hi ty here's a log……….
OTL logfile created on: 04/04/2011 10:07:43 - Run 2
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Administrator
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 57.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 81.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 465.76 Gb Total Space | 230.46 Gb Free Space | 49.48% Space Free | Partition Type: NTFS
Drive E: | 581.18 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: ANDREW-PC | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Administrator\OTL.exe (OldTimer Tools)
PRC - C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe (Eastman Kodak Company)
PRC - C:\Windows\System32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe (Check Point Software Technologies)
PRC - C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe (Creative Technology Ltd)
========== Modules (SafeList) ==========
MOD - C:\Users\Administrator\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll (Check Point Software Technologies)
MOD - C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d08d7da0442a985
d\msvcr80.dll (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d08d7da0442a985
d\msvcp80.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (vsmon) – C:\Windows\System32\ZoneLabs\vsmon.exe (Check Point Software Technologies LTD)
SRV - (IswSvc) – C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe (Check Point Software Technologies)
SRV - (Creative ALchemy AL6 Licensing Service) – C:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe (Creative Labs)
SRV - (Creative Media Toolbox 6 Licensing Service) – C:\Program Files\Common Files\Creative Labs Shared\Service\MT6Licensing.exe (Creative Labs)
SRV - (Creative Audio Engine Licensing Service) – C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (getPlusHelper) getPlus® – C:\Program Files\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (CTAudSvcService) – C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (ISWKL) – C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys (Check Point Software Technologies)
DRV - (Vsdatant) – C:\Windows\System32\drivers\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (t3) – C:\Windows\System32\drivers\t3.sys (Creative Technology Ltd.)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (nvstor32) – C:\Windows\system32\DRIVERS\nvstor32.sys (NVIDIA Corporation)
DRV - (MRV6X32P) – C:\Windows\System32\drivers\MRVW13B.sys (Marvell Semiconductor, Inc)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://uk.msn.com/
IE - HKLM\..\URLSearchHook: {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files\ZoneAlarm\tbZone.dll (Conduit Ltd.)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://uk.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
http://www.bing.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.co.uk/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files\ZoneAlarm\tbZone.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Yahoo!"
FF - prefs.js..extensions.enabledItems: {FFB96CC1-7EB3-449D-B827-DB661701C6BB}:[removed]
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:10.0.0.1178
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.type: 0
FF - HKLM\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker [2011/02/07 14:47:43 | 000,000,000 | -H-D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.14\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/02 23:00:33 | 000,000,000 | -H-D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.14\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/22 09:41:15 | 000,000,000 | -H-D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.7\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011/01/31 23:20:12 | 000,000,000 | -H-D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.1.7\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
[2011/01/31 23:20:13 | 000,000,000 | -H-D | M] (No name found) – C:\Users\Administrator\AppData\Roaming\Mozilla\Extensions
[2011/01/31 23:20:13 | 000,000,000 | -H-D | M] (No name found) – C:\Users\Administrator\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2011/03/27 13:53:13 | 000,000,000 | -H-D | M] (No name found) – C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\bhwd8ppd.default\extensions
[2011/02/06 09:59:22 | 000,000,000 | -H-D | M] (Microsoft .NET Framework Assistant) – C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\bhwd8ppd.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/01/31 23:08:32 | 000,000,000 | -H-D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) – C:\PROGRAM FILES\AVG\AVG10\FIREFOX
[2011/02/07 14:47:43 | 000,000,000 | -H-D | M] (ZoneAlarm Security Engine) – C:\PROGRAM FILES\CHECKPOINT\ZAFORCEFIELD\TRUSTCHECKER
[2010/12/03 18:47:02 | 000,001,538 | -H– | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/12/03 18:47:02 | 000,000,947 | -H– | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/12/03 18:47:02 | 000,000,769 | -H– | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2009/04/07 14:59:38 | 000,000,872 | -H– | M] () – C:\Program Files\Mozilla Firefox\searchplugins\Yahooober4735472.gif
[2011/02/16 19:31:31 | 000,000,199 | -H– | M] () – C:\Program Files\Mozilla Firefox\searchplugins\Yahooober4735472.src
O1 HOSTS File: ([2006/09/18 22:41:30 | 000,000,761 | -H– | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (ZoneAlarm Toolbar) - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files\ZoneAlarm\tbZone.dll (Conduit Ltd.)
