Start Menu\Programs\Startup\Delta Force-Black Hawk Down Team Sabre Registration.lnk = File not found
O4 - Startup: D:\Documents and Settings\Angel Fire\Start Menu\Programs\Startup\PowerReg Scheduler.exe ()
O4 - Startup: D:\Documents and Settings\Angel Fire\Start Menu\Programs\Startup\services.lnk = File not found
F3 - HKCU WinNT: Load - (C:\WINDOWS\system32\ebjymm\services.exe) - File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run: dcomcfg.exe = dcomcfg.exe
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoAdminPage = 1
O8 - Extra context menu item: &Yahoo;! Search - C:\Program Files\Yahoo!\Common [2009/01/26 23:03:01 | 000,000,000 | —D | M]
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Yahoo! &Dictionary; - C:\Program Files\Yahoo!\Common [2009/01/26 23:03:01 | 000,000,000 | —D | M]
O8 - Extra context menu item: Yahoo! &Maps; - C:\Program Files\Yahoo!\Common [2009/01/26 23:03:01 | 000,000,000 | —D | M]
O8 - Extra context menu item: Yahoo! &SMS; - C:\Program Files\Yahoo!\Common [2009/01/26 23:03:01 | 000,000,000 | —D | M]
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab (Checkers Class)
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab (MessengerStatsClient Class)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab (Minesweeper Flags Class)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537}
http://jamiej666.spaces.live.com//PhotoUpload/MsnPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab (MessengerStatsClient Class)
O16 - DPF: {AF2E62B6-F9E1-4D4F-A10A-9DC8E6DCBCC0} http://update.videoegg.com/Install/Windows…ggPublisher.exe (VideoEgg ActiveX Loader)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab (ZoneIntro Class)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab (Minesweeper Flags Class)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - AppInit_DLLs: (MsgPlusLoader.dll) - C:\WINDOWS\System32\MsgPlusLoader.dll (Patchou)
O20 - AppInit_DLLs: (C:\WINDOWS\system32\fagonosi.dll) - File not found
O20 - AppInit_DLLs: (c:\windows\system32\gupehimu.dll) - C:\WINDOWS\system32\GUPEHIMU.DLL ()
O20 - AppInit_DLLs: (c:\windows\system32\tugufime.dll) - File not found
O20 - AppInit_DLLs: (c:\windows\system32\nezapuju.dll) - File not found
O20 - AppInit_DLLs: (c:\windows\system32\benagaya.dll) - File not found
O20 - AppInit_DLLs: (c:\windows\system32\mobefuli.dll) - File not found
O20 - AppInit_DLLs: (c:\windows\system32\wanuhona.dll) - File not found
O20 - AppInit_DLLs: (c:\windows\system32\telorewe.dll) - File not found
O20 - AppInit_DLLs: (c:\windows\system32\hilatolu.dll) - File not found
O20 - AppInit_DLLs: (c:\windows\system32\zisuyire.dll) - File not found
O20 - AppInit_DLLs: (c:\windows\system32\nuromego.dll) - File not found
O20 - AppInit_DLLs: (c:\windows\system32\luwozuno.dll) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - File not found
O22 - SharedTaskScheduler: {EA26CE12-DE64-A1C5-9A4F-FC1A64E6AC2E} - SivuWare - Reg Error: Key error. File not found
O22 - SharedTaskScheduler: {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - STS - File not found
O24 - Desktop WallPaper: D:\Documents and Settings\Angel Fire\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: D:\Documents and Settings\Angel Fire\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/11/25 14:45:52 | 000,000,510 | R— | M] () - G:\AUTORUN.DAT – [ CDFS ]
O32 - AutoRun File - [2008/02/18 13:48:26 | 000,027,750 | R— | M] () - G:\AUTORUN.ICO – [ CDFS ]
O32 - AutoRun File - [2008/09/24 16:09:06 | 000,000,054 | R— | M] () - G:\AUTORUN.INF – [ CDFS ]
O33 - MountPoints2\{29306e86-ea46-11de-852f-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{29306e86-ea46-11de-852f-00038a000015}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{29306e86-ea46-11de-852f-00038a000015}\Shell\AutoRun\command - "" = G:\VersionControl.exe – [2009/12/30 15:31:26 | 000,093,760 | R— | M] (Birdstep)
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\VersionControl.exe – [2009/12/30 15:31:26 | 000,093,760 | R— | M] (Birdstep)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.dvacm - C:\Program Files\Common Files\Ulead Systems\vio\DVACM.acm (Ulead Systems, Inc.)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.mpegacm - C:\Program Files\Common Files\Ulead Systems\MPEG\MPEGACM.acm (Ulead Systems, Inc.)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.ulmp3acm - C:\Program Files\Common Files\Ulead Systems\MPEG\ulmp3acm.acm (Ulead systems)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivXNetworks)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.VP60 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\WINDOWS\system32\vp6vfw.dll (On2.com)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivXNetworks)
Unable to start service SrService!