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (ZoneAlarm Toolbar) - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - C:\Program Files\ZoneAlarm\tbZone.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Toolbar) - {66F2E20D-0DA8-4C11-A9C8-DD8477B88ACD} - C:\Program Files\ZoneAlarm\tbZone.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O4 - HKLM..\Run: [EKIJ5000StatusMonitor] C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe (Eastman Kodak Company)
O4 - HKLM..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
O4 - HKLM..\Run: [SPIRunE] C:\Windows\System32\SpiRunE.dll (Creative Technology Ltd.)
O4 - HKLM..\Run: [VolPanel] C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884}
http://ccfiles.creative.com/Web/softwareup…101/CTSUEng.cab (Creative Software AutoUpdate)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
https://fpdownload.macromedia.com/get/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147}
http://gfx2.hotmail.com/mail/w4/pr01/photo…NPUplden-gb.cab (Windows Live Hotmail Photo Upload Tool)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29}
http://ccfiles.creative.com/Web/softwareup…15112/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 22:43:36 | 000,000,024 | -H– | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2009/06/14 11:44:42 | 000,000,085 | R— | M] () - E:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{2d4de547-4e2a-11df-8e5e-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{2d4de547-4e2a-11df-8e5e-806e6f6e6963}\Shell\AutoRun\command - "" = E:\MATHSWATCH_Foundation_GCSE.exe – [2009/06/14 11:44:42 | 000,411,232 | R— | M] (TechSmith Corporation)
O33 - MountPoints2\{5425c359-4e37-11df-9bf2-0019dbf2f8a3}\Shell - "" = AutoRun
O33 - MountPoints2\{5425c359-4e37-11df-9bf2-0019dbf2f8a3}\Shell\AutoRun\command - "" = J:\LaunchU3.exe -a
O33 - MountPoints2\K\Shell - "" = AutoRun
O33 - MountPoints2\K\Shell\AutoRun\command - "" = K:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.IV41 - C:\Windows\System32\ir41_32.ax (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/04/04 10:05:23 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Users\Administrator\OTL.exe
[2011/04/04 10:03:10 | 000,000,000 | —D | C] – C:\Users\Administrator\AppData\Local\{A34D152F-16D7-436E-B4E7-0CE11E0F1EBF}
[2011/04/04 10:02:52 | 000,000,000 | —D | C] – C:\Windows\LastGood
[2011/04/03 23:21:57 | 000,000,000 | —D | C] – C:\Users\Administrator\tdsskiller
[2011/04/03 18:31:13 | 000,000,000 | R–D | C] – C:\32788R22FWJFW
[2011/04/03 15:35:56 | 001,090,912 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\Users\Administrator\avg_remover_stf_x86_2011_1184.exe
[2011/04/03 09:41:06 | 000,000,000 | —D | C] – C:\Users\Administrator\AppData\Local\{78EB8057-2B37-4E81-A487-74F19944D270}
[2011/04/02 09:39:20 | 000,000,000 | -H-D | C] – C:\Users\Administrator\RK_Quarantine
[2011/04/02 09:29:26 | 000,000,000 | -H-D | C] – C:\Users\Administrator\AppData\Local\{805C14E6-AA7B-4D3C-BE40-6F40DCA36B11}
[2011/04/01 11:06:06 | 000,000,000 | -H-D | C] – C:\Users\Administrator\AppData\Local\{7A0F5FB6-8BEC-4F9F-944D-DEB0FD832895}
[2011/04/01 10:57:39 | 000,000,000 | -H-D | C] – C:\Users\Administrator\AppData\Local\{73813386-9006-4EB5-BD8C-A921C07E10B6}
[2011/03/31 22:23:19 | 007,734,208 | —- | C] (Malwarebytes Corporation ) – C:\Users\Administrator\mbam-setup-1.50.1.1100.exe
[2011/03/31 22:15:03 | 000,000,000 | -H-D | C] – C:\Users\Administrator\AppData\Local\{9A1CCCB4-25D3-4CAF-8C6F-30CAB69455C7}
[2011/03/31 00:41:03 | 000,000,000 | -H-D | C] – C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Repair
[2011/03/31 00:31:48 | 000,546,304 | -H– | C] (TFTC) – C:\ProgramData\LGxJuggkBGegHQ.exe
[2011/03/30 21:21:03 | 000,000,000 | -H-D | C] – C:\Program Files\Trend Micro
[2011/03/30 21:21:03 | 000,000,000 | -H-D | C] – C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/03/23 14:51:05 | 001,068,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\DWrite.dll
[2011/03/23 14:51:05 | 000,288,768 | —- | C] (Microsoft Corporation) – C:\Windows\System32\XpsGdiConverter.dll
[2011/03/09 10:03:35 | 000,429,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2011/03/09 10:03:35 | 000,322,560 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbe.dll
[2011/03/09 10:03:35 | 000,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpg2splt.ax
[2011/03/09 10:03:35 | 000,153,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbeio.dll
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/04/04 10:05:25 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Administrator\OTL.exe
[2011/04/04 10:02:54 | 000,037,685 | —- | M] () – C:\ProgramData\nvModes.001
[2011/04/04 10:02:36 | 000,000,896 | -H– | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/04/04 10:02:32 | 000,004,192 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/04/04 10:02:32 | 000,004,192 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/04/04 10:02:29 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/04/04 10:02:27 | 3218,493,440 | -HS- | M] () – C:\hiberfil.sys
[2011/04/03 23:49:00 | 000,000,900 | -H– | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/04/03 23:20:11 | 001,263,721 | —- | M] () – C:\Users\Administrator\tdsskiller.zip
[2011/04/03 23:19:00 | 000,000,938 | -H– | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3164612162-256102785-1375235700-500UA.job
[2011/04/03 16:03:40 | 004,310,402 | —- | M] () – C:\Users\Administrator\mytool.exe
[2011/04/03 15:51:19 | 000,037,685 | —- | M] () – C:\ProgramData\nvModes.dat
[2011/04/03 15:35:57 | 001,090,912 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Users\Administrator\avg_remover_stf_x86_2011_1184.exe
[2011/04/03 09:48:57 | 000,879,081 | —- | M] () – C:\Users\Administrator\SecurityCheck.exe
[2011/04/02 17:19:33 | 000,000,886 | -H– | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3164612162-256102785-1375235700-500Core.job
[2011/04/02 17:15:12 | 007,734,208 | —- | M] (Malwarebytes Corporation ) – C:\Users\Administrator\mbam-setup-1.50.1.1100.exe
[2011/04/02 17:14:02 | 001,058,816 | —- | M] () – C:\Users\Administrator\RogueKiller.exe
[2011/04/01 18:26:55 | 341,400,810 | -H– | M] () – C:\Windows\MEMORY.DMP
[2011/03/31 22:21:55 | 001,006,778 | -H– | M] () – C:\Users\Administrator\rkill.com
[2011/03/31 22:20:16 | 001,006,778 | -H– | M] () – C:\Users\Administrator\rkill.exe
[2011/03/31 13:05:54 | 000,000,579 | -H– | M] () – C:\Users\Administrator\Desktop\Windows Repair.lnk
[2011/03/31 13:05:50 | 000,000,328 | -H– | M] () – C:\ProgramData\45473544
[2011/03/31 13:05:47 | 000,467,968 | -H– | M] () – C:\ProgramData\45473544.exe
[2011/03/31 12:41:54 | 000,000,328 | -H– | M] () – C:\ProgramData\46522120
[2011/03/31 12:13:06 | 000,000,344 | -H– | M] () – C:\ProgramData\45670152
[2011/03/31 08:36:25 | 000,000,336 | -H– | M] () – C:\ProgramData\43835144
[2011/03/31 07:00:17 | 000,070,656 | -H– | M] () – C:\Users\Administrator\English c-w essay 2011 childhood
[2011/03/31 06:59:55 | 000,611,664 | -H– | M] () – C:\Windows\System32\perfh009.dat
[2011/03/31 06:59:55 | 000,109,112 | -H– | M] () – C:\Windows\System32\perfc009.dat
[2011/03/31 00:40:58 | 000,000,336 | -H– | M] () – C:\ProgramData\48619272
[2011/03/31 00:31:46 | 000,546,304 | -H– | M] (TFTC) – C:\ProgramData\LGxJuggkBGegHQ.exe
[2011/03/30 21:22:05 | 000,002,539 | -H– | M] () – C:\Users\Administrator\Desktop\HiJackThis.lnk
[2011/03/29 07:04:24 | 000,002,281 | -H– | M] () – C:\Users\Public\Desktop\Safari.lnk
[2011/03/28 16:55:39 | 000,002,231 | -H– | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/03/26 01:20:13 | 000,002,082 | -H– | M] () – C:\Users\Administrator\Desktop\Google Chrome.lnk
[2011/03/26 01:20:13 | 000,002,044 | -H– | M] () – C:\Users\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/03/22 09:41:17 | 000,001,887 | -H– | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/04/03 23:20:09 | 001,263,721 | —- | C] () – C:\Users\Administrator\tdsskiller.zip
[2011/04/03 15:58:43 | 004,310,402 | —- | C] () – C:\Users\Administrator\mytool.exe
[2011/04/03 15:30:04 | 000,037,685 | —- | C] () – C:\ProgramData\nvModes.dat