========== Files/Folders - Created Within 30 Days ==========
[2011/02/25 15:09:10 | 000,577,024 | —- | C] (OldTimer Tools) – D:\Documents and Settings\Angel Fire\Desktop\OTL.exe
[2011/02/25 11:15:34 | 000,000,000 | —D | C] – D:\Documents and Settings\Angel Fire\Start Menu\Programs\HiJackThis
[2011/02/25 11:03:39 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Start Menu\Programs\HijackThis
[2011/02/25 11:03:36 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2011/02/24 09:43:30 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/02/24 09:43:30 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/02/24 09:43:30 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/02/24 09:41:13 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Application Data\McAfee
[2011/02/21 20:21:12 | 000,000,000 | —D | C] – D:\My Documents\Lectures
[2011/02/21 11:09:14 | 001,372,248 | —- | C] (Kaspersky Lab ZAO) – D:\Documents and Settings\Angel Fire\Desktop\TDSSKiller.exe
[2011/02/17 09:38:58 | 000,000,000 | —D | C] – D:\Documents and Settings\Angel Fire\Application Data\AVG10
[2011/02/17 09:34:55 | 000,000,000 | -H-D | C] – D:\Documents and Settings\All Users\Application Data\Common Files
[2011/02/17 09:34:10 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Start Menu\Programs\AVG 2011
[2011/02/17 09:32:03 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Application Data\AVG10
[2011/02/17 09:32:03 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\AVG
[2011/02/17 09:25:00 | 000,000,000 | -H-D | C] – C:\$AVG
[2011/02/17 09:12:51 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Application Data\MFAData
[2011/02/17 09:12:17 | 000,000,000 | —D | C] – D:\Documents and Settings\All Users\Application Data\Temp
[2011/02/05 12:01:14 | 000,000,000 | R–D | C] – D:\Documents and Settings\Angel Fire\Application Data\Brother
[2011/02/05 11:47:20 | 000,000,000 | —D | C] – D:\My Documents\PSM 2
[2006/04/15 11:06:33 | 005,689,344 | —- | C] (Gabest) – C:\Program Files\mplayerc.exe
[2006/03/11 23:25:41 | 000,061,440 | —- | C] ( ) – C:\WINDOWS\System32\csnpstd2.dll
[2006/03/11 23:25:41 | 000,040,960 | —- | C] ( ) – C:\WINDOWS\System32\rsnpstd2.dll
[2006/03/11 23:25:41 | 000,036,864 | —- | C] ( ) – C:\WINDOWS\System32\vsnpstd2.dll
[2005/12/14 10:31:30 | 000,014,976 | —- | C] ( ) – C:\WINDOWS\System32\drivers\winddx.sys
[2003/08/20 17:34:50 | 000,548,952 | —- | C] ( ) – C:\WINDOWS\System32\drivers\slntamr.sys
[2003/07/16 12:30:26 | 000,221,736 | —- | C] ( ) – C:\WINDOWS\System32\drivers\mtlmnt5.sys
[2003/07/02 16:26:36 | 001,301,128 | —- | C] ( ) – C:\WINDOWS\System32\drivers\mtlstrm.sys
[2003/07/02 16:24:36 | 000,086,128 | —- | C] ( ) – C:\WINDOWS\System32\drivers\slnthal.sys
[2003/07/02 15:57:10 | 000,167,384 | —- | C] ( ) – C:\WINDOWS\System32\drivers\ntmtlfax.sys
[5 D:\My Documents\*.tmp files -> D:\My Documents\*.tmp -> ]
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/02/25 15:09:11 | 000,577,024 | —- | M] (OldTimer Tools) – D:\Documents and Settings\Angel Fire\Desktop\OTL.exe
[2011/02/25 13:43:28 | 107,167,611 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/02/25 11:16:06 | 000,002,335 | —- | M] () – D:\Documents and Settings\Angel Fire\Desktop\HiJackThis.lnk
[2011/02/25 09:46:32 | 000,029,204 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2011/02/25 09:46:05 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/02/25 09:44:34 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/02/25 09:44:22 | 536,399,872 | -HS- | M] () – C:\hiberfil.sys
[2011/02/24 17:29:14 | 000,064,000 | —- | M] () – D:\Documents and Settings\Angel Fire\Desktop\Developmental 8.ppt
[2011/02/23 20:39:59 | 000,100,864 | —- | M] () – D:\Documents and Settings\Angel Fire\Desktop\Developmental 7.ppt
[2011/02/23 20:29:42 | 000,418,304 | —- | M] () – D:\Documents and Settings\Angel Fire\Desktop\CHIPs 8.ppt
[2011/02/23 19:15:47 | 000,000,020 | —- | M] () – C:\WINDOWS\System32\GUPEHIMU.DLL
[2011/02/21 20:20:42 | 001,925,120 | —- | M] () – D:\Documents and Settings\Angel Fire\Desktop\Numbers and the brain.ppt
[2011/02/21 20:16:04 | 000,252,416 | —- | M] () – D:\Documents and Settings\Angel Fire\Desktop\CHIPs 7.ppt
[2011/02/21 19:02:34 | 000,024,064 | —- | M] () – D:\My Documents\Online to-do list.doc
[2011/02/21 11:09:14 | 001,372,248 | —- | M] (Kaspersky Lab ZAO) – D:\Documents and Settings\Angel Fire\Desktop\TDSSKiller.exe
[2011/02/19 22:54:58 | 000,000,116 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2011/02/17 09:34:18 | 000,000,607 | —- | M] () – D:\Documents and Settings\All Users\Desktop\AVG 2011.lnk
[2011/02/15 11:20:23 | 000,153,088 | —- | M] () – D:\My Documents\Semester 2 syllabus.doc
[2011/02/02 21:40:39 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/02/02 21:40:38 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/02/02 21:40:36 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/02/02 21:40:23 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2011/02/02 19:19:39 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2011/01/28 11:32:49 | 000,001,409 | —- | M] () – C:\WINDOWS\System32\tmp77F35.FOT
[2011/01/28 11:32:49 | 000,001,409 | —- | M] () – C:\WINDOWS\System32\tmp4FF35.FOT
[2011/01/28 11:32:49 | 000,001,409 | —- | M] () – C:\WINDOWS\System32\tmp18045.FOT
[2011/01/28 11:32:48 | 000,001,409 | —- | M] () – C:\WINDOWS\System32\tmpD6E35.FOT
[2011/01/28 11:32:48 | 000,001,409 | —- | M] () – C:\WINDOWS\System32\tmpAFE35.FOT
[2011/01/28 11:32:48 | 000,001,409 | —- | M] () – C:\WINDOWS\System32\tmp2BD35.FOT
[2011/01/27 19:26:57 | 000,020,992 | —- | M] () – D:\My Documents\Application for research volunteering.doc
[2011/01/27 11:58:17 | 000,037,888 | —- | M] () – D:\My Documents\Stevey Lee revison.doc
[5 D:\My Documents\*.tmp files -> D:\My Documents\*.tmp -> ]
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/02/25 13:43:28 | 107,167,611 | —- | C] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/02/25 11:03:38 | 000,002,335 | —- | C] () – D:\Documents and Settings\Angel Fire\Desktop\HiJackThis.lnk
[2011/02/24 17:29:14 | 000,064,000 | —- | C] () – D:\Documents and Settings\Angel Fire\Desktop\Developmental 8.ppt
[2011/02/23 20:39:59 | 000,100,864 | —- | C] () – D:\Documents and Settings\Angel Fire\Desktop\Developmental 7.ppt
[2011/02/23 20:29:41 | 000,418,304 | —- | C] () – D:\Documents and Settings\Angel Fire\Desktop\CHIPs 8.ppt
[2011/02/23 19:15:47 | 000,000,020 | —- | C] () – C:\WINDOWS\System32\GUPEHIMU.DLL
[2011/02/21 20:20:42 | 001,925,120 | —- | C] () – D:\Documents and Settings\Angel Fire\Desktop\Numbers and the brain.ppt
[2011/02/21 20:16:04 | 000,252,416 | —- | C] () – D:\Documents and Settings\Angel Fire\Desktop\CHIPs 7.ppt
[2011/02/20 16:30:09 | 000,024,064 | —- | C] () – D:\My Documents\Online to-do list.doc
[2011/02/17 09:34:18 | 000,000,607 | —- | C] () – D:\Documents and Settings\All Users\Desktop\AVG 2011.lnk
[2011/02/17 09:12:42 | 000,003,664 | —- | C] () – D:\Documents and Settings\Angel Fire\commonpriv.log
[2011/02/17 09:12:42 | 000,000,000 | —- | C] () – D:\Documents and Settings\Angel Fire\commonpriv.log.lock
[2011/02/15 11:20:23 | 000,153,088 | —- | C] () – D:\My Documents\Semester 2 syllabus.doc
[2011/01/28 11:32:49 | 000,001,409 | —- | C] () – C:\WINDOWS\System32\tmp77F35.FOT
[2011/01/28 11:32:49 | 000,001,409 | —- | C] () – C:\WINDOWS\System32\tmp4FF35.FOT
[2011/01/28 11:32:49 | 000,001,409 | —- | C] () – C:\WINDOWS\System32\tmp18045.FOT
[2011/01/28 11:32:48 | 000,001,409 | —- | C] () – C:\WINDOWS\System32\tmpD6E35.FOT
[2011/01/28 11:32:48 | 000,001,409 | —- | C] () – C:\WINDOWS\System32\tmpAFE35.FOT
[2011/01/28 11:32:48 | 000,001,409 | —- | C] () – C:\WINDOWS\System32\tmp2BD35.FOT
[2011/01/27 19:26:56 | 000,020,992 | —- | C] () – D:\My Documents\Application for research volunteering.doc
[2010/11/02 14:43:23 | 000,000,027 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2010/11/02 14:43:22 | 000,000,419 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2010/02/20 21:32:11 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2009/12/14 19:18:36 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\drivers\mdvrmng.sys
[2009/08/23 11:57:35 | 000,000,012 | —- | C] () – D:\Documents and Settings\Angel Fire\Application Data\wiaserva.log
[2009/07/13 09:35:56 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\RemoveDevice.dll
[2009/03/08 15:35:07 | 000,000,046 | —- | C] () – C:\WINDOWS\smsafari.ini
[2009/01/09 16:50:39 | 000,000,268 | RH– | C] () – D:\Documents and Settings\All Users\Application Data\Helper Scripts
[2009/01/09 16:50:39 | 000,000,268 | RH– | C] () – D:\Documents and Settings\Angel Fire\Application Data\Guitars
[2009/01/09 16:50:39 | 000,000,020 | -H– | C] () – D:\Documents and Settings\All Users\Application Data\PKP_DLdu.DAT
[2009/01/09 16:50:39 | 000,000,012 | RH– | C] () – D:\Documents and Settings\All Users\Application Data\Hybrid Basic
[2008/05/17 02:01:41 | 000,000,118 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2008/04/29 14:55:23 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/09/11 20:32:57 | 000,022,328 | —- | C] () – C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2007/08/15 16:47:54 | 000,008,704 | —- | C] () – C:\WINDOWS\System32\CNMVS7B.DLL
[2007/07/08 14:24:10 | 000,000,018 | —- | C] () – C:\WINDOWS\gfact.ini
[2006/12/03 20:37:10 | 000,000,151 | —- | C] () – C:\WINDOWS\PhotoSnapViewer.INI
[2006/07/24 11:40:48 | 000,000,000 | —- | C] () – C:\WINDOWS\EAREMOVE.INI
[2006/05/31 18:28:09 | 000,642,560 | —- | C] () – C:\WINDOWS\System32\drivers\sptd.sys
[2006/05/31 18:28:09 | 000,096,384 | —- | C] () – C:\WINDOWS\System32\drivers\sptd2797.sys
[2006/04/27 16:05:53 | 000,197,120 | —- | C] () – C:\WINDOWS\patchw32.dll
[2006/04/26 16:23:12 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2006/04/23 19:20:37 | 000,000,000 | —- | C] () – D:\Documents and Settings\Angel Fire\Application Data\Install.dat
[2006/04/22 23:00:10 | 000,053,299 | —- | C] () – C:\WINDOWS\System32\pthreadVC.dll
[2006/04/14 15:41:38 | 000,000,028 | —- | C] () – C:\WINDOWS\AlphaPlayer.INI
[2006/04/13 13:44:48 | 000,000,114 | —- | C] () – C:\WINDOWS\Tiny_Run.ini
[2006/03/11 23:25:46 | 000,053,248 | —- | C] () – C:\WINDOWS\System32\dsnpstd2.dll
[2006/03/11 23:25:46 | 000,015,541 | —- | C] () – C:\WINDOWS\snpstd2.ini
[2006/03/11 23:25:44 | 000,302,720 | —- | C] () – C:\WINDOWS\System32\drivers\snpstd2.sys
[2006/02/26 17:14:45 | 000,000,409 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2006/02/23 22:53:01 | 000,000,116 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2006/02/14 19:22:20 | 000,000,000 | —- | C] () – C:\WINDOWS\MSDraw.ini
[2006/02/01 11:20:40 | 000,000,030 | —- | C] () – C:\WINDOWS\Iedit.INI