[2011/04/03 15:30:04 | 000,037,685 | —- | C] () – C:\ProgramData\nvModes.001
[2011/04/02 09:38:31 | 001,058,816 | —- | C] () – C:\Users\Administrator\RogueKiller.exe
[2011/04/01 21:21:15 | 3218,493,440 | -HS- | C] () – C:\hiberfil.sys
[2011/03/31 22:21:53 | 001,006,778 | -H– | C] () – C:\Users\Administrator\rkill.com
[2011/03/31 22:17:18 | 001,006,778 | -H– | C] () – C:\Users\Administrator\rkill.exe
[2011/03/31 13:05:54 | 000,000,579 | -H– | C] () – C:\Users\Administrator\Desktop\Windows Repair.lnk
[2011/03/31 13:05:50 | 000,000,328 | -H– | C] () – C:\ProgramData\45473544
[2011/03/31 13:05:47 | 000,467,968 | -H– | C] () – C:\ProgramData\45473544.exe
[2011/03/31 12:41:54 | 000,000,328 | -H– | C] () – C:\ProgramData\46522120
[2011/03/31 12:26:10 | 000,879,081 | —- | C] () – C:\Users\Administrator\SecurityCheck.exe
[2011/03/31 12:13:06 | 000,000,344 | -H– | C] () – C:\ProgramData\45670152
[2011/03/31 08:36:25 | 000,000,336 | -H– | C] () – C:\ProgramData\43835144
[2011/03/31 07:00:47 | 000,070,656 | -H– | C] () – C:\Users\Administrator\English c-w essay 2011 childhood
[2011/03/31 00:40:58 | 000,000,336 | -H– | C] () – C:\ProgramData\48619272
[2011/03/30 21:21:03 | 000,002,539 | -H– | C] () – C:\Users\Administrator\Desktop\HiJackThis.lnk
[2011/01/31 23:08:54 | 000,000,000 | -H– | C] () – C:\Windows\nsreg.dat
[2010/12/21 13:40:50 | 000,000,527 | -H– | C] () – C:\Windows\eReg.dat
[2010/07/25 18:40:19 | 000,003,584 | -H– | C] () – C:\Users\Administrator\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/14 10:48:32 | 000,000,210 | -H– | C] () – C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2010/07/10 11:46:25 | 000,134,044 | -H– | C] () – C:\Windows\System32\mlfcache.dat
[2010/05/04 16:00:13 | 000,004,626 | -H– | C] () – C:\Windows\System32\AudioDrv.ini
[2010/05/04 16:00:01 | 000,000,049 | RH– | C] () – C:\Windows\System32\ctzapxx.ini
[2010/05/03 17:01:54 | 000,073,728 | -H– | C] () – C:\Windows\System32\CmdRtr.DLL
[2010/05/03 17:01:53 | 000,148,480 | -H– | C] () – C:\Windows\System32\APOMngr.DLL
[2010/05/03 17:00:04 | 000,004,984 | -H– | C] () – C:\Windows\System32\drivers\nvphy.bin
[2010/04/26 11:49:48 | 000,107,612 | —- | C] () – C:\Windows\System32\StructuredQuerySchema.bin
[2010/04/26 11:49:47 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2010/04/24 16:49:11 | 000,000,376 | -H– | C] () – C:\Windows\ODBC.INI
[2010/04/24 08:38:08 | 000,018,904 | —- | C] () – C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2010/04/22 17:23:00 | 000,000,680 | -H– | C] () – C:\Users\Administrator\AppData\Local\d3d9caps.dat
[2009/08/26 05:29:28 | 000,150,016 | -H– | C] () – C:\Windows\System32\OemSpiE.dll
[2009/08/03 15:07:42 | 000,403,816 | -H– | C] () – C:\Windows\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | -H– | C] () – C:\Windows\System32\OGAEXEC.exe
[2009/07/15 08:22:48 | 000,032,914 | -H– | C] () – C:\Windows\System32\t3.ini
[2009/01/14 02:47:24 | 000,001,436 | -H– | C] () – C:\Windows\CfgHPSp.ini
[2009/01/14 02:47:24 | 000,001,434 | -H– | C] () – C:\Windows\Cfg05Sp.ini
[2009/01/14 02:47:24 | 000,001,434 | -H– | C] () – C:\Windows\Cfg04Sp.ini
[2009/01/14 02:47:24 | 000,001,091 | -H– | C] () – C:\Windows\Cfg03Sp.ini
[2009/01/14 02:47:24 | 000,001,091 | -H– | C] () – C:\Windows\Cfg02Sp.ini
[2009/01/14 02:47:24 | 000,001,000 | -H– | C] () – C:\Windows\Cfg01Sp.ini
[2009/01/14 02:47:24 | 000,000,932 | -H– | C] () – C:\Windows\CfgHPHp.ini
[2009/01/14 02:47:24 | 000,000,932 | -H– | C] () – C:\Windows\CfgHPDO.ini
[2009/01/14 02:47:24 | 000,000,932 | -H– | C] () – C:\Windows\Cfg05DO.ini
[2009/01/14 02:47:24 | 000,000,932 | -H– | C] () – C:\Windows\Cfg04DO.ini
[2009/01/14 02:47:24 | 000,000,930 | -H– | C] () – C:\Windows\Cfg05Hp.ini
[2009/01/14 02:47:24 | 000,000,930 | -H– | C] () – C:\Windows\Cfg04Hp.ini
[2009/01/14 02:47:24 | 000,000,818 | -H– | C] () – C:\Windows\Cfg01APR.ini
[2009/01/14 02:47:24 | 000,000,725 | -H– | C] () – C:\Windows\Cfg03Hp.ini
[2009/01/14 02:47:24 | 000,000,725 | -H– | C] () – C:\Windows\Cfg03DO.ini
[2009/01/14 02:47:24 | 000,000,725 | -H– | C] () – C:\Windows\Cfg02Hp.ini