[2006/01/29 15:03:50 | 000,123,392 | —- | C] () – D:\Documents and Settings\Angel Fire\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/01/23 12:24:03 | 000,006,424 | —- | C] () – D:\Documents and Settings\Angel Fire\Application Data\wklnhst.dat
[2006/01/23 12:08:07 | 000,000,099 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2006/01/23 12:06:24 | 000,000,025 | —- | C] () – C:\WINDOWS\CDE R240R245EU.ini
[2006/01/22 15:35:07 | 000,000,133 | —- | C] () – D:\Documents and Settings\Angel Fire\Local Settings\Application Data\fusioncache.dat
[2006/01/22 14:48:41 | 000,040,448 | —- | C] () – C:\WINDOWS\System32\regobj.dll
[2006/01/22 14:48:05 | 000,005,607 | —- | C] () – C:\WINDOWS\System32\stci.dll
[2005/12/14 11:13:57 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005/12/14 10:57:32 | 000,000,514 | —- | C] () – C:\WINDOWS\System32\SETUPPC.INI
[2005/12/14 10:51:41 | 000,007,584 | —- | C] () – C:\WINDOWS\HDReg.ini
[2005/12/14 10:41:12 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\34CoInstaller.dll
[2005/12/14 10:31:30 | 000,475,136 | —- | C] () – C:\WINDOWS\System32\SLLights.dll
[2005/12/14 10:31:30 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\amr_cpl.dll
[2005/12/14 10:31:30 | 000,135,168 | —- | C] () – C:\WINDOWS\System32\SLMOHServ.dll
[2005/10/21 15:28:56 | 000,005,968 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005/08/05 14:01:54 | 000,235,008 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005/08/02 16:35:00 | 001,662,976 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2005/08/02 16:35:00 | 001,466,368 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2005/08/02 16:35:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2005/08/02 16:35:00 | 000,540,672 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2005/08/02 16:35:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2005/08/02 16:35:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2005/04/28 04:22:38 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2005/04/28 04:22:34 | 000,831,488 | —- | C] () – C:\WINDOWS\System32\libeay32.dll
[2005/04/28 04:22:34 | 000,159,744 | —- | C] () – C:\WINDOWS\System32\ssleay32.dll
[2004/09/10 15:50:43 | 000,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/09/10 15:24:13 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2004/06/23 13:14:44 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2003/07/02 18:05:46 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\slextspk.dll
[2003/07/02 18:04:32 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\coinst.dll
[2003/07/02 17:35:48 | 000,159,744 | —- | C] () – C:\WINDOWS\System32\SLGen.dll
[1999/07/29 08:27:10 | 000,056,832 | —- | C] () – C:\WINDOWS\System32\iyvu9_32.dll
[1999/01/22 18:46:58 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
========== LOP Check ==========
[2009/08/24 12:05:31 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\19091254
[2011/02/17 09:36:38 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\AVG10
[2009/12/14 19:20:51 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\Birdstep Technology
[2007/08/15 16:47:20 | 000,000,000 | -H-D | M] – D:\Documents and Settings\All Users\Application Data\CanonBJ
[2011/02/17 09:34:55 | 000,000,000 | -H-D | M] – D:\Documents and Settings\All Users\Application Data\Common Files
[2009/01/09 16:50:39 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\EnterNHelp
[2008/11/26 14:36:00 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\Last.fm
[2006/05/17 14:29:38 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\Messenger Plus!
[2011/02/17 09:14:29 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\MFAData
[2009/01/09 16:51:03 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\Nikon
[2007/10/25 23:01:54 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\Oberon Games
[2006/02/21 00:46:08 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\OD2
[2006/03/22 09:17:55 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\Quark
[2011/02/17 09:12:17 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\Temp
[2006/01/23 12:11:18 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\UDL
[2005/12/14 10:59:44 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\Ulead Systems
[2009/01/09 16:50:39 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\Ultima_T15
[2005/12/14 10:51:11 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\Viewpoint
[2009/06/20 10:58:59 | 000,000,000 | —D | M] – D:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2006/04/27 16:07:11 | 000,000,000 | —D | M] – D:\Documents and Settings\Angel Fire\Application Data\Atari
[2011/02/17 09:38:58 | 000,000,000 | —D | M] – D:\Documents and Settings\Angel Fire\Application Data\AVG10
[2009/12/14 19:20:48 | 000,000,000 | —D | M] – D:\Documents and Settings\Angel Fire\Application Data\Birdstep Technology
[2007/09/09 17:38:51 | 000,000,000 | —D | M] – D:\Documents and Settings\Angel Fire\Application Data\FunWebProducts
[2006/01/29 15:05:43 | 000,000,000 | —D | M] – D:\Documents and Settings\Angel Fire\Application Data\Leadertech
[2006/01/30 23:38:48 | 000,000,000 | —D | M] – D:\Documents and Settings\Angel Fire\Application Data\Netscape
[2009/07/04 12:02:07 | 000,000,000 | —D | M] – D:\Documents and Settings\Angel Fire\Application Data\Nikon
[2006/03/06 16:08:27 | 000,000,000 | —D | M] – D:\Documents and Settings\Angel Fire\Application Data\Norman
[2006/01/22 15:12:32 | 000,000,000 | —D | M] – D:\Documents and Settings\Angel Fire\Application Data\OD2
[2006/03/22 09:19:40 | 000,000,000 | —D | M] – D:\Documents and Settings\Angel Fire\Application Data\Quark
[2007/11/18 11:49:33 | 000,000,000 | —D | M] – D:\Documents and Settings\Angel Fire\Application Data\Simple Star
[2006/05/31 18:09:09 | 000,000,000 | —D | M] – D:\Documents and Settings\Angel Fire\Application Data\SpeedProject
[2006/01/23 12:24:18 | 000,000,000 | —D | M] – D:\Documents and Settings\Angel Fire\Application Data\Template
[2006/02/11 16:07:53 | 000,000,000 | —D | M] – D:\Documents and Settings\Angel Fire\Application Data\Thunderbird
[2006/06/21 11:18:09 | 000,000,000 | —D | M] – D:\Documents and Settings\Angel Fire\Application Data\Ulead Systems
[2009/09/10 10:00:38 | 000,000,000 | —D | M] – D:\Documents and Settings\Angel Fire\Application Data\uTorrent
[2007/07/23 22:27:04 | 000,000,000 | —D | M] – D:\Documents and Settings\Angel Fire\Application Data\VideoEgg
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/01/11 21:52:00 | 000,000,000 | —- | M] () – C:\AILog.txt
[2007/06/27 16:08:22 | 000,084,403 | —- | M] () – C:\AnalysisLog.rar
[2007/06/27 16:03:33 | 000,286,629 | —- | M] () – C:\AnalysisLog.sr0
[2007/06/27 16:08:52 | 000,092,188 | —- | M] () – C:\AnalysisLog.zip
[2005/12/14 10:48:04 | 000,000,208 | RHS- | M] () – C:\BOOT.BAK
[2006/01/22 14:43:45 | 000,000,279 | RHS- | M] () – C:\BOOT.INI
[2004/08/10 14:00:00 | 000,260,272 | RHS- | M] () – C:\cmldr
[2005/12/14 12:24:48 | 000,005,937 | —- | M] () – C:\DWNLOG.TXT
[2006/02/26 00:46:10 | 000,377,344 | -HS- | M] () – C:\ehthumbs.db
[2006/09/30 15:39:05 | 000,000,093 | —- | M] () – C:\fmc_debug1
[2006/08/13 17:06:50 | 000,009,819 | —- | M] () – C:\fsmodtemp
[2011/02/25 09:44:22 | 536,399,872 | -HS- | M] () – C:\hiberfil.sys
[2008/12/04 16:24:52 | 000,230,424 | —- | M] () – C:\img2-001.raw
[2006/12/17 19:45:46 | 000,230,424 | —- | M] () – C:\img2-002.raw
[2005/12/14 10:49:40 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2005/12/14 10:51:19 | 000,000,899 | -H– | M] () – C:\IPH.PH
[2006/10/18 17:03:17 | 000,002,786 | —- | M] () – C:\LGSInst.Log
[2006/03/21 15:48:57 | 000,075,302 | —- | M] () – C:\MEDP1BCK.MIS
[2005/12/14 10:49:40 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/08/10 14:00:00 | 000,047,564 | —- | M] () – C:\NTDETECT.COM
[2008/11/01 10:57:48 | 000,250,048 | —- | M] () – C:\NTLDR
[2011/02/25 09:44:21 | 804,495,360 | -HS- | M] () – C:\pagefile.sys
[2005/12/13 20:50:56 | 000,001,196 | —- | M] () – C:\SAUDIT.TXT
[2007/07/16 21:24:53 | 000,000,232 | -H– | M] () – C:\sqmdata00.sqm
[2007/07/16 21:24:53 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2005/10/31 15:56:00 | 000,700,416 | —- | M] (LimeWire) – C:\StubInstaller.exe
[2011/02/25 15:11:47 | 000,058,956 | —- | M] () – C:\TDSSKiller.2.4.18.0_25.02.2011_15.11.02_log.txt
[2011/02/25 15:12:49 | 000,058,956 | —- | M] () – C:\TDSSKiller.2.4.18.0_25.02.2011_15.12.05_log.txt
[2009/05/13 21:17:29 | 000,000,135 | —- | M] () – C:\VundoFix.txt
[2009/01/26 23:03:01 | 000,000,150 | —- | M] () – C:\YServer.txt
[2006/02/27 22:39:55 | 000,068,707 | —- | M] () – C:\_crash.dmp
[2006/02/27 22:39:04 | 000,109,906 | —- | M] () – C:\_crash.log
< %systemroot%\Fonts\*.com >
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2004/09/10 15:37:20 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2005/05/07 05:00:00 | 000,020,992 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD7B.DLL
[2005/05/07 05:00:00 | 000,059,392 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP7B.DLL
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2004/06/01 18:35:20 | 000,417,792 | —- | M] () – C:\WINDOWS\PhotoShow.scr
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2006/03/20 14:37:52 | 005,689,344 | —- | M] (Gabest) – C:\Program Files\mplayerc.exe
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2004/09/10 15:22:10 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2004/09/10 15:22:08 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2004/09/10 15:22:08 | 000,851,968 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
[2007/02/25 12:31:28 | 000,000,000 | —D | M] – C:\Program Files\Microsoft Games\Combat Flight Simulator 2\AIRCRAFT\1US_P-47M\model\bak
[2007/02/25 12:31:28 | 000,000,000 | —D | M] – C:\Program Files\Microsoft Games\Combat Flight Simulator 2\AIRCRAFT\1US_P-47M\texture\bak
[2006/05/28 09:58:12 | 000,000,000 | —D | M] – C:\Program Files\Microsoft Games\Combat Flight Simulator 2\AIRCRAFT\P-47 Fuerza Aerea Mexicana\model\bak
[2006/05/28 09:58:12 | 000,000,000 | —D | M] – C:\Program Files\Microsoft Games\Combat Flight Simulator 2\AIRCRAFT\P-47 Fuerza Aerea Mexicana\texture\bak
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/11/01 11:03:48 | 000,000,272 | -HS- | M] () – D:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
[2004/06/09 14:26:16 | 000,005,120 | —- | M] () – C:\WINDOWS\system32\THUMBS.DB
[3 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2006/01/22 14:43:20 | 000,000,170 | -HS- | M] () – D:\Documents and Settings\Angel Fire\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2004/09/10 22:45:04 | 000,000,079 | —- | M] () – D:\Documents and Settings\Angel Fire\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2010/03/06 18:23:05 | 008,152,912 | —- | M] (Mozilla) – D:\Documents and Settings\Angel Fire\Desktop\Firefox Setup 3.6.exe