[2009/01/14 02:47:24 | 000,000,725 | -H– | C] () – C:\Windows\Cfg02DO.ini
[2009/01/14 02:47:24 | 000,000,725 | -H– | C] () – C:\Windows\Cfg01Hp.ini
[2009/01/14 02:47:24 | 000,000,725 | -H– | C] () – C:\Windows\Cfg01DO.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg03RMi.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg03RLI.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg03FMi.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg03DI.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg02RMi.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg02RLI.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg02FMi.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg02DI.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg01Mic.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg01LI.ini
[2009/01/14 02:47:24 | 000,000,453 | RH– | C] () – C:\Windows\Cfg01DI.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\CfgHPRMi.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\CfgHPRLI.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\CfgHPFMi.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\CfgHPDI.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\Cfg05RMi.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\Cfg05RLI.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\Cfg05FMi.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\Cfg05DI.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\Cfg04RMi.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\Cfg04RLI.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\Cfg04FMi.ini
[2009/01/14 02:47:24 | 000,000,453 | -H– | C] () – C:\Windows\Cfg04DI.ini
[2006/11/02 13:57:28 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 13:47:37 | 000,305,584 | -H– | C] () – C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 13:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 11:33:01 | 000,611,664 | -H– | C] () – C:\Windows\System32\perfh009.dat
[2006/11/02 11:33:01 | 000,287,440 | -H– | C] () – C:\Windows\System32\perfi009.dat
[2006/11/02 11:33:01 | 000,109,112 | -H– | C] () – C:\Windows\System32\perfc009.dat
[2006/11/02 11:33:01 | 000,030,674 | -H– | C] () – C:\Windows\System32\perfd009.dat
[2006/11/02 11:23:21 | 000,215,943 | -H– | C] () – C:\Windows\System32\dssec.dat
[2006/11/02 09:58:30 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2006/11/02 09:19:00 | 000,000,741 | -H– | C] () – C:\Windows\System32\NOISE.DAT
[2006/11/02 08:40:29 | 000,013,750 | -H– | C] () – C:\Windows\System32\pacerprf.ini
[2006/11/02 08:25:31 | 000,673,088 | -H– | C] () – C:\Windows\System32\mlang.dat
[2003/01/07 15:05:08 | 000,002,695 | -H– | C] () – C:\Windows\System32\OUTLPERF.INI
[1997/06/14 01:56:08 | 000,056,832 | -H– | C] () – C:\Windows\System32\iyvu9_32.dll
========== LOP Check ==========
[2011/02/16 19:31:51 | 000,000,000 | -H-D | M] – C:\Users\Administrator\AppData\Roaming\Artifex Mundi
[2010/10/15 10:34:33 | 000,000,000 | -H-D | M] – C:\Users\Administrator\AppData\Roaming\AVG10
[2010/04/22 17:39:24 | 000,000,000 | —D | M] – C:\Users\Administrator\AppData\Roaming\CheckPoint
[2011/02/15 00:15:43 | 000,000,000 | -H-D | M] – C:\Users\Administrator\AppData\Roaming\Flood Light Games
[2010/12/22 00:44:50 | 000,000,000 | -H-D | M] – C:\Users\Administrator\AppData\Roaming\GetRightToGo
[2010/08/01 22:12:38 | 000,000,000 | -H-D | M] – C:\Users\Administrator\AppData\Roaming\iCopyExpert
[2011/01/10 22:55:33 | 000,000,000 | -H-D | M] – C:\Users\Administrator\AppData\Roaming\Oberonv1000
[2010/11/17 21:43:10 | 000,000,000 | -H-D | M] – C:\Users\Administrator\AppData\Roaming\ShinyTales
[2011/01/31 23:20:12 | 000,000,000 | -H-D | M] – C:\Users\Administrator\AppData\Roaming\Thunderbird
[2011/01/27 11:27:41 | 000,000,000 | -H-D | M] – C:\Users\Administrator\AppData\Roaming\Windows Live Writer
[2011/04/03 23:57:24 | 000,032,648 | -H– | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2011/03/30 17:53:25 | 000,124,093 | -H– | M] () – C:\aaw7boot.log
[2006/09/18 22:43:36 | 000,000,024 | -H– | M] () – C:\autoexec.bat