[2002/07/09 04:45:40 | 000,086,016 | —- | M] (Annelid. With Icons By Vahagn) – D:\Documents and Settings\Angel Fire\Desktop\FWunlock.exe
[2011/02/25 15:09:11 | 000,577,024 | —- | M] (OldTimer Tools) – D:\Documents and Settings\Angel Fire\Desktop\OTL.exe
[2011/02/21 11:09:14 | 001,372,248 | —- | M] (Kaspersky Lab ZAO) – D:\Documents and Settings\Angel Fire\Desktop\TDSSKiller.exe
[2010/02/20 22:18:58 | 007,315,456 | —- | M] () – D:\Documents and Settings\Angel Fire\Desktop\WAPatch.exe
[2010/02/20 21:38:36 | 001,504,972 | —- | M] () – D:\Documents and Settings\Angel Fire\Desktop\WA_update-3.6.29.0_Beta_Installer.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
[2003/01/17 17:35:40 | 000,013,023 | —- | M] () – C:\WINDOWS\snpstd2.src
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2006/01/22 14:43:19 | 000,000,122 | -HS- | M] () – D:\Documents and Settings\Angel Fire\Favorites\Desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
Boeing B-52M Stratofortress Uninstaller.exe
Lockheed C-130J Hercules Uninstaller.exe
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
[2011/02/25 15:04:52 | 000,131,072 | —- | M] () – D:\Documents and Settings\Angel Fire\Cookies\index.dat
< %SystemRoot%\system32\fonts\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2009-04-17 02:06:48
< End of report >
OTL Extras logfile created on: 25/02/2011 15:16:10 - Run 1
OTL by OldTimer - Version 3.2.21.0 Folder = D:\Documents and Settings\Angel Fire\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
511.00 Mb Total Physical Memory | 174.00 Mb Available Physical Memory | 34.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 43.00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 29.99 Gb Total Space | 10.81 Gb Free Space | 36.05% Space Free | Partition Type: NTFS
Drive D: | 111.24 Gb Total Space | 44.41 Gb Free Space | 39.93% Space Free | Partition Type: NTFS
Drive G: | 21.97 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: SN049684320704 | User Name: Angel Fire | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
http [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
https [open] – "C:\Program Files\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] – "C:\Program Files\Winamp\Winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] – "C:\Program Files\Winamp\Winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] – "C:\Program Files\Winamp\Winamp.exe" "%1" (Nullsoft)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 1
"FirewallDisableNotify" = 1
"UpdatesDisableNotify" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 4
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"80:TCP" = 80:TCP:*:Enabled:Promo
"53:UDP" = 53:UDP:*:Enabled:Promo
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%ProgramFiles%\AOL 9.0\aol.exe" = %ProgramFiles%\AOL 9.0\aol.exe:*:Enabled:AOL – (America Online, Inc.)
"%ProgramFiles%\UBISOFT\Splinter Cell Pandora Tomorrow\pandora.exe" = %ProgramFiles%\UBISOFT\Splinter Cell Pandora Tomorrow\pandora.exe:*:Enabled:PANDORA
"C:\Program Files\Yahoo!\Messenger\YPager.exe" = C:\Program Files\Yahoo!\Messenger\YPager.exe:*:Enabled:Yahoo! Messenger
"C:\Program Files\Yahoo!\Messenger\YServer.exe" = C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server
"C:\Program Files\Grisoft\AVG Free\avginet.exe" = C:\Program Files\Grisoft\AVG Free\avginet.exe:*:Enabled:avginet.exe
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger
"C:\Program Files\Grisoft\AVG Free\avgamsvr.exe" = C:\Program Files\Grisoft\AVG Free\avgamsvr.exe:*:Enabled:avgamsvr.exe
"C:\Program Files\Grisoft\AVG Free\avgcc.exe" = C:\Program Files\Grisoft\AVG Free\avgcc.exe:*:Enabled:avgcc.exe
"C:\Program Files\EA GAMES\Medal of Honor Pacific Assault™\mohpa.exe" = C:\Program Files\EA GAMES\Medal of Honor Pacific Assault™\mohpa.exe:*:Disabled:Medal of Honor Pacific Assault™
"C:\Program Files\UBISOFT\Splinter Cell Pandora Tomorrow\logo_ubi.exe" = C:\Program Files\UBISOFT\Splinter Cell Pandora Tomorrow\logo_ubi.exe:*:Disabled:SPLINTER CELL PANDORA
"D:\Program Files\WarRock\WRLauncher.exe" = D:\Program Files\WarRock\WRLauncher.exe:*:Disabled:War Rock
"C:\Program Files\LimeWire\LimeWire.exe" = C:\Program Files\LimeWire\LimeWire.exe:*:Enabled:LimeWire – (Lime Wire, LLC)
"D:\Program Files\EA Games\Battlefield Vietnam\BfVietnam.exe" = D:\Program Files\EA Games\Battlefield Vietnam\BfVietnam.exe:*:Enabled:BfVietnam – ()
"D:\Program Files\Xfire\xfire.exe" = D:\Program Files\Xfire\xfire.exe:*:Enabled:Xfire – (Xfire Inc.)
"D:\Documents and Settings\Angel Fire\Desktop\utorrent.exe" = D:\Documents and Settings\Angel Fire\Desktop\utorrent.exe:*:Enabled:utorrent
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer – (RealNetworks, Inc.)
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\WINDOWS\explorer.exe" = C:\WINDOWS\explorer.exe:*:Enabled:Explorer – (Microsoft Corporation)
"C:\APPS\ABOARD\AOSD.EXE" = C:\APPS\ABOARD\AOSD.EXE:*:Enabled:AOSD – (NEC Computers International)
"C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe" = C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe:*:Enabled:jucheck – (Sun Microsystems, Inc.)
"C:\Program Files\MyWebSearch\bar\7.bin\MWSOEMON.EXE" = C:\Program Files\MyWebSearch\bar\7.bin\MWSOEMON.EXE:*:Enabled:mwsoemon
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\WINDOWS\Temp\_ex-08.exe" = C:\WINDOWS\Temp\_ex-08.exe:*:Enabled:Promo
"C:\Program Files\AVG\AVG10\avgnsx.exe" = C:\Program Files\AVG\AVG10\avgnsx.exe:*:Enabled:Online Shield – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgmfapx.exe" = C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:AVG Installer – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG10\avgemcx.exe" = C:\Program Files\AVG\AVG10\avgemcx.exe:*:Enabled:Personal E-mail Scanner – (AVG Technologies CZ, s.r.o.)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00000409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Premium
"{06F80017-8F98-4C94-B868-52358569FC32}" = Command & Conquer Generals
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{14CAA732-DB11-478A-B297-E19F2EF49C90}" = Canon iP6210D Memory Card Utility
"{1885AEC2-586A-11D6-B782-00A0CC7B9044}" = Just Flight Dam Busters v1.01
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1AC91509-E17B-46F7-A032-B54DCCA6E8BB}" = Microsoft Flight Simulator X Photo Scenery Display Update
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216021FF}" = Java™ 6 Update 24
"{27F650A9-6FAB-41C8-8621-92FF0118B0C4}" = EPSON Easy Photo Print
"{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}" = EPSON Scan Assistant
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{3248F0A8-6813-11D6-A77B-00B0D0150040}" = J2SE Runtime Environment 5.0 Update 4
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{34E39692-513F-46A3-B4C3-5DCD64B06E9E}" = Boeing 247 and 247D for FSX or FS2004
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}" = Microsoft Works
"{4310B3A0-2EB3-11D6-B782-00A0CC7B9044}" = Mosquito Squadron - CFS2
"{43DCF766-6838-4F9A-8C91-D92DA586DFA8}" = Microsoft Windows Journal Viewer
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4BDFD2CE-6329-42E4-9801-9B3D1F10D79B}" = Adobe® Photoshop® Album Starter Edition 3.0
"{4F587324-FDB9-4972-8E63-F02612F0AF6F}" = Harrier - Jump Jet CFS2
"{5D601655-6D54-4384-B52C-17EC5385FBBD}" = iTunes
"{6164D2E7-986B-42F5-B3A6-64D5E53FB889}" = Delta Force Black Hawk Down Team Sabre
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6815FCDD-401D-481E-BA88-31B4754C2B46}" = Macromedia Flash Player 8
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX
"{7D1D6A24-65D4-454C-8815-4F08A5FFF12C}" = Macromedia Shockwave Player
"{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}" = EPSON Web-To-Page
"{8355F970-601D-442D-A79B-1D7DB4F24CAD}" = Apple Mobile Device Support
"{83d96ed0-98aa-4515-8ddc-816f3efdd104}" = MyDsc2
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{8CB79677-9ACF-44C2-9BE3-AC1C726EAA60}" = Just Flight VFR Real Scenery Demo
"{8FE54D21-8254-4CCF-AEE0-066496AE43F4}" = Delta Force - Black Hawk Down
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{907B4640-266B-4A21-92FB-CD1A86CD0F63}" = RollerCoaster Tycoon® 3
"{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9527A496-5DF9-412A-ADC7-168BA5379CA6}" = Microsoft Flight Simulator X
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A276502A-8979-44FB-8090-90CF72F22ABC}" = AVG 2011
"{A3FEC306-FBFF-4B0D-95B9-F9C67C65079E}" = Brother MFL-Pro Suite
"{A899DA1F-D626-401C-8651-F2921E3B4CB3}" = 3Connect
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{AE6C571F-14D3-4A0B-B234-134CB1F9E4F5}" = CFS2 BoB v1.00
"{B508B3F1-A24A-32C0-B310-85786919EF28}" = Microsoft .NET Framework 2.0 Service Pack 1
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Web Player
"{B9242864-2841-4ADE-86E0-8F90F91B04DD}" = Logitech Gaming Software
"{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE29EBEB-36CE-44C5-8AC6-53E65FB16C8C}" = Vietnam Med Evac
"{D07643A3-CE41-4286-8C78-EB9C83E76DDB}" = PunkBuster for Battlefield Vietnam
"{D29092CC-0AD2-7B53-A090-4CC3D33A1033}" = Nero 7 Demo
"{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}" = Nikon Message Center
"{D41FAAA9-8048-4906-86B2-9AADEA1FA0B7}" = Alcatel SpeedTouch USB Software
"{D45E8C45-B601-4A80-AFD8-E16338744DE1}" = ArcSoft Panorama Maker 4
"{E35B3C63-E958-4E31-A178-95D22024109A}" = Battlefield Vietnam™
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E86BC406-944E-41F6-ADE6-2C136734C96B}" = EPSON File Manager
"{E9757890-7EC5-46C8-99AB-B00F07B6525C}" = Nikon Transfer
"{EADAA6F7-991F-4CE9-B5CE-FCF3D81F7C7D}" = USB PC Camera (SN9C103)
"{EFB21DE7-8C19-4A88-BB28-A766E16493BC}" = Adobe Photoshop CS
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F4C68898-EBA5-46A9-82B3-2D30426086BF}" = AVG 2011
"{FF0B0792-F6E7-4627-B820-EA50617E223B}" = QuarkXPress 6.5
"A-10A Thunderbolt II Weapons Expansion Pack" = A-10A Thunderbolt II Weapons Expansion Pack
"AceGain_LiveUpdate" = AceGain LiveUpdate 1.0
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Age of Empires 2.0" = Microsoft Age of Empires II
"Airbus A330-300RR V2.1" = Airbus A330-300RR V2.1
"AVG" = AVG 2011
"Boeing 737-600 v1.0" = Boeing 737-600 v1.0
"BTBusinessHub" = BTBusinessHub
"CANONBJ_Deinstall_CNMCP7B.DLL" = Canon iP6210D
"CDisplayEx_is1" = CDisplayEx 1.4
"Combat Flight Simulator 2.0" = Microsoft Combat Flight Simulator 2
"D-Day" = D-Day
"Easy-PhotoPrint" = Canon Utilities Easy-PhotoPrint
"Easy-PrintToolBox" = Canon Utilities Easy-PrintToolBox
"Easy-WebPrint" = Easy-WebPrint
"eMusic Promotion" = eMusic - 50 Free MP3 offer
"EPSON Printer and Utilities" = EPSON Printer Software
"ESPR240 User's Guide" = ESPR240 User's Guide
"Euro Truck Simulator" = Euro Truck Simulator 1.00
"F/A-18" = Jane's Combat Simulations F/A-18
"FDG P-61 Series" = FDG P-61 Series
"FDG P-61 series Gauge Installer" = FDG P-61 series Gauge Installer
"FDG US Weapons Addon v1.2" = FDG US Weapons Addon v1.2
"Fireeagle present the Truck Renault with Carobull-Trailer for FSX" = Fireeagle present the Truck Renault with Carobull-Trailer for FSX
"FS2000Patch" = Microsoft Flight Simulator 2000 Patch
"GameSpy Arcade" = GameSpy Arcade
"HaaliMkx" = Haali Media Splitter
"HijackThis" = HijackThis 2.0.2
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{06F80017-8F98-4C94-B868-52358569FC32}" = Command & Conquer Generals
"InstallShield_{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email