[2009/04/11 07:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2010/04/23 02:13:50 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 22:43:37 | 000,000,010 | -H– | M] () – C:\config.sys
[2010/05/04 16:21:15 | 000,007,236 | -H– | M] () – C:\CTSUFile.txt
[2011/04/04 10:02:27 | 3218,493,440 | -HS- | M] () – C:\hiberfil.sys
[2010/08/13 16:55:16 | 000,000,258 | -H– | M] () – C:\INSTALL.LOG
[2010/05/22 17:23:54 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/05/22 17:23:54 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2011/04/04 10:02:26 | 3534,176,256 | -HS- | M] () – C:\pagefile.sys
[2011/04/01 21:19:33 | 000,011,855 | -H– | M] () – C:\rkill.log
[2011/04/03 23:25:04 | 000,057,446 | —- | M] () – C:\TDSSKiller.2.4.21.0_03.04.2011_23.22.11_log.txt
[1 C:\*.tmp files -> C:\*.tmp -> ]
< %systemroot%\Fonts\*.com >
[2006/11/02 13:37:12 | 000,026,040 | -H– | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 13:37:12 | 000,026,489 | -H– | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 13:37:12 | 000,029,779 | -H– | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2010/06/06 07:33:36 | 000,037,665 | -H– | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 22:37:34 | 000,000,065 | -H– | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2010/09/02 16:17:50 | 000,196,608 | -H– | M] (Eastman Kodak Company) – C:\Windows\System32\spool\prtprocs\w32x86\EKIJ5000PPR.dll
[2006/11/02 13:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\jnwppr.dll
[2007/04/09 13:23:54 | 000,028,552 | -H– | M] (Microsoft Corporation) – C:\Windows\System32\spool\prtprocs\w32x86\mdippr.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010/11/10 02:28:46 | 000,301,936 | -H– | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2008/01/21 03:43:21 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2008/01/21 04:14:18 | 016,846,848 | -H– | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/21 04:14:08 | 000,106,496 | -H– | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/21 04:14:18 | 000,020,480 | -H– | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 11:34:08 | 010,133,504 | -H– | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 11:34:08 | 001,826,816 | -H– | M] () – C:\Windows\System32\config\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/05/03 11:51:07 | 000,000,286 | -HS- | M] () – C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-04-04 09:06:53
========== Alternate Data Streams ==========
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:97F0A1F8
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:77271429
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:868A72DA
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:8C885EDD
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:DD3F5AF4
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:A2947BEA
< End of report >
EXTRAS REPORT
OTL Extras logfile created on: 21/12/2010 20:58:06 - Run 1
OTL by OldTimer - Version 3.2.18.0 Folder = C:\Users\Administrator\Pictures
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18999)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 68.00% Memory free
6.00 Gb Paging File | 5.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 465.76 Gb Total Space | 244.22 Gb Free Space | 52.43% Space Free | Partition Type: NTFS
Drive D: | 574.44 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive E: | 464.26 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: ANDREW-PC | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"VistaSp2" = Reg Error: Unknown registry data type – File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{3955E427-117A-4BE6-AB63-8E4D06F6BFBF}" = lport=2869 | protocol=6 | dir=in | app=system |
"{45E4AA99-64CD-404B-9BE6-8CA3A0D1821D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{810817B0-8C1C-4CE9-845C-A119B17B1F30}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{D0C76E71-DF0B-4FA4-B5EE-52B79F5E9ED0}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{101E6024-0C73-41BD-B1ED-8F861C864BCB}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{11932108-C0A2-4AA3-9AA0-6D4DCBA6C63F}" = protocol=6 | dir=in | app=c:\windows\system32\zonelabs\vsmon.exe |
"{1237E594-8406-4C0C-A795-1AC2398AFB5F}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgnsx.exe |
"{2EEFD7D6-4A2E-4284-A8C4-F9321D6352DC}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgdiagex.exe |
"{54D2EC83-993C-472D-9F78-29C967AF62CC}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgemcx.exe |
"{55F71A2C-E322-45A0-8033-889230AC6203}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgnsx.exe |
"{5B04AF36-920A-4FCA-9282-B20D45A5C92B}" = protocol=6 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
"{65EEDF06-A856-4C09-B195-9F9BA413991A}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgdiagex.exe |
"{6DBDD273-1135-4397-9472-75084E1BEF72}" = dir=in | app=c:\program files\windows live\mesh\moe.exe |
"{705B05E4-2F0A-450F-8517-DD1ACCD61472}" = dir=in | app=c:\program files\windows live\contacts\wlcomm.exe |
"{78C60F0C-556D-4CFE-A35F-F004D3AA6391}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgemcx.exe |
"{83C9E410-81B6-481A-8687-01104ABC698B}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe |
"{92CD49EB-3602-441C-8483-94532E3B5208}" = protocol=17 | dir=in | app=c:\windows\system32\zonelabs\vsmon.exe |
"{9AFFEDD3-7D93-4790-A447-61FAA9AFBBD6}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{BF262C90-DBE3-421B-8840-89F6B4907CF5}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe |
"{C0C87586-D34E-4330-8B48-714BC3E0F72A}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{F0B5F759-9B25-4CE5-9FF0-6C310403AAC7}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{FD567F4C-4AE5-4217-900C-C8FE55AF07A7}" = protocol=17 | dir=in | app=c:\program files\ventrilo\ventrilo.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02E89EFC-7B07-4D5A-AA03-9EC0902914EE}" = VC 9.0 Runtime
"{0323CB96-221A-4042-84A3-93EDE47099FC}" = AVG 2011
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0C9D0200-FA32-44B7-BBB3-7C03F700C4A0}" = Sound Blaster X-Fi
"{17504ED4-DB08-40A8-81C2-27D8C01581DA}" = Windows Live Remote Service Resources
"{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
"{26A24AE4-039D-4CA4-87B4-2F83216017FF}" = Java™ 6 Update 22
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{294BF709-D758-4363-8D75-01479AD20927}" = Windows Live Family Safety
"{2CE5A2E7-3437-4CE7-BCF4-85ED6EEFF9E4}" = iTunes
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{3F50AF3B-8997-4916-0095-99D63DDB785A}" = Harry Potter TM
"{464B3406-A4D0-4914-910F-7CA4380DCC13}" = Windows Live Remote Client Resources
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{4EB34322-B940-46EB-810E-68E71A819269}" = AVG 2011
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{5AD96CF5-2627-4F29-9D2D-72FCD85F6355}" = AVG 2011
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{61AD15B2-50DB-4686-A739-14FE180D4429}" = Windows Live ID Sign-in Assistant
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{704BA20C-E4D5-4265-92B4-9768345AB76B}" = AVG 2011
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-119438363}" = Downtown Secrets
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{91120409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Standard Edition 2003
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-007A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A23061AF-5361-433C-B7F0-CE5F79A22C49}" = AVG 2011
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.1
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{AFAC914D-9E83-4A89-8ABE-427521C82CCF}" = Safari
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B5770FD5-7345-47E0-BEB8-54522270D58F}" = AVG 2011
"{BEEFC4F8-2909-48B3-AFAA-55D3533FDEDD}" = Creative MediaSource 5
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CCA1EEA3-555E-4D05-AC46-4B49C6C5D887}" = Apple Mobile Device Support
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DAEAFD68-BB4A-4507-A241-C8804D2EA66D}" = Apple Application Support
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E7004147-2CCA-431C-AA05-2AB166B9785D}" = QuickTime