"InstallShield_{9527A496-5DF9-412A-ADC7-168BA5379CA6}" = Microsoft Flight Simulator X
"LastFM_is1" = Last.fm 1.5.4.27091
"LimeWire" = LimeWire 4.18.8
"LiveUpdate" = LiveUpdate 3.0 (Symantec Corporation)
"Macromedia Shockwave Player" = Macromedia Shockwave Player
"Matroska Pack" = Matroska Pack
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Mozilla Firefox (3.6.13)" = Mozilla Firefox (3.6.13)
"Mozilla Thunderbird (1.5)" = Mozilla Thunderbird (1.5)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MsgPlus! Plugin" = Messenger Plus! 3
"MSNINST" = MSN
"MyWebSearch bar Uninstall" = My Web Search (Zwinky)
"Netscape Browser" = Netscape Browser (remove only)
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"PhotoShow Express" = PhotoShow Express
"Piper Tomahawk CC-PAL" = Piper Tomahawk CC-PAL
"Poland 39 Campaign" = Poland 39 Campaign
"RAAF Expansion for CFS2" = RAAF Expansion for CFS2
"RCS CFS2 B-25J Mitchell MkIII v1.0" = RCS CFS2 B-25J Mitchell MkIII v1.0
"RealPlayer 6.0" = RealPlayer
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"Squeez 5" = Squeez 5
"TGW" = TGW
"TGW 0.15" = TGW 0.15
"Turbo Pizza" = Turbo Pizza
"Webinblue A-10A Thunderbolt II for CFS2" = Webinblue A-10A Thunderbolt II for CFS2
"Whirlwind of Vietnam: UH-1_is1" = Whirlwind of Vietnam: UH-1
"Winamp" = Winamp (remove only)
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"WOLAPI" = Westwood Shared Internet Components
"Worms Armageddon" = Worms Armageddon
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xfire" = Xfire (remove only)
"Yahoo! Customizations" = Yahoo! Browser Services
"Yahoo! Internet Mail" = Yahoo! Internet Mail
"YInstHelper" = Yahoo! Install Manager
"ZENcast Organizer" = ZENcast Organizer
"Zoo Tycoon 1.0" = Zoo Tycoon - Dinosaur Digs
"ZTE_MF627_LEGACY_DRIVER_1.2059.0.4" = ZTE_MF627_USB_MODEM_1.2059.0.4
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Shoddy Battle" = Shoddy Battle
"uTorrent" = µTorrent
"VideoEgg" = VideoEgg Publisher
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 10/02/2011 17:08:38 | Computer Name = SN049684320704 | Source = Application Error | ID = 1000
Description = Faulting application wmplayer.exe, version 11.0.5721.5145, faulting
module quicktimeaudiosupport.qtx, version 7.6.6.0, fault address 0x001a2072.
Error - 13/02/2011 16:49:21 | Computer Name = SN049684320704 | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.2.3989, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 17/02/2011 05:37:07 | Computer Name = SN049684320704 | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: An internal certificate chaining error has occurred.
Error - 17/02/2011 05:44:36 | Computer Name = SN049684320704 | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.2.3989, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 17/02/2011 05:45:37 | Computer Name = SN049684320704 | Source = Application Error | ID = 1000
Description = Faulting application plugin-container.exe, version 1.9.2.3989, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x0000100b.
Error - 17/02/2011 07:21:12 | Computer Name = SN049684320704 | Source = Application Error | ID = 1000
Description = Faulting application plugin-container.exe, version 1.9.2.3989, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x0000100b.
Error - 21/02/2011 13:08:45 | Computer Name = SN049684320704 | Source = Application Hang | ID = 1002
Description = Hanging application firefox.exe, version 1.9.2.3989, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 21/02/2011 13:09:17 | Computer Name = SN049684320704 | Source = Application Error | ID = 1000
Description = Faulting application plugin-container.exe, version 1.9.2.3989, faulting
module ntdll.dll, version 5.1.2600.5755, fault address 0x0000100b.
Error - 23/02/2011 05:09:25 | Computer Name = SN049684320704 | Source = COM+ | ID = 135761
Description = The run-time environment has detected an inconsistency in its internal
state. This indicates a potential instability in the process that could be caused
by the custom components running in the COM+ application, the components they make
use of, or other factors. Error in f:\xpsp3\com\com1x\src\comsvcs\package\cpackage.cpp(1184),
hr = 8007041d: InitEventCollector fail
Error - 24/02/2011 05:37:44 | Computer Name = SN049684320704 | Source = crypt32 | ID = 131083
Description = Failed extract of third-party root list from auto update cab at: <
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: An internal certificate chaining error has occurred.
[ System Events ]
Error - 27/01/2011 06:35:29 | Computer Name = SN049684320704 | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the stisvc service.
Error - 17/02/2011 05:41:11 | Computer Name = SN049684320704 | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the stisvc service.
Error - 17/02/2011 19:35:40 | Computer Name = SN049684320704 | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the ALG service.
Error - 17/02/2011 19:35:41 | Computer Name = SN049684320704 | Source = Service Control Manager | ID = 7000
Description = The Application Layer Gateway Service service failed to start due
to the following error: %%1053
Error - 23/02/2011 05:09:25 | Computer Name = SN049684320704 | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the COM+ System Application
service to connect.
Error - 23/02/2011 05:09:25 | Computer Name = SN049684320704 | Source = DCOM | ID = 10005
Description = DCOM got error "%1053" attempting to start the service COMSysApp with
arguments "" in order to run the server: {ECABAFBC-7F19-11D2-978E-0000F8757E2A}
Error - 23/02/2011 05:09:25 | Computer Name = SN049684320704 | Source = Service Control Manager | ID = 7000
Description = The COM+ System Application service failed to start due to the following
error: %%1053
Error - 23/02/2011 05:09:29 | Computer Name = SN049684320704 | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
the NVSvc service.
Error - 25/02/2011 11:17:34 | Computer Name = SN049684320704 | Source = SRService | ID = 104
Description = The System Restore initialization process failed.
Error - 25/02/2011 11:17:35 | Computer Name = SN049684320704 | Source = Service Control Manager | ID = 7023
Description = The System Restore Service service terminated with the following error:
%%2
< End of report >