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F1A14CB2-A048-45A6-AFDA-3571296E1D76}" = Creative Media Toolbox 6
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F53D678E-238F-4A71-9742-08BB6774E9DC}" = Windows Live Family Safety
"{F8131A35-47FD-27AD-116D-0E79AF5DE5EE}" = Acrobat.com
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF1C31AE-0CDC-40CE-AB85-406F8B70D643}" = Bonjour
"Activision_StarTrekArmadaUninstallKey" = Star Trek: Armada
"Ad-Aware" = Ad-Aware
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adware Professional 5.0_is1" = Adware Professional v5.0
"Age of Empires 2.0" = Microsoft Age of Empires II
"Age of Empires II: The Conquerors Expansion 1.0" = Microsoft Age of Empires II: The Conquerors Expansion
"ALchemy" = Creative ALchemy
"AudioCS" = Creative Audio Control Panel
"AVG" = AVG 2011
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Creative Software AutoUpdate" = Creative Software AutoUpdate
"Creative Sound Blaster Properties" = Creative Sound Blaster Properties
"Diagnostics 4_5" = Creative Diagnostics
"Edraw Mind Map_is1" = Edraw Mind Map V4
"Host OpenAL" = Host OpenAL
"iCopyExpert_is1" = iCopyExpert 3.1.2
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"MSPUB5" = Microsoft Publisher 98
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"Uninstaller_B4736000_Creative Media Toolbox 6" = Creative Media Toolbox 6 (Shared Components)
"WinLiveSuite" = Windows Live Essentials
"ZoneAlarm" = ZoneAlarm
"ZoneAlarm Toolbar" = ZoneAlarm Toolbar
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 21/11/2010 15:06:58 | Computer Name = Andrew-PC | Source = WinMgmt | ID = 10
Description =
Error - 21/11/2010 15:45:25 | Computer Name = Andrew-PC | Source = WinMgmt | ID = 10
Description =
Error - 22/11/2010 04:41:34 | Computer Name = Andrew-PC | Source = WinMgmt | ID = 10
Description =
Error - 22/11/2010 12:38:16 | Computer Name = Andrew-PC | Source = WinMgmt | ID = 10
Description =
Error - 22/11/2010 13:49:13 | Computer Name = Andrew-PC | Source = WinMgmt | ID = 10
Description =
Error - 22/11/2010 15:14:49 | Computer Name = Andrew-PC | Source = EventSystem | ID = 4622
Description =
Error - 22/11/2010 15:14:49 | Computer Name = Andrew-PC | Source = EventSystem | ID = 4622
Description =
Error - 23/11/2010 05:08:12 | Computer Name = Andrew-PC | Source = WinMgmt | ID = 10
Description =
Error - 23/11/2010 10:17:26 | Computer Name = Andrew-PC | Source = WinMgmt | ID = 10
Description =
Error - 23/11/2010 11:04:56 | Computer Name = Andrew-PC | Source = Application Hang | ID = 1002
Description = The program iexplore.exe version 8.0.6001.18975 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 14e8 Start Time: 01cb8b1952997896 Termination Time: 16
[ System Events ]
Error - 19/12/2010 04:22:47 | Computer Name = Andrew-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 6
Description =
Error - 19/12/2010 08:15:27 | Computer Name = Andrew-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 6
Description =
Error - 19/12/2010 08:29:27 | Computer Name = Andrew-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 6
Description =
Error - 19/12/2010 08:29:54 | Computer Name = Andrew-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 12:28:36 on 19/12/2010 was unexpected.
Error - 20/12/2010 05:28:08 | Computer Name = Andrew-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 6
Description =
Error - 20/12/2010 11:38:34 | Computer Name = Andrew-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 6
Description =
Error - 21/12/2010 03:57:14 | Computer Name = Andrew-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 6
Description =
Error - 21/12/2010 03:59:06 | Computer Name = Andrew-PC | Source = Service Control Manager | ID = 7026
Description =
Error - 21/12/2010 06:56:28 | Computer Name = Andrew-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 6
Description =
Error - 21/12/2010 08:31:02 | Computer Name = Andrew-PC | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 6
Description =
< End of report >